Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00406F46 memcpy,memcpy,memcpy,memset,AcquireSRWLockExclusive,AcquireSRWLockExclusive,ReleaseSRWLockExclusive,ReleaseSRWLockExclusive,ReleaseSRWLockExclusive,GlobalMemoryStatusEx,K32GetPerformanceInfo,PdhOpenQueryA,PdhCollectQueryData,NtQuerySystemInformation,memcpy,memcpy,memcpy,memcpy,memcpy,memcpy,memcpy,memcpy,memcpy,GetUserNameW,GetUserNameW,GetNativeSystemInfo,GetCurrentProcessId,memcpy,memset, |
0_2_00406F46 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0047CF27 NtQueryInformationProcess,NtQueryInformationProcess, |
0_2_0047CF27 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0047BFDF NtQueryInformationProcess,NtQueryInformationProcess, |
0_2_0047BFDF |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00471040 |
0_2_00471040 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00441000 |
0_2_00441000 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0040B011 |
0_2_0040B011 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_004320CC |
0_2_004320CC |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0044C090 |
0_2_0044C090 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0041B160 |
0_2_0041B160 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00415130 |
0_2_00415130 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_004711E0 |
0_2_004711E0 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0041E1E8 |
0_2_0041E1E8 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0048327F |
0_2_0048327F |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_004242F5 |
0_2_004242F5 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00417280 |
0_2_00417280 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0046B300 |
0_2_0046B300 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0043132E |
0_2_0043132E |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0041C330 |
0_2_0041C330 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00426473 |
0_2_00426473 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0041141C |
0_2_0041141C |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00416430 |
0_2_00416430 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_004354CA |
0_2_004354CA |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_004084D4 |
0_2_004084D4 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_004084D9 |
0_2_004084D9 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_004084DE |
0_2_004084DE |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0042F4F7 |
0_2_0042F4F7 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_004334BF |
0_2_004334BF |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00408543 |
0_2_00408543 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00408545 |
0_2_00408545 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0040852D |
0_2_0040852D |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0040852F |
0_2_0040852F |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00408531 |
0_2_00408531 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_004735D0 |
0_2_004735D0 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00405648 |
0_2_00405648 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0047A670 |
0_2_0047A670 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00427712 |
0_2_00427712 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00401731 |
0_2_00401731 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0043E7A0 |
0_2_0043E7A0 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_004397A4 |
0_2_004397A4 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00422850 |
0_2_00422850 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0041B810 |
0_2_0041B810 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0043F830 |
0_2_0043F830 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0043383B |
0_2_0043383B |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0043883F |
0_2_0043883F |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0048794D |
0_2_0048794D |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00445932 |
0_2_00445932 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00423938 |
0_2_00423938 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0047CA4A |
0_2_0047CA4A |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0041FA00 |
0_2_0041FA00 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00405A2B |
0_2_00405A2B |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00411ACC |
0_2_00411ACC |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00417AE0 |
0_2_00417AE0 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0042BAEE |
0_2_0042BAEE |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00411A8C |
0_2_00411A8C |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0047BAA8 |
0_2_0047BAA8 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00479B50 |
0_2_00479B50 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00465BD0 |
0_2_00465BD0 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00441BF0 |
0_2_00441BF0 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00437BA5 |
0_2_00437BA5 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00434C66 |
0_2_00434C66 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0047EC69 |
0_2_0047EC69 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00467C10 |
0_2_00467C10 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00479CA0 |
0_2_00479CA0 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00471D50 |
0_2_00471D50 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0047BD62 |
0_2_0047BD62 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00424D7E |
0_2_00424D7E |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0042CD25 |
0_2_0042CD25 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0042CE47 |
0_2_0042CE47 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0043CE50 |
0_2_0043CE50 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00413E20 |
0_2_00413E20 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00402E36 |
0_2_00402E36 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00414EF0 |
0_2_00414EF0 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00406F46 |
0_2_00406F46 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00410F6F |
0_2_00410F6F |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00484F78 |
0_2_00484F78 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0046AFC0 |
0_2_0046AFC0 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_0047BFDF |
0_2_0047BFDF |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00430FB4 |
0_2_00430FB4 |
Source: doc-1.exe |
Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00406F46 memcpy,memcpy,memcpy,memset,AcquireSRWLockExclusive,AcquireSRWLockExclusive,ReleaseSRWLockExclusive,ReleaseSRWLockExclusive,ReleaseSRWLockExclusive,GlobalMemoryStatusEx,K32GetPerformanceInfo,PdhOpenQueryA,PdhCollectQueryData,NtQuerySystemInformation,memcpy,memcpy,memcpy,memcpy,memcpy,memcpy,memcpy,memcpy,memcpy,GetUserNameW,GetUserNameW,GetNativeSystemInfo,GetCurrentProcessId,memcpy,memset, |
0_2_00406F46 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00406F46 memcpy,memcpy,memcpy,memset,AcquireSRWLockExclusive,AcquireSRWLockExclusive,ReleaseSRWLockExclusive,ReleaseSRWLockExclusive,ReleaseSRWLockExclusive,GlobalMemoryStatusEx,K32GetPerformanceInfo,PdhOpenQueryA,PdhCollectQueryData,NtQuerySystemInformation,memcpy,memcpy,memcpy,memcpy,memcpy,memcpy,memcpy,memcpy,memcpy,GetUserNameW,GetUserNameW,GetNativeSystemInfo,GetCurrentProcessId,memcpy,memset, |
0_2_00406F46 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00401180 Sleep,Sleep,SetUnhandledExceptionFilter,malloc,strlen,malloc,memcpy,_cexit,_initterm,GetStartupInfoA,exit, |
0_2_00401180 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_004023D4 RtlAddVectoredExceptionHandler,SetThreadStackGuarantee,GetLastError, |
0_2_004023D4 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_004B8A18 SetUnhandledExceptionFilter, |
0_2_004B8A18 |
Source: C:\Users\user\Desktop\doc-1.exe |
Code function: 0_2_00406F46 memcpy,memcpy,memcpy,memset,AcquireSRWLockExclusive,AcquireSRWLockExclusive,ReleaseSRWLockExclusive,ReleaseSRWLockExclusive,ReleaseSRWLockExclusive,GlobalMemoryStatusEx,K32GetPerformanceInfo,PdhOpenQueryA,PdhCollectQueryData,NtQuerySystemInformation,memcpy,memcpy,memcpy,memcpy,memcpy,memcpy,memcpy,memcpy,memcpy,GetUserNameW,GetUserNameW,GetNativeSystemInfo,GetCurrentProcessId,memcpy,memset, |
0_2_00406F46 |