Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 3_2_00419D50 NtCreateFile, |
3_2_00419D50 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 3_2_00419E00 NtReadFile, |
3_2_00419E00 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 3_2_00419E80 NtClose, |
3_2_00419E80 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 3_2_00419F30 NtAllocateVirtualMemory, |
3_2_00419F30 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 3_2_00419D4A NtCreateFile, |
3_2_00419D4A |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 3_2_00419DFA NtReadFile, |
3_2_00419DFA |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 3_2_00419E7A NtClose, |
3_2_00419E7A |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 3_2_00419F2A NtAllocateVirtualMemory, |
3_2_00419F2A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639860 NtQuerySystemInformation,LdrInitializeThunk, |
7_2_04639860 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639840 NtDelayExecution,LdrInitializeThunk, |
7_2_04639840 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639540 NtReadFile,LdrInitializeThunk, |
7_2_04639540 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639910 NtAdjustPrivilegesToken,LdrInitializeThunk, |
7_2_04639910 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046395D0 NtClose,LdrInitializeThunk, |
7_2_046395D0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046399A0 NtCreateSection,LdrInitializeThunk, |
7_2_046399A0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639660 NtAllocateVirtualMemory,LdrInitializeThunk, |
7_2_04639660 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639A50 NtCreateFile,LdrInitializeThunk, |
7_2_04639A50 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639650 NtQueryValueKey,LdrInitializeThunk, |
7_2_04639650 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046396E0 NtFreeVirtualMemory,LdrInitializeThunk, |
7_2_046396E0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046396D0 NtCreateKey,LdrInitializeThunk, |
7_2_046396D0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639710 NtQueryInformationToken,LdrInitializeThunk, |
7_2_04639710 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639FE0 NtCreateMutant,LdrInitializeThunk, |
7_2_04639FE0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639780 NtMapViewOfSection,LdrInitializeThunk, |
7_2_04639780 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0463B040 NtSuspendThread, |
7_2_0463B040 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639820 NtEnumerateKey, |
7_2_04639820 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046398F0 NtReadVirtualMemory, |
7_2_046398F0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046398A0 NtWriteVirtualMemory, |
7_2_046398A0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639560 NtWriteFile, |
7_2_04639560 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639950 NtQueueApcThread, |
7_2_04639950 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639520 NtWaitForSingleObject, |
7_2_04639520 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0463AD30 NtSetContextThread, |
7_2_0463AD30 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046395F0 NtQueryInformationFile, |
7_2_046395F0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046399D0 NtCreateProcessEx, |
7_2_046399D0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639670 NtQueryInformationProcess, |
7_2_04639670 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639A20 NtResumeThread, |
7_2_04639A20 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639A00 NtProtectVirtualMemory, |
7_2_04639A00 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639610 NtEnumerateValueKey, |
7_2_04639610 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639A10 NtQuerySection, |
7_2_04639A10 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639A80 NtOpenDirectoryObject, |
7_2_04639A80 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639760 NtOpenProcess, |
7_2_04639760 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639770 NtSetInformationFile, |
7_2_04639770 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0463A770 NtOpenThread, |
7_2_0463A770 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639730 NtQueryVirtualMemory, |
7_2_04639730 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04639B00 NtSetValueKey, |
7_2_04639B00 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0463A710 NtOpenProcessToken, |
7_2_0463A710 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046397A0 NtUnmapViewOfSection, |
7_2_046397A0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0463A3B0 NtGetContextThread, |
7_2_0463A3B0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_00699D50 NtCreateFile, |
7_2_00699D50 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_00699E00 NtReadFile, |
7_2_00699E00 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_00699E80 NtClose, |
7_2_00699E80 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_00699F30 NtAllocateVirtualMemory, |
7_2_00699F30 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_00699D4A NtCreateFile, |
7_2_00699D4A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_00699DFA NtReadFile, |
7_2_00699DFA |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_00699E7A NtClose, |
7_2_00699E7A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_00699F2A NtAllocateVirtualMemory, |
7_2_00699F2A |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 1_2_033BC3A0 |
1_2_033BC3A0 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 1_2_033BA758 |
1_2_033BA758 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 1_2_0C146484 |
1_2_0C146484 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 1_2_0C141CC8 |
1_2_0C141CC8 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 1_2_0C1417F8 |
1_2_0C1417F8 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 1_2_0C148B30 |
1_2_0C148B30 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 1_2_0C141CB7 |
1_2_0C141CB7 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 1_2_0C146503 |
1_2_0C146503 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 1_2_0C145EB3 |
1_2_0C145EB3 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 1_2_0C145EB8 |
1_2_0C145EB8 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 1_2_0C140F10 |
1_2_0C140F10 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 1_2_0C140F09 |
1_2_0C140F09 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 1_2_0C141FB0 |
1_2_0C141FB0 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 1_2_0C141FAD |
1_2_0C141FAD |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 1_2_0C1417E8 |
1_2_0C1417E8 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 1_2_0C143823 |
1_2_0C143823 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 1_2_0C1408D3 |
1_2_0C1408D3 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 1_2_0C140908 |
1_2_0C140908 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 1_2_0C143205 |
1_2_0C143205 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 1_2_0C143208 |
1_2_0C143208 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 1_2_0C1462B0 |
1_2_0C1462B0 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 1_2_0C1462AD |
1_2_0C1462AD |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 3_2_00401030 |
3_2_00401030 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 3_2_0041DB46 |
3_2_0041DB46 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 3_2_0041D357 |
3_2_0041D357 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 3_2_0041D5DD |
3_2_0041D5DD |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 3_2_00409DEB |
3_2_00409DEB |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 3_2_00402D90 |
3_2_00402D90 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 3_2_0041DE05 |
3_2_0041DE05 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 3_2_00409E30 |
3_2_00409E30 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 3_2_0041DE9C |
3_2_0041DE9C |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 3_2_0041D701 |
3_2_0041D701 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 3_2_0041DFE3 |
3_2_0041DFE3 |
Source: C:\Users\user\Desktop\w73FtMA4ZTl9NFm.exe |
Code function: 3_2_00402FB0 |
3_2_00402FB0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046B1002 |
7_2_046B1002 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0460841F |
7_2_0460841F |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C28EC |
7_2_046C28EC |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046220A0 |
7_2_046220A0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C20A8 |
7_2_046C20A8 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0460B090 |
7_2_0460B090 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C1D55 |
7_2_046C1D55 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04614120 |
7_2_04614120 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045FF900 |
7_2_045FF900 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C2D07 |
7_2_046C2D07 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F0D20 |
7_2_045F0D20 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0460D5E0 |
7_2_0460D5E0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C25DD |
7_2_046C25DD |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04622581 |
7_2_04622581 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04616E30 |
7_2_04616E30 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C2EF7 |
7_2_046C2EF7 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C22AE |
7_2_046C22AE |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C2B28 |
7_2_046C2B28 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C1FF1 |
7_2_046C1FF1 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046BDBD2 |
7_2_046BDBD2 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462EBB0 |
7_2_0462EBB0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0069DB46 |
7_2_0069DB46 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_00689DEB |
7_2_00689DEB |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0069D5D7 |
7_2_0069D5D7 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_00682D90 |
7_2_00682D90 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_00689E30 |
7_2_00689E30 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0069DE05 |
7_2_0069DE05 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0069DE9C |
7_2_0069DE9C |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0069D702 |
7_2_0069D702 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0069DFE3 |
7_2_0069DFE3 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_00682FB0 |
7_2_00682FB0 |
Source: 00000003.00000002.287250589.0000000000400000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000003.00000002.287250589.0000000000400000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000003.00000002.288102436.00000000018D0000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000003.00000002.288102436.00000000018D0000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000007.00000002.508139744.0000000004460000.00000004.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000007.00000002.508139744.0000000004460000.00000004.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000003.00000002.287644899.0000000001550000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000003.00000002.287644899.0000000001550000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000007.00000002.502602967.0000000000680000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000007.00000002.502602967.0000000000680000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000001.00000002.247215566.00000000045E9000.00000004.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000001.00000002.247215566.00000000045E9000.00000004.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000007.00000002.505004698.0000000002C20000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000007.00000002.505004698.0000000002C20000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 3.2.w73FtMA4ZTl9NFm.exe.400000.0.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 3.2.w73FtMA4ZTl9NFm.exe.400000.0.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 3.2.w73FtMA4ZTl9NFm.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 3.2.w73FtMA4ZTl9NFm.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 1.2.w73FtMA4ZTl9NFm.exe.46875f8.3.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 1.2.w73FtMA4ZTl9NFm.exe.46875f8.3.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0461746D mov eax, dword ptr fs:[00000030h] |
7_2_0461746D |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046B2073 mov eax, dword ptr fs:[00000030h] |
7_2_046B2073 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C1074 mov eax, dword ptr fs:[00000030h] |
7_2_046C1074 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462A44B mov eax, dword ptr fs:[00000030h] |
7_2_0462A44B |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04610050 mov eax, dword ptr fs:[00000030h] |
7_2_04610050 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04610050 mov eax, dword ptr fs:[00000030h] |
7_2_04610050 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0468C450 mov eax, dword ptr fs:[00000030h] |
7_2_0468C450 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0468C450 mov eax, dword ptr fs:[00000030h] |
7_2_0468C450 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0460B02A mov eax, dword ptr fs:[00000030h] |
7_2_0460B02A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0460B02A mov eax, dword ptr fs:[00000030h] |
7_2_0460B02A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0460B02A mov eax, dword ptr fs:[00000030h] |
7_2_0460B02A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0460B02A mov eax, dword ptr fs:[00000030h] |
7_2_0460B02A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462BC2C mov eax, dword ptr fs:[00000030h] |
7_2_0462BC2C |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462002D mov eax, dword ptr fs:[00000030h] |
7_2_0462002D |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462002D mov eax, dword ptr fs:[00000030h] |
7_2_0462002D |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462002D mov eax, dword ptr fs:[00000030h] |
7_2_0462002D |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462002D mov eax, dword ptr fs:[00000030h] |
7_2_0462002D |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462002D mov eax, dword ptr fs:[00000030h] |
7_2_0462002D |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C740D mov eax, dword ptr fs:[00000030h] |
7_2_046C740D |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C740D mov eax, dword ptr fs:[00000030h] |
7_2_046C740D |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C740D mov eax, dword ptr fs:[00000030h] |
7_2_046C740D |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046B1C06 mov eax, dword ptr fs:[00000030h] |
7_2_046B1C06 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046B1C06 mov eax, dword ptr fs:[00000030h] |
7_2_046B1C06 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046B1C06 mov eax, dword ptr fs:[00000030h] |
7_2_046B1C06 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046B1C06 mov eax, dword ptr fs:[00000030h] |
7_2_046B1C06 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046B1C06 mov eax, dword ptr fs:[00000030h] |
7_2_046B1C06 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046B1C06 mov eax, dword ptr fs:[00000030h] |
7_2_046B1C06 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046B1C06 mov eax, dword ptr fs:[00000030h] |
7_2_046B1C06 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046B1C06 mov eax, dword ptr fs:[00000030h] |
7_2_046B1C06 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046B1C06 mov eax, dword ptr fs:[00000030h] |
7_2_046B1C06 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046B1C06 mov eax, dword ptr fs:[00000030h] |
7_2_046B1C06 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046B1C06 mov eax, dword ptr fs:[00000030h] |
7_2_046B1C06 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046B1C06 mov eax, dword ptr fs:[00000030h] |
7_2_046B1C06 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046B1C06 mov eax, dword ptr fs:[00000030h] |
7_2_046B1C06 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046B1C06 mov eax, dword ptr fs:[00000030h] |
7_2_046B1C06 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04676C0A mov eax, dword ptr fs:[00000030h] |
7_2_04676C0A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04676C0A mov eax, dword ptr fs:[00000030h] |
7_2_04676C0A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04676C0A mov eax, dword ptr fs:[00000030h] |
7_2_04676C0A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04676C0A mov eax, dword ptr fs:[00000030h] |
7_2_04676C0A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04677016 mov eax, dword ptr fs:[00000030h] |
7_2_04677016 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04677016 mov eax, dword ptr fs:[00000030h] |
7_2_04677016 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04677016 mov eax, dword ptr fs:[00000030h] |
7_2_04677016 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C4015 mov eax, dword ptr fs:[00000030h] |
7_2_046C4015 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C4015 mov eax, dword ptr fs:[00000030h] |
7_2_046C4015 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046B14FB mov eax, dword ptr fs:[00000030h] |
7_2_046B14FB |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04676CF0 mov eax, dword ptr fs:[00000030h] |
7_2_04676CF0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04676CF0 mov eax, dword ptr fs:[00000030h] |
7_2_04676CF0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04676CF0 mov eax, dword ptr fs:[00000030h] |
7_2_04676CF0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F58EC mov eax, dword ptr fs:[00000030h] |
7_2_045F58EC |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0468B8D0 mov eax, dword ptr fs:[00000030h] |
7_2_0468B8D0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0468B8D0 mov ecx, dword ptr fs:[00000030h] |
7_2_0468B8D0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0468B8D0 mov eax, dword ptr fs:[00000030h] |
7_2_0468B8D0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0468B8D0 mov eax, dword ptr fs:[00000030h] |
7_2_0468B8D0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0468B8D0 mov eax, dword ptr fs:[00000030h] |
7_2_0468B8D0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0468B8D0 mov eax, dword ptr fs:[00000030h] |
7_2_0468B8D0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C8CD6 mov eax, dword ptr fs:[00000030h] |
7_2_046C8CD6 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046220A0 mov eax, dword ptr fs:[00000030h] |
7_2_046220A0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046220A0 mov eax, dword ptr fs:[00000030h] |
7_2_046220A0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046220A0 mov eax, dword ptr fs:[00000030h] |
7_2_046220A0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046220A0 mov eax, dword ptr fs:[00000030h] |
7_2_046220A0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046220A0 mov eax, dword ptr fs:[00000030h] |
7_2_046220A0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046220A0 mov eax, dword ptr fs:[00000030h] |
7_2_046220A0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046390AF mov eax, dword ptr fs:[00000030h] |
7_2_046390AF |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462F0BF mov ecx, dword ptr fs:[00000030h] |
7_2_0462F0BF |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462F0BF mov eax, dword ptr fs:[00000030h] |
7_2_0462F0BF |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462F0BF mov eax, dword ptr fs:[00000030h] |
7_2_0462F0BF |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F9080 mov eax, dword ptr fs:[00000030h] |
7_2_045F9080 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04673884 mov eax, dword ptr fs:[00000030h] |
7_2_04673884 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04673884 mov eax, dword ptr fs:[00000030h] |
7_2_04673884 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0460849B mov eax, dword ptr fs:[00000030h] |
7_2_0460849B |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0461C577 mov eax, dword ptr fs:[00000030h] |
7_2_0461C577 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0461C577 mov eax, dword ptr fs:[00000030h] |
7_2_0461C577 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04633D43 mov eax, dword ptr fs:[00000030h] |
7_2_04633D43 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0461B944 mov eax, dword ptr fs:[00000030h] |
7_2_0461B944 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0461B944 mov eax, dword ptr fs:[00000030h] |
7_2_0461B944 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04673540 mov eax, dword ptr fs:[00000030h] |
7_2_04673540 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045FB171 mov eax, dword ptr fs:[00000030h] |
7_2_045FB171 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045FB171 mov eax, dword ptr fs:[00000030h] |
7_2_045FB171 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04617D50 mov eax, dword ptr fs:[00000030h] |
7_2_04617D50 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045FC962 mov eax, dword ptr fs:[00000030h] |
7_2_045FC962 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04614120 mov eax, dword ptr fs:[00000030h] |
7_2_04614120 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04614120 mov eax, dword ptr fs:[00000030h] |
7_2_04614120 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04614120 mov eax, dword ptr fs:[00000030h] |
7_2_04614120 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04614120 mov eax, dword ptr fs:[00000030h] |
7_2_04614120 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04614120 mov ecx, dword ptr fs:[00000030h] |
7_2_04614120 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0467A537 mov eax, dword ptr fs:[00000030h] |
7_2_0467A537 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046BE539 mov eax, dword ptr fs:[00000030h] |
7_2_046BE539 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04603D34 mov eax, dword ptr fs:[00000030h] |
7_2_04603D34 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04603D34 mov eax, dword ptr fs:[00000030h] |
7_2_04603D34 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04603D34 mov eax, dword ptr fs:[00000030h] |
7_2_04603D34 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04603D34 mov eax, dword ptr fs:[00000030h] |
7_2_04603D34 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04603D34 mov eax, dword ptr fs:[00000030h] |
7_2_04603D34 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04603D34 mov eax, dword ptr fs:[00000030h] |
7_2_04603D34 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04603D34 mov eax, dword ptr fs:[00000030h] |
7_2_04603D34 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04603D34 mov eax, dword ptr fs:[00000030h] |
7_2_04603D34 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04603D34 mov eax, dword ptr fs:[00000030h] |
7_2_04603D34 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04603D34 mov eax, dword ptr fs:[00000030h] |
7_2_04603D34 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04603D34 mov eax, dword ptr fs:[00000030h] |
7_2_04603D34 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04603D34 mov eax, dword ptr fs:[00000030h] |
7_2_04603D34 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04603D34 mov eax, dword ptr fs:[00000030h] |
7_2_04603D34 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C8D34 mov eax, dword ptr fs:[00000030h] |
7_2_046C8D34 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462513A mov eax, dword ptr fs:[00000030h] |
7_2_0462513A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462513A mov eax, dword ptr fs:[00000030h] |
7_2_0462513A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04624D3B mov eax, dword ptr fs:[00000030h] |
7_2_04624D3B |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04624D3B mov eax, dword ptr fs:[00000030h] |
7_2_04624D3B |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04624D3B mov eax, dword ptr fs:[00000030h] |
7_2_04624D3B |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F9100 mov eax, dword ptr fs:[00000030h] |
7_2_045F9100 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F9100 mov eax, dword ptr fs:[00000030h] |
7_2_045F9100 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F9100 mov eax, dword ptr fs:[00000030h] |
7_2_045F9100 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045FAD30 mov eax, dword ptr fs:[00000030h] |
7_2_045FAD30 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046841E8 mov eax, dword ptr fs:[00000030h] |
7_2_046841E8 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0460D5E0 mov eax, dword ptr fs:[00000030h] |
7_2_0460D5E0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0460D5E0 mov eax, dword ptr fs:[00000030h] |
7_2_0460D5E0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046BFDE2 mov eax, dword ptr fs:[00000030h] |
7_2_046BFDE2 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046BFDE2 mov eax, dword ptr fs:[00000030h] |
7_2_046BFDE2 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046BFDE2 mov eax, dword ptr fs:[00000030h] |
7_2_046BFDE2 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046BFDE2 mov eax, dword ptr fs:[00000030h] |
7_2_046BFDE2 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046A8DF1 mov eax, dword ptr fs:[00000030h] |
7_2_046A8DF1 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04676DC9 mov eax, dword ptr fs:[00000030h] |
7_2_04676DC9 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04676DC9 mov eax, dword ptr fs:[00000030h] |
7_2_04676DC9 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04676DC9 mov eax, dword ptr fs:[00000030h] |
7_2_04676DC9 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04676DC9 mov ecx, dword ptr fs:[00000030h] |
7_2_04676DC9 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04676DC9 mov eax, dword ptr fs:[00000030h] |
7_2_04676DC9 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04676DC9 mov eax, dword ptr fs:[00000030h] |
7_2_04676DC9 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045FB1E1 mov eax, dword ptr fs:[00000030h] |
7_2_045FB1E1 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045FB1E1 mov eax, dword ptr fs:[00000030h] |
7_2_045FB1E1 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045FB1E1 mov eax, dword ptr fs:[00000030h] |
7_2_045FB1E1 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C05AC mov eax, dword ptr fs:[00000030h] |
7_2_046C05AC |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C05AC mov eax, dword ptr fs:[00000030h] |
7_2_046C05AC |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046769A6 mov eax, dword ptr fs:[00000030h] |
7_2_046769A6 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046261A0 mov eax, dword ptr fs:[00000030h] |
7_2_046261A0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046261A0 mov eax, dword ptr fs:[00000030h] |
7_2_046261A0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046235A1 mov eax, dword ptr fs:[00000030h] |
7_2_046235A1 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F2D8A mov eax, dword ptr fs:[00000030h] |
7_2_045F2D8A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F2D8A mov eax, dword ptr fs:[00000030h] |
7_2_045F2D8A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F2D8A mov eax, dword ptr fs:[00000030h] |
7_2_045F2D8A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F2D8A mov eax, dword ptr fs:[00000030h] |
7_2_045F2D8A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F2D8A mov eax, dword ptr fs:[00000030h] |
7_2_045F2D8A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04621DB5 mov eax, dword ptr fs:[00000030h] |
7_2_04621DB5 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04621DB5 mov eax, dword ptr fs:[00000030h] |
7_2_04621DB5 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04621DB5 mov eax, dword ptr fs:[00000030h] |
7_2_04621DB5 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046751BE mov eax, dword ptr fs:[00000030h] |
7_2_046751BE |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046751BE mov eax, dword ptr fs:[00000030h] |
7_2_046751BE |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046751BE mov eax, dword ptr fs:[00000030h] |
7_2_046751BE |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046751BE mov eax, dword ptr fs:[00000030h] |
7_2_046751BE |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0461C182 mov eax, dword ptr fs:[00000030h] |
7_2_0461C182 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04622581 mov eax, dword ptr fs:[00000030h] |
7_2_04622581 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04622581 mov eax, dword ptr fs:[00000030h] |
7_2_04622581 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04622581 mov eax, dword ptr fs:[00000030h] |
7_2_04622581 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04622581 mov eax, dword ptr fs:[00000030h] |
7_2_04622581 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462A185 mov eax, dword ptr fs:[00000030h] |
7_2_0462A185 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04622990 mov eax, dword ptr fs:[00000030h] |
7_2_04622990 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462FD9B mov eax, dword ptr fs:[00000030h] |
7_2_0462FD9B |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462FD9B mov eax, dword ptr fs:[00000030h] |
7_2_0462FD9B |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046AB260 mov eax, dword ptr fs:[00000030h] |
7_2_046AB260 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046AB260 mov eax, dword ptr fs:[00000030h] |
7_2_046AB260 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0460766D mov eax, dword ptr fs:[00000030h] |
7_2_0460766D |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C8A62 mov eax, dword ptr fs:[00000030h] |
7_2_046C8A62 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0461AE73 mov eax, dword ptr fs:[00000030h] |
7_2_0461AE73 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0461AE73 mov eax, dword ptr fs:[00000030h] |
7_2_0461AE73 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0461AE73 mov eax, dword ptr fs:[00000030h] |
7_2_0461AE73 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0461AE73 mov eax, dword ptr fs:[00000030h] |
7_2_0461AE73 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0461AE73 mov eax, dword ptr fs:[00000030h] |
7_2_0461AE73 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0463927A mov eax, dword ptr fs:[00000030h] |
7_2_0463927A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F9240 mov eax, dword ptr fs:[00000030h] |
7_2_045F9240 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F9240 mov eax, dword ptr fs:[00000030h] |
7_2_045F9240 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F9240 mov eax, dword ptr fs:[00000030h] |
7_2_045F9240 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F9240 mov eax, dword ptr fs:[00000030h] |
7_2_045F9240 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04607E41 mov eax, dword ptr fs:[00000030h] |
7_2_04607E41 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04607E41 mov eax, dword ptr fs:[00000030h] |
7_2_04607E41 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04607E41 mov eax, dword ptr fs:[00000030h] |
7_2_04607E41 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04607E41 mov eax, dword ptr fs:[00000030h] |
7_2_04607E41 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04607E41 mov eax, dword ptr fs:[00000030h] |
7_2_04607E41 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04607E41 mov eax, dword ptr fs:[00000030h] |
7_2_04607E41 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046BAE44 mov eax, dword ptr fs:[00000030h] |
7_2_046BAE44 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046BAE44 mov eax, dword ptr fs:[00000030h] |
7_2_046BAE44 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046BEA55 mov eax, dword ptr fs:[00000030h] |
7_2_046BEA55 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04684257 mov eax, dword ptr fs:[00000030h] |
7_2_04684257 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045FAA16 mov eax, dword ptr fs:[00000030h] |
7_2_045FAA16 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045FAA16 mov eax, dword ptr fs:[00000030h] |
7_2_045FAA16 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04634A2C mov eax, dword ptr fs:[00000030h] |
7_2_04634A2C |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04634A2C mov eax, dword ptr fs:[00000030h] |
7_2_04634A2C |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F5210 mov eax, dword ptr fs:[00000030h] |
7_2_045F5210 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F5210 mov ecx, dword ptr fs:[00000030h] |
7_2_045F5210 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F5210 mov eax, dword ptr fs:[00000030h] |
7_2_045F5210 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F5210 mov eax, dword ptr fs:[00000030h] |
7_2_045F5210 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046AFE3F mov eax, dword ptr fs:[00000030h] |
7_2_046AFE3F |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045FC600 mov eax, dword ptr fs:[00000030h] |
7_2_045FC600 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045FC600 mov eax, dword ptr fs:[00000030h] |
7_2_045FC600 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045FC600 mov eax, dword ptr fs:[00000030h] |
7_2_045FC600 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04628E00 mov eax, dword ptr fs:[00000030h] |
7_2_04628E00 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046B1608 mov eax, dword ptr fs:[00000030h] |
7_2_046B1608 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04608A0A mov eax, dword ptr fs:[00000030h] |
7_2_04608A0A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04613A1C mov eax, dword ptr fs:[00000030h] |
7_2_04613A1C |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462A61C mov eax, dword ptr fs:[00000030h] |
7_2_0462A61C |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462A61C mov eax, dword ptr fs:[00000030h] |
7_2_0462A61C |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045FE620 mov eax, dword ptr fs:[00000030h] |
7_2_045FE620 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046216E0 mov ecx, dword ptr fs:[00000030h] |
7_2_046216E0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046076E2 mov eax, dword ptr fs:[00000030h] |
7_2_046076E2 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04622AE4 mov eax, dword ptr fs:[00000030h] |
7_2_04622AE4 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04638EC7 mov eax, dword ptr fs:[00000030h] |
7_2_04638EC7 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04622ACB mov eax, dword ptr fs:[00000030h] |
7_2_04622ACB |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046AFEC0 mov eax, dword ptr fs:[00000030h] |
7_2_046AFEC0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046236CC mov eax, dword ptr fs:[00000030h] |
7_2_046236CC |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C8ED6 mov eax, dword ptr fs:[00000030h] |
7_2_046C8ED6 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046746A7 mov eax, dword ptr fs:[00000030h] |
7_2_046746A7 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C0EA5 mov eax, dword ptr fs:[00000030h] |
7_2_046C0EA5 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C0EA5 mov eax, dword ptr fs:[00000030h] |
7_2_046C0EA5 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C0EA5 mov eax, dword ptr fs:[00000030h] |
7_2_046C0EA5 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0460AAB0 mov eax, dword ptr fs:[00000030h] |
7_2_0460AAB0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0460AAB0 mov eax, dword ptr fs:[00000030h] |
7_2_0460AAB0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462FAB0 mov eax, dword ptr fs:[00000030h] |
7_2_0462FAB0 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0468FE87 mov eax, dword ptr fs:[00000030h] |
7_2_0468FE87 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462D294 mov eax, dword ptr fs:[00000030h] |
7_2_0462D294 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462D294 mov eax, dword ptr fs:[00000030h] |
7_2_0462D294 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F52A5 mov eax, dword ptr fs:[00000030h] |
7_2_045F52A5 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F52A5 mov eax, dword ptr fs:[00000030h] |
7_2_045F52A5 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F52A5 mov eax, dword ptr fs:[00000030h] |
7_2_045F52A5 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F52A5 mov eax, dword ptr fs:[00000030h] |
7_2_045F52A5 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F52A5 mov eax, dword ptr fs:[00000030h] |
7_2_045F52A5 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0460FF60 mov eax, dword ptr fs:[00000030h] |
7_2_0460FF60 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C8F6A mov eax, dword ptr fs:[00000030h] |
7_2_046C8F6A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045FF358 mov eax, dword ptr fs:[00000030h] |
7_2_045FF358 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04623B7A mov eax, dword ptr fs:[00000030h] |
7_2_04623B7A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04623B7A mov eax, dword ptr fs:[00000030h] |
7_2_04623B7A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045FDB40 mov eax, dword ptr fs:[00000030h] |
7_2_045FDB40 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0460EF40 mov eax, dword ptr fs:[00000030h] |
7_2_0460EF40 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C8B58 mov eax, dword ptr fs:[00000030h] |
7_2_046C8B58 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045FDB60 mov ecx, dword ptr fs:[00000030h] |
7_2_045FDB60 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462E730 mov eax, dword ptr fs:[00000030h] |
7_2_0462E730 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C070D mov eax, dword ptr fs:[00000030h] |
7_2_046C070D |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C070D mov eax, dword ptr fs:[00000030h] |
7_2_046C070D |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462A70E mov eax, dword ptr fs:[00000030h] |
7_2_0462A70E |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462A70E mov eax, dword ptr fs:[00000030h] |
7_2_0462A70E |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046B131B mov eax, dword ptr fs:[00000030h] |
7_2_046B131B |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F4F2E mov eax, dword ptr fs:[00000030h] |
7_2_045F4F2E |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_045F4F2E mov eax, dword ptr fs:[00000030h] |
7_2_045F4F2E |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0461F716 mov eax, dword ptr fs:[00000030h] |
7_2_0461F716 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0468FF10 mov eax, dword ptr fs:[00000030h] |
7_2_0468FF10 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0468FF10 mov eax, dword ptr fs:[00000030h] |
7_2_0468FF10 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046203E2 mov eax, dword ptr fs:[00000030h] |
7_2_046203E2 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046203E2 mov eax, dword ptr fs:[00000030h] |
7_2_046203E2 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046203E2 mov eax, dword ptr fs:[00000030h] |
7_2_046203E2 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046203E2 mov eax, dword ptr fs:[00000030h] |
7_2_046203E2 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046203E2 mov eax, dword ptr fs:[00000030h] |
7_2_046203E2 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046203E2 mov eax, dword ptr fs:[00000030h] |
7_2_046203E2 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0461DBE9 mov eax, dword ptr fs:[00000030h] |
7_2_0461DBE9 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046337F5 mov eax, dword ptr fs:[00000030h] |
7_2_046337F5 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046753CA mov eax, dword ptr fs:[00000030h] |
7_2_046753CA |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046753CA mov eax, dword ptr fs:[00000030h] |
7_2_046753CA |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046C5BA5 mov eax, dword ptr fs:[00000030h] |
7_2_046C5BA5 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04624BAD mov eax, dword ptr fs:[00000030h] |
7_2_04624BAD |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04624BAD mov eax, dword ptr fs:[00000030h] |
7_2_04624BAD |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04624BAD mov eax, dword ptr fs:[00000030h] |
7_2_04624BAD |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046B138A mov eax, dword ptr fs:[00000030h] |
7_2_046B138A |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_046AD380 mov ecx, dword ptr fs:[00000030h] |
7_2_046AD380 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04601B8F mov eax, dword ptr fs:[00000030h] |
7_2_04601B8F |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04601B8F mov eax, dword ptr fs:[00000030h] |
7_2_04601B8F |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_0462B390 mov eax, dword ptr fs:[00000030h] |
7_2_0462B390 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04677794 mov eax, dword ptr fs:[00000030h] |
7_2_04677794 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04677794 mov eax, dword ptr fs:[00000030h] |
7_2_04677794 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04677794 mov eax, dword ptr fs:[00000030h] |
7_2_04677794 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04608794 mov eax, dword ptr fs:[00000030h] |
7_2_04608794 |
Source: C:\Windows\SysWOW64\cmstp.exe |
Code function: 7_2_04622397 mov eax, dword ptr fs:[00000030h] |
7_2_04622397 |