Source: POLITICALLY.exe, 0000000A.00000002.547813821.00000000008B9000.00000004.00000020.sdmp | String found in binary or memory: http://111.90.149.46/bin_XNLhDlJvG218.bin |
Source: POLITICALLY.exe, 0000000A.00000002.547813821.00000000008B9000.00000004.00000020.sdmp | String found in binary or memory: http://111.90.149.46/bin_XNLhDlJvG218.bin/ |
Source: POLITICALLY.exe, 0000000A.00000002.547813821.00000000008B9000.00000004.00000020.sdmp | String found in binary or memory: http://111.90.149.46/bin_XNLhDlJvG218.bin3 |
Source: POLITICALLY.exe, 0000000A.00000002.547813821.00000000008B9000.00000004.00000020.sdmp | String found in binary or memory: http://111.90.149.46/bin_XNLhDlJvG218.binb) |
Source: POLITICALLY.exe, 0000000A.00000002.547813821.00000000008B9000.00000004.00000020.sdmp | String found in binary or memory: http://111.90.149.46/bin_XNLhDlJvG218.binw |
Source: POLITICALLY.exe, 0000000A.00000002.547813821.00000000008B9000.00000004.00000020.sdmp | String found in binary or memory: http://111.90.149.46/in_XNLhDlJvG218.bin |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://fontfabrik.com |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.6923599.com |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.6923599.com/olg8/ |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.6923599.com/olg8/www.wiseowldigital.com |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.6923599.comReferer: |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0 |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.artboxxstudio.com |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.artboxxstudio.com/olg8/ |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.artboxxstudio.com/olg8/www.onlinewomensclasses.com |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.artboxxstudio.comReferer: |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.assroyalty.club |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.assroyalty.club/olg8/ |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.assroyalty.club/olg8/www.tuancai.net |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.assroyalty.clubReferer: |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.auroraleathers.com |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.auroraleathers.com/olg8/ |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.auroraleathers.com/olg8/www.artboxxstudio.com |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.auroraleathers.comReferer: |
Source: explorer.exe, 00000013.00000000.507594698.000000000095C000.00000004.00000020.sdmp | String found in binary or memory: http://www.autoitscript.com/autoit3/J |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.carterandcone.coml |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.cunerier.com |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.cunerier.com/olg8/ |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.cunerier.com/olg8/www.purplebean.company |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.cunerier.comReferer: |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.easiersell.com |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.easiersell.com/olg8/ |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.easiersell.com/olg8/www.assroyalty.club |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.easiersell.comReferer: |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com/designers |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com/designers/? |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com/designers/frere-jones.html |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com/designers8 |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com/designers? |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.fontbureau.com/designersG |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.fonts.com |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.founder.com.cn/cn |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.founder.com.cn/cn/bThe |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.founder.com.cn/cn/cThe |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.galapagosdesign.com/DPlease |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.goodfont.co.kr |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.jiyu-kobo.co.jp/ |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.moopyo.com |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.moopyo.com/olg8/ |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.moopyo.com/olg8/www.morgolf.com |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.moopyo.comReferer: |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.morgolf.com |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.morgolf.com/olg8/ |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.morgolf.com/olg8/www.easiersell.com |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.morgolf.comReferer: |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.nortier.cloud |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.nortier.cloud/olg8/ |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.nortier.cloudReferer: |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.onlinewomensclasses.com |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.onlinewomensclasses.com/olg8/ |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.onlinewomensclasses.com/olg8/www.policomercial.com |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.onlinewomensclasses.comReferer: |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.policomercial.com |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.policomercial.com/olg8/ |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.policomercial.com/olg8/www.6923599.com |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.policomercial.comReferer: |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.prismatiq.tech |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.prismatiq.tech/olg8/ |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.prismatiq.tech/olg8/www.soakstress.xyz |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.prismatiq.techReferer: |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.purplebean.company |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.purplebean.company/olg8/ |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.purplebean.company/olg8/www.nortier.cloud |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.purplebean.companyReferer: |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.sajatypeworks.com |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.sakkal.com |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.sandoll.co.kr |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.soakstress.xyz |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.soakstress.xyz/olg8/ |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.soakstress.xyz/olg8/www.moopyo.com |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.soakstress.xyzReferer: |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.tiro.com |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.tuancai.net |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.tuancai.net/olg8/ |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.tuancai.net/olg8/www.auroraleathers.com |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.tuancai.netReferer: |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.typography.netD |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.urwpp.deDPlease |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.wiseowldigital.com |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.wiseowldigital.com/olg8/ |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.wiseowldigital.com/olg8/www.cunerier.com |
Source: explorer.exe, 00000013.00000002.607074490.00000000062E0000.00000004.00000001.sdmp | String found in binary or memory: http://www.wiseowldigital.comReferer: |
Source: explorer.exe, 00000013.00000000.530948897.000000000B1A6000.00000002.00000001.sdmp | String found in binary or memory: http://www.zhongyicts.com.cn |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0222E459 NtProtectVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0222EB73 NtMapViewOfSection, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0221AE71 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0221DC36 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0222F270 NtMapViewOfSection, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0221E245 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0221B24A NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0221E378 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0221B3D0 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0222F3D4 NtMapViewOfSection, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0221B121 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0222F658 NtMapViewOfSection, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0221B698 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0222F768 NtMapViewOfSection, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0221B7FC NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0221B514 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0222F519 NtMapViewOfSection, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0221BA7C NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0221DB19 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_02212B60 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0221BBB2 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0222EB8C NtMapViewOfSection, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0222F896 NtMapViewOfSection, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0221B932 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0221BE0D NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0221AE76 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0221CEAB NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0222EF21 NtMapViewOfSection, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0221BF4D NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0221AFD8 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0221DFD8 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0221BCDC NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0222EDB9 NtMapViewOfSection, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0221DD81 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279660 NtAllocateVirtualMemory,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2796E0 NtFreeVirtualMemory,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279710 NtQueryInformationToken,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2797A0 NtUnmapViewOfSection,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279780 NtMapViewOfSection,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279FE0 NtCreateMutant,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279540 NtReadFile,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2795D0 NtClose,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279A20 NtResumeThread,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279A00 NtProtectVirtualMemory,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279A50 NtCreateFile,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279860 NtQuerySystemInformation,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279840 NtDelayExecution,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2798F0 NtReadVirtualMemory,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279910 NtAdjustPrivilegesToken,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2799A0 NtCreateSection,LdrInitializeThunk, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279610 NtEnumerateValueKey, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279670 NtQueryInformationProcess, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279650 NtQueryValueKey, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2796D0 NtCreateKey, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279730 NtQueryVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E27A710 NtOpenProcessToken, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279760 NtOpenProcess, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E27A770 NtOpenThread, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279770 NtSetInformationFile, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279520 NtWaitForSingleObject, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E27AD30 NtSetContextThread, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279560 NtWriteFile, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2795F0 NtQueryInformationFile, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279A10 NtQuerySection, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279A80 NtOpenDirectoryObject, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279B00 NtSetValueKey, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E27A3B0 NtGetContextThread, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279820 NtEnumerateKey, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E27B040 NtSuspendThread, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2798A0 NtWriteVirtualMemory, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E279950 NtQueueApcThread, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2799D0 NtCreateProcessEx, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048695D0 NtClose,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869540 NtReadFile,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048696D0 NtCreateKey,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048696E0 NtFreeVirtualMemory,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869650 NtQueryValueKey,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869660 NtAllocateVirtualMemory,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869780 NtMapViewOfSection,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869FE0 NtCreateMutant,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869710 NtQueryInformationToken,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869840 NtDelayExecution,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869860 NtQuerySystemInformation,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048699A0 NtCreateSection,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869910 NtAdjustPrivilegesToken,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869A50 NtCreateFile,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048695F0 NtQueryInformationFile, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869520 NtWaitForSingleObject, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0486AD30 NtSetContextThread, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869560 NtWriteFile, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869610 NtEnumerateValueKey, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869670 NtQueryInformationProcess, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048697A0 NtUnmapViewOfSection, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0486A710 NtOpenProcessToken, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869730 NtQueryVirtualMemory, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869760 NtOpenProcess, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0486A770 NtOpenThread, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869770 NtSetInformationFile, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048698A0 NtWriteVirtualMemory, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048698F0 NtReadVirtualMemory, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869820 NtEnumerateKey, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0486B040 NtSuspendThread, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048699D0 NtCreateProcessEx, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869950 NtQueueApcThread, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869A80 NtOpenDirectoryObject, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869A00 NtProtectVirtualMemory, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869A10 NtQuerySection, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869A20 NtResumeThread, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0486A3B0 NtGetContextThread, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04869B00 NtSetValueKey, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_030B83A0 NtAllocateVirtualMemory, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_030B8270 NtReadFile, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_030B82F0 NtClose, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_030B81C0 NtCreateFile, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_030B839A NtAllocateVirtualMemory, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_030B826A NtReadFile, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_030B82EA NtClose, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_030B81BA NtCreateFile, |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_02219212 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0222C0B8 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_02219102 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0222C1F4 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0222767D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_022197E8 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_022197DF mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0222440F mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0222C444 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_02217A2E mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_02219917 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0222BFB8 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 2_2_0221CD2F mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E23E620 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2EFE3F mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E23C600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E23C600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E23C600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E268E00 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2F1608 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26A61C mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26A61C mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E24766D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E25AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E25AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E25AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E25AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E25AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E247E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E247E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E247E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E247E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E247E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E247E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2FAE44 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2FAE44 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B46A7 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E300EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E300EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E300EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2CFE87 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2616E0 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2476E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E278EC7 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E308ED6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2636CC mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2EFEC0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E234F2E mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E234F2E mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26E730 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26A70E mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26A70E mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E25F716 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2CFF10 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2CFF10 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E30070D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E30070D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E24FF60 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E308F6A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E24EF40 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E248794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B7794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B7794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B7794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2737F5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26BC2C mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B6C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B6C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B6C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B6C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2F1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2F1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2F1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2F1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2F1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2F1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2F1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2F1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2F1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2F1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2F1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2F1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2F1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2F1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E30740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E30740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E30740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E25746D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26A44B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2CC450 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2CC450 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E24849B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2F14FB mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B6CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B6CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B6CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E308CD6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E308D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E243D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E243D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E243D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E243D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E243D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E243D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E243D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E243D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E243D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E243D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E243D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E243D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E243D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E23AD30 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2FE539 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2BA537 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E264D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E264D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E264D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E25C577 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E25C577 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E273D43 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B3540 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2E3D40 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E257D50 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2635A1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E261DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E261DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E261DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E3005AC mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E3005AC mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E262581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E262581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E262581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E262581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E232D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E232D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E232D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E232D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E232D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26FD9B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26FD9B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E24D5E0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E24D5E0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2FFDE2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2FFDE2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2FFDE2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2FFDE2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2E8DF1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B6DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B6DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B6DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B6DC9 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B6DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B6DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E274A2C mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E274A2C mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E248A0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E235210 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E235210 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E235210 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E235210 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E23AA16 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E23AA16 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E253A1C mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2FAA16 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2FAA16 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2EB260 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2EB260 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E308A62 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E27927A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E239240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E239240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E239240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E239240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2FEA55 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2C4257 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2352A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2352A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2352A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2352A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2352A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E24AAB0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E24AAB0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26FAB0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26D294 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26D294 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E262AE4 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E262ACB mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2F131B mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E23DB60 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E263B7A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E263B7A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E23DB40 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E308B58 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E23F358 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E264BAD mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E264BAD mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E264BAD mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E305BA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2F138A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E241B8F mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E241B8F mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2ED380 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E262397 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26B390 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2603E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2603E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2603E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2603E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2603E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2603E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E25DBE9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B53CA mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B53CA mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E24B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E24B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E24B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E24B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E304015 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E304015 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B7016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B7016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B7016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E301074 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2F2073 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E250050 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E250050 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2620A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2620A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2620A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2620A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2620A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2620A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2790AF mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26F0BF mov ecx, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26F0BF mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26F0BF mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E239080 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B3884 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B3884 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2340E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2340E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2340E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2358EC mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2CB8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2CB8D0 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2CB8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2CB8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2CB8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2CB8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E254120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E254120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E254120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E254120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E254120 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26513A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26513A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E239100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E239100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E239100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E23C962 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E23B171 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E23B171 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E25B944 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E25B944 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2661A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2661A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2F49A4 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2F49A4 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2F49A4 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2F49A4 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B69A6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B51BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B51BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B51BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2B51BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E26A185 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E25C182 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E262990 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E23B1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E23B1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E23B1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\POLITICALLY.exe | Code function: 10_2_1E2C41E8 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0483849B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048F8CD6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048E14FB mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A6CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A6CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A6CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A6C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A6C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A6C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A6C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048F740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048F740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048F740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048E1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048E1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048E1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048E1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048E1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048E1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048E1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048E1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048E1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048E1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048E1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048E1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048E1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048E1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0485BC2C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0485A44B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048BC450 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048BC450 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0484746D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04852581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04852581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04852581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04852581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04822D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04822D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04822D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04822D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04822D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0485FD9B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0485FD9B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048F05AC mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048F05AC mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048535A1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04851DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04851DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04851DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A6DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A6DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A6DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A6DC9 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A6DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A6DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0483D5E0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0483D5E0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048EFDE2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048EFDE2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048EFDE2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048EFDE2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048D8DF1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0482AD30 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04833D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04833D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04833D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04833D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04833D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04833D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04833D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04833D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04833D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04833D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04833D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04833D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04833D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048EE539 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048F8D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048AA537 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04854D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04854D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04854D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04863D43 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A3540 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04847D50 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0484C577 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0484C577 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048BFE87 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048F0EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048F0EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048F0EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A46A7 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04868EC7 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048536CC mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048DFEC0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048F8ED6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048376E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048516E0 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0482C600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0482C600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0482C600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04858E00 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048E1608 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0485A61C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0485A61C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0482E620 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048DFE3F mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04837E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04837E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04837E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04837E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04837E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04837E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048EAE44 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048EAE44 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0483766D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0484AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0484AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0484AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0484AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0484AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04838794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A7794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A7794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A7794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048637F5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048F070D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048F070D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0485A70E mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0485A70E mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0484F716 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048BFF10 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048BFF10 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04824F2E mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04824F2E mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0485E730 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0483EF40 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0483FF60 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048F8F6A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04829080 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A3884 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A3884 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048520A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048520A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048520A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048520A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048520A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048520A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048690AF mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0485F0BF mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0485F0BF mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0485F0BF mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048BB8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048BB8D0 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048BB8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048BB8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048BB8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048BB8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048258EC mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048F4015 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048F4015 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A7016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A7016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A7016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0485002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0485002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0485002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0485002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0485002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0483B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0483B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0483B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0483B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04840050 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04840050 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048F1074 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048E2073 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0485A185 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0484C182 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04852990 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048561A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048561A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A69A6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A51BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A51BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A51BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048A51BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048B41E8 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0482B1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0482B1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0482B1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04829100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04829100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04829100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04844120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04844120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04844120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04844120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_04844120 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0485513A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0485513A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0484B944 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0484B944 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0482C962 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0482B171 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0482B171 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0485D294 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_0485D294 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048252A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048252A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048252A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048252A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 23_2_048252A5 mov eax, dword ptr fs:[00000030h] |