Source: C:\Users\user\Desktop\NEW ORDER SOR 10531220.exe | Code function: 3_2_00419D60 NtCreateFile, | 3_2_00419D60 |
Source: C:\Users\user\Desktop\NEW ORDER SOR 10531220.exe | Code function: 3_2_00419E10 NtReadFile, | 3_2_00419E10 |
Source: C:\Users\user\Desktop\NEW ORDER SOR 10531220.exe | Code function: 3_2_00419E90 NtClose, | 3_2_00419E90 |
Source: C:\Users\user\Desktop\NEW ORDER SOR 10531220.exe | Code function: 3_2_00419F40 NtAllocateVirtualMemory, | 3_2_00419F40 |
Source: C:\Users\user\Desktop\NEW ORDER SOR 10531220.exe | Code function: 3_2_00419D5A NtCreateFile, | 3_2_00419D5A |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89840 NtDelayExecution,LdrInitializeThunk, | 15_2_00D89840 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89860 NtQuerySystemInformation,LdrInitializeThunk, | 15_2_00D89860 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D895D0 NtClose,LdrInitializeThunk, | 15_2_00D895D0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D899A0 NtCreateSection,LdrInitializeThunk, | 15_2_00D899A0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89540 NtReadFile,LdrInitializeThunk, | 15_2_00D89540 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89910 NtAdjustPrivilegesToken,LdrInitializeThunk, | 15_2_00D89910 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D896D0 NtCreateKey,LdrInitializeThunk, | 15_2_00D896D0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D896E0 NtFreeVirtualMemory,LdrInitializeThunk, | 15_2_00D896E0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89A50 NtCreateFile,LdrInitializeThunk, | 15_2_00D89A50 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89FE0 NtCreateMutant,LdrInitializeThunk, | 15_2_00D89FE0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89780 NtMapViewOfSection,LdrInitializeThunk, | 15_2_00D89780 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89710 NtQueryInformationToken,LdrInitializeThunk, | 15_2_00D89710 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D898F0 NtReadVirtualMemory, | 15_2_00D898F0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D898A0 NtWriteVirtualMemory, | 15_2_00D898A0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D8B040 NtSuspendThread, | 15_2_00D8B040 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89820 NtEnumerateKey, | 15_2_00D89820 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D899D0 NtCreateProcessEx, | 15_2_00D899D0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D895F0 NtQueryInformationFile, | 15_2_00D895F0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89950 NtQueueApcThread, | 15_2_00D89950 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89560 NtWriteFile, | 15_2_00D89560 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D8AD30 NtSetContextThread, | 15_2_00D8AD30 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89520 NtWaitForSingleObject, | 15_2_00D89520 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89A80 NtOpenDirectoryObject, | 15_2_00D89A80 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89650 NtQueryValueKey, | 15_2_00D89650 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89670 NtQueryInformationProcess, | 15_2_00D89670 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89660 NtAllocateVirtualMemory, | 15_2_00D89660 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89610 NtEnumerateValueKey, | 15_2_00D89610 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89A10 NtQuerySection, | 15_2_00D89A10 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89A00 NtProtectVirtualMemory, | 15_2_00D89A00 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89A20 NtResumeThread, | 15_2_00D89A20 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D8A3B0 NtGetContextThread, | 15_2_00D8A3B0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D897A0 NtUnmapViewOfSection, | 15_2_00D897A0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89770 NtSetInformationFile, | 15_2_00D89770 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D8A770 NtOpenThread, | 15_2_00D8A770 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89760 NtOpenProcess, | 15_2_00D89760 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D8A710 NtOpenProcessToken, | 15_2_00D8A710 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89B00 NtSetValueKey, | 15_2_00D89B00 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D89730 NtQueryVirtualMemory, | 15_2_00D89730 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00189D60 NtCreateFile, | 15_2_00189D60 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00189E10 NtReadFile, | 15_2_00189E10 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00189E90 NtClose, | 15_2_00189E90 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00189D5A NtCreateFile, | 15_2_00189D5A |
Source: 00000003.00000002.305618158.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000003.00000002.305618158.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0000000F.00000002.502736423.0000000000980000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0000000F.00000002.502736423.0000000000980000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000000.00000002.245056631.0000000003EE9000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000000.00000002.245056631.0000000003EE9000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0000000F.00000002.504085150.0000000000BD0000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0000000F.00000002.504085150.0000000000BD0000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000003.00000002.305837682.0000000000B70000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000003.00000002.305837682.0000000000B70000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0000000F.00000002.501752912.0000000000170000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0000000F.00000002.501752912.0000000000170000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000003.00000002.305819661.0000000000B40000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000003.00000002.305819661.0000000000B40000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 3.2.NEW ORDER SOR 10531220.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 3.2.NEW ORDER SOR 10531220.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 3.2.NEW ORDER SOR 10531220.exe.400000.0.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 3.2.NEW ORDER SOR 10531220.exe.400000.0.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DDB8D0 mov eax, dword ptr fs:[00000030h] | 15_2_00DDB8D0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DDB8D0 mov ecx, dword ptr fs:[00000030h] | 15_2_00DDB8D0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DDB8D0 mov eax, dword ptr fs:[00000030h] | 15_2_00DDB8D0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DDB8D0 mov eax, dword ptr fs:[00000030h] | 15_2_00DDB8D0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DDB8D0 mov eax, dword ptr fs:[00000030h] | 15_2_00DDB8D0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DDB8D0 mov eax, dword ptr fs:[00000030h] | 15_2_00DDB8D0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E014FB mov eax, dword ptr fs:[00000030h] | 15_2_00E014FB |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC6CF0 mov eax, dword ptr fs:[00000030h] | 15_2_00DC6CF0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC6CF0 mov eax, dword ptr fs:[00000030h] | 15_2_00DC6CF0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC6CF0 mov eax, dword ptr fs:[00000030h] | 15_2_00DC6CF0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E18CD6 mov eax, dword ptr fs:[00000030h] | 15_2_00E18CD6 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D458EC mov eax, dword ptr fs:[00000030h] | 15_2_00D458EC |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D5849B mov eax, dword ptr fs:[00000030h] | 15_2_00D5849B |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D49080 mov eax, dword ptr fs:[00000030h] | 15_2_00D49080 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC3884 mov eax, dword ptr fs:[00000030h] | 15_2_00DC3884 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC3884 mov eax, dword ptr fs:[00000030h] | 15_2_00DC3884 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7F0BF mov ecx, dword ptr fs:[00000030h] | 15_2_00D7F0BF |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7F0BF mov eax, dword ptr fs:[00000030h] | 15_2_00D7F0BF |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7F0BF mov eax, dword ptr fs:[00000030h] | 15_2_00D7F0BF |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D890AF mov eax, dword ptr fs:[00000030h] | 15_2_00D890AF |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D720A0 mov eax, dword ptr fs:[00000030h] | 15_2_00D720A0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D720A0 mov eax, dword ptr fs:[00000030h] | 15_2_00D720A0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D720A0 mov eax, dword ptr fs:[00000030h] | 15_2_00D720A0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D720A0 mov eax, dword ptr fs:[00000030h] | 15_2_00D720A0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D720A0 mov eax, dword ptr fs:[00000030h] | 15_2_00D720A0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D720A0 mov eax, dword ptr fs:[00000030h] | 15_2_00D720A0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D60050 mov eax, dword ptr fs:[00000030h] | 15_2_00D60050 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D60050 mov eax, dword ptr fs:[00000030h] | 15_2_00D60050 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DDC450 mov eax, dword ptr fs:[00000030h] | 15_2_00DDC450 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DDC450 mov eax, dword ptr fs:[00000030h] | 15_2_00DDC450 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E02073 mov eax, dword ptr fs:[00000030h] | 15_2_00E02073 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E11074 mov eax, dword ptr fs:[00000030h] | 15_2_00E11074 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7A44B mov eax, dword ptr fs:[00000030h] | 15_2_00D7A44B |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D6746D mov eax, dword ptr fs:[00000030h] | 15_2_00D6746D |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC7016 mov eax, dword ptr fs:[00000030h] | 15_2_00DC7016 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC7016 mov eax, dword ptr fs:[00000030h] | 15_2_00DC7016 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC7016 mov eax, dword ptr fs:[00000030h] | 15_2_00DC7016 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC6C0A mov eax, dword ptr fs:[00000030h] | 15_2_00DC6C0A |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC6C0A mov eax, dword ptr fs:[00000030h] | 15_2_00DC6C0A |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC6C0A mov eax, dword ptr fs:[00000030h] | 15_2_00DC6C0A |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC6C0A mov eax, dword ptr fs:[00000030h] | 15_2_00DC6C0A |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E01C06 mov eax, dword ptr fs:[00000030h] | 15_2_00E01C06 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E01C06 mov eax, dword ptr fs:[00000030h] | 15_2_00E01C06 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E01C06 mov eax, dword ptr fs:[00000030h] | 15_2_00E01C06 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E01C06 mov eax, dword ptr fs:[00000030h] | 15_2_00E01C06 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E01C06 mov eax, dword ptr fs:[00000030h] | 15_2_00E01C06 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E01C06 mov eax, dword ptr fs:[00000030h] | 15_2_00E01C06 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E01C06 mov eax, dword ptr fs:[00000030h] | 15_2_00E01C06 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E01C06 mov eax, dword ptr fs:[00000030h] | 15_2_00E01C06 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E01C06 mov eax, dword ptr fs:[00000030h] | 15_2_00E01C06 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E01C06 mov eax, dword ptr fs:[00000030h] | 15_2_00E01C06 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E01C06 mov eax, dword ptr fs:[00000030h] | 15_2_00E01C06 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E01C06 mov eax, dword ptr fs:[00000030h] | 15_2_00E01C06 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E01C06 mov eax, dword ptr fs:[00000030h] | 15_2_00E01C06 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E01C06 mov eax, dword ptr fs:[00000030h] | 15_2_00E01C06 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E1740D mov eax, dword ptr fs:[00000030h] | 15_2_00E1740D |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E1740D mov eax, dword ptr fs:[00000030h] | 15_2_00E1740D |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E1740D mov eax, dword ptr fs:[00000030h] | 15_2_00E1740D |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E14015 mov eax, dword ptr fs:[00000030h] | 15_2_00E14015 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E14015 mov eax, dword ptr fs:[00000030h] | 15_2_00E14015 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7002D mov eax, dword ptr fs:[00000030h] | 15_2_00D7002D |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7002D mov eax, dword ptr fs:[00000030h] | 15_2_00D7002D |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7002D mov eax, dword ptr fs:[00000030h] | 15_2_00D7002D |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7002D mov eax, dword ptr fs:[00000030h] | 15_2_00D7002D |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7002D mov eax, dword ptr fs:[00000030h] | 15_2_00D7002D |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7BC2C mov eax, dword ptr fs:[00000030h] | 15_2_00D7BC2C |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D5B02A mov eax, dword ptr fs:[00000030h] | 15_2_00D5B02A |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D5B02A mov eax, dword ptr fs:[00000030h] | 15_2_00D5B02A |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D5B02A mov eax, dword ptr fs:[00000030h] | 15_2_00D5B02A |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D5B02A mov eax, dword ptr fs:[00000030h] | 15_2_00D5B02A |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E0FDE2 mov eax, dword ptr fs:[00000030h] | 15_2_00E0FDE2 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E0FDE2 mov eax, dword ptr fs:[00000030h] | 15_2_00E0FDE2 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E0FDE2 mov eax, dword ptr fs:[00000030h] | 15_2_00E0FDE2 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E0FDE2 mov eax, dword ptr fs:[00000030h] | 15_2_00E0FDE2 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC6DC9 mov eax, dword ptr fs:[00000030h] | 15_2_00DC6DC9 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC6DC9 mov eax, dword ptr fs:[00000030h] | 15_2_00DC6DC9 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC6DC9 mov eax, dword ptr fs:[00000030h] | 15_2_00DC6DC9 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC6DC9 mov ecx, dword ptr fs:[00000030h] | 15_2_00DC6DC9 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC6DC9 mov eax, dword ptr fs:[00000030h] | 15_2_00DC6DC9 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC6DC9 mov eax, dword ptr fs:[00000030h] | 15_2_00DC6DC9 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DF8DF1 mov eax, dword ptr fs:[00000030h] | 15_2_00DF8DF1 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D4B1E1 mov eax, dword ptr fs:[00000030h] | 15_2_00D4B1E1 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D4B1E1 mov eax, dword ptr fs:[00000030h] | 15_2_00D4B1E1 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D4B1E1 mov eax, dword ptr fs:[00000030h] | 15_2_00D4B1E1 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DD41E8 mov eax, dword ptr fs:[00000030h] | 15_2_00DD41E8 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D5D5E0 mov eax, dword ptr fs:[00000030h] | 15_2_00D5D5E0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D5D5E0 mov eax, dword ptr fs:[00000030h] | 15_2_00D5D5E0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D72990 mov eax, dword ptr fs:[00000030h] | 15_2_00D72990 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7FD9B mov eax, dword ptr fs:[00000030h] | 15_2_00D7FD9B |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7FD9B mov eax, dword ptr fs:[00000030h] | 15_2_00D7FD9B |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E105AC mov eax, dword ptr fs:[00000030h] | 15_2_00E105AC |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E105AC mov eax, dword ptr fs:[00000030h] | 15_2_00E105AC |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7A185 mov eax, dword ptr fs:[00000030h] | 15_2_00D7A185 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D6C182 mov eax, dword ptr fs:[00000030h] | 15_2_00D6C182 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D72581 mov eax, dword ptr fs:[00000030h] | 15_2_00D72581 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D72581 mov eax, dword ptr fs:[00000030h] | 15_2_00D72581 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D72581 mov eax, dword ptr fs:[00000030h] | 15_2_00D72581 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D72581 mov eax, dword ptr fs:[00000030h] | 15_2_00D72581 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D42D8A mov eax, dword ptr fs:[00000030h] | 15_2_00D42D8A |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D42D8A mov eax, dword ptr fs:[00000030h] | 15_2_00D42D8A |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D42D8A mov eax, dword ptr fs:[00000030h] | 15_2_00D42D8A |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D42D8A mov eax, dword ptr fs:[00000030h] | 15_2_00D42D8A |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D42D8A mov eax, dword ptr fs:[00000030h] | 15_2_00D42D8A |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D71DB5 mov eax, dword ptr fs:[00000030h] | 15_2_00D71DB5 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D71DB5 mov eax, dword ptr fs:[00000030h] | 15_2_00D71DB5 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D71DB5 mov eax, dword ptr fs:[00000030h] | 15_2_00D71DB5 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC51BE mov eax, dword ptr fs:[00000030h] | 15_2_00DC51BE |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC51BE mov eax, dword ptr fs:[00000030h] | 15_2_00DC51BE |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC51BE mov eax, dword ptr fs:[00000030h] | 15_2_00DC51BE |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC51BE mov eax, dword ptr fs:[00000030h] | 15_2_00DC51BE |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D735A1 mov eax, dword ptr fs:[00000030h] | 15_2_00D735A1 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D761A0 mov eax, dword ptr fs:[00000030h] | 15_2_00D761A0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D761A0 mov eax, dword ptr fs:[00000030h] | 15_2_00D761A0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC69A6 mov eax, dword ptr fs:[00000030h] | 15_2_00DC69A6 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D67D50 mov eax, dword ptr fs:[00000030h] | 15_2_00D67D50 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D6B944 mov eax, dword ptr fs:[00000030h] | 15_2_00D6B944 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D6B944 mov eax, dword ptr fs:[00000030h] | 15_2_00D6B944 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D83D43 mov eax, dword ptr fs:[00000030h] | 15_2_00D83D43 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC3540 mov eax, dword ptr fs:[00000030h] | 15_2_00DC3540 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D6C577 mov eax, dword ptr fs:[00000030h] | 15_2_00D6C577 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D6C577 mov eax, dword ptr fs:[00000030h] | 15_2_00D6C577 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D4B171 mov eax, dword ptr fs:[00000030h] | 15_2_00D4B171 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D4B171 mov eax, dword ptr fs:[00000030h] | 15_2_00D4B171 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D4C962 mov eax, dword ptr fs:[00000030h] | 15_2_00D4C962 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D49100 mov eax, dword ptr fs:[00000030h] | 15_2_00D49100 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D49100 mov eax, dword ptr fs:[00000030h] | 15_2_00D49100 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D49100 mov eax, dword ptr fs:[00000030h] | 15_2_00D49100 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E18D34 mov eax, dword ptr fs:[00000030h] | 15_2_00E18D34 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D53D34 mov eax, dword ptr fs:[00000030h] | 15_2_00D53D34 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D53D34 mov eax, dword ptr fs:[00000030h] | 15_2_00D53D34 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D53D34 mov eax, dword ptr fs:[00000030h] | 15_2_00D53D34 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D53D34 mov eax, dword ptr fs:[00000030h] | 15_2_00D53D34 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D53D34 mov eax, dword ptr fs:[00000030h] | 15_2_00D53D34 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D53D34 mov eax, dword ptr fs:[00000030h] | 15_2_00D53D34 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D53D34 mov eax, dword ptr fs:[00000030h] | 15_2_00D53D34 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D53D34 mov eax, dword ptr fs:[00000030h] | 15_2_00D53D34 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D53D34 mov eax, dword ptr fs:[00000030h] | 15_2_00D53D34 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D53D34 mov eax, dword ptr fs:[00000030h] | 15_2_00D53D34 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D53D34 mov eax, dword ptr fs:[00000030h] | 15_2_00D53D34 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D53D34 mov eax, dword ptr fs:[00000030h] | 15_2_00D53D34 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D53D34 mov eax, dword ptr fs:[00000030h] | 15_2_00D53D34 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D4AD30 mov eax, dword ptr fs:[00000030h] | 15_2_00D4AD30 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DCA537 mov eax, dword ptr fs:[00000030h] | 15_2_00DCA537 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D74D3B mov eax, dword ptr fs:[00000030h] | 15_2_00D74D3B |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D74D3B mov eax, dword ptr fs:[00000030h] | 15_2_00D74D3B |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D74D3B mov eax, dword ptr fs:[00000030h] | 15_2_00D74D3B |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7513A mov eax, dword ptr fs:[00000030h] | 15_2_00D7513A |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7513A mov eax, dword ptr fs:[00000030h] | 15_2_00D7513A |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D64120 mov eax, dword ptr fs:[00000030h] | 15_2_00D64120 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D64120 mov eax, dword ptr fs:[00000030h] | 15_2_00D64120 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D64120 mov eax, dword ptr fs:[00000030h] | 15_2_00D64120 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D64120 mov eax, dword ptr fs:[00000030h] | 15_2_00D64120 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D64120 mov ecx, dword ptr fs:[00000030h] | 15_2_00D64120 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D736CC mov eax, dword ptr fs:[00000030h] | 15_2_00D736CC |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D72ACB mov eax, dword ptr fs:[00000030h] | 15_2_00D72ACB |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DFFEC0 mov eax, dword ptr fs:[00000030h] | 15_2_00DFFEC0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D88EC7 mov eax, dword ptr fs:[00000030h] | 15_2_00D88EC7 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D72AE4 mov eax, dword ptr fs:[00000030h] | 15_2_00D72AE4 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D716E0 mov ecx, dword ptr fs:[00000030h] | 15_2_00D716E0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E18ED6 mov eax, dword ptr fs:[00000030h] | 15_2_00E18ED6 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D576E2 mov eax, dword ptr fs:[00000030h] | 15_2_00D576E2 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7D294 mov eax, dword ptr fs:[00000030h] | 15_2_00D7D294 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7D294 mov eax, dword ptr fs:[00000030h] | 15_2_00D7D294 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E10EA5 mov eax, dword ptr fs:[00000030h] | 15_2_00E10EA5 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E10EA5 mov eax, dword ptr fs:[00000030h] | 15_2_00E10EA5 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E10EA5 mov eax, dword ptr fs:[00000030h] | 15_2_00E10EA5 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DDFE87 mov eax, dword ptr fs:[00000030h] | 15_2_00DDFE87 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D5AAB0 mov eax, dword ptr fs:[00000030h] | 15_2_00D5AAB0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D5AAB0 mov eax, dword ptr fs:[00000030h] | 15_2_00D5AAB0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7FAB0 mov eax, dword ptr fs:[00000030h] | 15_2_00D7FAB0 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D452A5 mov eax, dword ptr fs:[00000030h] | 15_2_00D452A5 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D452A5 mov eax, dword ptr fs:[00000030h] | 15_2_00D452A5 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D452A5 mov eax, dword ptr fs:[00000030h] | 15_2_00D452A5 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D452A5 mov eax, dword ptr fs:[00000030h] | 15_2_00D452A5 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D452A5 mov eax, dword ptr fs:[00000030h] | 15_2_00D452A5 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC46A7 mov eax, dword ptr fs:[00000030h] | 15_2_00DC46A7 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E18A62 mov eax, dword ptr fs:[00000030h] | 15_2_00E18A62 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DD4257 mov eax, dword ptr fs:[00000030h] | 15_2_00DD4257 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D49240 mov eax, dword ptr fs:[00000030h] | 15_2_00D49240 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D49240 mov eax, dword ptr fs:[00000030h] | 15_2_00D49240 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D49240 mov eax, dword ptr fs:[00000030h] | 15_2_00D49240 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D49240 mov eax, dword ptr fs:[00000030h] | 15_2_00D49240 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D57E41 mov eax, dword ptr fs:[00000030h] | 15_2_00D57E41 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D57E41 mov eax, dword ptr fs:[00000030h] | 15_2_00D57E41 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D57E41 mov eax, dword ptr fs:[00000030h] | 15_2_00D57E41 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D57E41 mov eax, dword ptr fs:[00000030h] | 15_2_00D57E41 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D57E41 mov eax, dword ptr fs:[00000030h] | 15_2_00D57E41 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D57E41 mov eax, dword ptr fs:[00000030h] | 15_2_00D57E41 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D8927A mov eax, dword ptr fs:[00000030h] | 15_2_00D8927A |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D6AE73 mov eax, dword ptr fs:[00000030h] | 15_2_00D6AE73 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D6AE73 mov eax, dword ptr fs:[00000030h] | 15_2_00D6AE73 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D6AE73 mov eax, dword ptr fs:[00000030h] | 15_2_00D6AE73 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D6AE73 mov eax, dword ptr fs:[00000030h] | 15_2_00D6AE73 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D6AE73 mov eax, dword ptr fs:[00000030h] | 15_2_00D6AE73 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E0EA55 mov eax, dword ptr fs:[00000030h] | 15_2_00E0EA55 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D5766D mov eax, dword ptr fs:[00000030h] | 15_2_00D5766D |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DFB260 mov eax, dword ptr fs:[00000030h] | 15_2_00DFB260 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DFB260 mov eax, dword ptr fs:[00000030h] | 15_2_00DFB260 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D4AA16 mov eax, dword ptr fs:[00000030h] | 15_2_00D4AA16 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D4AA16 mov eax, dword ptr fs:[00000030h] | 15_2_00D4AA16 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D45210 mov eax, dword ptr fs:[00000030h] | 15_2_00D45210 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D45210 mov ecx, dword ptr fs:[00000030h] | 15_2_00D45210 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D45210 mov eax, dword ptr fs:[00000030h] | 15_2_00D45210 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D45210 mov eax, dword ptr fs:[00000030h] | 15_2_00D45210 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D63A1C mov eax, dword ptr fs:[00000030h] | 15_2_00D63A1C |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7A61C mov eax, dword ptr fs:[00000030h] | 15_2_00D7A61C |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7A61C mov eax, dword ptr fs:[00000030h] | 15_2_00D7A61C |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D4C600 mov eax, dword ptr fs:[00000030h] | 15_2_00D4C600 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D4C600 mov eax, dword ptr fs:[00000030h] | 15_2_00D4C600 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D4C600 mov eax, dword ptr fs:[00000030h] | 15_2_00D4C600 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D78E00 mov eax, dword ptr fs:[00000030h] | 15_2_00D78E00 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D58A0A mov eax, dword ptr fs:[00000030h] | 15_2_00D58A0A |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DFFE3F mov eax, dword ptr fs:[00000030h] | 15_2_00DFFE3F |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E01608 mov eax, dword ptr fs:[00000030h] | 15_2_00E01608 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D4E620 mov eax, dword ptr fs:[00000030h] | 15_2_00D4E620 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D84A2C mov eax, dword ptr fs:[00000030h] | 15_2_00D84A2C |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D84A2C mov eax, dword ptr fs:[00000030h] | 15_2_00D84A2C |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC53CA mov eax, dword ptr fs:[00000030h] | 15_2_00DC53CA |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC53CA mov eax, dword ptr fs:[00000030h] | 15_2_00DC53CA |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D837F5 mov eax, dword ptr fs:[00000030h] | 15_2_00D837F5 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D703E2 mov eax, dword ptr fs:[00000030h] | 15_2_00D703E2 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D703E2 mov eax, dword ptr fs:[00000030h] | 15_2_00D703E2 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D703E2 mov eax, dword ptr fs:[00000030h] | 15_2_00D703E2 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D703E2 mov eax, dword ptr fs:[00000030h] | 15_2_00D703E2 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D703E2 mov eax, dword ptr fs:[00000030h] | 15_2_00D703E2 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D703E2 mov eax, dword ptr fs:[00000030h] | 15_2_00D703E2 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D6DBE9 mov eax, dword ptr fs:[00000030h] | 15_2_00D6DBE9 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D72397 mov eax, dword ptr fs:[00000030h] | 15_2_00D72397 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D58794 mov eax, dword ptr fs:[00000030h] | 15_2_00D58794 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E15BA5 mov eax, dword ptr fs:[00000030h] | 15_2_00E15BA5 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7B390 mov eax, dword ptr fs:[00000030h] | 15_2_00D7B390 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC7794 mov eax, dword ptr fs:[00000030h] | 15_2_00DC7794 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC7794 mov eax, dword ptr fs:[00000030h] | 15_2_00DC7794 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DC7794 mov eax, dword ptr fs:[00000030h] | 15_2_00DC7794 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D51B8F mov eax, dword ptr fs:[00000030h] | 15_2_00D51B8F |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D51B8F mov eax, dword ptr fs:[00000030h] | 15_2_00D51B8F |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DFD380 mov ecx, dword ptr fs:[00000030h] | 15_2_00DFD380 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E0138A mov eax, dword ptr fs:[00000030h] | 15_2_00E0138A |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D74BAD mov eax, dword ptr fs:[00000030h] | 15_2_00D74BAD |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D74BAD mov eax, dword ptr fs:[00000030h] | 15_2_00D74BAD |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D74BAD mov eax, dword ptr fs:[00000030h] | 15_2_00D74BAD |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E18F6A mov eax, dword ptr fs:[00000030h] | 15_2_00E18F6A |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D4F358 mov eax, dword ptr fs:[00000030h] | 15_2_00D4F358 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D4DB40 mov eax, dword ptr fs:[00000030h] | 15_2_00D4DB40 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D5EF40 mov eax, dword ptr fs:[00000030h] | 15_2_00D5EF40 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D73B7A mov eax, dword ptr fs:[00000030h] | 15_2_00D73B7A |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D73B7A mov eax, dword ptr fs:[00000030h] | 15_2_00D73B7A |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D4DB60 mov ecx, dword ptr fs:[00000030h] | 15_2_00D4DB60 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D5FF60 mov eax, dword ptr fs:[00000030h] | 15_2_00D5FF60 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E18B58 mov eax, dword ptr fs:[00000030h] | 15_2_00E18B58 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D6F716 mov eax, dword ptr fs:[00000030h] | 15_2_00D6F716 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DDFF10 mov eax, dword ptr fs:[00000030h] | 15_2_00DDFF10 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00DDFF10 mov eax, dword ptr fs:[00000030h] | 15_2_00DDFF10 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7A70E mov eax, dword ptr fs:[00000030h] | 15_2_00D7A70E |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7A70E mov eax, dword ptr fs:[00000030h] | 15_2_00D7A70E |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D7E730 mov eax, dword ptr fs:[00000030h] | 15_2_00D7E730 |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E1070D mov eax, dword ptr fs:[00000030h] | 15_2_00E1070D |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E1070D mov eax, dword ptr fs:[00000030h] | 15_2_00E1070D |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D44F2E mov eax, dword ptr fs:[00000030h] | 15_2_00D44F2E |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00D44F2E mov eax, dword ptr fs:[00000030h] | 15_2_00D44F2E |
Source: C:\Windows\SysWOW64\netsh.exe | Code function: 15_2_00E0131B mov eax, dword ptr fs:[00000030h] | 15_2_00E0131B |