Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02296EB1 NtUnmapViewOfSection, |
1_2_02296EB1 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02290715 EnumWindows,NtWriteVirtualMemory, |
1_2_02290715 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_0229292A NtWriteVirtualMemory, |
1_2_0229292A |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_0229350C NtAllocateVirtualMemory, |
1_2_0229350C |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02296962 NtProtectVirtualMemory, |
1_2_02296962 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02293636 NtAllocateVirtualMemory, |
1_2_02293636 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_0229720A NtUnmapViewOfSection, |
1_2_0229720A |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02292A0C NtWriteVirtualMemory, |
1_2_02292A0C |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02297277 NtUnmapViewOfSection, |
1_2_02297277 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02292A5C NtWriteVirtualMemory, |
1_2_02292A5C |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02297257 NtUnmapViewOfSection, |
1_2_02297257 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02296EBE NtUnmapViewOfSection, |
1_2_02296EBE |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02292A8B NtWriteVirtualMemory, |
1_2_02292A8B |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_022972E0 NtUnmapViewOfSection, |
1_2_022972E0 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02292AD8 NtWriteVirtualMemory, |
1_2_02292AD8 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02296F38 NtUnmapViewOfSection, |
1_2_02296F38 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02292B32 NtWriteVirtualMemory, |
1_2_02292B32 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02292B6F NtWriteVirtualMemory, |
1_2_02292B6F |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02296F48 NtUnmapViewOfSection, |
1_2_02296F48 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02296FEA NtUnmapViewOfSection, |
1_2_02296FEA |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02292BD4 NtWriteVirtualMemory, |
1_2_02292BD4 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02293C23 NtWriteVirtualMemory, |
1_2_02293C23 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02292C0F NtWriteVirtualMemory, |
1_2_02292C0F |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_0229700E NtUnmapViewOfSection, |
1_2_0229700E |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02292C56 NtWriteVirtualMemory, |
1_2_02292C56 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02292CAE NtWriteVirtualMemory, |
1_2_02292CAE |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_022970B6 NtUnmapViewOfSection, |
1_2_022970B6 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02297087 NtUnmapViewOfSection, |
1_2_02297087 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_022970FB NtUnmapViewOfSection, |
1_2_022970FB |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02297130 NtUnmapViewOfSection, |
1_2_02297130 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_0229290F NtWriteVirtualMemory, |
1_2_0229290F |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02292D04 NtWriteVirtualMemory, |
1_2_02292D04 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_0229351C NtAllocateVirtualMemory, |
1_2_0229351C |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_0229194A NtWriteVirtualMemory, |
1_2_0229194A |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_0229714E NtUnmapViewOfSection, |
1_2_0229714E |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02292943 NtWriteVirtualMemory, |
1_2_02292943 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02292D5C NtWriteVirtualMemory, |
1_2_02292D5C |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02293554 NtAllocateVirtualMemory, |
1_2_02293554 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02292DA7 NtWriteVirtualMemory, |
1_2_02292DA7 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_022935A6 NtAllocateVirtualMemory, |
1_2_022935A6 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_022971BE NtUnmapViewOfSection, |
1_2_022971BE |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_0229299B NtWriteVirtualMemory, |
1_2_0229299B |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_022935E0 NtAllocateVirtualMemory, |
1_2_022935E0 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_022935D1 NtAllocateVirtualMemory, |
1_2_022935D1 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_022929D0 NtWriteVirtualMemory, |
1_2_022929D0 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_00566962 NtProtectVirtualMemory, |
13_2_00566962 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_0056350C NtAllocateVirtualMemory, |
13_2_0056350C |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_005609FB NtProtectVirtualMemory, |
13_2_005609FB |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_00566EB1 NtSetInformationThread, |
13_2_00566EB1 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_0056700E NtSetInformationThread, |
13_2_0056700E |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_005670FB NtSetInformationThread, |
13_2_005670FB |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_00567087 NtSetInformationThread, |
13_2_00567087 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_005670B6 NtSetInformationThread, |
13_2_005670B6 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_00563554 NtAllocateVirtualMemory, |
13_2_00563554 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_0056714E NtSetInformationThread, |
13_2_0056714E |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_0056351C NtAllocateVirtualMemory, |
13_2_0056351C |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_00567130 NtSetInformationThread, |
13_2_00567130 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_005635D1 NtAllocateVirtualMemory, |
13_2_005635D1 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_005635E0 NtAllocateVirtualMemory, |
13_2_005635E0 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_005671BE NtSetInformationThread, |
13_2_005671BE |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_005635A6 NtAllocateVirtualMemory, |
13_2_005635A6 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_00567257 NtSetInformationThread, |
13_2_00567257 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_00567277 NtSetInformationThread, |
13_2_00567277 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_0056720A NtSetInformationThread, |
13_2_0056720A |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_00563636 NtAllocateVirtualMemory, |
13_2_00563636 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_005672E0 NtSetInformationThread, |
13_2_005672E0 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_00566EBE NtSetInformationThread, |
13_2_00566EBE |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_00566F48 NtSetInformationThread, |
13_2_00566F48 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_00566F38 NtSetInformationThread, |
13_2_00566F38 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_00560FFA NtProtectVirtualMemory, |
13_2_00560FFA |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_00566FEA NtSetInformationThread, |
13_2_00566FEA |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_00560FAC NtProtectVirtualMemory, |
13_2_00560FAC |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_00560FA8 NtProtectVirtualMemory, |
13_2_00560FA8 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
RDTSC instruction interceptor: First address: 0000000002295F8A second address: 0000000002295F8A instructions: |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
RDTSC instruction interceptor: First address: 0000000002296025 second address: 0000000002296025 instructions: |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
RDTSC instruction interceptor: First address: 0000000002295F27 second address: 0000000002295F27 instructions: |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
RDTSC instruction interceptor: First address: 0000000002295D71 second address: 0000000002295D71 instructions: 0x00000000 rdtsc 0x00000002 xor eax, eax 0x00000004 inc eax 0x00000005 cpuid 0x00000007 popad 0x00000008 call 00007FDABC9E8338h 0x0000000d lfence 0x00000010 mov edx, dword ptr [7FFE0014h] 0x00000016 lfence 0x00000019 ret 0x0000001a sub edx, esi 0x0000001c ret 0x0000001d test cx, cx 0x00000020 test bh, dh 0x00000022 add edi, edx 0x00000024 cmp ah, dh 0x00000026 dec dword ptr [ebp+000000F8h] 0x0000002c cmp dx, bx 0x0000002f cmp dword ptr [ebp+000000F8h], 00000000h 0x00000036 jne 00007FDABC9E830Fh 0x00000038 cmp ax, bx 0x0000003b call 00007FDABC9E837Eh 0x00000040 call 00007FDABC9E8348h 0x00000045 lfence 0x00000048 mov edx, dword ptr [7FFE0014h] 0x0000004e lfence 0x00000051 ret 0x00000052 mov esi, edx 0x00000054 pushad 0x00000055 rdtsc |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
RDTSC instruction interceptor: First address: 0000000002293DBD second address: 0000000002293DBD instructions: |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
RDTSC instruction interceptor: First address: 0000000002295F8A second address: 0000000002295F8A instructions: |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
RDTSC instruction interceptor: First address: 0000000002296025 second address: 0000000002296025 instructions: |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
RDTSC instruction interceptor: First address: 0000000002295F27 second address: 0000000002295F27 instructions: |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
RDTSC instruction interceptor: First address: 0000000002295D71 second address: 0000000002295D71 instructions: 0x00000000 rdtsc 0x00000002 xor eax, eax 0x00000004 inc eax 0x00000005 cpuid 0x00000007 popad 0x00000008 call 00007FDABC9E8338h 0x0000000d lfence 0x00000010 mov edx, dword ptr [7FFE0014h] 0x00000016 lfence 0x00000019 ret 0x0000001a sub edx, esi 0x0000001c ret 0x0000001d test cx, cx 0x00000020 test bh, dh 0x00000022 add edi, edx 0x00000024 cmp ah, dh 0x00000026 dec dword ptr [ebp+000000F8h] 0x0000002c cmp dx, bx 0x0000002f cmp dword ptr [ebp+000000F8h], 00000000h 0x00000036 jne 00007FDABC9E830Fh 0x00000038 cmp ax, bx 0x0000003b call 00007FDABC9E837Eh 0x00000040 call 00007FDABC9E8348h 0x00000045 lfence 0x00000048 mov edx, dword ptr [7FFE0014h] 0x0000004e lfence 0x00000051 ret 0x00000052 mov esi, edx 0x00000054 pushad 0x00000055 rdtsc |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
RDTSC instruction interceptor: First address: 0000000002295DB1 second address: 0000000002295DB1 instructions: 0x00000000 rdtsc 0x00000002 lfence 0x00000005 shl edx, 20h 0x00000008 or edx, eax 0x0000000a ret 0x0000000b mov esi, edx 0x0000000d pushad 0x0000000e xor eax, eax 0x00000010 inc eax 0x00000011 cpuid 0x00000013 bt ecx, 1Fh 0x00000017 jc 00007FDABC9BB85Eh 0x0000001d popad 0x0000001e call 00007FDABC9BB41Bh 0x00000023 lfence 0x00000026 rdtsc |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
RDTSC instruction interceptor: First address: 0000000002293DBD second address: 0000000002293DBD instructions: |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
RDTSC instruction interceptor: First address: 0000000000565DB1 second address: 0000000000565DB1 instructions: 0x00000000 rdtsc 0x00000002 lfence 0x00000005 shl edx, 20h 0x00000008 or edx, eax 0x0000000a ret 0x0000000b mov esi, edx 0x0000000d pushad 0x0000000e xor eax, eax 0x00000010 inc eax 0x00000011 cpuid 0x00000013 bt ecx, 1Fh 0x00000017 jc 00007FDABC9BB85Eh 0x0000001d popad 0x0000001e call 00007FDABC9BB41Bh 0x00000023 lfence 0x00000026 rdtsc |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02295A88 mov eax, dword ptr fs:[00000030h] |
1_2_02295A88 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_022952C8 mov eax, dword ptr fs:[00000030h] |
1_2_022952C8 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_022952DA mov eax, dword ptr fs:[00000030h] |
1_2_022952DA |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_022923FC mov eax, dword ptr fs:[00000030h] |
1_2_022923FC |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_022963F1 mov eax, dword ptr fs:[00000030h] |
1_2_022963F1 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_022963F4 mov eax, dword ptr fs:[00000030h] |
1_2_022963F4 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02291BC7 mov eax, dword ptr fs:[00000030h] |
1_2_02291BC7 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02292415 mov eax, dword ptr fs:[00000030h] |
1_2_02292415 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02296416 mov eax, dword ptr fs:[00000030h] |
1_2_02296416 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_0229644C mov eax, dword ptr fs:[00000030h] |
1_2_0229644C |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_02292440 mov eax, dword ptr fs:[00000030h] |
1_2_02292440 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 1_2_022930E0 mov eax, dword ptr fs:[00000030h] |
1_2_022930E0 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_00562440 mov eax, dword ptr fs:[00000030h] |
13_2_00562440 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_0056644C mov eax, dword ptr fs:[00000030h] |
13_2_0056644C |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_00566416 mov eax, dword ptr fs:[00000030h] |
13_2_00566416 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_00562415 mov eax, dword ptr fs:[00000030h] |
13_2_00562415 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_005630E0 mov eax, dword ptr fs:[00000030h] |
13_2_005630E0 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_005652DA mov eax, dword ptr fs:[00000030h] |
13_2_005652DA |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_005652C8 mov eax, dword ptr fs:[00000030h] |
13_2_005652C8 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_00565A88 mov eax, dword ptr fs:[00000030h] |
13_2_00565A88 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_00561BC7 mov eax, dword ptr fs:[00000030h] |
13_2_00561BC7 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_005663F4 mov eax, dword ptr fs:[00000030h] |
13_2_005663F4 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_005663F1 mov eax, dword ptr fs:[00000030h] |
13_2_005663F1 |
Source: C:\Users\user\Desktop\shipping Document and Bill Of Landing.exe |
Code function: 13_2_005623FC mov eax, dword ptr fs:[00000030h] |
13_2_005623FC |