Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_0040560F |
1_2_0040560F |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_00401C10 |
1_2_00401C10 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C06AA2 |
1_2_02C06AA2 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C05AD5 |
1_2_02C05AD5 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C056DD |
1_2_02C056DD |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C012F1 |
1_2_02C012F1 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0A6F1 |
1_2_02C0A6F1 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C032F5 |
1_2_02C032F5 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C00EF7 |
1_2_02C00EF7 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C046A1 |
1_2_02C046A1 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0A6A5 |
1_2_02C0A6A5 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C06AA7 |
1_2_02C06AA7 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C016A9 |
1_2_02C016A9 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0A6AA |
1_2_02C0A6AA |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C072AF |
1_2_02C072AF |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C066B0 |
1_2_02C066B0 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C09EB3 |
1_2_02C09EB3 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C052B7 |
1_2_02C052B7 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C066BB |
1_2_02C066BB |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C04645 |
1_2_02C04645 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0AA45 |
1_2_02C0AA45 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C01E4B |
1_2_02C01E4B |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C05A4E |
1_2_02C05A4E |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0565F |
1_2_02C0565F |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C03A6A |
1_2_02C03A6A |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C01E6D |
1_2_02C01E6D |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0AA7E |
1_2_02C0AA7E |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0521E |
1_2_02C0521E |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0162D |
1_2_02C0162D |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C07231 |
1_2_02C07231 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0A63C |
1_2_02C0A63C |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C037D5 |
1_2_02C037D5 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C037D7 |
1_2_02C037D7 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C05BE0 |
1_2_02C05BE0 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C013E9 |
1_2_02C013E9 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C03BEF |
1_2_02C03BEF |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0A6A5 |
1_2_02C0A6A5 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C05B85 |
1_2_02C05B85 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0A796 |
1_2_02C0A796 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C053B9 |
1_2_02C053B9 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0A7BA |
1_2_02C0A7BA |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0A752 |
1_2_02C0A752 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C05763 |
1_2_02C05763 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C03B66 |
1_2_02C03B66 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0136A |
1_2_02C0136A |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C06F78 |
1_2_02C06F78 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C05300 |
1_2_02C05300 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0AB0D |
1_2_02C0AB0D |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C03B0E |
1_2_02C03B0E |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C01729 |
1_2_02C01729 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0333E |
1_2_02C0333E |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C008C8 |
1_2_02C008C8 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C038C9 |
1_2_02C038C9 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0A8D9 |
1_2_02C0A8D9 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C058E4 |
1_2_02C058E4 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C070E6 |
1_2_02C070E6 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C044EA |
1_2_02C044EA |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C058F6 |
1_2_02C058F6 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C06AA2 |
1_2_02C06AA2 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C07085 |
1_2_02C07085 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0108B |
1_2_02C0108B |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C05099 |
1_2_02C05099 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C054B0 |
1_2_02C054B0 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C014B5 |
1_2_02C014B5 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0A842 |
1_2_02C0A842 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C01446 |
1_2_02C01446 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C03846 |
1_2_02C03846 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C08453 |
1_2_02C08453 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C05C6C |
1_2_02C05C6C |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C07077 |
1_2_02C07077 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0587D |
1_2_02C0587D |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C01001 |
1_2_02C01001 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C05812 |
1_2_02C05812 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0543B |
1_2_02C0543B |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C055C5 |
1_2_02C055C5 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C00DCB |
1_2_02C00DCB |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C071CE |
1_2_02C071CE |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C039D3 |
1_2_02C039D3 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C071D5 |
1_2_02C071D5 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0B5E7 |
1_2_02C0B5E7 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C011ED |
1_2_02C011ED |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C00DFF |
1_2_02C00DFF |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C05185 |
1_2_02C05185 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C07194 |
1_2_02C07194 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C045A3 |
1_2_02C045A3 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C015AF |
1_2_02C015AF |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0A9B7 |
1_2_02C0A9B7 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C059BD |
1_2_02C059BD |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0A942 |
1_2_02C0A942 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C05555 |
1_2_02C05555 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0B55A |
1_2_02C0B55A |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0395D |
1_2_02C0395D |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C01562 |
1_2_02C01562 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0B56A |
1_2_02C0B56A |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C01179 |
1_2_02C01179 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C05D06 |
1_2_02C05D06 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0A90B |
1_2_02C0A90B |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C04515 |
1_2_02C04515 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0111D |
1_2_02C0111D |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0AD1E |
1_2_02C0AD1E |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C05923 |
1_2_02C05923 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C05125 |
1_2_02C05125 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C032F5 |
1_2_02C032F5 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0A6A5 |
1_2_02C0A6A5 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C052B7 |
1_2_02C052B7 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C03A6A |
1_2_02C03A6A |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0521E |
1_2_02C0521E |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C037D5 |
1_2_02C037D5 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C037D7 |
1_2_02C037D7 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0A6A5 |
1_2_02C0A6A5 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C05300 |
1_2_02C05300 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C038C9 |
1_2_02C038C9 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C05099 |
1_2_02C05099 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C03846 |
1_2_02C03846 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C08453 |
1_2_02C08453 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C00DCB |
1_2_02C00DCB |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C039D3 |
1_2_02C039D3 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C05185 |
1_2_02C05185 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0AD9B |
1_2_02C0AD9B |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0395D |
1_2_02C0395D |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0AD1E |
1_2_02C0AD1E |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C05125 |
1_2_02C05125 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
RDTSC instruction interceptor: First address: 0000000002C098FF second address: 0000000002C098FF instructions: 0x00000000 rdtsc 0x00000002 lfence 0x00000005 shl edx, 20h 0x00000008 or edx, eax 0x0000000a popad 0x0000000b mov byte ptr [edx+ecx], al 0x0000000e inc ecx 0x0000000f jne 00007F366037329Dh 0x00000011 mov al, byte ptr [edx+ecx] 0x00000014 add ebx, esi 0x00000016 xor al, byte ptr [ebx] 0x00000018 sub ebx, esi 0x0000001a inc ebx 0x0000001b jne 00007F36603732C6h 0x0000001d pushad 0x0000001e lfence 0x00000021 rdtsc |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
RDTSC instruction interceptor: First address: 0000000002C09FB8 second address: 0000000002C09FB8 instructions: |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
RDTSC instruction interceptor: First address: 0000000002C09CD6 second address: 0000000002C09CD6 instructions: 0x00000000 rdtsc 0x00000002 mov eax, 35C87548h 0x00000007 xor eax, 95C7301Ch 0x0000000c add eax, 0F544615h 0x00000011 add eax, 509C7498h 0x00000016 cpuid 0x00000018 jmp 00007F36603732FAh 0x0000001a cmp cl, cl 0x0000001c popad 0x0000001d call 00007F36603732C8h 0x00000022 lfence 0x00000025 mov edx, D838CC93h 0x0000002a add edx, 4B48768Eh 0x00000030 add edx, CBB48C4Bh 0x00000036 xor edx, 90CBCF78h 0x0000003c mov edx, dword ptr [edx] 0x0000003e lfence 0x00000041 jmp 00007F36603732FAh 0x00000043 cmp edx, C46AF604h 0x00000049 ret 0x0000004a sub edx, esi 0x0000004c ret 0x0000004d cmp bx, bx 0x00000050 add edi, edx 0x00000052 dec dword ptr [ebp+000000F8h] 0x00000058 cmp dword ptr [ebp+000000F8h], 00000000h 0x0000005f jne 00007F36603732A9h 0x00000061 call 00007F3660373322h 0x00000066 call 00007F3660373325h 0x0000006b lfence 0x0000006e mov edx, D838CC93h 0x00000073 add edx, 4B48768Eh 0x00000079 add edx, CBB48C4Bh 0x0000007f xor edx, 90CBCF78h 0x00000085 mov edx, dword ptr [edx] 0x00000087 lfence 0x0000008a jmp 00007F36603732FAh 0x0000008c cmp edx, C46AF604h 0x00000092 ret 0x00000093 mov esi, edx 0x00000095 pushad 0x00000096 rdtsc |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0A6F1 mov eax, dword ptr fs:[00000030h] |
1_2_02C0A6F1 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0A6A5 mov eax, dword ptr fs:[00000030h] |
1_2_02C0A6A5 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0A6AA mov eax, dword ptr fs:[00000030h] |
1_2_02C0A6AA |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0A63C mov eax, dword ptr fs:[00000030h] |
1_2_02C0A63C |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C08FC3 mov eax, dword ptr fs:[00000030h] |
1_2_02C08FC3 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C037D5 mov eax, dword ptr fs:[00000030h] |
1_2_02C037D5 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0A6A5 mov eax, dword ptr fs:[00000030h] |
1_2_02C0A6A5 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0A796 mov eax, dword ptr fs:[00000030h] |
1_2_02C0A796 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C0A752 mov eax, dword ptr fs:[00000030h] |
1_2_02C0A752 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C044EA mov eax, dword ptr fs:[00000030h] |
1_2_02C044EA |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C09956 mov eax, dword ptr fs:[00000030h] |
1_2_02C09956 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C06570 mov eax, dword ptr fs:[00000030h] |
1_2_02C06570 |
Source: C:\Users\user\Desktop\2FQhmYZME4.exe |
Code function: 1_2_02C04515 mov eax, dword ptr fs:[00000030h] |
1_2_02C04515 |