Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 4_2_0041A060 NtClose, |
4_2_0041A060 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 4_2_0041A110 NtAllocateVirtualMemory, |
4_2_0041A110 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 4_2_00419F30 NtCreateFile, |
4_2_00419F30 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 4_2_00419FE0 NtReadFile, |
4_2_00419FE0 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 4_2_0041A05A NtClose, |
4_2_0041A05A |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 4_2_0041A10A NtAllocateVirtualMemory, |
4_2_0041A10A |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC96E0 NtFreeVirtualMemory,LdrInitializeThunk, |
9_2_02AC96E0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC96D0 NtCreateKey,LdrInitializeThunk, |
9_2_02AC96D0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9660 NtAllocateVirtualMemory,LdrInitializeThunk, |
9_2_02AC9660 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9650 NtQueryValueKey,LdrInitializeThunk, |
9_2_02AC9650 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9A50 NtCreateFile,LdrInitializeThunk, |
9_2_02AC9A50 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9780 NtMapViewOfSection,LdrInitializeThunk, |
9_2_02AC9780 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9FE0 NtCreateMutant,LdrInitializeThunk, |
9_2_02AC9FE0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9710 NtQueryInformationToken,LdrInitializeThunk, |
9_2_02AC9710 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9860 NtQuerySystemInformation,LdrInitializeThunk, |
9_2_02AC9860 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9840 NtDelayExecution,LdrInitializeThunk, |
9_2_02AC9840 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC99A0 NtCreateSection,LdrInitializeThunk, |
9_2_02AC99A0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC95D0 NtClose,LdrInitializeThunk, |
9_2_02AC95D0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9910 NtAdjustPrivilegesToken,LdrInitializeThunk, |
9_2_02AC9910 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9540 NtReadFile,LdrInitializeThunk, |
9_2_02AC9540 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9A80 NtOpenDirectoryObject, |
9_2_02AC9A80 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9A20 NtResumeThread, |
9_2_02AC9A20 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9A00 NtProtectVirtualMemory, |
9_2_02AC9A00 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9610 NtEnumerateValueKey, |
9_2_02AC9610 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9A10 NtQuerySection, |
9_2_02AC9A10 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9670 NtQueryInformationProcess, |
9_2_02AC9670 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC97A0 NtUnmapViewOfSection, |
9_2_02AC97A0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02ACA3B0 NtGetContextThread, |
9_2_02ACA3B0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9730 NtQueryVirtualMemory, |
9_2_02AC9730 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9B00 NtSetValueKey, |
9_2_02AC9B00 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02ACA710 NtOpenProcessToken, |
9_2_02ACA710 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9760 NtOpenProcess, |
9_2_02AC9760 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9770 NtSetInformationFile, |
9_2_02AC9770 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02ACA770 NtOpenThread, |
9_2_02ACA770 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC98A0 NtWriteVirtualMemory, |
9_2_02AC98A0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC98F0 NtReadVirtualMemory, |
9_2_02AC98F0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9820 NtEnumerateKey, |
9_2_02AC9820 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02ACB040 NtSuspendThread, |
9_2_02ACB040 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC95F0 NtQueryInformationFile, |
9_2_02AC95F0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC99D0 NtCreateProcessEx, |
9_2_02AC99D0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9520 NtWaitForSingleObject, |
9_2_02AC9520 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02ACAD30 NtSetContextThread, |
9_2_02ACAD30 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9560 NtWriteFile, |
9_2_02AC9560 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC9950 NtQueueApcThread, |
9_2_02AC9950 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_0242A060 NtClose, |
9_2_0242A060 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_0242A110 NtAllocateVirtualMemory, |
9_2_0242A110 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02429F30 NtCreateFile, |
9_2_02429F30 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02429FE0 NtReadFile, |
9_2_02429FE0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_0242A05A NtClose, |
9_2_0242A05A |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_0242A10A NtAllocateVirtualMemory, |
9_2_0242A10A |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_00C82160 |
0_2_00C82160 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_00C81790 |
0_2_00C81790 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_00C8E7B8 |
0_2_00C8E7B8 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_00C85770 |
0_2_00C85770 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_00C80FF0 |
0_2_00C80FF0 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_00C850F8 |
0_2_00C850F8 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_00C82151 |
0_2_00C82151 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_00C85108 |
0_2_00C85108 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_00C85301 |
0_2_00C85301 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_00C85310 |
0_2_00C85310 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_00C80480 |
0_2_00C80480 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_00C80479 |
0_2_00C80479 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_00C85548 |
0_2_00C85548 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_00C85558 |
0_2_00C85558 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_00C81781 |
0_2_00C81781 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_00C85760 |
0_2_00C85760 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_00C84A69 |
0_2_00C84A69 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_00C84A78 |
0_2_00C84A78 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_00C84D69 |
0_2_00C84D69 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_00C83E80 |
0_2_00C83E80 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_00C83E71 |
0_2_00C83E71 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_00C80F48 |
0_2_00C80F48 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F309A0 |
0_2_09F309A0 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F3D288 |
0_2_09F3D288 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F39E14 |
0_2_09F39E14 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F30990 |
0_2_09F30990 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F39850 |
0_2_09F39850 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F35858 |
0_2_09F35858 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F39840 |
0_2_09F39840 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F35849 |
0_2_09F35849 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F30012 |
0_2_09F30012 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F373C0 |
0_2_09F373C0 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F373BD |
0_2_09F373BD |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F35BA3 |
0_2_09F35BA3 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F34BA2 |
0_2_09F34BA2 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F30398 |
0_2_09F30398 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F30389 |
0_2_09F30389 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F35358 |
0_2_09F35358 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F35348 |
0_2_09F35348 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F35AF7 |
0_2_09F35AF7 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F35AF8 |
0_2_09F35AF8 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F34AC0 |
0_2_09F34AC0 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F34ABF |
0_2_09F34ABF |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F30580 |
0_2_09F30580 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F37584 |
0_2_09F37584 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F30571 |
0_2_09F30571 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F36D61 |
0_2_09F36D61 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F36D68 |
0_2_09F36D68 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F31497 |
0_2_09F31497 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F31498 |
0_2_09F31498 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F39C57 |
0_2_09F39C57 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F39C58 |
0_2_09F39C58 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F35C31 |
0_2_09F35C31 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F307C0 |
0_2_09F307C0 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F307B0 |
0_2_09F307B0 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F33720 |
0_2_09F33720 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F39E83 |
0_2_09F39E83 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 0_2_09F39E65 |
0_2_09F39E65 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 4_2_00401030 |
4_2_00401030 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 4_2_0041E1CF |
4_2_0041E1CF |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 4_2_0041D23B |
4_2_0041D23B |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 4_2_00402D87 |
4_2_00402D87 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 4_2_00402D90 |
4_2_00402D90 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 4_2_00409E40 |
4_2_00409E40 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 4_2_0041D6CF |
4_2_0041D6CF |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 4_2_00402FB0 |
4_2_00402FB0 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe |
Code function: 4_2_0041BFB6 |
4_2_0041BFB6 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AA6E30 |
9_2_02AA6E30 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02ABEBB0 |
9_2_02ABEBB0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A9B090 |
9_2_02A9B090 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B41002 |
9_2_02B41002 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A9841F |
9_2_02A9841F |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB2581 |
9_2_02AB2581 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A9D5E0 |
9_2_02A9D5E0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A80D20 |
9_2_02A80D20 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AA4120 |
9_2_02AA4120 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A8F900 |
9_2_02A8F900 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B51D55 |
9_2_02B51D55 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_0242D23B |
9_2_0242D23B |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_0242E1CF |
9_2_0242E1CF |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02419E40 |
9_2_02419E40 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02412FB0 |
9_2_02412FB0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_0242BFB6 |
9_2_0242BFB6 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02412D87 |
9_2_02412D87 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02412D90 |
9_2_02412D90 |
Source: 00000009.00000002.925821980.0000000002410000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000009.00000002.925821980.0000000002410000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000004.00000002.729070321.0000000000B00000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000004.00000002.729070321.0000000000B00000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000004.00000002.728648868.0000000000400000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000004.00000002.728648868.0000000000400000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000004.00000002.729033636.0000000000AD0000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000004.00000002.729033636.0000000000AD0000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000000.00000002.676742229.00000000040C9000.00000004.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000000.00000002.676742229.00000000040C9000.00000004.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000009.00000002.925566371.00000000000D0000.00000004.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000009.00000002.925566371.00000000000D0000.00000004.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000004.00000000.671897283.0000000000400000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000004.00000000.671897283.0000000000400000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 4.0.GiG35Rwmz6.exe.400000.1.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 4.0.GiG35Rwmz6.exe.400000.1.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 4.2.GiG35Rwmz6.exe.400000.0.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 4.2.GiG35Rwmz6.exe.400000.0.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 4.0.GiG35Rwmz6.exe.400000.1.unpack, type: UNPACKEDPE |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 4.0.GiG35Rwmz6.exe.400000.1.unpack, type: UNPACKEDPE |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 4.2.GiG35Rwmz6.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 4.2.GiG35Rwmz6.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0.2.GiG35Rwmz6.exe.40c9950.2.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0.2.GiG35Rwmz6.exe.40c9950.2.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A852A5 mov eax, dword ptr fs:[00000030h] |
9_2_02A852A5 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A852A5 mov eax, dword ptr fs:[00000030h] |
9_2_02A852A5 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A852A5 mov eax, dword ptr fs:[00000030h] |
9_2_02A852A5 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A852A5 mov eax, dword ptr fs:[00000030h] |
9_2_02A852A5 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A852A5 mov eax, dword ptr fs:[00000030h] |
9_2_02A852A5 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B50EA5 mov eax, dword ptr fs:[00000030h] |
9_2_02B50EA5 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B50EA5 mov eax, dword ptr fs:[00000030h] |
9_2_02B50EA5 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B50EA5 mov eax, dword ptr fs:[00000030h] |
9_2_02B50EA5 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B046A7 mov eax, dword ptr fs:[00000030h] |
9_2_02B046A7 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A9AAB0 mov eax, dword ptr fs:[00000030h] |
9_2_02A9AAB0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A9AAB0 mov eax, dword ptr fs:[00000030h] |
9_2_02A9AAB0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02ABFAB0 mov eax, dword ptr fs:[00000030h] |
9_2_02ABFAB0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B1FE87 mov eax, dword ptr fs:[00000030h] |
9_2_02B1FE87 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02ABD294 mov eax, dword ptr fs:[00000030h] |
9_2_02ABD294 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02ABD294 mov eax, dword ptr fs:[00000030h] |
9_2_02ABD294 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB16E0 mov ecx, dword ptr fs:[00000030h] |
9_2_02AB16E0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A976E2 mov eax, dword ptr fs:[00000030h] |
9_2_02A976E2 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB2AE4 mov eax, dword ptr fs:[00000030h] |
9_2_02AB2AE4 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB2ACB mov eax, dword ptr fs:[00000030h] |
9_2_02AB2ACB |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B58ED6 mov eax, dword ptr fs:[00000030h] |
9_2_02B58ED6 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB36CC mov eax, dword ptr fs:[00000030h] |
9_2_02AB36CC |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC8EC7 mov eax, dword ptr fs:[00000030h] |
9_2_02AC8EC7 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B3FEC0 mov eax, dword ptr fs:[00000030h] |
9_2_02B3FEC0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A8E620 mov eax, dword ptr fs:[00000030h] |
9_2_02A8E620 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B3FE3F mov eax, dword ptr fs:[00000030h] |
9_2_02B3FE3F |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A98A0A mov eax, dword ptr fs:[00000030h] |
9_2_02A98A0A |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A8C600 mov eax, dword ptr fs:[00000030h] |
9_2_02A8C600 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A8C600 mov eax, dword ptr fs:[00000030h] |
9_2_02A8C600 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A8C600 mov eax, dword ptr fs:[00000030h] |
9_2_02A8C600 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB8E00 mov eax, dword ptr fs:[00000030h] |
9_2_02AB8E00 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AA3A1C mov eax, dword ptr fs:[00000030h] |
9_2_02AA3A1C |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02ABA61C mov eax, dword ptr fs:[00000030h] |
9_2_02ABA61C |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02ABA61C mov eax, dword ptr fs:[00000030h] |
9_2_02ABA61C |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A8AA16 mov eax, dword ptr fs:[00000030h] |
9_2_02A8AA16 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A8AA16 mov eax, dword ptr fs:[00000030h] |
9_2_02A8AA16 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A9766D mov eax, dword ptr fs:[00000030h] |
9_2_02A9766D |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B3B260 mov eax, dword ptr fs:[00000030h] |
9_2_02B3B260 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B3B260 mov eax, dword ptr fs:[00000030h] |
9_2_02B3B260 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC927A mov eax, dword ptr fs:[00000030h] |
9_2_02AC927A |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B58A62 mov eax, dword ptr fs:[00000030h] |
9_2_02B58A62 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AAAE73 mov eax, dword ptr fs:[00000030h] |
9_2_02AAAE73 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AAAE73 mov eax, dword ptr fs:[00000030h] |
9_2_02AAAE73 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AAAE73 mov eax, dword ptr fs:[00000030h] |
9_2_02AAAE73 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AAAE73 mov eax, dword ptr fs:[00000030h] |
9_2_02AAAE73 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AAAE73 mov eax, dword ptr fs:[00000030h] |
9_2_02AAAE73 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B14257 mov eax, dword ptr fs:[00000030h] |
9_2_02B14257 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A89240 mov eax, dword ptr fs:[00000030h] |
9_2_02A89240 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A89240 mov eax, dword ptr fs:[00000030h] |
9_2_02A89240 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A89240 mov eax, dword ptr fs:[00000030h] |
9_2_02A89240 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A89240 mov eax, dword ptr fs:[00000030h] |
9_2_02A89240 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A97E41 mov eax, dword ptr fs:[00000030h] |
9_2_02A97E41 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A97E41 mov eax, dword ptr fs:[00000030h] |
9_2_02A97E41 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A97E41 mov eax, dword ptr fs:[00000030h] |
9_2_02A97E41 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A97E41 mov eax, dword ptr fs:[00000030h] |
9_2_02A97E41 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A97E41 mov eax, dword ptr fs:[00000030h] |
9_2_02A97E41 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A97E41 mov eax, dword ptr fs:[00000030h] |
9_2_02A97E41 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B55BA5 mov eax, dword ptr fs:[00000030h] |
9_2_02B55BA5 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B07794 mov eax, dword ptr fs:[00000030h] |
9_2_02B07794 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B07794 mov eax, dword ptr fs:[00000030h] |
9_2_02B07794 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B07794 mov eax, dword ptr fs:[00000030h] |
9_2_02B07794 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A91B8F mov eax, dword ptr fs:[00000030h] |
9_2_02A91B8F |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A91B8F mov eax, dword ptr fs:[00000030h] |
9_2_02A91B8F |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B3D380 mov ecx, dword ptr fs:[00000030h] |
9_2_02B3D380 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02ABB390 mov eax, dword ptr fs:[00000030h] |
9_2_02ABB390 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A98794 mov eax, dword ptr fs:[00000030h] |
9_2_02A98794 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B4138A mov eax, dword ptr fs:[00000030h] |
9_2_02B4138A |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB03E2 mov eax, dword ptr fs:[00000030h] |
9_2_02AB03E2 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB03E2 mov eax, dword ptr fs:[00000030h] |
9_2_02AB03E2 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB03E2 mov eax, dword ptr fs:[00000030h] |
9_2_02AB03E2 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB03E2 mov eax, dword ptr fs:[00000030h] |
9_2_02AB03E2 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB03E2 mov eax, dword ptr fs:[00000030h] |
9_2_02AB03E2 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB03E2 mov eax, dword ptr fs:[00000030h] |
9_2_02AB03E2 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC37F5 mov eax, dword ptr fs:[00000030h] |
9_2_02AC37F5 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B053CA mov eax, dword ptr fs:[00000030h] |
9_2_02B053CA |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B053CA mov eax, dword ptr fs:[00000030h] |
9_2_02B053CA |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A84F2E mov eax, dword ptr fs:[00000030h] |
9_2_02A84F2E |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A84F2E mov eax, dword ptr fs:[00000030h] |
9_2_02A84F2E |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02ABE730 mov eax, dword ptr fs:[00000030h] |
9_2_02ABE730 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B1FF10 mov eax, dword ptr fs:[00000030h] |
9_2_02B1FF10 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B1FF10 mov eax, dword ptr fs:[00000030h] |
9_2_02B1FF10 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02ABA70E mov eax, dword ptr fs:[00000030h] |
9_2_02ABA70E |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02ABA70E mov eax, dword ptr fs:[00000030h] |
9_2_02ABA70E |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B4131B mov eax, dword ptr fs:[00000030h] |
9_2_02B4131B |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B5070D mov eax, dword ptr fs:[00000030h] |
9_2_02B5070D |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B5070D mov eax, dword ptr fs:[00000030h] |
9_2_02B5070D |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AAF716 mov eax, dword ptr fs:[00000030h] |
9_2_02AAF716 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A8DB60 mov ecx, dword ptr fs:[00000030h] |
9_2_02A8DB60 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A9FF60 mov eax, dword ptr fs:[00000030h] |
9_2_02A9FF60 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB3B7A mov eax, dword ptr fs:[00000030h] |
9_2_02AB3B7A |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB3B7A mov eax, dword ptr fs:[00000030h] |
9_2_02AB3B7A |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B58F6A mov eax, dword ptr fs:[00000030h] |
9_2_02B58F6A |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A8DB40 mov eax, dword ptr fs:[00000030h] |
9_2_02A8DB40 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A9EF40 mov eax, dword ptr fs:[00000030h] |
9_2_02A9EF40 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B58B58 mov eax, dword ptr fs:[00000030h] |
9_2_02B58B58 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A8F358 mov eax, dword ptr fs:[00000030h] |
9_2_02A8F358 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC90AF mov eax, dword ptr fs:[00000030h] |
9_2_02AC90AF |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02ABF0BF mov ecx, dword ptr fs:[00000030h] |
9_2_02ABF0BF |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02ABF0BF mov eax, dword ptr fs:[00000030h] |
9_2_02ABF0BF |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02ABF0BF mov eax, dword ptr fs:[00000030h] |
9_2_02ABF0BF |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A89080 mov eax, dword ptr fs:[00000030h] |
9_2_02A89080 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A9849B mov eax, dword ptr fs:[00000030h] |
9_2_02A9849B |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B03884 mov eax, dword ptr fs:[00000030h] |
9_2_02B03884 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B03884 mov eax, dword ptr fs:[00000030h] |
9_2_02B03884 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B06CF0 mov eax, dword ptr fs:[00000030h] |
9_2_02B06CF0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B06CF0 mov eax, dword ptr fs:[00000030h] |
9_2_02B06CF0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B06CF0 mov eax, dword ptr fs:[00000030h] |
9_2_02B06CF0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B414FB mov eax, dword ptr fs:[00000030h] |
9_2_02B414FB |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B1B8D0 mov eax, dword ptr fs:[00000030h] |
9_2_02B1B8D0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B1B8D0 mov ecx, dword ptr fs:[00000030h] |
9_2_02B1B8D0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B1B8D0 mov eax, dword ptr fs:[00000030h] |
9_2_02B1B8D0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B1B8D0 mov eax, dword ptr fs:[00000030h] |
9_2_02B1B8D0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B1B8D0 mov eax, dword ptr fs:[00000030h] |
9_2_02B1B8D0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B1B8D0 mov eax, dword ptr fs:[00000030h] |
9_2_02B1B8D0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B58CD6 mov eax, dword ptr fs:[00000030h] |
9_2_02B58CD6 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A9B02A mov eax, dword ptr fs:[00000030h] |
9_2_02A9B02A |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A9B02A mov eax, dword ptr fs:[00000030h] |
9_2_02A9B02A |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A9B02A mov eax, dword ptr fs:[00000030h] |
9_2_02A9B02A |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A9B02A mov eax, dword ptr fs:[00000030h] |
9_2_02A9B02A |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB002D mov eax, dword ptr fs:[00000030h] |
9_2_02AB002D |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB002D mov eax, dword ptr fs:[00000030h] |
9_2_02AB002D |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB002D mov eax, dword ptr fs:[00000030h] |
9_2_02AB002D |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB002D mov eax, dword ptr fs:[00000030h] |
9_2_02AB002D |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB002D mov eax, dword ptr fs:[00000030h] |
9_2_02AB002D |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02ABBC2C mov eax, dword ptr fs:[00000030h] |
9_2_02ABBC2C |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B54015 mov eax, dword ptr fs:[00000030h] |
9_2_02B54015 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B54015 mov eax, dword ptr fs:[00000030h] |
9_2_02B54015 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B07016 mov eax, dword ptr fs:[00000030h] |
9_2_02B07016 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B07016 mov eax, dword ptr fs:[00000030h] |
9_2_02B07016 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B07016 mov eax, dword ptr fs:[00000030h] |
9_2_02B07016 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] |
9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] |
9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] |
9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] |
9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] |
9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] |
9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] |
9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] |
9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] |
9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] |
9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] |
9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] |
9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] |
9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] |
9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B5740D mov eax, dword ptr fs:[00000030h] |
9_2_02B5740D |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B5740D mov eax, dword ptr fs:[00000030h] |
9_2_02B5740D |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B5740D mov eax, dword ptr fs:[00000030h] |
9_2_02B5740D |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B06C0A mov eax, dword ptr fs:[00000030h] |
9_2_02B06C0A |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B06C0A mov eax, dword ptr fs:[00000030h] |
9_2_02B06C0A |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B06C0A mov eax, dword ptr fs:[00000030h] |
9_2_02B06C0A |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B06C0A mov eax, dword ptr fs:[00000030h] |
9_2_02B06C0A |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B51074 mov eax, dword ptr fs:[00000030h] |
9_2_02B51074 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B42073 mov eax, dword ptr fs:[00000030h] |
9_2_02B42073 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AA746D mov eax, dword ptr fs:[00000030h] |
9_2_02AA746D |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02ABA44B mov eax, dword ptr fs:[00000030h] |
9_2_02ABA44B |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B1C450 mov eax, dword ptr fs:[00000030h] |
9_2_02B1C450 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B1C450 mov eax, dword ptr fs:[00000030h] |
9_2_02B1C450 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AA0050 mov eax, dword ptr fs:[00000030h] |
9_2_02AA0050 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AA0050 mov eax, dword ptr fs:[00000030h] |
9_2_02AA0050 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB35A1 mov eax, dword ptr fs:[00000030h] |
9_2_02AB35A1 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB61A0 mov eax, dword ptr fs:[00000030h] |
9_2_02AB61A0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB61A0 mov eax, dword ptr fs:[00000030h] |
9_2_02AB61A0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B051BE mov eax, dword ptr fs:[00000030h] |
9_2_02B051BE |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B051BE mov eax, dword ptr fs:[00000030h] |
9_2_02B051BE |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B051BE mov eax, dword ptr fs:[00000030h] |
9_2_02B051BE |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B051BE mov eax, dword ptr fs:[00000030h] |
9_2_02B051BE |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B069A6 mov eax, dword ptr fs:[00000030h] |
9_2_02B069A6 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB1DB5 mov eax, dword ptr fs:[00000030h] |
9_2_02AB1DB5 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB1DB5 mov eax, dword ptr fs:[00000030h] |
9_2_02AB1DB5 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB1DB5 mov eax, dword ptr fs:[00000030h] |
9_2_02AB1DB5 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A82D8A mov eax, dword ptr fs:[00000030h] |
9_2_02A82D8A |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A82D8A mov eax, dword ptr fs:[00000030h] |
9_2_02A82D8A |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A82D8A mov eax, dword ptr fs:[00000030h] |
9_2_02A82D8A |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A82D8A mov eax, dword ptr fs:[00000030h] |
9_2_02A82D8A |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A82D8A mov eax, dword ptr fs:[00000030h] |
9_2_02A82D8A |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AAC182 mov eax, dword ptr fs:[00000030h] |
9_2_02AAC182 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB2581 mov eax, dword ptr fs:[00000030h] |
9_2_02AB2581 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB2581 mov eax, dword ptr fs:[00000030h] |
9_2_02AB2581 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB2581 mov eax, dword ptr fs:[00000030h] |
9_2_02AB2581 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02ABA185 mov eax, dword ptr fs:[00000030h] |
9_2_02ABA185 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02ABFD9B mov eax, dword ptr fs:[00000030h] |
9_2_02ABFD9B |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02ABFD9B mov eax, dword ptr fs:[00000030h] |
9_2_02ABFD9B |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB2990 mov eax, dword ptr fs:[00000030h] |
9_2_02AB2990 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B38DF1 mov eax, dword ptr fs:[00000030h] |
9_2_02B38DF1 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A8B1E1 mov eax, dword ptr fs:[00000030h] |
9_2_02A8B1E1 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A8B1E1 mov eax, dword ptr fs:[00000030h] |
9_2_02A8B1E1 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A8B1E1 mov eax, dword ptr fs:[00000030h] |
9_2_02A8B1E1 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A9D5E0 mov eax, dword ptr fs:[00000030h] |
9_2_02A9D5E0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A9D5E0 mov eax, dword ptr fs:[00000030h] |
9_2_02A9D5E0 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B141E8 mov eax, dword ptr fs:[00000030h] |
9_2_02B141E8 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B58D34 mov eax, dword ptr fs:[00000030h] |
9_2_02B58D34 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B0A537 mov eax, dword ptr fs:[00000030h] |
9_2_02B0A537 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AA4120 mov eax, dword ptr fs:[00000030h] |
9_2_02AA4120 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AA4120 mov eax, dword ptr fs:[00000030h] |
9_2_02AA4120 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AA4120 mov eax, dword ptr fs:[00000030h] |
9_2_02AA4120 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AA4120 mov eax, dword ptr fs:[00000030h] |
9_2_02AA4120 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AA4120 mov ecx, dword ptr fs:[00000030h] |
9_2_02AA4120 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB4D3B mov eax, dword ptr fs:[00000030h] |
9_2_02AB4D3B |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB4D3B mov eax, dword ptr fs:[00000030h] |
9_2_02AB4D3B |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB4D3B mov eax, dword ptr fs:[00000030h] |
9_2_02AB4D3B |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB513A mov eax, dword ptr fs:[00000030h] |
9_2_02AB513A |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AB513A mov eax, dword ptr fs:[00000030h] |
9_2_02AB513A |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A8AD30 mov eax, dword ptr fs:[00000030h] |
9_2_02A8AD30 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] |
9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] |
9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] |
9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] |
9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] |
9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] |
9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] |
9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] |
9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] |
9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] |
9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] |
9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] |
9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] |
9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A89100 mov eax, dword ptr fs:[00000030h] |
9_2_02A89100 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A89100 mov eax, dword ptr fs:[00000030h] |
9_2_02A89100 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A89100 mov eax, dword ptr fs:[00000030h] |
9_2_02A89100 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A8C962 mov eax, dword ptr fs:[00000030h] |
9_2_02A8C962 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A8B171 mov eax, dword ptr fs:[00000030h] |
9_2_02A8B171 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02A8B171 mov eax, dword ptr fs:[00000030h] |
9_2_02A8B171 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AAC577 mov eax, dword ptr fs:[00000030h] |
9_2_02AAC577 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AAC577 mov eax, dword ptr fs:[00000030h] |
9_2_02AAC577 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AAB944 mov eax, dword ptr fs:[00000030h] |
9_2_02AAB944 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AAB944 mov eax, dword ptr fs:[00000030h] |
9_2_02AAB944 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AC3D43 mov eax, dword ptr fs:[00000030h] |
9_2_02AC3D43 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02B03540 mov eax, dword ptr fs:[00000030h] |
9_2_02B03540 |
Source: C:\Windows\SysWOW64\help.exe |
Code function: 9_2_02AA7D50 mov eax, dword ptr fs:[00000030h] |
9_2_02AA7D50 |