Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 4_2_0041A060 NtClose, | 4_2_0041A060 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 4_2_0041A110 NtAllocateVirtualMemory, | 4_2_0041A110 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 4_2_00419F30 NtCreateFile, | 4_2_00419F30 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 4_2_00419FE0 NtReadFile, | 4_2_00419FE0 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 4_2_0041A05A NtClose, | 4_2_0041A05A |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 4_2_0041A10A NtAllocateVirtualMemory, | 4_2_0041A10A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC96E0 NtFreeVirtualMemory,LdrInitializeThunk, | 9_2_02AC96E0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC96D0 NtCreateKey,LdrInitializeThunk, | 9_2_02AC96D0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9660 NtAllocateVirtualMemory,LdrInitializeThunk, | 9_2_02AC9660 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9650 NtQueryValueKey,LdrInitializeThunk, | 9_2_02AC9650 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9A50 NtCreateFile,LdrInitializeThunk, | 9_2_02AC9A50 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9780 NtMapViewOfSection,LdrInitializeThunk, | 9_2_02AC9780 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9FE0 NtCreateMutant,LdrInitializeThunk, | 9_2_02AC9FE0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9710 NtQueryInformationToken,LdrInitializeThunk, | 9_2_02AC9710 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9860 NtQuerySystemInformation,LdrInitializeThunk, | 9_2_02AC9860 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9840 NtDelayExecution,LdrInitializeThunk, | 9_2_02AC9840 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC99A0 NtCreateSection,LdrInitializeThunk, | 9_2_02AC99A0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC95D0 NtClose,LdrInitializeThunk, | 9_2_02AC95D0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9910 NtAdjustPrivilegesToken,LdrInitializeThunk, | 9_2_02AC9910 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9540 NtReadFile,LdrInitializeThunk, | 9_2_02AC9540 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9A80 NtOpenDirectoryObject, | 9_2_02AC9A80 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9A20 NtResumeThread, | 9_2_02AC9A20 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9A00 NtProtectVirtualMemory, | 9_2_02AC9A00 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9610 NtEnumerateValueKey, | 9_2_02AC9610 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9A10 NtQuerySection, | 9_2_02AC9A10 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9670 NtQueryInformationProcess, | 9_2_02AC9670 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC97A0 NtUnmapViewOfSection, | 9_2_02AC97A0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02ACA3B0 NtGetContextThread, | 9_2_02ACA3B0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9730 NtQueryVirtualMemory, | 9_2_02AC9730 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9B00 NtSetValueKey, | 9_2_02AC9B00 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02ACA710 NtOpenProcessToken, | 9_2_02ACA710 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9760 NtOpenProcess, | 9_2_02AC9760 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9770 NtSetInformationFile, | 9_2_02AC9770 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02ACA770 NtOpenThread, | 9_2_02ACA770 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC98A0 NtWriteVirtualMemory, | 9_2_02AC98A0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC98F0 NtReadVirtualMemory, | 9_2_02AC98F0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9820 NtEnumerateKey, | 9_2_02AC9820 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02ACB040 NtSuspendThread, | 9_2_02ACB040 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC95F0 NtQueryInformationFile, | 9_2_02AC95F0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC99D0 NtCreateProcessEx, | 9_2_02AC99D0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9520 NtWaitForSingleObject, | 9_2_02AC9520 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02ACAD30 NtSetContextThread, | 9_2_02ACAD30 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9560 NtWriteFile, | 9_2_02AC9560 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC9950 NtQueueApcThread, | 9_2_02AC9950 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_0242A060 NtClose, | 9_2_0242A060 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_0242A110 NtAllocateVirtualMemory, | 9_2_0242A110 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02429F30 NtCreateFile, | 9_2_02429F30 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02429FE0 NtReadFile, | 9_2_02429FE0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_0242A05A NtClose, | 9_2_0242A05A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_0242A10A NtAllocateVirtualMemory, | 9_2_0242A10A |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_00C82160 | 0_2_00C82160 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_00C81790 | 0_2_00C81790 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_00C8E7B8 | 0_2_00C8E7B8 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_00C85770 | 0_2_00C85770 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_00C80FF0 | 0_2_00C80FF0 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_00C850F8 | 0_2_00C850F8 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_00C82151 | 0_2_00C82151 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_00C85108 | 0_2_00C85108 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_00C85301 | 0_2_00C85301 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_00C85310 | 0_2_00C85310 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_00C80480 | 0_2_00C80480 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_00C80479 | 0_2_00C80479 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_00C85548 | 0_2_00C85548 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_00C85558 | 0_2_00C85558 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_00C81781 | 0_2_00C81781 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_00C85760 | 0_2_00C85760 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_00C84A69 | 0_2_00C84A69 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_00C84A78 | 0_2_00C84A78 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_00C84D69 | 0_2_00C84D69 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_00C83E80 | 0_2_00C83E80 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_00C83E71 | 0_2_00C83E71 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_00C80F48 | 0_2_00C80F48 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F309A0 | 0_2_09F309A0 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F3D288 | 0_2_09F3D288 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F39E14 | 0_2_09F39E14 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F30990 | 0_2_09F30990 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F39850 | 0_2_09F39850 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F35858 | 0_2_09F35858 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F39840 | 0_2_09F39840 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F35849 | 0_2_09F35849 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F30012 | 0_2_09F30012 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F373C0 | 0_2_09F373C0 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F373BD | 0_2_09F373BD |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F35BA3 | 0_2_09F35BA3 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F34BA2 | 0_2_09F34BA2 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F30398 | 0_2_09F30398 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F30389 | 0_2_09F30389 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F35358 | 0_2_09F35358 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F35348 | 0_2_09F35348 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F35AF7 | 0_2_09F35AF7 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F35AF8 | 0_2_09F35AF8 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F34AC0 | 0_2_09F34AC0 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F34ABF | 0_2_09F34ABF |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F30580 | 0_2_09F30580 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F37584 | 0_2_09F37584 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F30571 | 0_2_09F30571 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F36D61 | 0_2_09F36D61 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F36D68 | 0_2_09F36D68 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F31497 | 0_2_09F31497 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F31498 | 0_2_09F31498 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F39C57 | 0_2_09F39C57 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F39C58 | 0_2_09F39C58 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F35C31 | 0_2_09F35C31 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F307C0 | 0_2_09F307C0 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F307B0 | 0_2_09F307B0 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F33720 | 0_2_09F33720 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F39E83 | 0_2_09F39E83 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 0_2_09F39E65 | 0_2_09F39E65 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 4_2_00401030 | 4_2_00401030 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 4_2_0041E1CF | 4_2_0041E1CF |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 4_2_0041D23B | 4_2_0041D23B |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 4_2_00402D87 | 4_2_00402D87 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 4_2_00402D90 | 4_2_00402D90 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 4_2_00409E40 | 4_2_00409E40 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 4_2_0041D6CF | 4_2_0041D6CF |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 4_2_00402FB0 | 4_2_00402FB0 |
Source: C:\Users\user\Desktop\GiG35Rwmz6.exe | Code function: 4_2_0041BFB6 | 4_2_0041BFB6 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AA6E30 | 9_2_02AA6E30 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02ABEBB0 | 9_2_02ABEBB0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A9B090 | 9_2_02A9B090 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B41002 | 9_2_02B41002 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A9841F | 9_2_02A9841F |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB2581 | 9_2_02AB2581 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A9D5E0 | 9_2_02A9D5E0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A80D20 | 9_2_02A80D20 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AA4120 | 9_2_02AA4120 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A8F900 | 9_2_02A8F900 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B51D55 | 9_2_02B51D55 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_0242D23B | 9_2_0242D23B |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_0242E1CF | 9_2_0242E1CF |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02419E40 | 9_2_02419E40 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02412FB0 | 9_2_02412FB0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_0242BFB6 | 9_2_0242BFB6 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02412D87 | 9_2_02412D87 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02412D90 | 9_2_02412D90 |
Source: 00000009.00000002.925821980.0000000002410000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000009.00000002.925821980.0000000002410000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000004.00000002.729070321.0000000000B00000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000004.00000002.729070321.0000000000B00000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000004.00000002.728648868.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000004.00000002.728648868.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000004.00000002.729033636.0000000000AD0000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000004.00000002.729033636.0000000000AD0000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000000.00000002.676742229.00000000040C9000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000000.00000002.676742229.00000000040C9000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000009.00000002.925566371.00000000000D0000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000009.00000002.925566371.00000000000D0000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000004.00000000.671897283.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000004.00000000.671897283.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 4.0.GiG35Rwmz6.exe.400000.1.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 4.0.GiG35Rwmz6.exe.400000.1.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 4.2.GiG35Rwmz6.exe.400000.0.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 4.2.GiG35Rwmz6.exe.400000.0.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 4.0.GiG35Rwmz6.exe.400000.1.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 4.0.GiG35Rwmz6.exe.400000.1.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 4.2.GiG35Rwmz6.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 4.2.GiG35Rwmz6.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0.2.GiG35Rwmz6.exe.40c9950.2.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0.2.GiG35Rwmz6.exe.40c9950.2.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A852A5 mov eax, dword ptr fs:[00000030h] | 9_2_02A852A5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A852A5 mov eax, dword ptr fs:[00000030h] | 9_2_02A852A5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A852A5 mov eax, dword ptr fs:[00000030h] | 9_2_02A852A5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A852A5 mov eax, dword ptr fs:[00000030h] | 9_2_02A852A5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A852A5 mov eax, dword ptr fs:[00000030h] | 9_2_02A852A5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B50EA5 mov eax, dword ptr fs:[00000030h] | 9_2_02B50EA5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B50EA5 mov eax, dword ptr fs:[00000030h] | 9_2_02B50EA5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B50EA5 mov eax, dword ptr fs:[00000030h] | 9_2_02B50EA5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B046A7 mov eax, dword ptr fs:[00000030h] | 9_2_02B046A7 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A9AAB0 mov eax, dword ptr fs:[00000030h] | 9_2_02A9AAB0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A9AAB0 mov eax, dword ptr fs:[00000030h] | 9_2_02A9AAB0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02ABFAB0 mov eax, dword ptr fs:[00000030h] | 9_2_02ABFAB0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B1FE87 mov eax, dword ptr fs:[00000030h] | 9_2_02B1FE87 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02ABD294 mov eax, dword ptr fs:[00000030h] | 9_2_02ABD294 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02ABD294 mov eax, dword ptr fs:[00000030h] | 9_2_02ABD294 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB16E0 mov ecx, dword ptr fs:[00000030h] | 9_2_02AB16E0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A976E2 mov eax, dword ptr fs:[00000030h] | 9_2_02A976E2 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB2AE4 mov eax, dword ptr fs:[00000030h] | 9_2_02AB2AE4 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB2ACB mov eax, dword ptr fs:[00000030h] | 9_2_02AB2ACB |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B58ED6 mov eax, dword ptr fs:[00000030h] | 9_2_02B58ED6 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB36CC mov eax, dword ptr fs:[00000030h] | 9_2_02AB36CC |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC8EC7 mov eax, dword ptr fs:[00000030h] | 9_2_02AC8EC7 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B3FEC0 mov eax, dword ptr fs:[00000030h] | 9_2_02B3FEC0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A8E620 mov eax, dword ptr fs:[00000030h] | 9_2_02A8E620 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B3FE3F mov eax, dword ptr fs:[00000030h] | 9_2_02B3FE3F |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A98A0A mov eax, dword ptr fs:[00000030h] | 9_2_02A98A0A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A8C600 mov eax, dword ptr fs:[00000030h] | 9_2_02A8C600 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A8C600 mov eax, dword ptr fs:[00000030h] | 9_2_02A8C600 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A8C600 mov eax, dword ptr fs:[00000030h] | 9_2_02A8C600 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB8E00 mov eax, dword ptr fs:[00000030h] | 9_2_02AB8E00 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AA3A1C mov eax, dword ptr fs:[00000030h] | 9_2_02AA3A1C |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02ABA61C mov eax, dword ptr fs:[00000030h] | 9_2_02ABA61C |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02ABA61C mov eax, dword ptr fs:[00000030h] | 9_2_02ABA61C |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A8AA16 mov eax, dword ptr fs:[00000030h] | 9_2_02A8AA16 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A8AA16 mov eax, dword ptr fs:[00000030h] | 9_2_02A8AA16 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A9766D mov eax, dword ptr fs:[00000030h] | 9_2_02A9766D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B3B260 mov eax, dword ptr fs:[00000030h] | 9_2_02B3B260 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B3B260 mov eax, dword ptr fs:[00000030h] | 9_2_02B3B260 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC927A mov eax, dword ptr fs:[00000030h] | 9_2_02AC927A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B58A62 mov eax, dword ptr fs:[00000030h] | 9_2_02B58A62 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AAAE73 mov eax, dword ptr fs:[00000030h] | 9_2_02AAAE73 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AAAE73 mov eax, dword ptr fs:[00000030h] | 9_2_02AAAE73 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AAAE73 mov eax, dword ptr fs:[00000030h] | 9_2_02AAAE73 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AAAE73 mov eax, dword ptr fs:[00000030h] | 9_2_02AAAE73 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AAAE73 mov eax, dword ptr fs:[00000030h] | 9_2_02AAAE73 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B14257 mov eax, dword ptr fs:[00000030h] | 9_2_02B14257 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A89240 mov eax, dword ptr fs:[00000030h] | 9_2_02A89240 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A89240 mov eax, dword ptr fs:[00000030h] | 9_2_02A89240 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A89240 mov eax, dword ptr fs:[00000030h] | 9_2_02A89240 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A89240 mov eax, dword ptr fs:[00000030h] | 9_2_02A89240 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A97E41 mov eax, dword ptr fs:[00000030h] | 9_2_02A97E41 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A97E41 mov eax, dword ptr fs:[00000030h] | 9_2_02A97E41 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A97E41 mov eax, dword ptr fs:[00000030h] | 9_2_02A97E41 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A97E41 mov eax, dword ptr fs:[00000030h] | 9_2_02A97E41 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A97E41 mov eax, dword ptr fs:[00000030h] | 9_2_02A97E41 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A97E41 mov eax, dword ptr fs:[00000030h] | 9_2_02A97E41 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B55BA5 mov eax, dword ptr fs:[00000030h] | 9_2_02B55BA5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B07794 mov eax, dword ptr fs:[00000030h] | 9_2_02B07794 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B07794 mov eax, dword ptr fs:[00000030h] | 9_2_02B07794 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B07794 mov eax, dword ptr fs:[00000030h] | 9_2_02B07794 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A91B8F mov eax, dword ptr fs:[00000030h] | 9_2_02A91B8F |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A91B8F mov eax, dword ptr fs:[00000030h] | 9_2_02A91B8F |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B3D380 mov ecx, dword ptr fs:[00000030h] | 9_2_02B3D380 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02ABB390 mov eax, dword ptr fs:[00000030h] | 9_2_02ABB390 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A98794 mov eax, dword ptr fs:[00000030h] | 9_2_02A98794 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B4138A mov eax, dword ptr fs:[00000030h] | 9_2_02B4138A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB03E2 mov eax, dword ptr fs:[00000030h] | 9_2_02AB03E2 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB03E2 mov eax, dword ptr fs:[00000030h] | 9_2_02AB03E2 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB03E2 mov eax, dword ptr fs:[00000030h] | 9_2_02AB03E2 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB03E2 mov eax, dword ptr fs:[00000030h] | 9_2_02AB03E2 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB03E2 mov eax, dword ptr fs:[00000030h] | 9_2_02AB03E2 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB03E2 mov eax, dword ptr fs:[00000030h] | 9_2_02AB03E2 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC37F5 mov eax, dword ptr fs:[00000030h] | 9_2_02AC37F5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B053CA mov eax, dword ptr fs:[00000030h] | 9_2_02B053CA |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B053CA mov eax, dword ptr fs:[00000030h] | 9_2_02B053CA |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A84F2E mov eax, dword ptr fs:[00000030h] | 9_2_02A84F2E |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A84F2E mov eax, dword ptr fs:[00000030h] | 9_2_02A84F2E |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02ABE730 mov eax, dword ptr fs:[00000030h] | 9_2_02ABE730 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B1FF10 mov eax, dword ptr fs:[00000030h] | 9_2_02B1FF10 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B1FF10 mov eax, dword ptr fs:[00000030h] | 9_2_02B1FF10 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02ABA70E mov eax, dword ptr fs:[00000030h] | 9_2_02ABA70E |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02ABA70E mov eax, dword ptr fs:[00000030h] | 9_2_02ABA70E |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B4131B mov eax, dword ptr fs:[00000030h] | 9_2_02B4131B |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B5070D mov eax, dword ptr fs:[00000030h] | 9_2_02B5070D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B5070D mov eax, dword ptr fs:[00000030h] | 9_2_02B5070D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AAF716 mov eax, dword ptr fs:[00000030h] | 9_2_02AAF716 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A8DB60 mov ecx, dword ptr fs:[00000030h] | 9_2_02A8DB60 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A9FF60 mov eax, dword ptr fs:[00000030h] | 9_2_02A9FF60 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB3B7A mov eax, dword ptr fs:[00000030h] | 9_2_02AB3B7A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB3B7A mov eax, dword ptr fs:[00000030h] | 9_2_02AB3B7A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B58F6A mov eax, dword ptr fs:[00000030h] | 9_2_02B58F6A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A8DB40 mov eax, dword ptr fs:[00000030h] | 9_2_02A8DB40 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A9EF40 mov eax, dword ptr fs:[00000030h] | 9_2_02A9EF40 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B58B58 mov eax, dword ptr fs:[00000030h] | 9_2_02B58B58 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A8F358 mov eax, dword ptr fs:[00000030h] | 9_2_02A8F358 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC90AF mov eax, dword ptr fs:[00000030h] | 9_2_02AC90AF |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02ABF0BF mov ecx, dword ptr fs:[00000030h] | 9_2_02ABF0BF |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02ABF0BF mov eax, dword ptr fs:[00000030h] | 9_2_02ABF0BF |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02ABF0BF mov eax, dword ptr fs:[00000030h] | 9_2_02ABF0BF |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A89080 mov eax, dword ptr fs:[00000030h] | 9_2_02A89080 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A9849B mov eax, dword ptr fs:[00000030h] | 9_2_02A9849B |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B03884 mov eax, dword ptr fs:[00000030h] | 9_2_02B03884 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B03884 mov eax, dword ptr fs:[00000030h] | 9_2_02B03884 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B06CF0 mov eax, dword ptr fs:[00000030h] | 9_2_02B06CF0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B06CF0 mov eax, dword ptr fs:[00000030h] | 9_2_02B06CF0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B06CF0 mov eax, dword ptr fs:[00000030h] | 9_2_02B06CF0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B414FB mov eax, dword ptr fs:[00000030h] | 9_2_02B414FB |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B1B8D0 mov eax, dword ptr fs:[00000030h] | 9_2_02B1B8D0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B1B8D0 mov ecx, dword ptr fs:[00000030h] | 9_2_02B1B8D0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B1B8D0 mov eax, dword ptr fs:[00000030h] | 9_2_02B1B8D0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B1B8D0 mov eax, dword ptr fs:[00000030h] | 9_2_02B1B8D0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B1B8D0 mov eax, dword ptr fs:[00000030h] | 9_2_02B1B8D0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B1B8D0 mov eax, dword ptr fs:[00000030h] | 9_2_02B1B8D0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B58CD6 mov eax, dword ptr fs:[00000030h] | 9_2_02B58CD6 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A9B02A mov eax, dword ptr fs:[00000030h] | 9_2_02A9B02A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A9B02A mov eax, dword ptr fs:[00000030h] | 9_2_02A9B02A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A9B02A mov eax, dword ptr fs:[00000030h] | 9_2_02A9B02A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A9B02A mov eax, dword ptr fs:[00000030h] | 9_2_02A9B02A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB002D mov eax, dword ptr fs:[00000030h] | 9_2_02AB002D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB002D mov eax, dword ptr fs:[00000030h] | 9_2_02AB002D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB002D mov eax, dword ptr fs:[00000030h] | 9_2_02AB002D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB002D mov eax, dword ptr fs:[00000030h] | 9_2_02AB002D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB002D mov eax, dword ptr fs:[00000030h] | 9_2_02AB002D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02ABBC2C mov eax, dword ptr fs:[00000030h] | 9_2_02ABBC2C |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B54015 mov eax, dword ptr fs:[00000030h] | 9_2_02B54015 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B54015 mov eax, dword ptr fs:[00000030h] | 9_2_02B54015 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B07016 mov eax, dword ptr fs:[00000030h] | 9_2_02B07016 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B07016 mov eax, dword ptr fs:[00000030h] | 9_2_02B07016 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B07016 mov eax, dword ptr fs:[00000030h] | 9_2_02B07016 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] | 9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] | 9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] | 9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] | 9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] | 9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] | 9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] | 9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] | 9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] | 9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] | 9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] | 9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] | 9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] | 9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B41C06 mov eax, dword ptr fs:[00000030h] | 9_2_02B41C06 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B5740D mov eax, dword ptr fs:[00000030h] | 9_2_02B5740D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B5740D mov eax, dword ptr fs:[00000030h] | 9_2_02B5740D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B5740D mov eax, dword ptr fs:[00000030h] | 9_2_02B5740D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B06C0A mov eax, dword ptr fs:[00000030h] | 9_2_02B06C0A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B06C0A mov eax, dword ptr fs:[00000030h] | 9_2_02B06C0A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B06C0A mov eax, dword ptr fs:[00000030h] | 9_2_02B06C0A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B06C0A mov eax, dword ptr fs:[00000030h] | 9_2_02B06C0A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B51074 mov eax, dword ptr fs:[00000030h] | 9_2_02B51074 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B42073 mov eax, dword ptr fs:[00000030h] | 9_2_02B42073 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AA746D mov eax, dword ptr fs:[00000030h] | 9_2_02AA746D |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02ABA44B mov eax, dword ptr fs:[00000030h] | 9_2_02ABA44B |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B1C450 mov eax, dword ptr fs:[00000030h] | 9_2_02B1C450 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B1C450 mov eax, dword ptr fs:[00000030h] | 9_2_02B1C450 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AA0050 mov eax, dword ptr fs:[00000030h] | 9_2_02AA0050 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AA0050 mov eax, dword ptr fs:[00000030h] | 9_2_02AA0050 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB35A1 mov eax, dword ptr fs:[00000030h] | 9_2_02AB35A1 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB61A0 mov eax, dword ptr fs:[00000030h] | 9_2_02AB61A0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB61A0 mov eax, dword ptr fs:[00000030h] | 9_2_02AB61A0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B051BE mov eax, dword ptr fs:[00000030h] | 9_2_02B051BE |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B051BE mov eax, dword ptr fs:[00000030h] | 9_2_02B051BE |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B051BE mov eax, dword ptr fs:[00000030h] | 9_2_02B051BE |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B051BE mov eax, dword ptr fs:[00000030h] | 9_2_02B051BE |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B069A6 mov eax, dword ptr fs:[00000030h] | 9_2_02B069A6 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB1DB5 mov eax, dword ptr fs:[00000030h] | 9_2_02AB1DB5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB1DB5 mov eax, dword ptr fs:[00000030h] | 9_2_02AB1DB5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB1DB5 mov eax, dword ptr fs:[00000030h] | 9_2_02AB1DB5 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A82D8A mov eax, dword ptr fs:[00000030h] | 9_2_02A82D8A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A82D8A mov eax, dword ptr fs:[00000030h] | 9_2_02A82D8A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A82D8A mov eax, dword ptr fs:[00000030h] | 9_2_02A82D8A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A82D8A mov eax, dword ptr fs:[00000030h] | 9_2_02A82D8A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A82D8A mov eax, dword ptr fs:[00000030h] | 9_2_02A82D8A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AAC182 mov eax, dword ptr fs:[00000030h] | 9_2_02AAC182 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB2581 mov eax, dword ptr fs:[00000030h] | 9_2_02AB2581 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB2581 mov eax, dword ptr fs:[00000030h] | 9_2_02AB2581 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB2581 mov eax, dword ptr fs:[00000030h] | 9_2_02AB2581 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02ABA185 mov eax, dword ptr fs:[00000030h] | 9_2_02ABA185 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02ABFD9B mov eax, dword ptr fs:[00000030h] | 9_2_02ABFD9B |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02ABFD9B mov eax, dword ptr fs:[00000030h] | 9_2_02ABFD9B |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB2990 mov eax, dword ptr fs:[00000030h] | 9_2_02AB2990 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B38DF1 mov eax, dword ptr fs:[00000030h] | 9_2_02B38DF1 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A8B1E1 mov eax, dword ptr fs:[00000030h] | 9_2_02A8B1E1 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A8B1E1 mov eax, dword ptr fs:[00000030h] | 9_2_02A8B1E1 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A8B1E1 mov eax, dword ptr fs:[00000030h] | 9_2_02A8B1E1 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A9D5E0 mov eax, dword ptr fs:[00000030h] | 9_2_02A9D5E0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A9D5E0 mov eax, dword ptr fs:[00000030h] | 9_2_02A9D5E0 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B141E8 mov eax, dword ptr fs:[00000030h] | 9_2_02B141E8 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B58D34 mov eax, dword ptr fs:[00000030h] | 9_2_02B58D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B0A537 mov eax, dword ptr fs:[00000030h] | 9_2_02B0A537 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AA4120 mov eax, dword ptr fs:[00000030h] | 9_2_02AA4120 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AA4120 mov eax, dword ptr fs:[00000030h] | 9_2_02AA4120 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AA4120 mov eax, dword ptr fs:[00000030h] | 9_2_02AA4120 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AA4120 mov eax, dword ptr fs:[00000030h] | 9_2_02AA4120 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AA4120 mov ecx, dword ptr fs:[00000030h] | 9_2_02AA4120 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB4D3B mov eax, dword ptr fs:[00000030h] | 9_2_02AB4D3B |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB4D3B mov eax, dword ptr fs:[00000030h] | 9_2_02AB4D3B |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB4D3B mov eax, dword ptr fs:[00000030h] | 9_2_02AB4D3B |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB513A mov eax, dword ptr fs:[00000030h] | 9_2_02AB513A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AB513A mov eax, dword ptr fs:[00000030h] | 9_2_02AB513A |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A8AD30 mov eax, dword ptr fs:[00000030h] | 9_2_02A8AD30 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] | 9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] | 9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] | 9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] | 9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] | 9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] | 9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] | 9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] | 9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] | 9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] | 9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] | 9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] | 9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A93D34 mov eax, dword ptr fs:[00000030h] | 9_2_02A93D34 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A89100 mov eax, dword ptr fs:[00000030h] | 9_2_02A89100 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A89100 mov eax, dword ptr fs:[00000030h] | 9_2_02A89100 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A89100 mov eax, dword ptr fs:[00000030h] | 9_2_02A89100 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A8C962 mov eax, dword ptr fs:[00000030h] | 9_2_02A8C962 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A8B171 mov eax, dword ptr fs:[00000030h] | 9_2_02A8B171 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02A8B171 mov eax, dword ptr fs:[00000030h] | 9_2_02A8B171 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AAC577 mov eax, dword ptr fs:[00000030h] | 9_2_02AAC577 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AAC577 mov eax, dword ptr fs:[00000030h] | 9_2_02AAC577 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AAB944 mov eax, dword ptr fs:[00000030h] | 9_2_02AAB944 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AAB944 mov eax, dword ptr fs:[00000030h] | 9_2_02AAB944 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AC3D43 mov eax, dword ptr fs:[00000030h] | 9_2_02AC3D43 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02B03540 mov eax, dword ptr fs:[00000030h] | 9_2_02B03540 |
Source: C:\Windows\SysWOW64\help.exe | Code function: 9_2_02AA7D50 mov eax, dword ptr fs:[00000030h] | 9_2_02AA7D50 |