Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D76825 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D794D7 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D792D3 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D76EDC |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D798C4 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D714C4 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D74ACE |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D78ECA |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D746CA |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D73CF4 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D74AF4 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D7A0FC |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D730F8 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D72AEE |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D7AEBF |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D706BD |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D792BA |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D72AAE |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D79E57 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D7245B |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D72C58 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D7AE46 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D73445 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D74C43 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D7304D |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D7687F |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D7A478 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D75262 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D74817 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D7A015 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D73219 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D73018 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D71218 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D74234 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D74A23 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D7082B |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D70FDD |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D79BD9 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D715C7 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D78DC3 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D73FC9 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D73BF4 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D793FA |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D73FF9 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D74FF9 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D76FE2 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D76D95 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D79D9A |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D70F85 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D73D83 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D79B89 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D76DB1 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D7AFBE |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D7B3BA |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D745B8 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D747AE |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D7ADAB |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D7AF52 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D74551 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D7655D |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D7AD47 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D71174 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D72D70 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D74970 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D7417B |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D74D78 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D71F6E |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D7156A |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D74F07 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D7090B |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D7490B |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D74B36 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D7AD35 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D71331 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D72B31 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D73325 |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D79F2C |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | RDTSC instruction interceptor: First address: 0000000002D76090 second address: 0000000002D76090 instructions: 0x00000000 rdtsc 0x00000002 mov eax, D06691AFh 0x00000007 xor eax, 51795B17h 0x0000000c sub eax, E89895FEh 0x00000011 sub eax, 988734B9h 0x00000016 cpuid 0x00000018 jmp 00007FDE10E500D6h 0x0000001a test bx, 62F2h 0x0000001f popad 0x00000020 call 00007FDE10E5008Ch 0x00000025 lfence 0x00000028 mov edx, 3126F457h 0x0000002d xor edx, A11635D2h 0x00000033 xor edx, 122A2AF9h 0x00000039 xor edx, FDE4EB68h 0x0000003f mov edx, dword ptr [edx] 0x00000041 lfence 0x00000044 ret 0x00000045 cmp dh, ch 0x00000047 sub edx, esi 0x00000049 ret 0x0000004a test ah, dh 0x0000004c pop ecx 0x0000004d add edi, edx 0x0000004f dec ecx 0x00000050 mov dword ptr [ebp+0000017Ch], 339F83C1h 0x0000005a sub dword ptr [ebp+0000017Ch], 00B60B54h 0x00000064 sub dword ptr [ebp+0000017Ch], 2594365Ah 0x0000006e add dword ptr [ebp+0000017Ch], F2AABDEDh 0x00000078 cmp ecx, dword ptr [ebp+0000017Ch] 0x0000007e jne 00007FDE10E4FFD4h 0x00000084 jmp 00007FDE10E500E2h 0x00000086 test ch, dh 0x00000088 mov dword ptr [ebp+00000274h], edi 0x0000008e mov edi, ecx 0x00000090 push edi 0x00000091 mov edi, dword ptr [ebp+00000274h] 0x00000097 call 00007FDE10E500F4h 0x0000009c call 00007FDE10E50108h 0x000000a1 lfence 0x000000a4 mov edx, 3126F457h 0x000000a9 xor edx, A11635D2h 0x000000af xor edx, 122A2AF9h 0x000000b5 xor edx, FDE4EB68h 0x000000bb mov edx, dword ptr [edx] 0x000000bd lfence 0x000000c0 ret 0x000000c1 mov esi, edx 0x000000c3 pushad 0x000000c4 rdtsc |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D75EA3 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D78C1A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D73018 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D73BF4 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D79D9A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\7keerHhHvn.exe | Code function: 0_2_02D7915A mov eax, dword ptr fs:[00000030h] |