Source: 2.2.scan files 15-9-21.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 2.2.scan files 15-9-21.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 2.2.scan files 15-9-21.exe.400000.0.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 2.2.scan files 15-9-21.exe.400000.0.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000002.00000002.342717924.00000000015D0000.00000040.00020000.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000002.00000002.342717924.00000000015D0000.00000040.00020000.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000002.00000002.340222255.0000000000400000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000002.00000002.340222255.0000000000400000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000003.00000000.296739231.000000000E0BC000.00000040.00020000.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000003.00000000.296739231.000000000E0BC000.00000040.00020000.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000003.00000000.316398859.000000000E0BC000.00000040.00020000.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000003.00000000.316398859.000000000E0BC000.00000040.00020000.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0000000D.00000002.520331838.0000000000870000.00000040.00020000.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0000000D.00000002.520331838.0000000000870000.00000040.00020000.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000002.00000002.342785187.0000000001600000.00000040.00020000.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000002.00000002.342785187.0000000001600000.00000040.00020000.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0000000D.00000002.520884940.0000000000A80000.00000040.00020000.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0000000D.00000002.520884940.0000000000A80000.00000040.00020000.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0000000D.00000002.521187644.0000000000B00000.00000004.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0000000D.00000002.521187644.0000000000B00000.00000004.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000000.00000002.262326263.0000000003979000.00000004.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000000.00000002.262326263.0000000003979000.00000004.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: C:\Users\user\Desktop\scan files 15-9-21.exe |
Code function: 2_2_004181C0 NtCreateFile, |
2_2_004181C0 |
Source: C:\Users\user\Desktop\scan files 15-9-21.exe |
Code function: 2_2_00418270 NtReadFile, |
2_2_00418270 |
Source: C:\Users\user\Desktop\scan files 15-9-21.exe |
Code function: 2_2_004182F0 NtClose, |
2_2_004182F0 |
Source: C:\Users\user\Desktop\scan files 15-9-21.exe |
Code function: 2_2_004183A0 NtAllocateVirtualMemory, |
2_2_004183A0 |
Source: C:\Users\user\Desktop\scan files 15-9-21.exe |
Code function: 2_2_0041826A NtReadFile, |
2_2_0041826A |
Source: C:\Users\user\Desktop\scan files 15-9-21.exe |
Code function: 2_2_0041839A NtAllocateVirtualMemory, |
2_2_0041839A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9710 NtQueryInformationToken,LdrInitializeThunk, |
13_2_036A9710 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9FE0 NtCreateMutant,LdrInitializeThunk, |
13_2_036A9FE0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9780 NtMapViewOfSection,LdrInitializeThunk, |
13_2_036A9780 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9660 NtAllocateVirtualMemory,LdrInitializeThunk, |
13_2_036A9660 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9650 NtQueryValueKey,LdrInitializeThunk, |
13_2_036A9650 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9A50 NtCreateFile,LdrInitializeThunk, |
13_2_036A9A50 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A96E0 NtFreeVirtualMemory,LdrInitializeThunk, |
13_2_036A96E0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A96D0 NtCreateKey,LdrInitializeThunk, |
13_2_036A96D0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9540 NtReadFile,LdrInitializeThunk, |
13_2_036A9540 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9910 NtAdjustPrivilegesToken,LdrInitializeThunk, |
13_2_036A9910 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A95D0 NtClose,LdrInitializeThunk, |
13_2_036A95D0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A99A0 NtCreateSection,LdrInitializeThunk, |
13_2_036A99A0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9860 NtQuerySystemInformation,LdrInitializeThunk, |
13_2_036A9860 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9840 NtDelayExecution,LdrInitializeThunk, |
13_2_036A9840 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9760 NtOpenProcess, |
13_2_036A9760 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9770 NtSetInformationFile, |
13_2_036A9770 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036AA770 NtOpenThread, |
13_2_036AA770 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9730 NtQueryVirtualMemory, |
13_2_036A9730 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9B00 NtSetValueKey, |
13_2_036A9B00 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036AA710 NtOpenProcessToken, |
13_2_036AA710 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A97A0 NtUnmapViewOfSection, |
13_2_036A97A0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036AA3B0 NtGetContextThread, |
13_2_036AA3B0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9670 NtQueryInformationProcess, |
13_2_036A9670 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9A20 NtResumeThread, |
13_2_036A9A20 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9A00 NtProtectVirtualMemory, |
13_2_036A9A00 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9610 NtEnumerateValueKey, |
13_2_036A9610 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9A10 NtQuerySection, |
13_2_036A9A10 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9A80 NtOpenDirectoryObject, |
13_2_036A9A80 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9560 NtWriteFile, |
13_2_036A9560 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9950 NtQueueApcThread, |
13_2_036A9950 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9520 NtWaitForSingleObject, |
13_2_036A9520 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036AAD30 NtSetContextThread, |
13_2_036AAD30 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A95F0 NtQueryInformationFile, |
13_2_036A95F0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A99D0 NtCreateProcessEx, |
13_2_036A99D0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036AB040 NtSuspendThread, |
13_2_036AB040 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A9820 NtEnumerateKey, |
13_2_036A9820 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A98F0 NtReadVirtualMemory, |
13_2_036A98F0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A98A0 NtWriteVirtualMemory, |
13_2_036A98A0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_008881C0 NtCreateFile, |
13_2_008881C0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_008882F0 NtClose, |
13_2_008882F0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_00888270 NtReadFile, |
13_2_00888270 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_008883A0 NtAllocateVirtualMemory, |
13_2_008883A0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0088826A NtReadFile, |
13_2_0088826A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0088839A NtAllocateVirtualMemory, |
13_2_0088839A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0366DB60 mov ecx, dword ptr fs:[00000030h] |
13_2_0366DB60 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0367FF60 mov eax, dword ptr fs:[00000030h] |
13_2_0367FF60 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03693B7A mov eax, dword ptr fs:[00000030h] |
13_2_03693B7A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03693B7A mov eax, dword ptr fs:[00000030h] |
13_2_03693B7A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03738F6A mov eax, dword ptr fs:[00000030h] |
13_2_03738F6A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0366DB40 mov eax, dword ptr fs:[00000030h] |
13_2_0366DB40 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0367EF40 mov eax, dword ptr fs:[00000030h] |
13_2_0367EF40 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03738B58 mov eax, dword ptr fs:[00000030h] |
13_2_03738B58 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0366F358 mov eax, dword ptr fs:[00000030h] |
13_2_0366F358 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03664F2E mov eax, dword ptr fs:[00000030h] |
13_2_03664F2E |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03664F2E mov eax, dword ptr fs:[00000030h] |
13_2_03664F2E |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369E730 mov eax, dword ptr fs:[00000030h] |
13_2_0369E730 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369A70E mov eax, dword ptr fs:[00000030h] |
13_2_0369A70E |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369A70E mov eax, dword ptr fs:[00000030h] |
13_2_0369A70E |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0372131B mov eax, dword ptr fs:[00000030h] |
13_2_0372131B |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0373070D mov eax, dword ptr fs:[00000030h] |
13_2_0373070D |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0373070D mov eax, dword ptr fs:[00000030h] |
13_2_0373070D |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0368F716 mov eax, dword ptr fs:[00000030h] |
13_2_0368F716 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036FFF10 mov eax, dword ptr fs:[00000030h] |
13_2_036FFF10 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036FFF10 mov eax, dword ptr fs:[00000030h] |
13_2_036FFF10 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036903E2 mov eax, dword ptr fs:[00000030h] |
13_2_036903E2 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036903E2 mov eax, dword ptr fs:[00000030h] |
13_2_036903E2 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036903E2 mov eax, dword ptr fs:[00000030h] |
13_2_036903E2 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036903E2 mov eax, dword ptr fs:[00000030h] |
13_2_036903E2 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036903E2 mov eax, dword ptr fs:[00000030h] |
13_2_036903E2 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036903E2 mov eax, dword ptr fs:[00000030h] |
13_2_036903E2 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A37F5 mov eax, dword ptr fs:[00000030h] |
13_2_036A37F5 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E53CA mov eax, dword ptr fs:[00000030h] |
13_2_036E53CA |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E53CA mov eax, dword ptr fs:[00000030h] |
13_2_036E53CA |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03694BAD mov eax, dword ptr fs:[00000030h] |
13_2_03694BAD |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03694BAD mov eax, dword ptr fs:[00000030h] |
13_2_03694BAD |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03694BAD mov eax, dword ptr fs:[00000030h] |
13_2_03694BAD |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03735BA5 mov eax, dword ptr fs:[00000030h] |
13_2_03735BA5 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03671B8F mov eax, dword ptr fs:[00000030h] |
13_2_03671B8F |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03671B8F mov eax, dword ptr fs:[00000030h] |
13_2_03671B8F |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0371D380 mov ecx, dword ptr fs:[00000030h] |
13_2_0371D380 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03678794 mov eax, dword ptr fs:[00000030h] |
13_2_03678794 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0372138A mov eax, dword ptr fs:[00000030h] |
13_2_0372138A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369B390 mov eax, dword ptr fs:[00000030h] |
13_2_0369B390 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E7794 mov eax, dword ptr fs:[00000030h] |
13_2_036E7794 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E7794 mov eax, dword ptr fs:[00000030h] |
13_2_036E7794 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E7794 mov eax, dword ptr fs:[00000030h] |
13_2_036E7794 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03692397 mov eax, dword ptr fs:[00000030h] |
13_2_03692397 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0367766D mov eax, dword ptr fs:[00000030h] |
13_2_0367766D |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A927A mov eax, dword ptr fs:[00000030h] |
13_2_036A927A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0371B260 mov eax, dword ptr fs:[00000030h] |
13_2_0371B260 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0371B260 mov eax, dword ptr fs:[00000030h] |
13_2_0371B260 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03738A62 mov eax, dword ptr fs:[00000030h] |
13_2_03738A62 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0368AE73 mov eax, dword ptr fs:[00000030h] |
13_2_0368AE73 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0368AE73 mov eax, dword ptr fs:[00000030h] |
13_2_0368AE73 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0368AE73 mov eax, dword ptr fs:[00000030h] |
13_2_0368AE73 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0368AE73 mov eax, dword ptr fs:[00000030h] |
13_2_0368AE73 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0368AE73 mov eax, dword ptr fs:[00000030h] |
13_2_0368AE73 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03669240 mov eax, dword ptr fs:[00000030h] |
13_2_03669240 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03669240 mov eax, dword ptr fs:[00000030h] |
13_2_03669240 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03669240 mov eax, dword ptr fs:[00000030h] |
13_2_03669240 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03669240 mov eax, dword ptr fs:[00000030h] |
13_2_03669240 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03677E41 mov eax, dword ptr fs:[00000030h] |
13_2_03677E41 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03677E41 mov eax, dword ptr fs:[00000030h] |
13_2_03677E41 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03677E41 mov eax, dword ptr fs:[00000030h] |
13_2_03677E41 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03677E41 mov eax, dword ptr fs:[00000030h] |
13_2_03677E41 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03677E41 mov eax, dword ptr fs:[00000030h] |
13_2_03677E41 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03677E41 mov eax, dword ptr fs:[00000030h] |
13_2_03677E41 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036F4257 mov eax, dword ptr fs:[00000030h] |
13_2_036F4257 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0366E620 mov eax, dword ptr fs:[00000030h] |
13_2_0366E620 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A4A2C mov eax, dword ptr fs:[00000030h] |
13_2_036A4A2C |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A4A2C mov eax, dword ptr fs:[00000030h] |
13_2_036A4A2C |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0371FE3F mov eax, dword ptr fs:[00000030h] |
13_2_0371FE3F |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0366C600 mov eax, dword ptr fs:[00000030h] |
13_2_0366C600 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0366C600 mov eax, dword ptr fs:[00000030h] |
13_2_0366C600 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0366C600 mov eax, dword ptr fs:[00000030h] |
13_2_0366C600 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03698E00 mov eax, dword ptr fs:[00000030h] |
13_2_03698E00 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03678A0A mov eax, dword ptr fs:[00000030h] |
13_2_03678A0A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0366AA16 mov eax, dword ptr fs:[00000030h] |
13_2_0366AA16 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0366AA16 mov eax, dword ptr fs:[00000030h] |
13_2_0366AA16 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03683A1C mov eax, dword ptr fs:[00000030h] |
13_2_03683A1C |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369A61C mov eax, dword ptr fs:[00000030h] |
13_2_0369A61C |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369A61C mov eax, dword ptr fs:[00000030h] |
13_2_0369A61C |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036776E2 mov eax, dword ptr fs:[00000030h] |
13_2_036776E2 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036916E0 mov ecx, dword ptr fs:[00000030h] |
13_2_036916E0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03692AE4 mov eax, dword ptr fs:[00000030h] |
13_2_03692AE4 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03692ACB mov eax, dword ptr fs:[00000030h] |
13_2_03692ACB |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03738ED6 mov eax, dword ptr fs:[00000030h] |
13_2_03738ED6 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036936CC mov eax, dword ptr fs:[00000030h] |
13_2_036936CC |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A8EC7 mov eax, dword ptr fs:[00000030h] |
13_2_036A8EC7 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0371FEC0 mov eax, dword ptr fs:[00000030h] |
13_2_0371FEC0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036652A5 mov eax, dword ptr fs:[00000030h] |
13_2_036652A5 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036652A5 mov eax, dword ptr fs:[00000030h] |
13_2_036652A5 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036652A5 mov eax, dword ptr fs:[00000030h] |
13_2_036652A5 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036652A5 mov eax, dword ptr fs:[00000030h] |
13_2_036652A5 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036652A5 mov eax, dword ptr fs:[00000030h] |
13_2_036652A5 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E46A7 mov eax, dword ptr fs:[00000030h] |
13_2_036E46A7 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03730EA5 mov eax, dword ptr fs:[00000030h] |
13_2_03730EA5 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03730EA5 mov eax, dword ptr fs:[00000030h] |
13_2_03730EA5 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03730EA5 mov eax, dword ptr fs:[00000030h] |
13_2_03730EA5 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0367AAB0 mov eax, dword ptr fs:[00000030h] |
13_2_0367AAB0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0367AAB0 mov eax, dword ptr fs:[00000030h] |
13_2_0367AAB0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369FAB0 mov eax, dword ptr fs:[00000030h] |
13_2_0369FAB0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036FFE87 mov eax, dword ptr fs:[00000030h] |
13_2_036FFE87 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369D294 mov eax, dword ptr fs:[00000030h] |
13_2_0369D294 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369D294 mov eax, dword ptr fs:[00000030h] |
13_2_0369D294 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0366C962 mov eax, dword ptr fs:[00000030h] |
13_2_0366C962 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0366B171 mov eax, dword ptr fs:[00000030h] |
13_2_0366B171 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0366B171 mov eax, dword ptr fs:[00000030h] |
13_2_0366B171 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0368C577 mov eax, dword ptr fs:[00000030h] |
13_2_0368C577 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0368C577 mov eax, dword ptr fs:[00000030h] |
13_2_0368C577 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A3D43 mov eax, dword ptr fs:[00000030h] |
13_2_036A3D43 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0368B944 mov eax, dword ptr fs:[00000030h] |
13_2_0368B944 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0368B944 mov eax, dword ptr fs:[00000030h] |
13_2_0368B944 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E3540 mov eax, dword ptr fs:[00000030h] |
13_2_036E3540 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03687D50 mov eax, dword ptr fs:[00000030h] |
13_2_03687D50 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03738D34 mov eax, dword ptr fs:[00000030h] |
13_2_03738D34 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03684120 mov eax, dword ptr fs:[00000030h] |
13_2_03684120 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03684120 mov eax, dword ptr fs:[00000030h] |
13_2_03684120 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03684120 mov eax, dword ptr fs:[00000030h] |
13_2_03684120 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03684120 mov eax, dword ptr fs:[00000030h] |
13_2_03684120 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03684120 mov ecx, dword ptr fs:[00000030h] |
13_2_03684120 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03694D3B mov eax, dword ptr fs:[00000030h] |
13_2_03694D3B |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03694D3B mov eax, dword ptr fs:[00000030h] |
13_2_03694D3B |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03694D3B mov eax, dword ptr fs:[00000030h] |
13_2_03694D3B |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369513A mov eax, dword ptr fs:[00000030h] |
13_2_0369513A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369513A mov eax, dword ptr fs:[00000030h] |
13_2_0369513A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
13_2_03673D34 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
13_2_03673D34 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
13_2_03673D34 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
13_2_03673D34 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
13_2_03673D34 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
13_2_03673D34 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
13_2_03673D34 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
13_2_03673D34 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
13_2_03673D34 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
13_2_03673D34 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
13_2_03673D34 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
13_2_03673D34 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
13_2_03673D34 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0366AD30 mov eax, dword ptr fs:[00000030h] |
13_2_0366AD30 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036EA537 mov eax, dword ptr fs:[00000030h] |
13_2_036EA537 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03669100 mov eax, dword ptr fs:[00000030h] |
13_2_03669100 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03669100 mov eax, dword ptr fs:[00000030h] |
13_2_03669100 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03669100 mov eax, dword ptr fs:[00000030h] |
13_2_03669100 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03718DF1 mov eax, dword ptr fs:[00000030h] |
13_2_03718DF1 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0366B1E1 mov eax, dword ptr fs:[00000030h] |
13_2_0366B1E1 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0366B1E1 mov eax, dword ptr fs:[00000030h] |
13_2_0366B1E1 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0366B1E1 mov eax, dword ptr fs:[00000030h] |
13_2_0366B1E1 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036F41E8 mov eax, dword ptr fs:[00000030h] |
13_2_036F41E8 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0367D5E0 mov eax, dword ptr fs:[00000030h] |
13_2_0367D5E0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0367D5E0 mov eax, dword ptr fs:[00000030h] |
13_2_0367D5E0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036935A1 mov eax, dword ptr fs:[00000030h] |
13_2_036935A1 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E69A6 mov eax, dword ptr fs:[00000030h] |
13_2_036E69A6 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036961A0 mov eax, dword ptr fs:[00000030h] |
13_2_036961A0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036961A0 mov eax, dword ptr fs:[00000030h] |
13_2_036961A0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E51BE mov eax, dword ptr fs:[00000030h] |
13_2_036E51BE |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E51BE mov eax, dword ptr fs:[00000030h] |
13_2_036E51BE |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E51BE mov eax, dword ptr fs:[00000030h] |
13_2_036E51BE |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E51BE mov eax, dword ptr fs:[00000030h] |
13_2_036E51BE |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03691DB5 mov eax, dword ptr fs:[00000030h] |
13_2_03691DB5 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03691DB5 mov eax, dword ptr fs:[00000030h] |
13_2_03691DB5 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03691DB5 mov eax, dword ptr fs:[00000030h] |
13_2_03691DB5 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03692581 mov eax, dword ptr fs:[00000030h] |
13_2_03692581 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03692581 mov eax, dword ptr fs:[00000030h] |
13_2_03692581 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03692581 mov eax, dword ptr fs:[00000030h] |
13_2_03692581 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03692581 mov eax, dword ptr fs:[00000030h] |
13_2_03692581 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0368C182 mov eax, dword ptr fs:[00000030h] |
13_2_0368C182 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369A185 mov eax, dword ptr fs:[00000030h] |
13_2_0369A185 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03662D8A mov eax, dword ptr fs:[00000030h] |
13_2_03662D8A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03662D8A mov eax, dword ptr fs:[00000030h] |
13_2_03662D8A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03662D8A mov eax, dword ptr fs:[00000030h] |
13_2_03662D8A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03662D8A mov eax, dword ptr fs:[00000030h] |
13_2_03662D8A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03662D8A mov eax, dword ptr fs:[00000030h] |
13_2_03662D8A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369FD9B mov eax, dword ptr fs:[00000030h] |
13_2_0369FD9B |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369FD9B mov eax, dword ptr fs:[00000030h] |
13_2_0369FD9B |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03692990 mov eax, dword ptr fs:[00000030h] |
13_2_03692990 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03722073 mov eax, dword ptr fs:[00000030h] |
13_2_03722073 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0368746D mov eax, dword ptr fs:[00000030h] |
13_2_0368746D |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03731074 mov eax, dword ptr fs:[00000030h] |
13_2_03731074 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369A44B mov eax, dword ptr fs:[00000030h] |
13_2_0369A44B |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03680050 mov eax, dword ptr fs:[00000030h] |
13_2_03680050 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03680050 mov eax, dword ptr fs:[00000030h] |
13_2_03680050 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036FC450 mov eax, dword ptr fs:[00000030h] |
13_2_036FC450 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036FC450 mov eax, dword ptr fs:[00000030h] |
13_2_036FC450 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369002D mov eax, dword ptr fs:[00000030h] |
13_2_0369002D |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369002D mov eax, dword ptr fs:[00000030h] |
13_2_0369002D |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369002D mov eax, dword ptr fs:[00000030h] |
13_2_0369002D |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369002D mov eax, dword ptr fs:[00000030h] |
13_2_0369002D |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369002D mov eax, dword ptr fs:[00000030h] |
13_2_0369002D |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369BC2C mov eax, dword ptr fs:[00000030h] |
13_2_0369BC2C |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0367B02A mov eax, dword ptr fs:[00000030h] |
13_2_0367B02A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0367B02A mov eax, dword ptr fs:[00000030h] |
13_2_0367B02A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0367B02A mov eax, dword ptr fs:[00000030h] |
13_2_0367B02A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0367B02A mov eax, dword ptr fs:[00000030h] |
13_2_0367B02A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E6C0A mov eax, dword ptr fs:[00000030h] |
13_2_036E6C0A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E6C0A mov eax, dword ptr fs:[00000030h] |
13_2_036E6C0A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E6C0A mov eax, dword ptr fs:[00000030h] |
13_2_036E6C0A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E6C0A mov eax, dword ptr fs:[00000030h] |
13_2_036E6C0A |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03734015 mov eax, dword ptr fs:[00000030h] |
13_2_03734015 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03734015 mov eax, dword ptr fs:[00000030h] |
13_2_03734015 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
13_2_03721C06 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
13_2_03721C06 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
13_2_03721C06 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
13_2_03721C06 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
13_2_03721C06 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
13_2_03721C06 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
13_2_03721C06 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
13_2_03721C06 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
13_2_03721C06 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
13_2_03721C06 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
13_2_03721C06 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
13_2_03721C06 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
13_2_03721C06 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
13_2_03721C06 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E7016 mov eax, dword ptr fs:[00000030h] |
13_2_036E7016 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E7016 mov eax, dword ptr fs:[00000030h] |
13_2_036E7016 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E7016 mov eax, dword ptr fs:[00000030h] |
13_2_036E7016 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0373740D mov eax, dword ptr fs:[00000030h] |
13_2_0373740D |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0373740D mov eax, dword ptr fs:[00000030h] |
13_2_0373740D |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0373740D mov eax, dword ptr fs:[00000030h] |
13_2_0373740D |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_037214FB mov eax, dword ptr fs:[00000030h] |
13_2_037214FB |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036658EC mov eax, dword ptr fs:[00000030h] |
13_2_036658EC |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E6CF0 mov eax, dword ptr fs:[00000030h] |
13_2_036E6CF0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E6CF0 mov eax, dword ptr fs:[00000030h] |
13_2_036E6CF0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E6CF0 mov eax, dword ptr fs:[00000030h] |
13_2_036E6CF0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03738CD6 mov eax, dword ptr fs:[00000030h] |
13_2_03738CD6 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036FB8D0 mov eax, dword ptr fs:[00000030h] |
13_2_036FB8D0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036FB8D0 mov ecx, dword ptr fs:[00000030h] |
13_2_036FB8D0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036FB8D0 mov eax, dword ptr fs:[00000030h] |
13_2_036FB8D0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036FB8D0 mov eax, dword ptr fs:[00000030h] |
13_2_036FB8D0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036FB8D0 mov eax, dword ptr fs:[00000030h] |
13_2_036FB8D0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036FB8D0 mov eax, dword ptr fs:[00000030h] |
13_2_036FB8D0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036A90AF mov eax, dword ptr fs:[00000030h] |
13_2_036A90AF |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036920A0 mov eax, dword ptr fs:[00000030h] |
13_2_036920A0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036920A0 mov eax, dword ptr fs:[00000030h] |
13_2_036920A0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036920A0 mov eax, dword ptr fs:[00000030h] |
13_2_036920A0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036920A0 mov eax, dword ptr fs:[00000030h] |
13_2_036920A0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036920A0 mov eax, dword ptr fs:[00000030h] |
13_2_036920A0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036920A0 mov eax, dword ptr fs:[00000030h] |
13_2_036920A0 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369F0BF mov ecx, dword ptr fs:[00000030h] |
13_2_0369F0BF |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369F0BF mov eax, dword ptr fs:[00000030h] |
13_2_0369F0BF |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0369F0BF mov eax, dword ptr fs:[00000030h] |
13_2_0369F0BF |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_03669080 mov eax, dword ptr fs:[00000030h] |
13_2_03669080 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E3884 mov eax, dword ptr fs:[00000030h] |
13_2_036E3884 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_036E3884 mov eax, dword ptr fs:[00000030h] |
13_2_036E3884 |
Source: C:\Windows\SysWOW64\WWAHost.exe |
Code function: 13_2_0367849B mov eax, dword ptr fs:[00000030h] |
13_2_0367849B |