Source: 2.2.scan files 15-9-21.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 2.2.scan files 15-9-21.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 2.2.scan files 15-9-21.exe.400000.0.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 2.2.scan files 15-9-21.exe.400000.0.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000002.00000002.342717924.00000000015D0000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000002.00000002.342717924.00000000015D0000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000002.00000002.340222255.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000002.00000002.340222255.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000003.00000000.296739231.000000000E0BC000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000003.00000000.296739231.000000000E0BC000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000003.00000000.316398859.000000000E0BC000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000003.00000000.316398859.000000000E0BC000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0000000D.00000002.520331838.0000000000870000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0000000D.00000002.520331838.0000000000870000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000002.00000002.342785187.0000000001600000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000002.00000002.342785187.0000000001600000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0000000D.00000002.520884940.0000000000A80000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0000000D.00000002.520884940.0000000000A80000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0000000D.00000002.521187644.0000000000B00000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0000000D.00000002.521187644.0000000000B00000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000000.00000002.262326263.0000000003979000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000000.00000002.262326263.0000000003979000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: C:\Users\user\Desktop\scan files 15-9-21.exe | Code function: 2_2_004181C0 NtCreateFile, |
Source: C:\Users\user\Desktop\scan files 15-9-21.exe | Code function: 2_2_00418270 NtReadFile, |
Source: C:\Users\user\Desktop\scan files 15-9-21.exe | Code function: 2_2_004182F0 NtClose, |
Source: C:\Users\user\Desktop\scan files 15-9-21.exe | Code function: 2_2_004183A0 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\scan files 15-9-21.exe | Code function: 2_2_0041826A NtReadFile, |
Source: C:\Users\user\Desktop\scan files 15-9-21.exe | Code function: 2_2_0041839A NtAllocateVirtualMemory, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9710 NtQueryInformationToken,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9FE0 NtCreateMutant,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9780 NtMapViewOfSection,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9660 NtAllocateVirtualMemory,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9650 NtQueryValueKey,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9A50 NtCreateFile,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A96E0 NtFreeVirtualMemory,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A96D0 NtCreateKey,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9540 NtReadFile,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9910 NtAdjustPrivilegesToken,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A95D0 NtClose,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A99A0 NtCreateSection,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9860 NtQuerySystemInformation,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9840 NtDelayExecution,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9760 NtOpenProcess, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9770 NtSetInformationFile, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036AA770 NtOpenThread, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9730 NtQueryVirtualMemory, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9B00 NtSetValueKey, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036AA710 NtOpenProcessToken, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A97A0 NtUnmapViewOfSection, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036AA3B0 NtGetContextThread, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9670 NtQueryInformationProcess, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9A20 NtResumeThread, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9A00 NtProtectVirtualMemory, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9610 NtEnumerateValueKey, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9A10 NtQuerySection, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9A80 NtOpenDirectoryObject, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9560 NtWriteFile, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9950 NtQueueApcThread, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9520 NtWaitForSingleObject, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036AAD30 NtSetContextThread, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A95F0 NtQueryInformationFile, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A99D0 NtCreateProcessEx, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036AB040 NtSuspendThread, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A9820 NtEnumerateKey, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A98F0 NtReadVirtualMemory, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A98A0 NtWriteVirtualMemory, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_008881C0 NtCreateFile, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_008882F0 NtClose, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_00888270 NtReadFile, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_008883A0 NtAllocateVirtualMemory, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0088826A NtReadFile, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0088839A NtAllocateVirtualMemory, |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0366DB60 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0367FF60 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03693B7A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03693B7A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03738F6A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0366DB40 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0367EF40 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03738B58 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0366F358 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03664F2E mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03664F2E mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369E730 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369A70E mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369A70E mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0372131B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0373070D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0373070D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0368F716 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036FFF10 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036FFF10 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036903E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036903E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036903E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036903E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036903E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036903E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A37F5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E53CA mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E53CA mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03694BAD mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03694BAD mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03694BAD mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03735BA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03671B8F mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03671B8F mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0371D380 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03678794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0372138A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369B390 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E7794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E7794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E7794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03692397 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0367766D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A927A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0371B260 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0371B260 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03738A62 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0368AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0368AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0368AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0368AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0368AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03669240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03669240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03669240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03669240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03677E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03677E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03677E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03677E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03677E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03677E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036F4257 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0366E620 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A4A2C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A4A2C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0371FE3F mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0366C600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0366C600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0366C600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03698E00 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03678A0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0366AA16 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0366AA16 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03683A1C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369A61C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369A61C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036776E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036916E0 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03692AE4 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03692ACB mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03738ED6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036936CC mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A8EC7 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0371FEC0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036652A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036652A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036652A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036652A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036652A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E46A7 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03730EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03730EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03730EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0367AAB0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0367AAB0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369FAB0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036FFE87 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369D294 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369D294 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0366C962 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0366B171 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0366B171 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0368C577 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0368C577 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A3D43 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0368B944 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0368B944 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E3540 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03687D50 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03738D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03684120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03684120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03684120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03684120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03684120 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03694D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03694D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03694D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369513A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369513A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03673D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0366AD30 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036EA537 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03669100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03669100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03669100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03718DF1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0366B1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0366B1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0366B1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036F41E8 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0367D5E0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0367D5E0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036935A1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E69A6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036961A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036961A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E51BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E51BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E51BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E51BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03691DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03691DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03691DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03692581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03692581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03692581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03692581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0368C182 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369A185 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03662D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03662D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03662D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03662D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03662D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369FD9B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369FD9B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03692990 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03722073 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0368746D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03731074 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369A44B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03680050 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03680050 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036FC450 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036FC450 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369BC2C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0367B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0367B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0367B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0367B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E6C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E6C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E6C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E6C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03734015 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03734015 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03721C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E7016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E7016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E7016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0373740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0373740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0373740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_037214FB mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036658EC mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E6CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E6CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E6CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03738CD6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036FB8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036FB8D0 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036FB8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036FB8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036FB8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036FB8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036A90AF mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036920A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036920A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036920A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036920A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036920A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036920A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369F0BF mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369F0BF mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0369F0BF mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_03669080 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E3884 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_036E3884 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\WWAHost.exe | Code function: 13_2_0367849B mov eax, dword ptr fs:[00000030h] |