Source: 6.2.tgamf4XuLa.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 6.2.tgamf4XuLa.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 6.2.tgamf4XuLa.exe.400000.0.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 6.2.tgamf4XuLa.exe.400000.0.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000007.00000000.315374095.000000000E2BC000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000007.00000000.315374095.000000000E2BC000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000006.00000002.342682536.0000000000D80000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000006.00000002.342682536.0000000000D80000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000014.00000002.498298801.0000000003320000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000014.00000002.498298801.0000000003320000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000000.00000002.237658820.00000000039C9000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000000.00000002.237658820.00000000039C9000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000014.00000002.497021542.0000000002EC0000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000014.00000002.497021542.0000000002EC0000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000007.00000000.289170372.000000000E2BC000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000007.00000000.289170372.000000000E2BC000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000006.00000002.343304464.00000000012B0000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000006.00000002.343304464.00000000012B0000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000014.00000002.503591641.0000000004DA0000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000014.00000002.503591641.0000000004DA0000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000006.00000002.339207093.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000006.00000002.339207093.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: C:\Users\user\Desktop\tgamf4XuLa.exe | Code function: 6_2_004181C0 NtCreateFile, |
Source: C:\Users\user\Desktop\tgamf4XuLa.exe | Code function: 6_2_00418270 NtReadFile, |
Source: C:\Users\user\Desktop\tgamf4XuLa.exe | Code function: 6_2_004182F0 NtClose, |
Source: C:\Users\user\Desktop\tgamf4XuLa.exe | Code function: 6_2_004183A0 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\tgamf4XuLa.exe | Code function: 6_2_004181BA NtCreateFile, |
Source: C:\Users\user\Desktop\tgamf4XuLa.exe | Code function: 6_2_0041826A NtReadFile, |
Source: C:\Users\user\Desktop\tgamf4XuLa.exe | Code function: 6_2_004182EA NtClose, |
Source: C:\Users\user\Desktop\tgamf4XuLa.exe | Code function: 6_2_0041839A NtAllocateVirtualMemory, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9910 NtAdjustPrivilegesToken,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9540 NtReadFile,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C99A0 NtCreateSection,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C95D0 NtClose,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9840 NtDelayExecution,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9860 NtQuerySystemInformation,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9710 NtQueryInformationToken,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9780 NtMapViewOfSection,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9FE0 NtCreateMutant,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9650 NtQueryValueKey,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9A50 NtCreateFile,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9660 NtAllocateVirtualMemory,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C96D0 NtCreateKey,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C96E0 NtFreeVirtualMemory,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9520 NtWaitForSingleObject, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050CAD30 NtSetContextThread, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9950 NtQueueApcThread, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9560 NtWriteFile, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C99D0 NtCreateProcessEx, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C95F0 NtQueryInformationFile, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9820 NtEnumerateKey, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050CB040 NtSuspendThread, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C98A0 NtWriteVirtualMemory, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C98F0 NtReadVirtualMemory, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9B00 NtSetValueKey, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050CA710 NtOpenProcessToken, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9730 NtQueryVirtualMemory, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9760 NtOpenProcess, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9770 NtSetInformationFile, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050CA770 NtOpenThread, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C97A0 NtUnmapViewOfSection, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050CA3B0 NtGetContextThread, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9A00 NtProtectVirtualMemory, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9610 NtEnumerateValueKey, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9A10 NtQuerySection, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9A20 NtResumeThread, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9670 NtQueryInformationProcess, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C9A80 NtOpenDirectoryObject, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_02ED82F0 NtClose, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_02ED8270 NtReadFile, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_02ED83A0 NtAllocateVirtualMemory, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_02ED81C0 NtCreateFile, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_02ED82EA NtClose, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_02ED826A NtReadFile, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_02ED839A NtAllocateVirtualMemory, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_02ED81BA NtCreateFile, |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05089100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05089100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05089100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05158D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0510A537 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050A4120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050A4120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050A4120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050A4120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050A4120 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B4D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B4D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B4D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B513A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B513A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0508AD30 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05093D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05093D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05093D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05093D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05093D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05093D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05093D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05093D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05093D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05093D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05093D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05093D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05093D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050AB944 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050AB944 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C3D43 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05103540 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050A7D50 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0508C962 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0508B171 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0508B171 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050AC577 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050AC577 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05082D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05082D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05082D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05082D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05082D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050AC182 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050BA185 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050BFD9B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050BFD9B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B2990 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B35A1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B61A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B61A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_051051BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_051051BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_051051BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_051051BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_051069A6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B1DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B1DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B1DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05138DF1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0508B1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0508B1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0508B1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0509D5E0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0509D5E0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_051141E8 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05154015 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05154015 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05107016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05107016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05107016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05141C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05141C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05141C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05141C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05141C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05141C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05141C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05141C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05141C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05141C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05141C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05141C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05141C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05141C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0515740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0515740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0515740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05106C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05106C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05106C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05106C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0509B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0509B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0509B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0509B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050BBC2C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050BA44B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0511C450 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0511C450 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050A0050 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050A0050 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05151074 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05142073 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050A746D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05089080 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0509849B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05103884 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05103884 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C90AF mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050BF0BF mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050BF0BF mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050BF0BF mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0511B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0511B8D0 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0511B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0511B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0511B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0511B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05158CD6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05106CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05106CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05106CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050858EC mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_051414FB mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0511FF10 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0511FF10 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050BA70E mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050BA70E mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0514131B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0515070D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0515070D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050AF716 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05084F2E mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05084F2E mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050BE730 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0508DB40 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0509EF40 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05158B58 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0508F358 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0508DB60 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0509FF60 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B3B7A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B3B7A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05158F6A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05107794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05107794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05107794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05091B8F mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05091B8F mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0513D380 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050BB390 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B2397 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05098794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0514138A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B4BAD mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B4BAD mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B4BAD mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05155BA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_051053CA mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_051053CA mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B03E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B03E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B03E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B03E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B03E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B03E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C37F5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05098A0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0508C600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0508C600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0508C600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B8E00 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050A3A1C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050BA61C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050BA61C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0508AA16 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0508AA16 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C4A2C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C4A2C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0508E620 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0513FE3F mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05114257 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05089240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05089240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05089240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05089240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05097E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05097E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05097E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05097E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05097E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05097E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0509766D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0513B260 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0513B260 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C927A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05158A62 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050AAE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050AAE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050AAE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050AAE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050AAE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0511FE87 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050BD294 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050BD294 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050852A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050852A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050852A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050852A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050852A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05150EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05150EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05150EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_051046A7 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0509AAB0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0509AAB0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050BFAB0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B2ACB mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_05158ED6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B36CC mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050C8EC7 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_0513FEC0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B16E0 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050976E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\control.exe | Code function: 20_2_050B2AE4 mov eax, dword ptr fs:[00000030h] |