Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E7D6430 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E7D5580 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E7F2E50 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E800FF9 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E7E9F89 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E7E9CDF |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E7DED30 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E7FBDD1 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E7D28D0 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E7E98C0 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E7E996D |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E802744 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E7EA50B |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E7EA250 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E7ED32D |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E7E7307 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E7E1300 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 0_2_6E7ED0FD |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E7D6430 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E7D5580 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E7F2E50 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E800FF9 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E7E9F89 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E7E9CDF |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E7DED30 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E7FBDD1 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E7D28D0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E7E98C0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E7E996D |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E802744 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E7EA50B |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E7EA250 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E7ED32D |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E7E7307 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E7E1300 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 2_2_6E7ED0FD |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B441E |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007CCAA8 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007C43B3 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B1C76 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007C406E |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B9A57 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B2654 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007BA048 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B2043 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B2A46 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007CE441 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B3845 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007D1A3C |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007CF83F |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007BD223 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B9E22 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007C5220 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007BEC27 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007BF41F |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007BE21C |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007C1C10 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B1A0A |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B220A |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B8C09 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B4C00 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007CDEF4 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007CA8F0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B30F6 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007CAEEB |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007CECE3 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007C0ADE |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007CCCD4 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007D08D1 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007C7ED1 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007CBEC9 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007C98BD |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007C90BA |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B5AB2 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007BDAAE |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007C44AA |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007C78A5 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007BFEA0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007CD6A7 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007CAC9B |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B3C91 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007CD091 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007BAC95 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007C4E8A |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007C748A |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007BCC8D |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B7283 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007D0687 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007C577E |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007C056A |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007C1F6B |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007BC158 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B3F5C |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007CF14D |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B3345 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007D1343 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007D0B34 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007D292B |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B5923 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B6B25 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B251C |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007CFD10 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B2309 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B3502 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007BC5FE |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007D03F1 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B55E8 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007CBFE8 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007BA3DF |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007D25C3 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B6FC4 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007CB1B5 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007BBFB6 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007C7BB2 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007C4BAA |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007C9DA1 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007C2FA2 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007CD99A |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007BFD91 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007CB397 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007D1193 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007C4D8D |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B758F |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B4F8E |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 3_2_007B9384 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0063441E |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0064CAA8 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_006443B3 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0064406E |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00631C76 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00632043 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00632A46 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0064E441 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00633845 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0063A048 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00639A57 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00632654 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0063D223 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00639E22 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00645220 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0063EC27 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00651A3C |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0064F83F |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00634C00 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00631A0A |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0063220A |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00638C09 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00641C10 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0063F41F |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0063E21C |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0064ECE3 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0064AEEB |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0064DEF4 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0064A8F0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_006330F6 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0064BEC9 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0064CCD4 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_006508D1 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00647ED1 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00640ADE |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_006478A5 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0063FEA0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0064D6A7 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0063DAAE |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_006444AA |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00635AB2 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_006498BD |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_006490BA |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00637283 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00650687 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00644E8A |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0064748A |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0063CC8D |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00633C91 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0064D091 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0063AC95 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0064AC9B |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0064056A |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00641F6B |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0064577E |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00633345 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00651343 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0064F14D |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0063C158 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00633F5C |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00635923 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00636B25 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0065292B |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00650B34 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00633502 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00632309 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0064FD10 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0063251C |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_006355E8 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0064BFE8 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_006503F1 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0063C5FE |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_006525C3 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00636FC4 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0063A3DF |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00649DA1 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00642FA2 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00644BAA |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0064B1B5 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0063BFB6 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00647BB2 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00639384 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00644D8D |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0063758F |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00634F8E |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0063FD91 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0064B397 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_00651193 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_0064D99A |
Source: C:\Windows\SysWOW64\rundll32.exe | RDTSC instruction interceptor: First address: 000000006E7D6482 second address: 000000006E7D64B3 instructions: 0x00000000 rdtscp 0x00000003 mov dword ptr [ebp-18h], ecx 0x00000006 test edx, edx 0x00000008 jne 00007FD9E483B642h 0x0000000a mov dword ptr [ebp-20h], 09705DBFh 0x00000011 rdtscp |
Source: C:\Windows\SysWOW64\rundll32.exe | RDTSC instruction interceptor: First address: 000000006E7D8047 second address: 000000006E7D805A instructions: 0x00000000 rdtscp 0x00000003 test edx, edx 0x00000005 jnbe 00007FD9E483859Eh 0x00000007 rdtscp |
Source: C:\Windows\SysWOW64\rundll32.exe | RDTSC instruction interceptor: First address: 000000006E7D805A second address: 000000006E7D8047 instructions: 0x00000000 rdtscp 0x00000003 mov ecx, dword ptr [esp+0Ch] 0x00000007 ror esi, 0Dh 0x0000000a mov eax, esi 0x0000000c pop esi 0x0000000d xor ecx, esp 0x0000000f call 00007FD9E48479C1h 0x00000014 cmp ecx, dword ptr [6E81E008h] 0x0000001a jne 00007FD9E483B625h 0x0000001d ret 0x0000001f mov esp, ebp 0x00000021 pop ebp 0x00000022 ret 0x00000023 mov edx, dword ptr [ebp-24h] 0x00000026 mov edi, eax 0x00000028 jmp 00007FD9E483B691h 0x0000002a mov al, byte ptr [esi] 0x0000002c cmp al, 61h 0x0000002e movzx eax, al 0x00000031 jc 00007FD9E483B625h 0x00000033 add edi, FFFFFFE0h 0x00000036 mov ecx, dword ptr [ebp-18h] 0x00000039 add edi, eax 0x0000003b mov eax, dword ptr [ebp-50h] 0x0000003e inc esi 0x0000003f add ecx, 0000FFFFh 0x00000045 mov dword ptr [ebp-34h], edi 0x00000048 mov dword ptr [ebp-44h], esi 0x0000004b mov dword ptr [ebp-74h], esi 0x0000004e mov dword ptr [ebp-18h], ecx 0x00000051 test cx, cx 0x00000054 jne 00007FD9E483B56Fh 0x0000005a cmp eax, dword ptr [ebp-30h] 0x0000005d jl 00007FD9E483B635h 0x0000005f mov edx, 0000000Dh 0x00000064 mov ecx, edi 0x00000066 call 00007FD9E483CF8Eh 0x0000006b push ebp 0x0000006c mov ebp, esp 0x0000006e and esp, FFFFFFF8h 0x00000071 sub esp, 0Ch 0x00000074 mov eax, dword ptr [6E81E008h] 0x00000079 xor eax, esp 0x0000007b mov dword ptr [esp+08h], eax 0x0000007f push esi 0x00000080 mov esi, ecx 0x00000082 rdtscp |
Source: C:\Windows\SysWOW64\rundll32.exe | RDTSC instruction interceptor: First address: 000000006E7D6482 second address: 000000006E7D64B3 instructions: 0x00000000 rdtscp 0x00000003 mov dword ptr [ebp-18h], ecx 0x00000006 test edx, edx 0x00000008 jne 00007FD9E48385B2h 0x0000000a mov dword ptr [ebp-20h], 09705DBFh 0x00000011 rdtscp |
Source: C:\Windows\SysWOW64\rundll32.exe | RDTSC instruction interceptor: First address: 000000006E7D8047 second address: 000000006E7D805A instructions: 0x00000000 rdtscp 0x00000003 test edx, edx 0x00000005 jnbe 00007FD9E483B62Eh 0x00000007 rdtscp |
Source: C:\Windows\SysWOW64\rundll32.exe | RDTSC instruction interceptor: First address: 000000006E7D805A second address: 000000006E7D8047 instructions: 0x00000000 rdtscp 0x00000003 mov ecx, dword ptr [esp+0Ch] 0x00000007 ror esi, 0Dh 0x0000000a mov eax, esi 0x0000000c pop esi 0x0000000d xor ecx, esp 0x0000000f call 00007FD9E4844931h 0x00000014 cmp ecx, dword ptr [6E81E008h] 0x0000001a jne 00007FD9E4838595h 0x0000001d ret 0x0000001f mov esp, ebp 0x00000021 pop ebp 0x00000022 ret 0x00000023 mov edx, dword ptr [ebp-24h] 0x00000026 mov edi, eax 0x00000028 jmp 00007FD9E4838601h 0x0000002a mov al, byte ptr [esi] 0x0000002c cmp al, 61h 0x0000002e movzx eax, al 0x00000031 jc 00007FD9E4838595h 0x00000033 add edi, FFFFFFE0h 0x00000036 mov ecx, dword ptr [ebp-18h] 0x00000039 add edi, eax 0x0000003b mov eax, dword ptr [ebp-50h] 0x0000003e inc esi 0x0000003f add ecx, 0000FFFFh 0x00000045 mov dword ptr [ebp-34h], edi 0x00000048 mov dword ptr [ebp-44h], esi 0x0000004b mov dword ptr [ebp-74h], esi 0x0000004e mov dword ptr [ebp-18h], ecx 0x00000051 test cx, cx 0x00000054 jne 00007FD9E48384DFh 0x0000005a cmp eax, dword ptr [ebp-30h] 0x0000005d jl 00007FD9E48385A5h 0x0000005f mov edx, 0000000Dh 0x00000064 mov ecx, edi 0x00000066 call 00007FD9E4839EFEh 0x0000006b push ebp 0x0000006c mov ebp, esp 0x0000006e and esp, FFFFFFF8h 0x00000071 sub esp, 0Ch 0x00000074 mov eax, dword ptr [6E81E008h] 0x00000079 xor eax, esp 0x0000007b mov dword ptr [esp+08h], eax 0x0000007f push esi 0x00000080 mov esi, ecx 0x00000082 rdtscp |
Source: C:\Windows\System32\loaddll32.exe | RDTSC instruction interceptor: First address: 000000006E7D6482 second address: 000000006E7D64B3 instructions: 0x00000000 rdtscp 0x00000003 mov dword ptr [ebp-18h], ecx 0x00000006 test edx, edx 0x00000008 jne 00007FD9E483B642h 0x0000000a mov dword ptr [ebp-20h], 09705DBFh 0x00000011 rdtscp |
Source: C:\Windows\System32\loaddll32.exe | RDTSC instruction interceptor: First address: 000000006E7D8047 second address: 000000006E7D805A instructions: 0x00000000 rdtscp 0x00000003 test edx, edx 0x00000005 jnbe 00007FD9E483859Eh 0x00000007 rdtscp |
Source: C:\Windows\System32\loaddll32.exe | RDTSC instruction interceptor: First address: 000000006E7D805A second address: 000000006E7D8047 instructions: 0x00000000 rdtscp 0x00000003 mov ecx, dword ptr [esp+0Ch] 0x00000007 ror esi, 0Dh 0x0000000a mov eax, esi 0x0000000c pop esi 0x0000000d xor ecx, esp 0x0000000f call 00007FD9E48479C1h 0x00000014 cmp ecx, dword ptr [6E81E008h] 0x0000001a jne 00007FD9E483B625h 0x0000001d ret 0x0000001f mov esp, ebp 0x00000021 pop ebp 0x00000022 ret 0x00000023 mov edx, dword ptr [ebp-24h] 0x00000026 mov edi, eax 0x00000028 jmp 00007FD9E483B691h 0x0000002a mov al, byte ptr [esi] 0x0000002c cmp al, 61h 0x0000002e movzx eax, al 0x00000031 jc 00007FD9E483B625h 0x00000033 add edi, FFFFFFE0h 0x00000036 mov ecx, dword ptr [ebp-18h] 0x00000039 add edi, eax 0x0000003b mov eax, dword ptr [ebp-50h] 0x0000003e inc esi 0x0000003f add ecx, 0000FFFFh 0x00000045 mov dword ptr [ebp-34h], edi 0x00000048 mov dword ptr [ebp-44h], esi 0x0000004b mov dword ptr [ebp-74h], esi 0x0000004e mov dword ptr [ebp-18h], ecx 0x00000051 test cx, cx 0x00000054 jne 00007FD9E483B56Fh 0x0000005a cmp eax, dword ptr [ebp-30h] 0x0000005d jl 00007FD9E483B635h 0x0000005f mov edx, 0000000Dh 0x00000064 mov ecx, edi 0x00000066 call 00007FD9E483CF8Eh 0x0000006b push ebp 0x0000006c mov ebp, esp 0x0000006e and esp, FFFFFFF8h 0x00000071 sub esp, 0Ch 0x00000074 mov eax, dword ptr [6E81E008h] 0x00000079 xor eax, esp 0x0000007b mov dword ptr [esp+08h], eax 0x0000007f push esi 0x00000080 mov esi, ecx 0x00000082 rdtscp |
Source: C:\Windows\System32\loaddll32.exe | Code function: IsValidCodePage,_wcschr,_wcschr,GetLocaleInfoW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: EnumSystemLocalesW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
Source: C:\Windows\System32\loaddll32.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: EnumSystemLocalesW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: EnumSystemLocalesW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: EnumSystemLocalesW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: IsValidCodePage,_wcschr,_wcschr,GetLocaleInfoW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: EnumSystemLocalesW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: EnumSystemLocalesW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: EnumSystemLocalesW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: EnumSystemLocalesW, |