Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DB06EF |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DAED95 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DA7EDD |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DB0AD3 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D954C0 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DB20F8 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D9E6FD |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D9BEF5 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D9A8E8 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D9F699 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D9D899 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D9C69B |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D93085 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DAB0BA |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D9AEB9 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DA3ABE |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DA56A9 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D968AD |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D9F4A5 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DA04A4 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DA645F |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DA604E |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DAE478 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DB1C71 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DB0C66 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DABA18 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DA1C12 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DB2C16 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D9F20D |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D93E3B |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DACC3F |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DA0A37 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DA0824 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DAE7DA |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DA89DA |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DA13DB |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D95DC3 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D939C3 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D92DC5 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DA4DC5 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DA0FC5 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D91DF9 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DAD5FE |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D96BFE |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DA91F7 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D9B7EC |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D9FBEF |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DB35E3 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D9938F |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DB1987 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D9F984 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D97D87 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D933A9 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DABFA1 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DA77A7 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D98D59 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D9635F |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DB314A |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DB2D4F |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D94F42 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DAC145 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D9597D |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D92B7C |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DA5B7C |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DAC772 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D92575 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D92176 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D9196D |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D9996C |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DAF561 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DB2560 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D99565 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D95166 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D9DD66 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DA8518 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D98112 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D95314 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D94716 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DAD10B |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DA710D |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DB3306 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D97739 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DA473A |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DA3130 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D9E336 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00DACF2C |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D9B12E |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_00D96125 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_6E8F5980 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_6E8F6100 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_6E91AE28 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_6E921F65 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_6E902C70 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_6E90FD1F |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_6E8F2D10 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_6E911D50 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_6E9258EF |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_6E8FE6B0 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_6E9257CB |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_6E920569 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_6E8F9380 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_6E90C366 |
Source: C:\Windows\System32\loaddll32.exe | Code function: 1_2_6E90C132 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_6E8F5980 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_6E8F6100 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_6E91AE28 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_6E921F65 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_6E902C70 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_6E90FD1F |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_6E8F2D10 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_6E911D50 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_6E9258EF |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_6E8FE6B0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_6E9257CB |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_6E920569 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_6E8F9380 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_6E90C366 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 4_2_6E90C132 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0114ED95 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_011506EF |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01138112 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01134716 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01135314 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01148518 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01153306 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0114710D |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0114D10B |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01143130 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0113E336 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01137739 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0114473A |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01136125 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0114CF2C |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0113B12E |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01138D59 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0113635F |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01134F42 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0114C145 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01152D4F |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0115314A |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01132176 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0114C772 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01132575 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01145B7C |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0113597D |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01132B7C |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0114F561 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01135166 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0113DD66 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01152560 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01139565 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0113196D |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0113996C |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01151987 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01137D87 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0113F984 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0113938F |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_011477A7 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0114BFA1 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_011333A9 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0114E7DA |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_011489DA |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_011413DB |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01135DC3 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_011339C3 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01144DC5 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01140FC5 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01132DC5 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_011491F7 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01131DF9 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0114D5FE |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01136BFE |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_011535E3 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0113FBEF |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0113B7EC |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01152C16 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01141C12 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0114BA18 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0113F20D |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01140A37 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01133E3B |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0114CC3F |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01140824 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0114645F |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0114604E |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01151C71 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0114E478 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01150C66 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0113C69B |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0113F699 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0113D899 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01133085 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01143ABE |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0113AEB9 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0114B0BA |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_011404A4 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0113F4A5 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_011456A9 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_011368AD |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01150AD3 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_01147EDD |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_011354C0 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0113BEF5 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_011520F8 |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0113E6FD |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: 5_2_0113A8E8 |
Source: C:\Windows\SysWOW64\rundll32.exe | RDTSC instruction interceptor: First address: 000000006E8F6134 second address: 000000006E8F6168 instructions: 0x00000000 rdtscp 0x00000003 mov dword ptr [ebp-08h], ecx 0x00000006 test edx, edx 0x00000008 jne 00007FEE48EA84B4h 0x0000000a mov edi, 00D66F8Ch 0x0000000f mov dword ptr [ebp-14h], edi 0x00000012 rdtscp |
Source: C:\Windows\SysWOW64\rundll32.exe | RDTSC instruction interceptor: First address: 000000006E8F79F7 second address: 000000006E8F7A0A instructions: 0x00000000 rdtscp 0x00000003 test edx, edx 0x00000005 jnbe 00007FEE48B5C3DEh 0x00000007 rdtscp |
Source: C:\Windows\SysWOW64\rundll32.exe | RDTSC instruction interceptor: First address: 000000006E8F7A0A second address: 000000006E8F79F7 instructions: 0x00000000 rdtscp 0x00000003 mov ecx, dword ptr [esp+0Ch] 0x00000007 ror esi, 0Dh 0x0000000a mov eax, esi 0x0000000c pop esi 0x0000000d xor ecx, esp 0x0000000f call 00007FEE48EB4BD7h 0x00000014 cmp ecx, dword ptr [6E93D008h] 0x0000001a jne 00007FEE48EA8493h 0x0000001c ret 0x0000001d mov esp, ebp 0x0000001f pop ebp 0x00000020 ret 0x00000021 mov cl, byte ptr [esi] 0x00000023 mov edi, eax 0x00000025 cmp cl, 00000061h 0x00000028 jc 00007FEE48EA849Fh 0x0000002a movzx eax, cl 0x0000002d add edi, FFFFFFE0h 0x00000030 add edi, eax 0x00000032 jmp 00007FEE48EA85F2h 0x00000037 mov eax, dword ptr [ebp-14h] 0x0000003a mov ecx, dword ptr [ebp-18h] 0x0000003d cdq 0x0000003e sub eax, edx 0x00000040 sar eax, 1 0x00000042 cmp eax, ecx 0x00000044 jl 00007FEE48EA865Eh 0x0000004a add ebx, 0000FFFFh 0x00000050 inc esi 0x00000051 test bx, bx 0x00000054 jne 00007FEE48EA82EEh 0x0000005a mov eax, dword ptr [ebp-14h] 0x0000005d cmp eax, ecx 0x0000005f cmovle eax, ecx 0x00000062 mov ecx, edi 0x00000064 mov dword ptr [ebp-14h], eax 0x00000067 call 00007FEE48EA99F3h 0x0000006c push ebp 0x0000006d mov ebp, esp 0x0000006f and esp, FFFFFFF8h 0x00000072 sub esp, 0Ch 0x00000075 mov eax, dword ptr [6E93D008h] 0x0000007a xor eax, esp 0x0000007c mov dword ptr [esp+08h], eax 0x00000080 push esi 0x00000081 mov esi, ecx 0x00000083 rdtscp |
Source: C:\Windows\SysWOW64\rundll32.exe | RDTSC instruction interceptor: First address: 000000006E8F6134 second address: 000000006E8F6168 instructions: 0x00000000 rdtscp 0x00000003 mov dword ptr [ebp-08h], ecx 0x00000006 test edx, edx 0x00000008 jne 00007FEE48B5C3F4h 0x0000000a mov edi, 00D66F8Ch 0x0000000f mov dword ptr [ebp-14h], edi 0x00000012 rdtscp |
Source: C:\Windows\SysWOW64\rundll32.exe | RDTSC instruction interceptor: First address: 000000006E8F79F7 second address: 000000006E8F7A0A instructions: 0x00000000 rdtscp 0x00000003 test edx, edx 0x00000005 jnbe 00007FEE48EA849Eh 0x00000007 rdtscp |
Source: C:\Windows\SysWOW64\rundll32.exe | RDTSC instruction interceptor: First address: 000000006E8F7A0A second address: 000000006E8F79F7 instructions: 0x00000000 rdtscp 0x00000003 mov ecx, dword ptr [esp+0Ch] 0x00000007 ror esi, 0Dh 0x0000000a mov eax, esi 0x0000000c pop esi 0x0000000d xor ecx, esp 0x0000000f call 00007FEE48B68B17h 0x00000014 cmp ecx, dword ptr [6E93D008h] 0x0000001a jne 00007FEE48B5C3D3h 0x0000001c ret 0x0000001d mov esp, ebp 0x0000001f pop ebp 0x00000020 ret 0x00000021 mov cl, byte ptr [esi] 0x00000023 mov edi, eax 0x00000025 cmp cl, 00000061h 0x00000028 jc 00007FEE48B5C3DFh 0x0000002a movzx eax, cl 0x0000002d add edi, FFFFFFE0h 0x00000030 add edi, eax 0x00000032 jmp 00007FEE48B5C532h 0x00000037 mov eax, dword ptr [ebp-14h] 0x0000003a mov ecx, dword ptr [ebp-18h] 0x0000003d cdq 0x0000003e sub eax, edx 0x00000040 sar eax, 1 0x00000042 cmp eax, ecx 0x00000044 jl 00007FEE48B5C59Eh 0x0000004a add ebx, 0000FFFFh 0x00000050 inc esi 0x00000051 test bx, bx 0x00000054 jne 00007FEE48B5C22Eh 0x0000005a mov eax, dword ptr [ebp-14h] 0x0000005d cmp eax, ecx 0x0000005f cmovle eax, ecx 0x00000062 mov ecx, edi 0x00000064 mov dword ptr [ebp-14h], eax 0x00000067 call 00007FEE48B5D933h 0x0000006c push ebp 0x0000006d mov ebp, esp 0x0000006f and esp, FFFFFFF8h 0x00000072 sub esp, 0Ch 0x00000075 mov eax, dword ptr [6E93D008h] 0x0000007a xor eax, esp 0x0000007c mov dword ptr [esp+08h], eax 0x00000080 push esi 0x00000081 mov esi, ecx 0x00000083 rdtscp |
Source: C:\Windows\System32\loaddll32.exe | RDTSC instruction interceptor: First address: 000000006E8F6134 second address: 000000006E8F6168 instructions: 0x00000000 rdtscp 0x00000003 mov dword ptr [ebp-08h], ecx 0x00000006 test edx, edx 0x00000008 jne 00007FEE48EA84B4h 0x0000000a mov edi, 00D66F8Ch 0x0000000f mov dword ptr [ebp-14h], edi 0x00000012 rdtscp |
Source: C:\Windows\System32\loaddll32.exe | RDTSC instruction interceptor: First address: 000000006E8F79F7 second address: 000000006E8F7A0A instructions: 0x00000000 rdtscp 0x00000003 test edx, edx 0x00000005 jnbe 00007FEE48B5C3DEh 0x00000007 rdtscp |
Source: C:\Windows\System32\loaddll32.exe | RDTSC instruction interceptor: First address: 000000006E8F7A0A second address: 000000006E8F79F7 instructions: 0x00000000 rdtscp 0x00000003 mov ecx, dword ptr [esp+0Ch] 0x00000007 ror esi, 0Dh 0x0000000a mov eax, esi 0x0000000c pop esi 0x0000000d xor ecx, esp 0x0000000f call 00007FEE48EB4BD7h 0x00000014 cmp ecx, dword ptr [6E93D008h] 0x0000001a jne 00007FEE48EA8493h 0x0000001c ret 0x0000001d mov esp, ebp 0x0000001f pop ebp 0x00000020 ret 0x00000021 mov cl, byte ptr [esi] 0x00000023 mov edi, eax 0x00000025 cmp cl, 00000061h 0x00000028 jc 00007FEE48EA849Fh 0x0000002a movzx eax, cl 0x0000002d add edi, FFFFFFE0h 0x00000030 add edi, eax 0x00000032 jmp 00007FEE48EA85F2h 0x00000037 mov eax, dword ptr [ebp-14h] 0x0000003a mov ecx, dword ptr [ebp-18h] 0x0000003d cdq 0x0000003e sub eax, edx 0x00000040 sar eax, 1 0x00000042 cmp eax, ecx 0x00000044 jl 00007FEE48EA865Eh 0x0000004a add ebx, 0000FFFFh 0x00000050 inc esi 0x00000051 test bx, bx 0x00000054 jne 00007FEE48EA82EEh 0x0000005a mov eax, dword ptr [ebp-14h] 0x0000005d cmp eax, ecx 0x0000005f cmovle eax, ecx 0x00000062 mov ecx, edi 0x00000064 mov dword ptr [ebp-14h], eax 0x00000067 call 00007FEE48EA99F3h 0x0000006c push ebp 0x0000006d mov ebp, esp 0x0000006f and esp, FFFFFFF8h 0x00000072 sub esp, 0Ch 0x00000075 mov eax, dword ptr [6E93D008h] 0x0000007a xor eax, esp 0x0000007c mov dword ptr [esp+08h], eax 0x00000080 push esi 0x00000081 mov esi, ecx 0x00000083 rdtscp |
Source: C:\Windows\System32\loaddll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
Source: C:\Windows\System32\loaddll32.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: EnumSystemLocalesW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: EnumSystemLocalesW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: EnumSystemLocalesW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: EnumSystemLocalesW, |
Source: C:\Windows\System32\loaddll32.exe | Code function: GetACP,IsValidCodePage,_wcschr,_wcschr,GetLocaleInfoW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: EnumSystemLocalesW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: GetLocaleInfoW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: EnumSystemLocalesW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: EnumSystemLocalesW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: EnumSystemLocalesW, |
Source: C:\Windows\SysWOW64\rundll32.exe | Code function: GetACP,IsValidCodePage,_wcschr,_wcschr,GetLocaleInfoW, |