Source: 6.0.Solicitud urgente de Quotaion_U1197,pdf.exe.400000.8.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 6.0.Solicitud urgente de Quotaion_U1197,pdf.exe.400000.8.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 6.0.Solicitud urgente de Quotaion_U1197,pdf.exe.400000.6.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 6.0.Solicitud urgente de Quotaion_U1197,pdf.exe.400000.6.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 6.2.Solicitud urgente de Quotaion_U1197,pdf.exe.400000.0.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 6.2.Solicitud urgente de Quotaion_U1197,pdf.exe.400000.0.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 6.0.Solicitud urgente de Quotaion_U1197,pdf.exe.400000.4.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 6.0.Solicitud urgente de Quotaion_U1197,pdf.exe.400000.4.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 6.0.Solicitud urgente de Quotaion_U1197,pdf.exe.400000.8.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 6.0.Solicitud urgente de Quotaion_U1197,pdf.exe.400000.8.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 6.0.Solicitud urgente de Quotaion_U1197,pdf.exe.400000.6.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 6.0.Solicitud urgente de Quotaion_U1197,pdf.exe.400000.6.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 6.2.Solicitud urgente de Quotaion_U1197,pdf.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 6.2.Solicitud urgente de Quotaion_U1197,pdf.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000006.00000000.298321821.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000006.00000000.298321821.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0000000A.00000002.560174409.0000000000770000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0000000A.00000002.560174409.0000000000770000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000006.00000002.372897742.0000000001730000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000006.00000002.372897742.0000000001730000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000006.00000000.298732907.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000006.00000000.298732907.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000007.00000000.338321770.00000000100B5000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000007.00000000.338321770.00000000100B5000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000006.00000002.372402095.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000006.00000002.372402095.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0000000A.00000002.563987618.00000000007C0000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0000000A.00000002.563987618.00000000007C0000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000007.00000000.354531059.00000000100B5000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000007.00000000.354531059.00000000100B5000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000006.00000002.373637862.0000000001A90000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000006.00000002.373637862.0000000001A90000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0000000A.00000002.558246949.0000000000120000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0000000A.00000002.558246949.0000000000120000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000000.00000002.301296785.0000000004309000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000000.00000002.301296785.0000000004309000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: C:\Users\user\Desktop\Solicitud urgente de Quotaion_U1197,pdf.exe | Code function: 6_2_0041A360 NtCreateFile, |
Source: C:\Users\user\Desktop\Solicitud urgente de Quotaion_U1197,pdf.exe | Code function: 6_2_0041A410 NtReadFile, |
Source: C:\Users\user\Desktop\Solicitud urgente de Quotaion_U1197,pdf.exe | Code function: 6_2_0041A490 NtClose, |
Source: C:\Users\user\Desktop\Solicitud urgente de Quotaion_U1197,pdf.exe | Code function: 6_2_0041A540 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\Solicitud urgente de Quotaion_U1197,pdf.exe | Code function: 6_2_0041A3B3 NtReadFile, |
Source: C:\Users\user\Desktop\Solicitud urgente de Quotaion_U1197,pdf.exe | Code function: 6_2_0041A40B NtReadFile, |
Source: C:\Users\user\Desktop\Solicitud urgente de Quotaion_U1197,pdf.exe | Code function: 6_2_0041A53A NtAllocateVirtualMemory, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649540 NtReadFile,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046495D0 NtClose,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649660 NtAllocateVirtualMemory,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649650 NtQueryValueKey,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046496E0 NtFreeVirtualMemory,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046496D0 NtCreateKey,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649710 NtQueryInformationToken,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649FE0 NtCreateMutant,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649780 NtMapViewOfSection,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649860 NtQuerySystemInformation,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649840 NtDelayExecution,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649910 NtAdjustPrivilegesToken,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046499A0 NtCreateSection,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649A50 NtCreateFile,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649560 NtWriteFile, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649520 NtWaitForSingleObject, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0464AD30 NtSetContextThread, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046495F0 NtQueryInformationFile, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649670 NtQueryInformationProcess, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649610 NtEnumerateValueKey, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649760 NtOpenProcess, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0464A770 NtOpenThread, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649770 NtSetInformationFile, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649730 NtQueryVirtualMemory, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0464A710 NtOpenProcessToken, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046497A0 NtUnmapViewOfSection, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0464B040 NtSuspendThread, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649820 NtEnumerateKey, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046498F0 NtReadVirtualMemory, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046498A0 NtWriteVirtualMemory, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649950 NtQueueApcThread, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046499D0 NtCreateProcessEx, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649A20 NtResumeThread, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649A00 NtProtectVirtualMemory, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649A10 NtQuerySection, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649A80 NtOpenDirectoryObject, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04649B00 NtSetValueKey, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0464A3B0 NtGetContextThread, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0013A360 NtCreateFile, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0013A410 NtReadFile, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0013A490 NtClose, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0013A540 NtAllocateVirtualMemory, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0013A3B3 NtReadFile, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0013A40B NtReadFile, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0013A53A NtAllocateVirtualMemory, |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0462746D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463A44B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0469C450 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0469C450 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463BC2C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046D740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046D740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046D740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04686C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04686C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04686C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04686C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046C1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046C1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046C1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046C1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046C1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046C1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046C1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046C1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046C1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046C1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046C1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046C1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046C1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046C1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046C14FB mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04686CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04686CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04686CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046D8CD6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0461849B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0462C577 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0462C577 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04643D43 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04683540 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046B3D40 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04627D50 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0460AD30 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04613D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04613D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04613D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04613D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04613D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04613D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04613D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04613D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04613D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04613D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04613D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04613D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04613D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046CE539 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04634D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04634D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04634D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046D8D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0468A537 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0461D5E0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0461D5E0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046CFDE2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046CFDE2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046CFDE2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046CFDE2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046B8DF1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04686DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04686DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04686DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04686DC9 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04686DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04686DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046D05AC mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046D05AC mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046335A1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04631DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04631DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04631DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04632581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04632581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04632581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04632581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04602D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04602D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04602D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04602D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04602D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463FD9B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463FD9B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0461766D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0462AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0462AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0462AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0462AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0462AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04617E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04617E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04617E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04617E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04617E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04617E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046CAE44 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046CAE44 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0460E620 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046BFE3F mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0460C600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0460C600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0460C600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04638E00 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046C1608 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463A61C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463A61C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046316E0 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046176E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04648EC7 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046BFEC0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046336CC mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046D8ED6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046D0EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046D0EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046D0EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046846A7 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0469FE87 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0461FF60 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046D8F6A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0461EF40 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04604F2E mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04604F2E mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463E730 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046D070D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046D070D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463A70E mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463A70E mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0462F716 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0469FF10 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0469FF10 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046437F5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04618794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04687794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04687794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04687794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046D1074 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046C2073 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04620050 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04620050 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0461B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0461B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0461B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0461B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046D4015 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046D4015 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04687016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04687016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04687016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046040E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046040E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046040E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046058EC mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0469B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0469B8D0 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0469B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0469B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0469B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0469B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046320A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046320A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046320A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046320A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046320A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046320A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046490AF mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463F0BF mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463F0BF mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463F0BF mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04609080 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04683884 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04683884 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0460C962 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0460B171 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0460B171 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0462B944 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0462B944 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04624120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04624120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04624120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04624120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04624120 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463513A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463513A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04609100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04609100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04609100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046941E8 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0460B1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0460B1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0460B1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046361A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046361A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046C49A4 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046C49A4 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046C49A4 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046C49A4 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046869A6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046851BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046851BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046851BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046851BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0462C182 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463A185 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04632990 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046BB260 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046BB260 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046D8A62 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0464927A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04609240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04609240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04609240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04609240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046CEA55 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04694257 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04644A2C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04644A2C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04618A0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04605210 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04605210 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04605210 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04605210 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0460AA16 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0460AA16 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046CAA16 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046CAA16 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04623A1C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04632AE4 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04632ACB mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046052A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046052A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046052A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046052A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046052A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0461AAB0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0461AAB0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463FAB0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463D294 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463D294 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0460DB60 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04633B7A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04633B7A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0460DB40 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046D8B58 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0460F358 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046C131B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046303E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046303E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046303E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046303E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046303E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046303E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0462DBE9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046853CA mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046853CA mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046D5BA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04634BAD mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04634BAD mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04634BAD mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046C138A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_046BD380 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04611B8F mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04611B8F mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_0463B390 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\msdt.exe | Code function: 10_2_04632397 mov eax, dword ptr fs:[00000030h] |