Source: 1.2.DHL DOC 3406506482.exe.400000.0.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 1.2.DHL DOC 3406506482.exe.400000.0.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 1.0.DHL DOC 3406506482.exe.400000.6.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 1.0.DHL DOC 3406506482.exe.400000.6.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 1.2.DHL DOC 3406506482.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 1.2.DHL DOC 3406506482.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 1.0.DHL DOC 3406506482.exe.400000.4.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 1.0.DHL DOC 3406506482.exe.400000.4.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 1.0.DHL DOC 3406506482.exe.400000.8.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 1.0.DHL DOC 3406506482.exe.400000.8.raw.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 1.0.DHL DOC 3406506482.exe.400000.8.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 1.0.DHL DOC 3406506482.exe.400000.8.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 1.0.DHL DOC 3406506482.exe.400000.6.unpack, type: UNPACKEDPE | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 1.0.DHL DOC 3406506482.exe.400000.6.unpack, type: UNPACKEDPE | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0000000E.00000002.513609784.0000000002D70000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0000000E.00000002.513609784.0000000002D70000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000001.00000000.245861481.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000001.00000000.245861481.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000002.00000000.290164309.00000000070EF000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000002.00000000.290164309.00000000070EF000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000001.00000002.316002438.0000000000AD0000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000001.00000002.316002438.0000000000AD0000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000001.00000002.315948001.00000000009C0000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000001.00000002.315948001.00000000009C0000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000001.00000000.246580702.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000001.00000000.246580702.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0000000E.00000002.513416867.0000000002C70000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0000000E.00000002.513416867.0000000002C70000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 0000000E.00000002.512624428.0000000000790000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 0000000E.00000002.512624428.0000000000790000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000002.00000000.275035294.00000000070EF000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000002.00000000.275035294.00000000070EF000.00000040.00020000.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000000.00000002.249416535.0000000003799000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000000.00000002.249416535.0000000003799000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000001.00000002.315617862.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000001.00000002.315617862.0000000000400000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: C:\Users\user\Desktop\DHL DOC 3406506482.exe | Code function: 1_2_0041A360 NtCreateFile, |
Source: C:\Users\user\Desktop\DHL DOC 3406506482.exe | Code function: 1_2_0041A410 NtReadFile, |
Source: C:\Users\user\Desktop\DHL DOC 3406506482.exe | Code function: 1_2_0041A490 NtClose, |
Source: C:\Users\user\Desktop\DHL DOC 3406506482.exe | Code function: 1_2_0041A540 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\DHL DOC 3406506482.exe | Code function: 1_2_0041A35A NtCreateFile, |
Source: C:\Users\user\Desktop\DHL DOC 3406506482.exe | Code function: 1_2_0041A48A NtReadFile,NtClose, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49860 NtQuerySystemInformation,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49840 NtDelayExecution,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A499A0 NtCreateSection,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A495D0 NtClose,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49910 NtAdjustPrivilegesToken,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49540 NtReadFile,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A496E0 NtFreeVirtualMemory,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A496D0 NtCreateKey,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49660 NtAllocateVirtualMemory,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49650 NtQueryValueKey,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49A50 NtCreateFile,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49780 NtMapViewOfSection,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49FE0 NtCreateMutant,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49710 NtQueryInformationToken,LdrInitializeThunk, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A498A0 NtWriteVirtualMemory, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A498F0 NtReadVirtualMemory, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49820 NtEnumerateKey, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A4B040 NtSuspendThread, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A495F0 NtQueryInformationFile, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A499D0 NtCreateProcessEx, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49520 NtWaitForSingleObject, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A4AD30 NtSetContextThread, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49560 NtWriteFile, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49950 NtQueueApcThread, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49A80 NtOpenDirectoryObject, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49A20 NtResumeThread, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49A00 NtProtectVirtualMemory, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49610 NtEnumerateValueKey, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49A10 NtQuerySection, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49670 NtQueryInformationProcess, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A497A0 NtUnmapViewOfSection, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A4A3B0 NtGetContextThread, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49730 NtQueryVirtualMemory, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49B00 NtSetValueKey, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A4A710 NtOpenProcessToken, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49760 NtOpenProcess, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A49770 NtSetInformationFile, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A4A770 NtOpenThread, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_02D8A360 NtCreateFile, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_02D8A490 NtClose, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_02D8A410 NtReadFile, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_02D8A540 NtAllocateVirtualMemory, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_02D8A35A NtCreateFile, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_02D8A48A NtReadFile,NtClose, |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A320A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A320A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A320A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A320A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A320A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A320A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A490AF mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3F0BF mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3F0BF mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3F0BF mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A09080 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A83884 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A83884 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A1849B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A058EC mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AC14FB mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A86CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A86CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A86CF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A9B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A9B8D0 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A9B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A9B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A9B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A9B8D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AD8CD6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A1B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A1B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A1B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A1B02A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3002D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3BC2C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AD740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AD740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AD740D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A86C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A86C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A86C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A86C0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AC1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AC1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AC1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AC1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AC1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AC1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AC1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AC1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AC1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AC1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AC1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AC1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AC1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AC1C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AD4015 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AD4015 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A87016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A87016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A87016 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A2746D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AD1074 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AC2073 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3A44B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A20050 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A20050 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A9C450 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A9C450 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A335A1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A361A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A361A0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A869A6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A31DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A31DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A31DB5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A851BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A851BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A851BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A851BE mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A2C182 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A32581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A32581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A32581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A32581 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3A185 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A02D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A02D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A02D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A02D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A02D8A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A32990 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3FD9B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3FD9B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A0B1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A0B1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A0B1E1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A941E8 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A1D5E0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A1D5E0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AB8DF1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A86DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A86DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A86DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A86DC9 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A86DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A86DC9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A24120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A24120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A24120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A24120 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A24120 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A0AD30 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A13D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A13D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A13D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A13D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A13D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A13D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A13D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A13D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A13D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A13D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A13D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A13D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A13D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A34D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A34D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A34D3B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AD8D34 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3513A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3513A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A8A537 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A09100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A09100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A09100 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A0C962 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A0B171 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A0B171 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A2C577 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A2C577 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A2B944 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A2B944 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A43D43 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A83540 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A27D50 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A052A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A052A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A052A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A052A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A052A5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AD0EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AD0EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AD0EA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A846A7 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A1AAB0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A1AAB0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3FAB0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A9FE87 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3D294 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3D294 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A316E0 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A176E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A32AE4 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A48EC7 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A32ACB mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04ABFEC0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A336CC mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AD8ED6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A0E620 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A44A2C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A44A2C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04ABFE3F mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A0C600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A0C600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A0C600 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A38E00 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A18A0A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A05210 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A05210 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A05210 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A05210 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A0AA16 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A0AA16 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A23A1C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3A61C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3A61C mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04ABB260 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04ABB260 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A1766D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AD8A62 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A2AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A2AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A2AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A2AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A2AE73 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A4927A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A09240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A09240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A09240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A09240 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A17E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A17E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A17E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A17E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A17E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A17E41 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A94257 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AD5BA5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A34BAD mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A34BAD mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A34BAD mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AC138A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04ABD380 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A11B8F mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A11B8F mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3B390 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A32397 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A18794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A87794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A87794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A87794 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A303E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A303E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A303E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A303E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A303E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A303E2 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A2DBE9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A437F5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A853CA mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A853CA mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A04F2E mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A04F2E mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3E730 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AD070D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AD070D mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3A70E mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A3A70E mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A2F716 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AC131B mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A9FF10 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A9FF10 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A0DB60 mov ecx, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A1FF60 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AD8F6A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A33B7A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A33B7A mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A0DB40 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A1EF40 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04AD8B58 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\SysWOW64\explorer.exe | Code function: 14_2_04A0F358 mov eax, dword ptr fs:[00000030h] |