Source: G47wmLn8uy.exe, 00000000.00000000.667550110.000000000042B000.00000002.00020000.sdmp | Binary or memory string: OriginalFilenameFort.exe vs G47wmLn8uy.exe |
Source: G47wmLn8uy.exe, 00000000.00000002.1190054948.00000000020C0000.00000004.00000001.sdmp | Binary or memory string: OriginalFilenameFort.exeFE2X vs G47wmLn8uy.exe |
Source: G47wmLn8uy.exe | Binary or memory string: OriginalFilenameFort.exe vs G47wmLn8uy.exe |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1841D |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1D38F |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D104CA |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D18498 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1749D |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1C4BD |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1C45D |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D18441 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D105C3 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D165C9 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D16589 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D10549 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1057D |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D10517 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1C509 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D136F8 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1C66C |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1663D |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D16759 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1C70E |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D160CA |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D160F6 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D19085 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1C052 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1706B |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D16005 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D18180 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1C2E9 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D18255 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1C259 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D16214 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1C226 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1C3D1 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D163ED |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1838C |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1C37D |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1632E |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D16C93 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D17C39 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D16DC9 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D16EE9 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D15F92 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D16F8D |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D168D1 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D169B1 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D159A7 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D189A8 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D16951 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1595B |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D18A90 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D16A75 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D18A15 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D18BD1 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D15BF0 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D15BB1 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D18B59 |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D16B4E |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1841D NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D184D9 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D18498 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D18441 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D18551 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D18663 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D18621 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D18255 NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1838C NtAllocateVirtualMemory, |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_00406471 push edi; iretd |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_00409011 push esp; retf |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_0040682F push esi; retf |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_0040A490 push ds; iretd |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_004079F6 push eax; retf |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_004055BF push ds; ret |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_00405ECC push ebp; ret |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_00407F27 push edi; ret |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_00407FBA push eax; iretd |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1747D pushfd ; iretd |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D17404 pushfd ; iretd |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D100CA push 5D54C3DCh; ret |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D19157 push E8BBB633h; retf 001Bh |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D14344 push 8122E3ECh; ret |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D17371 pushfd ; iretd |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D17368 pushfd ; iretd |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D11F01 push esi; ret |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D19B93 pushfd ; iretd |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | RDTSC instruction interceptor: First address: 0000000004D17C16 second address: 0000000004D17C16 instructions: 0x00000000 rdtsc 0x00000002 mov eax, B4901491h 0x00000007 sub eax, 05E3F0C7h 0x0000000c xor eax, 8F9A272Fh 0x00000011 sub eax, 213604E4h 0x00000016 cpuid 0x00000018 popad 0x00000019 call 00007F65F4CB431Dh 0x0000001e lfence 0x00000021 mov edx, 238EE826h 0x00000026 sub edx, 0388C43Eh 0x0000002c xor edx, E448541Bh 0x00000032 xor edx, BBB077E7h 0x00000038 mov edx, dword ptr [edx] 0x0000003a lfence 0x0000003d ret 0x0000003e sub edx, esi 0x00000040 ret 0x00000041 pop ecx 0x00000042 add edi, edx 0x00000044 dec ecx 0x00000045 mov dword ptr [ebp+00000229h], AD8B339Ah 0x0000004f xor dword ptr [ebp+00000229h], 22419229h 0x00000059 xor dword ptr [ebp+00000229h], 3996C157h 0x00000063 sub dword ptr [ebp+00000229h], B65C60E4h 0x0000006d cmp ecx, dword ptr [ebp+00000229h] 0x00000073 jne 00007F65F4CB4237h 0x00000075 cmp cx, ax 0x00000078 mov dword ptr [ebp+0000020Bh], ebx 0x0000007e mov ebx, ecx 0x00000080 push ebx 0x00000081 mov ebx, dword ptr [ebp+0000020Bh] 0x00000087 jmp 00007F65F4CB42DEh 0x00000089 cmp dl, bl 0x0000008b call 00007F65F4CB4321h 0x00000090 call 00007F65F4CB433Eh 0x00000095 lfence 0x00000098 mov edx, 238EE826h 0x0000009d sub edx, 0388C43Eh 0x000000a3 xor edx, E448541Bh 0x000000a9 xor edx, BBB077E7h 0x000000af mov edx, dword ptr [edx] 0x000000b1 lfence 0x000000b4 ret 0x000000b5 mov esi, edx 0x000000b7 pushad 0x000000b8 rdtsc |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1B2F5 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1C259 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1C226 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D1ACF0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\G47wmLn8uy.exe | Code function: 0_2_04D17A41 mov eax, dword ptr fs:[00000030h] |
Source: G47wmLn8uy.exe, 00000000.00000002.1189999307.0000000000C40000.00000002.00020000.sdmp | Binary or memory string: Program Manager |
Source: G47wmLn8uy.exe, 00000000.00000002.1189999307.0000000000C40000.00000002.00020000.sdmp | Binary or memory string: Shell_TrayWnd |
Source: G47wmLn8uy.exe, 00000000.00000002.1189999307.0000000000C40000.00000002.00020000.sdmp | Binary or memory string: Progman |
Source: G47wmLn8uy.exe, 00000000.00000002.1189999307.0000000000C40000.00000002.00020000.sdmp | Binary or memory string: Progmanlock |
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.