Windows Analysis Report
DHL Delivery Documents.exe

Overview

General Information

Sample Name: DHL Delivery Documents.exe
Analysis ID: 562120
MD5: 5bc8492c9f262d1f9840635b87edf9c5
SHA1: da867a8b837e43c91414ff46d239ab95b799d04b
SHA256: 7a4424af54555e5a81f6fa4e2b2c42c6d19c71bbcc261cd1be14af245c3b711c
Tags: exe
Infos:

Detection

FormBook
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected FormBook
Malicious sample detected (through community Yara rule)
Antivirus detection for URL or domain
Sample uses process hollowing technique
Maps a DLL or memory area into another process
Initial sample is a PE file and has a suspicious name
Writes to foreign memory regions
Machine Learning detection for sample
Allocates memory in foreign processes
.NET source code contains potential unpacker
Injects a PE file into a foreign processes
Queues an APC in another process (thread injection)
Tries to detect virtualization through RDTSC time measurements
Modifies the context of a thread in another process (thread injection)
Executable has a suspicious name (potential lure to open the executable)
C2 URLs / IPs found in malware configuration
Queries the volume information (name, serial number etc) of a device
Yara signature match
Antivirus or Machine Learning detection for unpacked file
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Sigma detected: Suspicious aspnet_compiler.exe Execution
Detected potential crypto function
Found potential string decryption / allocating functions
Sample execution stops while process was sleeping (likely an evasion)
JA3 SSL client fingerprint seen in connection with other malware
Contains functionality to call native functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Uses insecure TLS / SSL version for HTTPS connection
Contains functionality for execution timing, often used to detect debuggers
Contains long sleeps (>= 3 min)
Enables debug privileges
Found inlined nop instructions (likely shell or obfuscated code)
PE file does not import any functions
Sample file is different than original file name gathered from version info
PE file contains strange resources
Contains functionality to read the PEB
Checks if the current process is being debugged
Found large amount of non-executed APIs
Creates a process in suspended mode (likely to inject code)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)

Classification

AV Detection

barindex
Source: 00000007.00000000.296093050.0000000000400000.00000040.00000400.00020000.00000000.sdmp Malware Configuration Extractor: FormBook {"C2 list": ["www.trabaho-academy.net/zqzw/"], "decoy": ["laurentmathieu.com", "nohohonndana.com", "hhmc.info", "shophallows.com", "blazebunk.com", "goodbridge.xyz", "flakycloud.com", "bakermckenziegroups.com", "formation-adistance.com", "lovingearthbotanicals.com", "tbrservice.plus", "heritagehousehotels.com", "drwbuildersco.com", "lacsghb.com", "wain3x.com", "dadreview.club", "continiutycp.com", "cockgirls.com", "48mpt.xyz", "033skz.xyz", "gmconstructionlnc.com", "ms-mint.com", "aenrione.xyz", "honxuan.com", "snowmanvila.com", "cig-online.com", "valetvolley.com", "bjsnft.com", "bennystrom.com", "flw.ink", "clarissagrandiart.com", "samfamstudio.com", "pamschams.com", "edgar-regale.com", "combi-tech.tech", "00xwq.online", "eclipseconstrucciones.com", "plick-click.com", "dive.education", "regenelis.com", "blue-chipwordtoscan-today.info", "xn--rsso51aevf65u.com", "maonagrana.com", "lucasdebatintrader.com", "cassijohnson.com", "roeten.online", "into-concrete.xyz", "motovip.store", "floryfab.com", "slkykq.com", "vidyakala.com", "stairwaystowealth.com", "meganandbobbyprine.com", "arestradings.com", "emilyschlueter.com", "platanin.com", "hnhstudios.com", "dmembutidos.com", "dcassorealtor.com", "megamobil.wien", "001skz.xyz", "5t45urfgurkhgbvkhbuh.com", "a3hd.com", "newmexicotruckwrecklawyers.com"]}
Source: DHL Delivery Documents.exe Virustotal: Detection: 30% Perma Link
Source: Yara match File source: 7.0.aspnet_compiler.exe.400000.1.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.0.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.0.aspnet_compiler.exe.400000.2.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.0.aspnet_compiler.exe.400000.2.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.0.aspnet_compiler.exe.400000.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000007.00000000.296093050.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000008.00000000.331650604.000000001025A000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000C.00000002.592017625.00000000035D0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000000.296408181.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000002.00000002.299090873.0000000013AD4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.356715878.00000000012E0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.356781952.0000000001320000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000C.00000002.596403511.0000000004FF0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.356484497.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000C.00000002.586492056.0000000003130000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
Source: www.trabaho-academy.net/zqzw/ Avira URL Cloud: Label: malware
Source: DHL Delivery Documents.exe Joe Sandbox ML: detected
Source: 7.0.aspnet_compiler.exe.400000.1.unpack Avira: Label: TR/Crypt.ZPACK.Gen
Source: 7.2.aspnet_compiler.exe.400000.0.unpack Avira: Label: TR/Crypt.ZPACK.Gen
Source: 7.0.aspnet_compiler.exe.400000.2.unpack Avira: Label: TR/Crypt.ZPACK.Gen
Source: 7.0.aspnet_compiler.exe.400000.0.unpack Avira: Label: TR/Crypt.ZPACK.Gen

Compliance

barindex
Source: unknown HTTPS traffic detected: 144.76.136.153:443 -> 192.168.2.3:49751 version: TLS 1.0
Source: DHL Delivery Documents.exe Static PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
Source: Binary string: msdt.pdbGCTL source: aspnet_compiler.exe, 00000007.00000002.358011544.0000000002FC0000.00000040.10000000.00040000.00000000.sdmp
Source: Binary string: BNCXGAS.pdb source: DHL Delivery Documents.exe
Source: Binary string: wntdll.pdbUGP source: aspnet_compiler.exe, 00000007.00000002.356998480.00000000014EF000.00000040.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000007.00000003.296854295.00000000010A0000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000007.00000002.356845668.00000000013D0000.00000040.00000800.00020000.00000000.sdmp, msdt.exe, 0000000C.00000002.608610032.000000000556F000.00000040.00000800.00020000.00000000.sdmp, msdt.exe, 0000000C.00000002.602202907.0000000005450000.00000040.00000800.00020000.00000000.sdmp, msdt.exe, 0000000C.00000003.357056996.0000000005120000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: .pdbBSJB source: DHL Delivery Documents.exe, 00000002.00000002.297160400.0000000001350000.00000004.08000000.00040000.00000000.sdmp, DHL Delivery Documents.exe, 00000002.00000002.297652300.0000000003B63000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: wntdll.pdb source: aspnet_compiler.exe, aspnet_compiler.exe, 00000007.00000002.356998480.00000000014EF000.00000040.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000007.00000003.296854295.00000000010A0000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000007.00000002.356845668.00000000013D0000.00000040.00000800.00020000.00000000.sdmp, msdt.exe, msdt.exe, 0000000C.00000002.608610032.000000000556F000.00000040.00000800.00020000.00000000.sdmp, msdt.exe, 0000000C.00000002.602202907.0000000005450000.00000040.00000800.00020000.00000000.sdmp, msdt.exe, 0000000C.00000003.357056996.0000000005120000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: aspnet_compiler.pdb source: msdt.exe, 0000000C.00000002.620930532.0000000005987000.00000004.10000000.00040000.00000000.sdmp, msdt.exe, 0000000C.00000002.596381462.0000000003775000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: msdt.pdb source: aspnet_compiler.exe, 00000007.00000002.358011544.0000000002FC0000.00000040.10000000.00040000.00000000.sdmp

Software Vulnerabilities

barindex
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 4x nop then pop edi 7_2_0040C3A9
Source: C:\Windows\SysWOW64\msdt.exe Code function: 4x nop then pop edi 12_2_0313C3A9

Networking

barindex
Source: Malware configuration extractor URLs: www.trabaho-academy.net/zqzw/
Source: Joe Sandbox View JA3 fingerprint: 54328bd36c14bd82ddaa0c04b25ed9ad
Source: global traffic HTTP traffic detected: GET /get/mVKia7/BINCC.txt HTTP/1.1Host: transfer.shConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /get/KkxDr1/bbbbbbbbbbb.txt HTTP/1.1Host: transfer.sh
Source: Joe Sandbox View IP Address: 144.76.136.153 144.76.136.153
Source: Joe Sandbox View IP Address: 144.76.136.153 144.76.136.153
Source: unknown HTTPS traffic detected: 144.76.136.153:443 -> 192.168.2.3:49751 version: TLS 1.0
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49752
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751
Source: unknown Network traffic detected: HTTP traffic on port 49751 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49752 -> 443
Source: DHL Delivery Documents.exe, 00000002.00000002.297310779.000000000146A000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.globalsign.net/root-r2.crl0
Source: DHL Delivery Documents.exe, 00000002.00000002.300447432.000000001E2C4000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.microf
Source: DHL Delivery Documents.exe, 00000002.00000002.300447432.000000001E2C4000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.micros.
Source: DHL Delivery Documents.exe, 00000002.00000002.297376238.0000000003AC1000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: DHL Delivery Documents.exe, 00000002.00000002.300447432.000000001E2C4000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.microsoft.c
Source: DHL Delivery Documents.exe, 00000002.00000002.297376238.0000000003AC1000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://transfer.sh
Source: DHL Delivery Documents.exe String found in binary or memory: https://transfer.sh/get/KkxDr1/bbbbbbbbbbb.txt
Source: DHL Delivery Documents.exe String found in binary or memory: https://transfer.sh/get/KkxDr1/bbbbbbbbbbb.txt9BNCXGAS.Properties.ResourcesL
Source: DHL Delivery Documents.exe, 00000002.00000002.297598334.0000000003B1B000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://transfer.sh/get/KkxDr1/bbbbbbbbbbb.txtx
Source: DHL Delivery Documents.exe String found in binary or memory: https://transfer.sh/get/mVKia7/BINCC.txt
Source: unknown DNS traffic detected: queries for: transfer.sh
Source: global traffic HTTP traffic detected: GET /get/mVKia7/BINCC.txt HTTP/1.1Host: transfer.shConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /get/KkxDr1/bbbbbbbbbbb.txt HTTP/1.1Host: transfer.sh

E-Banking Fraud

barindex
Source: Yara match File source: 7.0.aspnet_compiler.exe.400000.1.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.0.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.0.aspnet_compiler.exe.400000.2.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.0.aspnet_compiler.exe.400000.2.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.0.aspnet_compiler.exe.400000.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000007.00000000.296093050.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000008.00000000.331650604.000000001025A000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000C.00000002.592017625.00000000035D0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000000.296408181.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000002.00000002.299090873.0000000013AD4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.356715878.00000000012E0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.356781952.0000000001320000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000C.00000002.596403511.0000000004FF0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.356484497.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000C.00000002.586492056.0000000003130000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY

System Summary

barindex
Source: 7.0.aspnet_compiler.exe.400000.1.unpack, type: UNPACKEDPE Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 7.0.aspnet_compiler.exe.400000.1.unpack, type: UNPACKEDPE Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 7.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 7.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 7.0.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 7.0.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 7.0.aspnet_compiler.exe.400000.2.unpack, type: UNPACKEDPE Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 7.0.aspnet_compiler.exe.400000.2.unpack, type: UNPACKEDPE Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 7.0.aspnet_compiler.exe.400000.2.raw.unpack, type: UNPACKEDPE Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 7.0.aspnet_compiler.exe.400000.2.raw.unpack, type: UNPACKEDPE Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 7.0.aspnet_compiler.exe.400000.1.raw.unpack, type: UNPACKEDPE Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 7.0.aspnet_compiler.exe.400000.1.raw.unpack, type: UNPACKEDPE Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 7.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPE Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 7.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPE Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 00000007.00000000.296093050.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 00000007.00000000.296093050.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 00000008.00000000.331650604.000000001025A000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 00000008.00000000.331650604.000000001025A000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 0000000C.00000002.592017625.00000000035D0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 0000000C.00000002.592017625.00000000035D0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 00000007.00000000.296408181.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 00000007.00000000.296408181.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 00000002.00000002.299090873.0000000013AD4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 00000002.00000002.299090873.0000000013AD4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 00000007.00000002.356715878.00000000012E0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 00000007.00000002.356715878.00000000012E0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 00000007.00000002.356781952.0000000001320000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 00000007.00000002.356781952.0000000001320000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 0000000C.00000002.596403511.0000000004FF0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 0000000C.00000002.596403511.0000000004FF0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 00000007.00000002.356484497.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 00000007.00000002.356484497.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 0000000C.00000002.586492056.0000000003130000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 0000000C.00000002.586492056.0000000003130000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: initial sample Static PE information: Filename: DHL Delivery Documents.exe
Source: DHL Delivery Documents.exe Static file information: Suspicious name
Source: 7.0.aspnet_compiler.exe.400000.1.unpack, type: UNPACKEDPE Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 7.0.aspnet_compiler.exe.400000.1.unpack, type: UNPACKEDPE Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 7.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 7.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 7.0.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 7.0.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 7.0.aspnet_compiler.exe.400000.2.unpack, type: UNPACKEDPE Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 7.0.aspnet_compiler.exe.400000.2.unpack, type: UNPACKEDPE Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 7.0.aspnet_compiler.exe.400000.2.raw.unpack, type: UNPACKEDPE Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 7.0.aspnet_compiler.exe.400000.2.raw.unpack, type: UNPACKEDPE Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 7.0.aspnet_compiler.exe.400000.1.raw.unpack, type: UNPACKEDPE Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 7.0.aspnet_compiler.exe.400000.1.raw.unpack, type: UNPACKEDPE Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 7.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPE Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 7.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPE Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 00000007.00000000.296093050.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 00000007.00000000.296093050.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 00000008.00000000.331650604.000000001025A000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 00000008.00000000.331650604.000000001025A000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 0000000C.00000002.592017625.00000000035D0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 0000000C.00000002.592017625.00000000035D0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 00000007.00000000.296408181.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 00000007.00000000.296408181.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 00000002.00000002.299090873.0000000013AD4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 00000002.00000002.299090873.0000000013AD4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 00000007.00000002.356715878.00000000012E0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 00000007.00000002.356715878.00000000012E0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 00000007.00000002.356781952.0000000001320000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 00000007.00000002.356781952.0000000001320000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 0000000C.00000002.596403511.0000000004FF0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 0000000C.00000002.596403511.0000000004FF0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 00000007.00000002.356484497.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 00000007.00000002.356484497.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 0000000C.00000002.586492056.0000000003130000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 0000000C.00000002.586492056.0000000003130000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Code function: 2_2_00007FFC081C3C37 2_2_00007FFC081C3C37
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_00401027 7_2_00401027
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_00401030 7_2_00401030
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0041C130 7_2_0041C130
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0041C235 7_2_0041C235
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0041C367 7_2_0041C367
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_00408C90 7_2_00408C90
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_00402D88 7_2_00402D88
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_00402D90 7_2_00402D90
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0041A6DA 7_2_0041A6DA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0041CF30 7_2_0041CF30
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_00402FB0 7_2_00402FB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013FF900 7_2_013FF900
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01414120 7_2_01414120
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014199BF 7_2_014199BF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B1002 7_2_014B1002
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014CE824 7_2_014CE824
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A830 7_2_0141A830
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C28EC 7_2_014C28EC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0140B090 7_2_0140B090
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014220A0 7_2_014220A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C20A8 7_2_014C20A8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141AB40 7_2_0141AB40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0149CB4F 7_2_0149CB4F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A309 7_2_0141A309
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C2B28 7_2_014C2B28
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B03DA 7_2_014B03DA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014BDBD2 7_2_014BDBD2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142ABD8 7_2_0142ABD8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014A23E3 7_2_014A23E3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142138B 7_2_0142138B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142EBB0 7_2_0142EBB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014AFA2B 7_2_014AFA2B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B236 7_2_0141B236
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4AEF 7_2_014B4AEF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C22AE 7_2_014C22AE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C1D55 7_2_014C1D55
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F0D20 7_2_013F0D20
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C2D07 7_2_014C2D07
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C25DD 7_2_014C25DD
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0140D5E0 7_2_0140D5E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01422581 7_2_01422581
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B2D82 7_2_014B2D82
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014BD466 7_2_014BD466
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B477 7_2_0141B477
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0140841F 7_2_0140841F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4496 7_2_014B4496
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014CDFCE 7_2_014CDFCE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C1FF1 7_2_014C1FF1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014BD616 7_2_014BD616
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01416E30 7_2_01416E30
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C2EF7 7_2_014C2EF7
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05541D55 12_2_05541D55
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05542D07 12_2_05542D07
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05470D20 12_2_05470D20
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_055425DD 12_2_055425DD
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0548D5E0 12_2_0548D5E0
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054A2581 12_2_054A2581
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05532D82 12_2_05532D82
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0553D466 12_2_0553D466
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0549B477 12_2_0549B477
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0548841F 12_2_0548841F
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05534496 12_2_05534496
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0554DFCE 12_2_0554DFCE
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05541FF1 12_2_05541FF1
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0553D616 12_2_0553D616
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05496E30 12_2_05496E30
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05542EF7 12_2_05542EF7
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0547F900 12_2_0547F900
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05494120 12_2_05494120
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054999BF 12_2_054999BF
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05531002 12_2_05531002
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0554E824 12_2_0554E824
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0549A830 12_2_0549A830
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_055428EC 12_2_055428EC
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0548B090 12_2_0548B090
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054A20A0 12_2_054A20A0
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_055420A8 12_2_055420A8
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0549AB40 12_2_0549AB40
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0551CB4F 12_2_0551CB4F
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0549A309 12_2_0549A309
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05542B28 12_2_05542B28
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0553DBD2 12_2_0553DBD2
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_055303DA 12_2_055303DA
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054AABD8 12_2_054AABD8
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_055223E3 12_2_055223E3
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054A138B 12_2_054A138B
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054AEBB0 12_2_054AEBB0
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0552FA2B 12_2_0552FA2B
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0549B236 12_2_0549B236
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05534AEF 12_2_05534AEF
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_055422AE 12_2_055422AE
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0314C367 12_2_0314C367
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0314C130 12_2_0314C130
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0314CF30 12_2_0314CF30
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_03132FB0 12_2_03132FB0
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0314A6DA 12_2_0314A6DA
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_03132D90 12_2_03132D90
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_03132D88 12_2_03132D88
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_03138C90 12_2_03138C90
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: String function: 013FB150 appears 136 times
Source: C:\Windows\SysWOW64\msdt.exe Code function: String function: 0547B150 appears 136 times
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_004185F0 NtCreateFile, 7_2_004185F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_004186A0 NtReadFile, 7_2_004186A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_00418720 NtClose, 7_2_00418720
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_004187D0 NtAllocateVirtualMemory, 7_2_004187D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_004185EC NtCreateFile, 7_2_004185EC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0041869A NtCreateFile, 7_2_0041869A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0041869F NtReadFile, 7_2_0041869F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0041871A NtClose, 7_2_0041871A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_004187CA NtAllocateVirtualMemory, 7_2_004187CA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439910 NtAdjustPrivilegesToken,LdrInitializeThunk, 7_2_01439910
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014399A0 NtCreateSection,LdrInitializeThunk, 7_2_014399A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439840 NtDelayExecution,LdrInitializeThunk, 7_2_01439840
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439860 NtQuerySystemInformation,LdrInitializeThunk, 7_2_01439860
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014398F0 NtReadVirtualMemory,LdrInitializeThunk, 7_2_014398F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439A50 NtCreateFile,LdrInitializeThunk, 7_2_01439A50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439A00 NtProtectVirtualMemory,LdrInitializeThunk, 7_2_01439A00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439A20 NtResumeThread,LdrInitializeThunk, 7_2_01439A20
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439540 NtReadFile,LdrInitializeThunk, 7_2_01439540
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014395D0 NtClose,LdrInitializeThunk, 7_2_014395D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439710 NtQueryInformationToken,LdrInitializeThunk, 7_2_01439710
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439FE0 NtCreateMutant,LdrInitializeThunk, 7_2_01439FE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439780 NtMapViewOfSection,LdrInitializeThunk, 7_2_01439780
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014397A0 NtUnmapViewOfSection,LdrInitializeThunk, 7_2_014397A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439660 NtAllocateVirtualMemory,LdrInitializeThunk, 7_2_01439660
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014396E0 NtFreeVirtualMemory,LdrInitializeThunk, 7_2_014396E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439950 NtQueueApcThread, 7_2_01439950
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014399D0 NtCreateProcessEx, 7_2_014399D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0143B040 NtSuspendThread, 7_2_0143B040
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439820 NtEnumerateKey, 7_2_01439820
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014398A0 NtWriteVirtualMemory, 7_2_014398A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439B00 NtSetValueKey, 7_2_01439B00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0143A3B0 NtGetContextThread, 7_2_0143A3B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439A10 NtQuerySection, 7_2_01439A10
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439A80 NtOpenDirectoryObject, 7_2_01439A80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439560 NtWriteFile, 7_2_01439560
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439520 NtWaitForSingleObject, 7_2_01439520
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0143AD30 NtSetContextThread, 7_2_0143AD30
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014395F0 NtQueryInformationFile, 7_2_014395F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439760 NtOpenProcess, 7_2_01439760
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439770 NtSetInformationFile, 7_2_01439770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0143A770 NtOpenThread, 7_2_0143A770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0143A710 NtOpenProcessToken, 7_2_0143A710
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439730 NtQueryVirtualMemory, 7_2_01439730
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439650 NtQueryValueKey, 7_2_01439650
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439670 NtQueryInformationProcess, 7_2_01439670
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01439610 NtEnumerateValueKey, 7_2_01439610
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014396D0 NtCreateKey, 7_2_014396D0
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9540 NtReadFile,LdrInitializeThunk, 12_2_054B9540
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B95D0 NtClose,LdrInitializeThunk, 12_2_054B95D0
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9710 NtQueryInformationToken,LdrInitializeThunk, 12_2_054B9710
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9FE0 NtCreateMutant,LdrInitializeThunk, 12_2_054B9FE0
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9780 NtMapViewOfSection,LdrInitializeThunk, 12_2_054B9780
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9650 NtQueryValueKey,LdrInitializeThunk, 12_2_054B9650
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9660 NtAllocateVirtualMemory,LdrInitializeThunk, 12_2_054B9660
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B96D0 NtCreateKey,LdrInitializeThunk, 12_2_054B96D0
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B96E0 NtFreeVirtualMemory,LdrInitializeThunk, 12_2_054B96E0
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9910 NtAdjustPrivilegesToken,LdrInitializeThunk, 12_2_054B9910
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B99A0 NtCreateSection,LdrInitializeThunk, 12_2_054B99A0
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9840 NtDelayExecution,LdrInitializeThunk, 12_2_054B9840
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9860 NtQuerySystemInformation,LdrInitializeThunk, 12_2_054B9860
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9A50 NtCreateFile,LdrInitializeThunk, 12_2_054B9A50
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9560 NtWriteFile, 12_2_054B9560
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9520 NtWaitForSingleObject, 12_2_054B9520
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054BAD30 NtSetContextThread, 12_2_054BAD30
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B95F0 NtQueryInformationFile, 12_2_054B95F0
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9760 NtOpenProcess, 12_2_054B9760
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054BA770 NtOpenThread, 12_2_054BA770
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9770 NtSetInformationFile, 12_2_054B9770
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054BA710 NtOpenProcessToken, 12_2_054BA710
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9730 NtQueryVirtualMemory, 12_2_054B9730
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B97A0 NtUnmapViewOfSection, 12_2_054B97A0
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9670 NtQueryInformationProcess, 12_2_054B9670
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9610 NtEnumerateValueKey, 12_2_054B9610
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9950 NtQueueApcThread, 12_2_054B9950
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B99D0 NtCreateProcessEx, 12_2_054B99D0
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054BB040 NtSuspendThread, 12_2_054BB040
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9820 NtEnumerateKey, 12_2_054B9820
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B98F0 NtReadVirtualMemory, 12_2_054B98F0
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B98A0 NtWriteVirtualMemory, 12_2_054B98A0
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9B00 NtSetValueKey, 12_2_054B9B00
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054BA3B0 NtGetContextThread, 12_2_054BA3B0
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9A00 NtProtectVirtualMemory, 12_2_054B9A00
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9A10 NtQuerySection, 12_2_054B9A10
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9A20 NtResumeThread, 12_2_054B9A20
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B9A80 NtOpenDirectoryObject, 12_2_054B9A80
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_03148720 NtClose, 12_2_03148720
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_031487D0 NtAllocateVirtualMemory, 12_2_031487D0
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_031486A0 NtReadFile, 12_2_031486A0
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_031485F0 NtCreateFile, 12_2_031485F0
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0314871A NtClose, 12_2_0314871A
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_031487CA NtAllocateVirtualMemory, 12_2_031487CA
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0314869F NtReadFile, 12_2_0314869F
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0314869A NtCreateFile, 12_2_0314869A
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_031485EC NtCreateFile, 12_2_031485EC
Source: DHL Delivery Documents.exe Static PE information: No import functions for PE file found
Source: DHL Delivery Documents.exe Binary or memory string: OriginalFilename vs DHL Delivery Documents.exe
Source: DHL Delivery Documents.exe, 00000002.00000002.297172945.0000000001360000.00000004.08000000.00040000.00000000.sdmp Binary or memory string: OriginalFilenameResourceAssembly.dllD vs DHL Delivery Documents.exe
Source: DHL Delivery Documents.exe, 00000002.00000002.297160400.0000000001350000.00000004.08000000.00040000.00000000.sdmp Binary or memory string: OriginalFilename vs DHL Delivery Documents.exe
Source: DHL Delivery Documents.exe, 00000002.00000002.297081764.0000000000AD2000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilenameBNCXGAS.exe0 vs DHL Delivery Documents.exe
Source: DHL Delivery Documents.exe, 00000002.00000002.297652300.0000000003B63000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilename vs DHL Delivery Documents.exe
Source: DHL Delivery Documents.exe, 00000002.00000002.297652300.0000000003B63000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameResourceAssembly.dllD vs DHL Delivery Documents.exe
Source: DHL Delivery Documents.exe, 00000002.00000002.297200414.000000000139A000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameclr.dllT vs DHL Delivery Documents.exe
Source: DHL Delivery Documents.exe Binary or memory string: OriginalFilenameBNCXGAS.exe0 vs DHL Delivery Documents.exe
Source: DHL Delivery Documents.exe Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: DHL Delivery Documents.exe Virustotal: Detection: 30%
Source: DHL Delivery Documents.exe Static PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\DHL Delivery Documents.exe "C:\Users\user\Desktop\DHL Delivery Documents.exe"
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
Source: C:\Windows\explorer.exe Process created: C:\Windows\SysWOW64\msdt.exe C:\Windows\SysWOW64\msdt.exe
Source: C:\Windows\SysWOW64\msdt.exe Process created: C:\Windows\SysWOW64\cmd.exe /c del "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe"
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process created: C:\Windows\SysWOW64\cmd.exe /c del "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe" Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe File created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\DHL Delivery Documents.exe.log Jump to behavior
Source: classification engine Classification label: mal100.troj.evad.winEXE@7/1@1/1
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_64\mscorlib\ac26e2af62f23e37e645b5e44068a025\mscorlib.ni.dll Jump to behavior
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5256:120:WilError_01
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe File opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dll Jump to behavior
Source: DHL Delivery Documents.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
Source: DHL Delivery Documents.exe Static PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
Source: DHL Delivery Documents.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: msdt.pdbGCTL source: aspnet_compiler.exe, 00000007.00000002.358011544.0000000002FC0000.00000040.10000000.00040000.00000000.sdmp
Source: Binary string: BNCXGAS.pdb source: DHL Delivery Documents.exe
Source: Binary string: wntdll.pdbUGP source: aspnet_compiler.exe, 00000007.00000002.356998480.00000000014EF000.00000040.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000007.00000003.296854295.00000000010A0000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000007.00000002.356845668.00000000013D0000.00000040.00000800.00020000.00000000.sdmp, msdt.exe, 0000000C.00000002.608610032.000000000556F000.00000040.00000800.00020000.00000000.sdmp, msdt.exe, 0000000C.00000002.602202907.0000000005450000.00000040.00000800.00020000.00000000.sdmp, msdt.exe, 0000000C.00000003.357056996.0000000005120000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: .pdbBSJB source: DHL Delivery Documents.exe, 00000002.00000002.297160400.0000000001350000.00000004.08000000.00040000.00000000.sdmp, DHL Delivery Documents.exe, 00000002.00000002.297652300.0000000003B63000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: wntdll.pdb source: aspnet_compiler.exe, aspnet_compiler.exe, 00000007.00000002.356998480.00000000014EF000.00000040.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000007.00000003.296854295.00000000010A0000.00000004.00000800.00020000.00000000.sdmp, aspnet_compiler.exe, 00000007.00000002.356845668.00000000013D0000.00000040.00000800.00020000.00000000.sdmp, msdt.exe, msdt.exe, 0000000C.00000002.608610032.000000000556F000.00000040.00000800.00020000.00000000.sdmp, msdt.exe, 0000000C.00000002.602202907.0000000005450000.00000040.00000800.00020000.00000000.sdmp, msdt.exe, 0000000C.00000003.357056996.0000000005120000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: aspnet_compiler.pdb source: msdt.exe, 0000000C.00000002.620930532.0000000005987000.00000004.10000000.00040000.00000000.sdmp, msdt.exe, 0000000C.00000002.596381462.0000000003775000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: msdt.pdb source: aspnet_compiler.exe, 00000007.00000002.358011544.0000000002FC0000.00000040.10000000.00040000.00000000.sdmp

Data Obfuscation

barindex
Source: DHL Delivery Documents.exe, BNCXGAS/Program.cs .Net Code: Main System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0041C805 push edx; ret 7_2_0041B9DA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0041B832 push eax; ret 7_2_0041B838
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0041B83B push eax; ret 7_2_0041B8A2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0041B8D3 push edx; ret 7_2_0041B9DA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0041B89C push eax; ret 7_2_0041B8A2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0041C130 push edx; ret 7_2_0041B9DA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0041C235 push edx; ret 7_2_0041B9DA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0041C367 push edx; ret 7_2_0041B9DA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0041C31E push edx; ret 7_2_0041B9DA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0040D438 push es; retf 7_2_0040D43F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_00414F52 push eax; ret 7_2_00414F53
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0041B7E5 push eax; ret 7_2_0041B838
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0144D0D1 push ecx; ret 7_2_0144D0E4
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054CD0D1 push ecx; ret 12_2_054CD0E4
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0314C31E push edx; ret 12_2_0314B9DA
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0314C367 push edx; ret 12_2_0314B9DA
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0314C281 push edx; ret 12_2_0314B9DA
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0314C130 push edx; ret 12_2_0314B9DA
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0314C805 push edx; ret 12_2_0314B9DA
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0314B832 push eax; ret 12_2_0314B838
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0314B83B push eax; ret 12_2_0314B8A2
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0314B89C push eax; ret 12_2_0314B8A2
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0314B8D3 push edx; ret 12_2_0314B9DA
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_03144F52 push eax; ret 12_2_03144F53
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0314B7E5 push eax; ret 12_2_0314B838
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0313D438 push es; retf 12_2_0313D43F
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process information set: NOOPENFILEERRORBOX Jump to behavior

Malware Analysis System Evasion

barindex
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe RDTSC instruction interceptor: First address: 0000000000408614 second address: 000000000040861A instructions: 0x00000000 rdtsc 0x00000002 xor ecx, ecx 0x00000004 add ecx, eax 0x00000006 rdtsc
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe RDTSC instruction interceptor: First address: 00000000004089AE second address: 00000000004089B4 instructions: 0x00000000 rdtsc 0x00000002 xor ecx, ecx 0x00000004 add ecx, eax 0x00000006 rdtsc
Source: C:\Windows\SysWOW64\msdt.exe RDTSC instruction interceptor: First address: 0000000003138614 second address: 000000000313861A instructions: 0x00000000 rdtsc 0x00000002 xor ecx, ecx 0x00000004 add ecx, eax 0x00000006 rdtsc
Source: C:\Windows\SysWOW64\msdt.exe RDTSC instruction interceptor: First address: 00000000031389AE second address: 00000000031389B4 instructions: 0x00000000 rdtsc 0x00000002 xor ecx, ecx 0x00000004 add ecx, eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe TID: 2228 Thread sleep time: -30000s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe TID: 6792 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Last function: Thread delayed
Source: C:\Windows\SysWOW64\msdt.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_004088E0 rdtsc 7_2_004088E0
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe API coverage: 6.3 %
Source: C:\Windows\SysWOW64\msdt.exe API coverage: 6.5 %
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: explorer.exe, 00000008.00000000.327847130.00000000086C9000.00000004.00000001.00020000.00000000.sdmp Binary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#5&280b647&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}
Source: explorer.exe, 00000008.00000000.309195507.0000000008778000.00000004.00000001.00020000.00000000.sdmp Binary or memory string: SCSI\Disk&Ven_VMware&Prod_Virtual_disk\5&1ec51bf7&0&000000}
Source: explorer.exe, 00000008.00000000.327847130.00000000086C9000.00000004.00000001.00020000.00000000.sdmp Binary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#5&280b647&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}&
Source: explorer.exe, 00000008.00000000.323844313.00000000067C2000.00000004.00000001.00020000.00000000.sdmp Binary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: explorer.exe, 00000008.00000000.323844313.00000000067C2000.00000004.00000001.00020000.00000000.sdmp Binary or memory string: SCSI\CDROM&VEN_NECVMWAR&PROD_VMWARE_SATA_CD00\5&280B647&0&000000m32)
Source: explorer.exe, 00000008.00000000.301405872.0000000000C10000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}osoft S
Source: explorer.exe, 00000008.00000000.327847130.00000000086C9000.00000004.00000001.00020000.00000000.sdmp Binary or memory string: SCSI\CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00\5&280b647&0&000000
Source: DHL Delivery Documents.exe, 00000002.00000002.297292575.000000000144A000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll

Anti Debugging

barindex
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_004088E0 rdtsc 7_2_004088E0
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B944 mov eax, dword ptr fs:[00000030h] 7_2_0141B944
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B944 mov eax, dword ptr fs:[00000030h] 7_2_0141B944
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F9100 mov eax, dword ptr fs:[00000030h] 7_2_013F9100
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F9100 mov eax, dword ptr fs:[00000030h] 7_2_013F9100
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F9100 mov eax, dword ptr fs:[00000030h] 7_2_013F9100
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013FB171 mov eax, dword ptr fs:[00000030h] 7_2_013FB171
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013FB171 mov eax, dword ptr fs:[00000030h] 7_2_013FB171
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013FC962 mov eax, dword ptr fs:[00000030h] 7_2_013FC962
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01414120 mov eax, dword ptr fs:[00000030h] 7_2_01414120
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01414120 mov eax, dword ptr fs:[00000030h] 7_2_01414120
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01414120 mov eax, dword ptr fs:[00000030h] 7_2_01414120
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01414120 mov eax, dword ptr fs:[00000030h] 7_2_01414120
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01414120 mov ecx, dword ptr fs:[00000030h] 7_2_01414120
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142513A mov eax, dword ptr fs:[00000030h] 7_2_0142513A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142513A mov eax, dword ptr fs:[00000030h] 7_2_0142513A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014841E8 mov eax, dword ptr fs:[00000030h] 7_2_014841E8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141C182 mov eax, dword ptr fs:[00000030h] 7_2_0141C182
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142A185 mov eax, dword ptr fs:[00000030h] 7_2_0142A185
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01422990 mov eax, dword ptr fs:[00000030h] 7_2_01422990
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013FB1E1 mov eax, dword ptr fs:[00000030h] 7_2_013FB1E1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013FB1E1 mov eax, dword ptr fs:[00000030h] 7_2_013FB1E1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013FB1E1 mov eax, dword ptr fs:[00000030h] 7_2_013FB1E1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014769A6 mov eax, dword ptr fs:[00000030h] 7_2_014769A6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014261A0 mov eax, dword ptr fs:[00000030h] 7_2_014261A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014261A0 mov eax, dword ptr fs:[00000030h] 7_2_014261A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B49A4 mov eax, dword ptr fs:[00000030h] 7_2_014B49A4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B49A4 mov eax, dword ptr fs:[00000030h] 7_2_014B49A4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B49A4 mov eax, dword ptr fs:[00000030h] 7_2_014B49A4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B49A4 mov eax, dword ptr fs:[00000030h] 7_2_014B49A4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014751BE mov eax, dword ptr fs:[00000030h] 7_2_014751BE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014751BE mov eax, dword ptr fs:[00000030h] 7_2_014751BE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014751BE mov eax, dword ptr fs:[00000030h] 7_2_014751BE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014751BE mov eax, dword ptr fs:[00000030h] 7_2_014751BE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014199BF mov ecx, dword ptr fs:[00000030h] 7_2_014199BF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014199BF mov ecx, dword ptr fs:[00000030h] 7_2_014199BF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014199BF mov eax, dword ptr fs:[00000030h] 7_2_014199BF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014199BF mov ecx, dword ptr fs:[00000030h] 7_2_014199BF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014199BF mov ecx, dword ptr fs:[00000030h] 7_2_014199BF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014199BF mov eax, dword ptr fs:[00000030h] 7_2_014199BF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014199BF mov ecx, dword ptr fs:[00000030h] 7_2_014199BF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014199BF mov ecx, dword ptr fs:[00000030h] 7_2_014199BF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014199BF mov eax, dword ptr fs:[00000030h] 7_2_014199BF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014199BF mov ecx, dword ptr fs:[00000030h] 7_2_014199BF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014199BF mov ecx, dword ptr fs:[00000030h] 7_2_014199BF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014199BF mov eax, dword ptr fs:[00000030h] 7_2_014199BF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01410050 mov eax, dword ptr fs:[00000030h] 7_2_01410050
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01410050 mov eax, dword ptr fs:[00000030h] 7_2_01410050
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B2073 mov eax, dword ptr fs:[00000030h] 7_2_014B2073
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C1074 mov eax, dword ptr fs:[00000030h] 7_2_014C1074
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01477016 mov eax, dword ptr fs:[00000030h] 7_2_01477016
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01477016 mov eax, dword ptr fs:[00000030h] 7_2_01477016
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01477016 mov eax, dword ptr fs:[00000030h] 7_2_01477016
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C4015 mov eax, dword ptr fs:[00000030h] 7_2_014C4015
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C4015 mov eax, dword ptr fs:[00000030h] 7_2_014C4015
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0140B02A mov eax, dword ptr fs:[00000030h] 7_2_0140B02A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0140B02A mov eax, dword ptr fs:[00000030h] 7_2_0140B02A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0140B02A mov eax, dword ptr fs:[00000030h] 7_2_0140B02A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0140B02A mov eax, dword ptr fs:[00000030h] 7_2_0140B02A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142002D mov eax, dword ptr fs:[00000030h] 7_2_0142002D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142002D mov eax, dword ptr fs:[00000030h] 7_2_0142002D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142002D mov eax, dword ptr fs:[00000030h] 7_2_0142002D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142002D mov eax, dword ptr fs:[00000030h] 7_2_0142002D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142002D mov eax, dword ptr fs:[00000030h] 7_2_0142002D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A830 mov eax, dword ptr fs:[00000030h] 7_2_0141A830
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A830 mov eax, dword ptr fs:[00000030h] 7_2_0141A830
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A830 mov eax, dword ptr fs:[00000030h] 7_2_0141A830
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A830 mov eax, dword ptr fs:[00000030h] 7_2_0141A830
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0148B8D0 mov eax, dword ptr fs:[00000030h] 7_2_0148B8D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0148B8D0 mov ecx, dword ptr fs:[00000030h] 7_2_0148B8D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0148B8D0 mov eax, dword ptr fs:[00000030h] 7_2_0148B8D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0148B8D0 mov eax, dword ptr fs:[00000030h] 7_2_0148B8D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0148B8D0 mov eax, dword ptr fs:[00000030h] 7_2_0148B8D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0148B8D0 mov eax, dword ptr fs:[00000030h] 7_2_0148B8D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B8E4 mov eax, dword ptr fs:[00000030h] 7_2_0141B8E4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B8E4 mov eax, dword ptr fs:[00000030h] 7_2_0141B8E4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F9080 mov eax, dword ptr fs:[00000030h] 7_2_013F9080
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01473884 mov eax, dword ptr fs:[00000030h] 7_2_01473884
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01473884 mov eax, dword ptr fs:[00000030h] 7_2_01473884
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F58EC mov eax, dword ptr fs:[00000030h] 7_2_013F58EC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F40E1 mov eax, dword ptr fs:[00000030h] 7_2_013F40E1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F40E1 mov eax, dword ptr fs:[00000030h] 7_2_013F40E1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F40E1 mov eax, dword ptr fs:[00000030h] 7_2_013F40E1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014220A0 mov eax, dword ptr fs:[00000030h] 7_2_014220A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014220A0 mov eax, dword ptr fs:[00000030h] 7_2_014220A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014220A0 mov eax, dword ptr fs:[00000030h] 7_2_014220A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014220A0 mov eax, dword ptr fs:[00000030h] 7_2_014220A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014220A0 mov eax, dword ptr fs:[00000030h] 7_2_014220A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014220A0 mov eax, dword ptr fs:[00000030h] 7_2_014220A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014390AF mov eax, dword ptr fs:[00000030h] 7_2_014390AF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142F0BF mov ecx, dword ptr fs:[00000030h] 7_2_0142F0BF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142F0BF mov eax, dword ptr fs:[00000030h] 7_2_0142F0BF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142F0BF mov eax, dword ptr fs:[00000030h] 7_2_0142F0BF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C8B58 mov eax, dword ptr fs:[00000030h] 7_2_014C8B58
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01423B7A mov eax, dword ptr fs:[00000030h] 7_2_01423B7A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01423B7A mov eax, dword ptr fs:[00000030h] 7_2_01423B7A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A309 mov eax, dword ptr fs:[00000030h] 7_2_0141A309
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A309 mov eax, dword ptr fs:[00000030h] 7_2_0141A309
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A309 mov eax, dword ptr fs:[00000030h] 7_2_0141A309
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A309 mov eax, dword ptr fs:[00000030h] 7_2_0141A309
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A309 mov eax, dword ptr fs:[00000030h] 7_2_0141A309
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A309 mov eax, dword ptr fs:[00000030h] 7_2_0141A309
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A309 mov eax, dword ptr fs:[00000030h] 7_2_0141A309
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A309 mov eax, dword ptr fs:[00000030h] 7_2_0141A309
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A309 mov eax, dword ptr fs:[00000030h] 7_2_0141A309
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A309 mov eax, dword ptr fs:[00000030h] 7_2_0141A309
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A309 mov eax, dword ptr fs:[00000030h] 7_2_0141A309
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A309 mov eax, dword ptr fs:[00000030h] 7_2_0141A309
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A309 mov eax, dword ptr fs:[00000030h] 7_2_0141A309
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A309 mov eax, dword ptr fs:[00000030h] 7_2_0141A309
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A309 mov eax, dword ptr fs:[00000030h] 7_2_0141A309
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A309 mov eax, dword ptr fs:[00000030h] 7_2_0141A309
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A309 mov eax, dword ptr fs:[00000030h] 7_2_0141A309
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A309 mov eax, dword ptr fs:[00000030h] 7_2_0141A309
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A309 mov eax, dword ptr fs:[00000030h] 7_2_0141A309
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A309 mov eax, dword ptr fs:[00000030h] 7_2_0141A309
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A309 mov eax, dword ptr fs:[00000030h] 7_2_0141A309
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B131B mov eax, dword ptr fs:[00000030h] 7_2_014B131B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013FDB60 mov ecx, dword ptr fs:[00000030h] 7_2_013FDB60
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013FF358 mov eax, dword ptr fs:[00000030h] 7_2_013FF358
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013FDB40 mov eax, dword ptr fs:[00000030h] 7_2_013FDB40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014753CA mov eax, dword ptr fs:[00000030h] 7_2_014753CA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014753CA mov eax, dword ptr fs:[00000030h] 7_2_014753CA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014203E2 mov eax, dword ptr fs:[00000030h] 7_2_014203E2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014203E2 mov eax, dword ptr fs:[00000030h] 7_2_014203E2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014203E2 mov eax, dword ptr fs:[00000030h] 7_2_014203E2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014203E2 mov eax, dword ptr fs:[00000030h] 7_2_014203E2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014203E2 mov eax, dword ptr fs:[00000030h] 7_2_014203E2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014203E2 mov eax, dword ptr fs:[00000030h] 7_2_014203E2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141DBE9 mov eax, dword ptr fs:[00000030h] 7_2_0141DBE9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014A23E3 mov ecx, dword ptr fs:[00000030h] 7_2_014A23E3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014A23E3 mov ecx, dword ptr fs:[00000030h] 7_2_014A23E3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014A23E3 mov eax, dword ptr fs:[00000030h] 7_2_014A23E3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B138A mov eax, dword ptr fs:[00000030h] 7_2_014B138A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142138B mov eax, dword ptr fs:[00000030h] 7_2_0142138B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142138B mov eax, dword ptr fs:[00000030h] 7_2_0142138B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142138B mov eax, dword ptr fs:[00000030h] 7_2_0142138B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014AD380 mov ecx, dword ptr fs:[00000030h] 7_2_014AD380
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01401B8F mov eax, dword ptr fs:[00000030h] 7_2_01401B8F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01401B8F mov eax, dword ptr fs:[00000030h] 7_2_01401B8F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142B390 mov eax, dword ptr fs:[00000030h] 7_2_0142B390
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01422397 mov eax, dword ptr fs:[00000030h] 7_2_01422397
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C5BA5 mov eax, dword ptr fs:[00000030h] 7_2_014C5BA5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01424BAD mov eax, dword ptr fs:[00000030h] 7_2_01424BAD
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01424BAD mov eax, dword ptr fs:[00000030h] 7_2_01424BAD
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01424BAD mov eax, dword ptr fs:[00000030h] 7_2_01424BAD
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014BEA55 mov eax, dword ptr fs:[00000030h] 7_2_014BEA55
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01484257 mov eax, dword ptr fs:[00000030h] 7_2_01484257
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013FAA16 mov eax, dword ptr fs:[00000030h] 7_2_013FAA16
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013FAA16 mov eax, dword ptr fs:[00000030h] 7_2_013FAA16
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014AB260 mov eax, dword ptr fs:[00000030h] 7_2_014AB260
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014AB260 mov eax, dword ptr fs:[00000030h] 7_2_014AB260
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C8A62 mov eax, dword ptr fs:[00000030h] 7_2_014C8A62
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F5210 mov eax, dword ptr fs:[00000030h] 7_2_013F5210
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F5210 mov ecx, dword ptr fs:[00000030h] 7_2_013F5210
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F5210 mov eax, dword ptr fs:[00000030h] 7_2_013F5210
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F5210 mov eax, dword ptr fs:[00000030h] 7_2_013F5210
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0143927A mov eax, dword ptr fs:[00000030h] 7_2_0143927A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01408A0A mov eax, dword ptr fs:[00000030h] 7_2_01408A0A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01413A1C mov eax, dword ptr fs:[00000030h] 7_2_01413A1C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014BAA16 mov eax, dword ptr fs:[00000030h] 7_2_014BAA16
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014BAA16 mov eax, dword ptr fs:[00000030h] 7_2_014BAA16
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A229 mov eax, dword ptr fs:[00000030h] 7_2_0141A229
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A229 mov eax, dword ptr fs:[00000030h] 7_2_0141A229
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A229 mov eax, dword ptr fs:[00000030h] 7_2_0141A229
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A229 mov eax, dword ptr fs:[00000030h] 7_2_0141A229
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A229 mov eax, dword ptr fs:[00000030h] 7_2_0141A229
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A229 mov eax, dword ptr fs:[00000030h] 7_2_0141A229
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A229 mov eax, dword ptr fs:[00000030h] 7_2_0141A229
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A229 mov eax, dword ptr fs:[00000030h] 7_2_0141A229
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141A229 mov eax, dword ptr fs:[00000030h] 7_2_0141A229
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01434A2C mov eax, dword ptr fs:[00000030h] 7_2_01434A2C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01434A2C mov eax, dword ptr fs:[00000030h] 7_2_01434A2C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B236 mov eax, dword ptr fs:[00000030h] 7_2_0141B236
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B236 mov eax, dword ptr fs:[00000030h] 7_2_0141B236
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B236 mov eax, dword ptr fs:[00000030h] 7_2_0141B236
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B236 mov eax, dword ptr fs:[00000030h] 7_2_0141B236
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B236 mov eax, dword ptr fs:[00000030h] 7_2_0141B236
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B236 mov eax, dword ptr fs:[00000030h] 7_2_0141B236
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F9240 mov eax, dword ptr fs:[00000030h] 7_2_013F9240
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F9240 mov eax, dword ptr fs:[00000030h] 7_2_013F9240
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F9240 mov eax, dword ptr fs:[00000030h] 7_2_013F9240
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F9240 mov eax, dword ptr fs:[00000030h] 7_2_013F9240
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01422ACB mov eax, dword ptr fs:[00000030h] 7_2_01422ACB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F52A5 mov eax, dword ptr fs:[00000030h] 7_2_013F52A5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F52A5 mov eax, dword ptr fs:[00000030h] 7_2_013F52A5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F52A5 mov eax, dword ptr fs:[00000030h] 7_2_013F52A5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F52A5 mov eax, dword ptr fs:[00000030h] 7_2_013F52A5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F52A5 mov eax, dword ptr fs:[00000030h] 7_2_013F52A5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4AEF mov eax, dword ptr fs:[00000030h] 7_2_014B4AEF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4AEF mov eax, dword ptr fs:[00000030h] 7_2_014B4AEF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4AEF mov eax, dword ptr fs:[00000030h] 7_2_014B4AEF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4AEF mov eax, dword ptr fs:[00000030h] 7_2_014B4AEF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4AEF mov eax, dword ptr fs:[00000030h] 7_2_014B4AEF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4AEF mov eax, dword ptr fs:[00000030h] 7_2_014B4AEF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4AEF mov eax, dword ptr fs:[00000030h] 7_2_014B4AEF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4AEF mov eax, dword ptr fs:[00000030h] 7_2_014B4AEF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4AEF mov eax, dword ptr fs:[00000030h] 7_2_014B4AEF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4AEF mov eax, dword ptr fs:[00000030h] 7_2_014B4AEF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4AEF mov eax, dword ptr fs:[00000030h] 7_2_014B4AEF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4AEF mov eax, dword ptr fs:[00000030h] 7_2_014B4AEF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4AEF mov eax, dword ptr fs:[00000030h] 7_2_014B4AEF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4AEF mov eax, dword ptr fs:[00000030h] 7_2_014B4AEF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01422AE4 mov eax, dword ptr fs:[00000030h] 7_2_01422AE4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142D294 mov eax, dword ptr fs:[00000030h] 7_2_0142D294
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142D294 mov eax, dword ptr fs:[00000030h] 7_2_0142D294
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0140AAB0 mov eax, dword ptr fs:[00000030h] 7_2_0140AAB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0140AAB0 mov eax, dword ptr fs:[00000030h] 7_2_0140AAB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142FAB0 mov eax, dword ptr fs:[00000030h] 7_2_0142FAB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01433D43 mov eax, dword ptr fs:[00000030h] 7_2_01433D43
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01473540 mov eax, dword ptr fs:[00000030h] 7_2_01473540
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014A3D40 mov eax, dword ptr fs:[00000030h] 7_2_014A3D40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013FAD30 mov eax, dword ptr fs:[00000030h] 7_2_013FAD30
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01417D50 mov eax, dword ptr fs:[00000030h] 7_2_01417D50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141C577 mov eax, dword ptr fs:[00000030h] 7_2_0141C577
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141C577 mov eax, dword ptr fs:[00000030h] 7_2_0141C577
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0147A537 mov eax, dword ptr fs:[00000030h] 7_2_0147A537
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014BE539 mov eax, dword ptr fs:[00000030h] 7_2_014BE539
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01403D34 mov eax, dword ptr fs:[00000030h] 7_2_01403D34
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01403D34 mov eax, dword ptr fs:[00000030h] 7_2_01403D34
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01403D34 mov eax, dword ptr fs:[00000030h] 7_2_01403D34
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01403D34 mov eax, dword ptr fs:[00000030h] 7_2_01403D34
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01403D34 mov eax, dword ptr fs:[00000030h] 7_2_01403D34
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01403D34 mov eax, dword ptr fs:[00000030h] 7_2_01403D34
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01403D34 mov eax, dword ptr fs:[00000030h] 7_2_01403D34
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01403D34 mov eax, dword ptr fs:[00000030h] 7_2_01403D34
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01403D34 mov eax, dword ptr fs:[00000030h] 7_2_01403D34
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01403D34 mov eax, dword ptr fs:[00000030h] 7_2_01403D34
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01403D34 mov eax, dword ptr fs:[00000030h] 7_2_01403D34
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01403D34 mov eax, dword ptr fs:[00000030h] 7_2_01403D34
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01403D34 mov eax, dword ptr fs:[00000030h] 7_2_01403D34
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C8D34 mov eax, dword ptr fs:[00000030h] 7_2_014C8D34
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01424D3B mov eax, dword ptr fs:[00000030h] 7_2_01424D3B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01424D3B mov eax, dword ptr fs:[00000030h] 7_2_01424D3B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01424D3B mov eax, dword ptr fs:[00000030h] 7_2_01424D3B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01476DC9 mov eax, dword ptr fs:[00000030h] 7_2_01476DC9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01476DC9 mov eax, dword ptr fs:[00000030h] 7_2_01476DC9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01476DC9 mov eax, dword ptr fs:[00000030h] 7_2_01476DC9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01476DC9 mov ecx, dword ptr fs:[00000030h] 7_2_01476DC9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01476DC9 mov eax, dword ptr fs:[00000030h] 7_2_01476DC9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01476DC9 mov eax, dword ptr fs:[00000030h] 7_2_01476DC9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0140D5E0 mov eax, dword ptr fs:[00000030h] 7_2_0140D5E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0140D5E0 mov eax, dword ptr fs:[00000030h] 7_2_0140D5E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014BFDE2 mov eax, dword ptr fs:[00000030h] 7_2_014BFDE2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014BFDE2 mov eax, dword ptr fs:[00000030h] 7_2_014BFDE2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014BFDE2 mov eax, dword ptr fs:[00000030h] 7_2_014BFDE2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014BFDE2 mov eax, dword ptr fs:[00000030h] 7_2_014BFDE2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F2D8A mov eax, dword ptr fs:[00000030h] 7_2_013F2D8A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F2D8A mov eax, dword ptr fs:[00000030h] 7_2_013F2D8A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F2D8A mov eax, dword ptr fs:[00000030h] 7_2_013F2D8A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F2D8A mov eax, dword ptr fs:[00000030h] 7_2_013F2D8A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F2D8A mov eax, dword ptr fs:[00000030h] 7_2_013F2D8A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014A8DF1 mov eax, dword ptr fs:[00000030h] 7_2_014A8DF1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01422581 mov eax, dword ptr fs:[00000030h] 7_2_01422581
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01422581 mov eax, dword ptr fs:[00000030h] 7_2_01422581
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01422581 mov eax, dword ptr fs:[00000030h] 7_2_01422581
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01422581 mov eax, dword ptr fs:[00000030h] 7_2_01422581
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B2D82 mov eax, dword ptr fs:[00000030h] 7_2_014B2D82
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B2D82 mov eax, dword ptr fs:[00000030h] 7_2_014B2D82
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B2D82 mov eax, dword ptr fs:[00000030h] 7_2_014B2D82
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B2D82 mov eax, dword ptr fs:[00000030h] 7_2_014B2D82
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B2D82 mov eax, dword ptr fs:[00000030h] 7_2_014B2D82
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B2D82 mov eax, dword ptr fs:[00000030h] 7_2_014B2D82
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B2D82 mov eax, dword ptr fs:[00000030h] 7_2_014B2D82
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142FD9B mov eax, dword ptr fs:[00000030h] 7_2_0142FD9B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142FD9B mov eax, dword ptr fs:[00000030h] 7_2_0142FD9B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C05AC mov eax, dword ptr fs:[00000030h] 7_2_014C05AC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C05AC mov eax, dword ptr fs:[00000030h] 7_2_014C05AC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014235A1 mov eax, dword ptr fs:[00000030h] 7_2_014235A1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01421DB5 mov eax, dword ptr fs:[00000030h] 7_2_01421DB5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01421DB5 mov eax, dword ptr fs:[00000030h] 7_2_01421DB5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01421DB5 mov eax, dword ptr fs:[00000030h] 7_2_01421DB5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142A44B mov eax, dword ptr fs:[00000030h] 7_2_0142A44B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0148C450 mov eax, dword ptr fs:[00000030h] 7_2_0148C450
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0148C450 mov eax, dword ptr fs:[00000030h] 7_2_0148C450
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141746D mov eax, dword ptr fs:[00000030h] 7_2_0141746D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B477 mov eax, dword ptr fs:[00000030h] 7_2_0141B477
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B477 mov eax, dword ptr fs:[00000030h] 7_2_0141B477
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B477 mov eax, dword ptr fs:[00000030h] 7_2_0141B477
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B477 mov eax, dword ptr fs:[00000030h] 7_2_0141B477
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B477 mov eax, dword ptr fs:[00000030h] 7_2_0141B477
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B477 mov eax, dword ptr fs:[00000030h] 7_2_0141B477
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B477 mov eax, dword ptr fs:[00000030h] 7_2_0141B477
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B477 mov eax, dword ptr fs:[00000030h] 7_2_0141B477
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B477 mov eax, dword ptr fs:[00000030h] 7_2_0141B477
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B477 mov eax, dword ptr fs:[00000030h] 7_2_0141B477
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B477 mov eax, dword ptr fs:[00000030h] 7_2_0141B477
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B477 mov eax, dword ptr fs:[00000030h] 7_2_0141B477
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142AC7B mov eax, dword ptr fs:[00000030h] 7_2_0142AC7B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142AC7B mov eax, dword ptr fs:[00000030h] 7_2_0142AC7B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142AC7B mov eax, dword ptr fs:[00000030h] 7_2_0142AC7B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142AC7B mov eax, dword ptr fs:[00000030h] 7_2_0142AC7B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142AC7B mov eax, dword ptr fs:[00000030h] 7_2_0142AC7B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142AC7B mov eax, dword ptr fs:[00000030h] 7_2_0142AC7B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142AC7B mov eax, dword ptr fs:[00000030h] 7_2_0142AC7B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142AC7B mov eax, dword ptr fs:[00000030h] 7_2_0142AC7B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142AC7B mov eax, dword ptr fs:[00000030h] 7_2_0142AC7B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142AC7B mov eax, dword ptr fs:[00000030h] 7_2_0142AC7B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142AC7B mov eax, dword ptr fs:[00000030h] 7_2_0142AC7B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C740D mov eax, dword ptr fs:[00000030h] 7_2_014C740D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C740D mov eax, dword ptr fs:[00000030h] 7_2_014C740D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C740D mov eax, dword ptr fs:[00000030h] 7_2_014C740D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B1C06 mov eax, dword ptr fs:[00000030h] 7_2_014B1C06
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B1C06 mov eax, dword ptr fs:[00000030h] 7_2_014B1C06
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B1C06 mov eax, dword ptr fs:[00000030h] 7_2_014B1C06
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B1C06 mov eax, dword ptr fs:[00000030h] 7_2_014B1C06
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B1C06 mov eax, dword ptr fs:[00000030h] 7_2_014B1C06
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B1C06 mov eax, dword ptr fs:[00000030h] 7_2_014B1C06
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B1C06 mov eax, dword ptr fs:[00000030h] 7_2_014B1C06
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B1C06 mov eax, dword ptr fs:[00000030h] 7_2_014B1C06
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B1C06 mov eax, dword ptr fs:[00000030h] 7_2_014B1C06
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B1C06 mov eax, dword ptr fs:[00000030h] 7_2_014B1C06
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B1C06 mov eax, dword ptr fs:[00000030h] 7_2_014B1C06
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B1C06 mov eax, dword ptr fs:[00000030h] 7_2_014B1C06
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B1C06 mov eax, dword ptr fs:[00000030h] 7_2_014B1C06
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B1C06 mov eax, dword ptr fs:[00000030h] 7_2_014B1C06
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01476C0A mov eax, dword ptr fs:[00000030h] 7_2_01476C0A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01476C0A mov eax, dword ptr fs:[00000030h] 7_2_01476C0A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01476C0A mov eax, dword ptr fs:[00000030h] 7_2_01476C0A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01476C0A mov eax, dword ptr fs:[00000030h] 7_2_01476C0A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142BC2C mov eax, dword ptr fs:[00000030h] 7_2_0142BC2C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C8CD6 mov eax, dword ptr fs:[00000030h] 7_2_014C8CD6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B14FB mov eax, dword ptr fs:[00000030h] 7_2_014B14FB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01476CF0 mov eax, dword ptr fs:[00000030h] 7_2_01476CF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01476CF0 mov eax, dword ptr fs:[00000030h] 7_2_01476CF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01476CF0 mov eax, dword ptr fs:[00000030h] 7_2_01476CF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0140849B mov eax, dword ptr fs:[00000030h] 7_2_0140849B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4496 mov eax, dword ptr fs:[00000030h] 7_2_014B4496
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4496 mov eax, dword ptr fs:[00000030h] 7_2_014B4496
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4496 mov eax, dword ptr fs:[00000030h] 7_2_014B4496
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4496 mov eax, dword ptr fs:[00000030h] 7_2_014B4496
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4496 mov eax, dword ptr fs:[00000030h] 7_2_014B4496
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4496 mov eax, dword ptr fs:[00000030h] 7_2_014B4496
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4496 mov eax, dword ptr fs:[00000030h] 7_2_014B4496
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4496 mov eax, dword ptr fs:[00000030h] 7_2_014B4496
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4496 mov eax, dword ptr fs:[00000030h] 7_2_014B4496
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4496 mov eax, dword ptr fs:[00000030h] 7_2_014B4496
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4496 mov eax, dword ptr fs:[00000030h] 7_2_014B4496
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4496 mov eax, dword ptr fs:[00000030h] 7_2_014B4496
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B4496 mov eax, dword ptr fs:[00000030h] 7_2_014B4496
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0140EF40 mov eax, dword ptr fs:[00000030h] 7_2_0140EF40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F4F2E mov eax, dword ptr fs:[00000030h] 7_2_013F4F2E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013F4F2E mov eax, dword ptr fs:[00000030h] 7_2_013F4F2E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0140FF60 mov eax, dword ptr fs:[00000030h] 7_2_0140FF60
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C8F6A mov eax, dword ptr fs:[00000030h] 7_2_014C8F6A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C070D mov eax, dword ptr fs:[00000030h] 7_2_014C070D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C070D mov eax, dword ptr fs:[00000030h] 7_2_014C070D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142A70E mov eax, dword ptr fs:[00000030h] 7_2_0142A70E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142A70E mov eax, dword ptr fs:[00000030h] 7_2_0142A70E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141F716 mov eax, dword ptr fs:[00000030h] 7_2_0141F716
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0148FF10 mov eax, dword ptr fs:[00000030h] 7_2_0148FF10
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0148FF10 mov eax, dword ptr fs:[00000030h] 7_2_0148FF10
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142E730 mov eax, dword ptr fs:[00000030h] 7_2_0142E730
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B73D mov eax, dword ptr fs:[00000030h] 7_2_0141B73D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141B73D mov eax, dword ptr fs:[00000030h] 7_2_0141B73D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014337F5 mov eax, dword ptr fs:[00000030h] 7_2_014337F5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01477794 mov eax, dword ptr fs:[00000030h] 7_2_01477794
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01477794 mov eax, dword ptr fs:[00000030h] 7_2_01477794
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01477794 mov eax, dword ptr fs:[00000030h] 7_2_01477794
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01408794 mov eax, dword ptr fs:[00000030h] 7_2_01408794
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01407E41 mov eax, dword ptr fs:[00000030h] 7_2_01407E41
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01407E41 mov eax, dword ptr fs:[00000030h] 7_2_01407E41
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01407E41 mov eax, dword ptr fs:[00000030h] 7_2_01407E41
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01407E41 mov eax, dword ptr fs:[00000030h] 7_2_01407E41
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01407E41 mov eax, dword ptr fs:[00000030h] 7_2_01407E41
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01407E41 mov eax, dword ptr fs:[00000030h] 7_2_01407E41
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014BAE44 mov eax, dword ptr fs:[00000030h] 7_2_014BAE44
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014BAE44 mov eax, dword ptr fs:[00000030h] 7_2_014BAE44
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013FE620 mov eax, dword ptr fs:[00000030h] 7_2_013FE620
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0140766D mov eax, dword ptr fs:[00000030h] 7_2_0140766D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141AE73 mov eax, dword ptr fs:[00000030h] 7_2_0141AE73
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141AE73 mov eax, dword ptr fs:[00000030h] 7_2_0141AE73
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141AE73 mov eax, dword ptr fs:[00000030h] 7_2_0141AE73
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141AE73 mov eax, dword ptr fs:[00000030h] 7_2_0141AE73
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0141AE73 mov eax, dword ptr fs:[00000030h] 7_2_0141AE73
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013FC600 mov eax, dword ptr fs:[00000030h] 7_2_013FC600
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013FC600 mov eax, dword ptr fs:[00000030h] 7_2_013FC600
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_013FC600 mov eax, dword ptr fs:[00000030h] 7_2_013FC600
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01428E00 mov eax, dword ptr fs:[00000030h] 7_2_01428E00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014B1608 mov eax, dword ptr fs:[00000030h] 7_2_014B1608
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142A61C mov eax, dword ptr fs:[00000030h] 7_2_0142A61C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0142A61C mov eax, dword ptr fs:[00000030h] 7_2_0142A61C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014AFE3F mov eax, dword ptr fs:[00000030h] 7_2_014AFE3F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_01438EC7 mov eax, dword ptr fs:[00000030h] 7_2_01438EC7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014AFEC0 mov eax, dword ptr fs:[00000030h] 7_2_014AFEC0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014236CC mov eax, dword ptr fs:[00000030h] 7_2_014236CC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C8ED6 mov eax, dword ptr fs:[00000030h] 7_2_014C8ED6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014216E0 mov ecx, dword ptr fs:[00000030h] 7_2_014216E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014076E2 mov eax, dword ptr fs:[00000030h] 7_2_014076E2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_0148FE87 mov eax, dword ptr fs:[00000030h] 7_2_0148FE87
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014746A7 mov eax, dword ptr fs:[00000030h] 7_2_014746A7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C0EA5 mov eax, dword ptr fs:[00000030h] 7_2_014C0EA5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C0EA5 mov eax, dword ptr fs:[00000030h] 7_2_014C0EA5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_014C0EA5 mov eax, dword ptr fs:[00000030h] 7_2_014C0EA5
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054B3D43 mov eax, dword ptr fs:[00000030h] 12_2_054B3D43
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054F3540 mov eax, dword ptr fs:[00000030h] 12_2_054F3540
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05523D40 mov eax, dword ptr fs:[00000030h] 12_2_05523D40
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05497D50 mov eax, dword ptr fs:[00000030h] 12_2_05497D50
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0549C577 mov eax, dword ptr fs:[00000030h] 12_2_0549C577
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0549C577 mov eax, dword ptr fs:[00000030h] 12_2_0549C577
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05548D34 mov eax, dword ptr fs:[00000030h] 12_2_05548D34
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0553E539 mov eax, dword ptr fs:[00000030h] 12_2_0553E539
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054A4D3B mov eax, dword ptr fs:[00000030h] 12_2_054A4D3B
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054A4D3B mov eax, dword ptr fs:[00000030h] 12_2_054A4D3B
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054A4D3B mov eax, dword ptr fs:[00000030h] 12_2_054A4D3B
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0547AD30 mov eax, dword ptr fs:[00000030h] 12_2_0547AD30
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054FA537 mov eax, dword ptr fs:[00000030h] 12_2_054FA537
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05483D34 mov eax, dword ptr fs:[00000030h] 12_2_05483D34
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05483D34 mov eax, dword ptr fs:[00000030h] 12_2_05483D34
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05483D34 mov eax, dword ptr fs:[00000030h] 12_2_05483D34
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05483D34 mov eax, dword ptr fs:[00000030h] 12_2_05483D34
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05483D34 mov eax, dword ptr fs:[00000030h] 12_2_05483D34
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05483D34 mov eax, dword ptr fs:[00000030h] 12_2_05483D34
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05483D34 mov eax, dword ptr fs:[00000030h] 12_2_05483D34
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05483D34 mov eax, dword ptr fs:[00000030h] 12_2_05483D34
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05483D34 mov eax, dword ptr fs:[00000030h] 12_2_05483D34
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05483D34 mov eax, dword ptr fs:[00000030h] 12_2_05483D34
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05483D34 mov eax, dword ptr fs:[00000030h] 12_2_05483D34
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05483D34 mov eax, dword ptr fs:[00000030h] 12_2_05483D34
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05483D34 mov eax, dword ptr fs:[00000030h] 12_2_05483D34
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054F6DC9 mov eax, dword ptr fs:[00000030h] 12_2_054F6DC9
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054F6DC9 mov eax, dword ptr fs:[00000030h] 12_2_054F6DC9
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054F6DC9 mov eax, dword ptr fs:[00000030h] 12_2_054F6DC9
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054F6DC9 mov ecx, dword ptr fs:[00000030h] 12_2_054F6DC9
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054F6DC9 mov eax, dword ptr fs:[00000030h] 12_2_054F6DC9
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054F6DC9 mov eax, dword ptr fs:[00000030h] 12_2_054F6DC9
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05528DF1 mov eax, dword ptr fs:[00000030h] 12_2_05528DF1
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0548D5E0 mov eax, dword ptr fs:[00000030h] 12_2_0548D5E0
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0548D5E0 mov eax, dword ptr fs:[00000030h] 12_2_0548D5E0
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0553FDE2 mov eax, dword ptr fs:[00000030h] 12_2_0553FDE2
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0553FDE2 mov eax, dword ptr fs:[00000030h] 12_2_0553FDE2
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0553FDE2 mov eax, dword ptr fs:[00000030h] 12_2_0553FDE2
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0553FDE2 mov eax, dword ptr fs:[00000030h] 12_2_0553FDE2
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054A2581 mov eax, dword ptr fs:[00000030h] 12_2_054A2581
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054A2581 mov eax, dword ptr fs:[00000030h] 12_2_054A2581
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054A2581 mov eax, dword ptr fs:[00000030h] 12_2_054A2581
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054A2581 mov eax, dword ptr fs:[00000030h] 12_2_054A2581
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05472D8A mov eax, dword ptr fs:[00000030h] 12_2_05472D8A
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05472D8A mov eax, dword ptr fs:[00000030h] 12_2_05472D8A
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05472D8A mov eax, dword ptr fs:[00000030h] 12_2_05472D8A
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05472D8A mov eax, dword ptr fs:[00000030h] 12_2_05472D8A
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05472D8A mov eax, dword ptr fs:[00000030h] 12_2_05472D8A
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054AFD9B mov eax, dword ptr fs:[00000030h] 12_2_054AFD9B
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054AFD9B mov eax, dword ptr fs:[00000030h] 12_2_054AFD9B
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05532D82 mov eax, dword ptr fs:[00000030h] 12_2_05532D82
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05532D82 mov eax, dword ptr fs:[00000030h] 12_2_05532D82
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05532D82 mov eax, dword ptr fs:[00000030h] 12_2_05532D82
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05532D82 mov eax, dword ptr fs:[00000030h] 12_2_05532D82
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05532D82 mov eax, dword ptr fs:[00000030h] 12_2_05532D82
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05532D82 mov eax, dword ptr fs:[00000030h] 12_2_05532D82
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05532D82 mov eax, dword ptr fs:[00000030h] 12_2_05532D82
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054A35A1 mov eax, dword ptr fs:[00000030h] 12_2_054A35A1
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_055405AC mov eax, dword ptr fs:[00000030h] 12_2_055405AC
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_055405AC mov eax, dword ptr fs:[00000030h] 12_2_055405AC
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054A1DB5 mov eax, dword ptr fs:[00000030h] 12_2_054A1DB5
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054A1DB5 mov eax, dword ptr fs:[00000030h] 12_2_054A1DB5
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054A1DB5 mov eax, dword ptr fs:[00000030h] 12_2_054A1DB5
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0550C450 mov eax, dword ptr fs:[00000030h] 12_2_0550C450
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0550C450 mov eax, dword ptr fs:[00000030h] 12_2_0550C450
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054AA44B mov eax, dword ptr fs:[00000030h] 12_2_054AA44B
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0549746D mov eax, dword ptr fs:[00000030h] 12_2_0549746D
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054AAC7B mov eax, dword ptr fs:[00000030h] 12_2_054AAC7B
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054AAC7B mov eax, dword ptr fs:[00000030h] 12_2_054AAC7B
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054AAC7B mov eax, dword ptr fs:[00000030h] 12_2_054AAC7B
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054AAC7B mov eax, dword ptr fs:[00000030h] 12_2_054AAC7B
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054AAC7B mov eax, dword ptr fs:[00000030h] 12_2_054AAC7B
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054AAC7B mov eax, dword ptr fs:[00000030h] 12_2_054AAC7B
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054AAC7B mov eax, dword ptr fs:[00000030h] 12_2_054AAC7B
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054AAC7B mov eax, dword ptr fs:[00000030h] 12_2_054AAC7B
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054AAC7B mov eax, dword ptr fs:[00000030h] 12_2_054AAC7B
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054AAC7B mov eax, dword ptr fs:[00000030h] 12_2_054AAC7B
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054AAC7B mov eax, dword ptr fs:[00000030h] 12_2_054AAC7B
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0549B477 mov eax, dword ptr fs:[00000030h] 12_2_0549B477
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0549B477 mov eax, dword ptr fs:[00000030h] 12_2_0549B477
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0549B477 mov eax, dword ptr fs:[00000030h] 12_2_0549B477
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0549B477 mov eax, dword ptr fs:[00000030h] 12_2_0549B477
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0549B477 mov eax, dword ptr fs:[00000030h] 12_2_0549B477
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0549B477 mov eax, dword ptr fs:[00000030h] 12_2_0549B477
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0549B477 mov eax, dword ptr fs:[00000030h] 12_2_0549B477
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0549B477 mov eax, dword ptr fs:[00000030h] 12_2_0549B477
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0549B477 mov eax, dword ptr fs:[00000030h] 12_2_0549B477
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0549B477 mov eax, dword ptr fs:[00000030h] 12_2_0549B477
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0549B477 mov eax, dword ptr fs:[00000030h] 12_2_0549B477
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_0549B477 mov eax, dword ptr fs:[00000030h] 12_2_0549B477
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054F6C0A mov eax, dword ptr fs:[00000030h] 12_2_054F6C0A
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054F6C0A mov eax, dword ptr fs:[00000030h] 12_2_054F6C0A
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054F6C0A mov eax, dword ptr fs:[00000030h] 12_2_054F6C0A
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_054F6C0A mov eax, dword ptr fs:[00000030h] 12_2_054F6C0A
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05531C06 mov eax, dword ptr fs:[00000030h] 12_2_05531C06
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05531C06 mov eax, dword ptr fs:[00000030h] 12_2_05531C06
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05531C06 mov eax, dword ptr fs:[00000030h] 12_2_05531C06
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05531C06 mov eax, dword ptr fs:[00000030h] 12_2_05531C06
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05531C06 mov eax, dword ptr fs:[00000030h] 12_2_05531C06
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05531C06 mov eax, dword ptr fs:[00000030h] 12_2_05531C06
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05531C06 mov eax, dword ptr fs:[00000030h] 12_2_05531C06
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05531C06 mov eax, dword ptr fs:[00000030h] 12_2_05531C06
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05531C06 mov eax, dword ptr fs:[00000030h] 12_2_05531C06
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05531C06 mov eax, dword ptr fs:[00000030h] 12_2_05531C06
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05531C06 mov eax, dword ptr fs:[00000030h] 12_2_05531C06
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05531C06 mov eax, dword ptr fs:[00000030h] 12_2_05531C06
Source: C:\Windows\SysWOW64\msdt.exe Code function: 12_2_05531C06 mov eax, dword ptr fs:[00000030h] 12_2_05531C06
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Process queried: DebugPort Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process queried: DebugPort Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 7_2_00409B50 LdrLoadDll, 7_2_00409B50
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Memory allocated: page read and write | page guard Jump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Section unmapped: C:\Windows\SysWOW64\msdt.exe base address: EB0000 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Section loaded: unknown target: C:\Windows\explorer.exe protection: execute and read and write Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Section loaded: unknown target: C:\Windows\SysWOW64\msdt.exe protection: execute and read and write Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Section loaded: unknown target: C:\Windows\SysWOW64\msdt.exe protection: execute and read and write Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Section loaded: unknown target: C:\Windows\explorer.exe protection: read write Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Section loaded: unknown target: C:\Windows\explorer.exe protection: execute and read and write Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe base: 400000 Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe base: 401000 Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe base: BFF008 Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Memory allocated: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe base: 400000 protect: page execute and read and write Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe base: 400000 value starts with: 4D5A Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Thread APC queued: target process: C:\Windows\explorer.exe Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Thread register set: target process: 3352 Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Thread register set: target process: 3352 Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Jump to behavior
Source: C:\Windows\SysWOW64\msdt.exe Process created: C:\Windows\SysWOW64\cmd.exe /c del "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe" Jump to behavior
Source: explorer.exe, 00000008.00000000.335316675.00000000011E0000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 00000008.00000000.301532126.00000000011E0000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 00000008.00000000.317758768.00000000011E0000.00000002.00000001.00040000.00000000.sdmp Binary or memory string: Program Manager
Source: explorer.exe, 00000008.00000000.301326680.0000000000B68000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000008.00000000.334866837.0000000000B68000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000008.00000000.316167591.0000000000B68000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Progman\Pr
Source: explorer.exe, 00000008.00000000.335316675.00000000011E0000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 00000008.00000000.301532126.00000000011E0000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 00000008.00000000.317758768.00000000011E0000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 00000008.00000000.339922682.0000000005E10000.00000004.00000001.00020000.00000000.sdmp Binary or memory string: Shell_TrayWnd
Source: explorer.exe, 00000008.00000000.335316675.00000000011E0000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 00000008.00000000.301532126.00000000011E0000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 00000008.00000000.317758768.00000000011E0000.00000002.00000001.00040000.00000000.sdmp Binary or memory string: Progman
Source: explorer.exe, 00000008.00000000.335316675.00000000011E0000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 00000008.00000000.301532126.00000000011E0000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 00000008.00000000.317758768.00000000011E0000.00000002.00000001.00040000.00000000.sdmp Binary or memory string: Progmanlock
Source: explorer.exe, 00000008.00000000.344779338.0000000008778000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000008.00000000.309195507.0000000008778000.00000004.00000001.00020000.00000000.sdmp Binary or memory string: Shell_TrayWndh

Language, Device and Operating System Detection

barindex
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Queries volume information: C:\Users\user\Desktop\DHL Delivery Documents.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\DHL Delivery Documents.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior

Stealing of Sensitive Information

barindex
Source: Yara match File source: 7.0.aspnet_compiler.exe.400000.1.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.0.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.0.aspnet_compiler.exe.400000.2.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.0.aspnet_compiler.exe.400000.2.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.0.aspnet_compiler.exe.400000.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000007.00000000.296093050.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000008.00000000.331650604.000000001025A000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000C.00000002.592017625.00000000035D0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000000.296408181.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000002.00000002.299090873.0000000013AD4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.356715878.00000000012E0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.356781952.0000000001320000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000C.00000002.596403511.0000000004FF0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.356484497.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000C.00000002.586492056.0000000003130000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY

Remote Access Functionality

barindex
Source: Yara match File source: 7.0.aspnet_compiler.exe.400000.1.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.0.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.0.aspnet_compiler.exe.400000.2.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.0.aspnet_compiler.exe.400000.2.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.0.aspnet_compiler.exe.400000.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000007.00000000.296093050.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000008.00000000.331650604.000000001025A000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000C.00000002.592017625.00000000035D0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000000.296408181.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000002.00000002.299090873.0000000013AD4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.356715878.00000000012E0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.356781952.0000000001320000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000C.00000002.596403511.0000000004FF0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.356484497.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000C.00000002.586492056.0000000003130000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs