Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov eax, dword ptr [esp+04h] |
0_2_6D378530 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov word ptr [eax], cx |
0_2_6D390D8C |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov eax, dword ptr [esp+00000230h] |
0_2_6D381D80 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov word ptr [edx], cx |
0_2_6D383DF8 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
0_2_6D3A3DE0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
0_2_6D3A3DE0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then add ebx, 02h |
0_2_6D383C39 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
0_2_6D38D470 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then jmp eax |
0_2_6D38FC57 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov eax, ecx |
0_2_6D391CE1 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then cmp byte ptr [ecx+eax], 00000000h |
0_2_6D37ECE8 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov dword ptr [esp+00000A98h], 00000000h |
0_2_6D37ECE8 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov eax, dword ptr [esp+00000230h] |
0_2_6D37E724 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov word ptr [eax], cx |
0_2_6D384F2B |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then movsx eax, byte ptr [esi+ecx] |
0_2_6D37B700 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov eax, dword ptr [esp+04h] |
0_2_6D3A7F60 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then cmp byte ptr [ebx+esi], 00000000h |
0_2_6D39079B |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
0_2_6D3A37F0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then xor eax, eax |
0_2_6D38F61A |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then xor eax, eax |
0_2_6D38F53A |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov eax, dword ptr [esp+04h] |
0_2_6D3A8130 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then movzx edx, byte ptr [esi+edi] |
0_2_6D371160 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then cmp byte ptr [ebp+00h], 00000000h |
0_2_6D383190 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov byte ptr [edi], al |
0_2_6D3939D8 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov eax, dword ptr [004401D8h] |
0_2_6D38081C |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov eax, dword ptr [004401D8h] |
0_2_6D38281B |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov eax, dword ptr [004401D8h] |
0_2_6D38081C |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then cmp word ptr [eax+ebx+02h], 0000h |
0_2_6D392070 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov eax, dword ptr [004401D8h] |
0_2_6D38081C |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov eax, dword ptr [esp+000000D8h] |
0_2_6D37F889 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov ecx, dword ptr [esp+04h] |
0_2_6D3910F7 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov byte ptr [edx], al |
0_2_6D3780D0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov byte ptr [ecx], al |
0_2_6D390310 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then cmp word ptr [esi+eax+02h], 0000h |
0_2_6D392300 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then cmp byte ptr [ecx], 00000000h |
0_2_6D37F3A5 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then cmp word ptr [eax], 0000h |
0_2_6D381399 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov eax, dword ptr [esp+00000888h] |
0_2_6D38C38A |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov eax, dword ptr [esp+00000888h] |
0_2_6D38C3F0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then push esi |
0_2_6D3863D3 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov dword ptr [esp+00000A98h], 00000000h |
0_2_6D3823C0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov edi, ecx |
0_2_6D385A1E |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov ebx, dword ptr [edi+04h] |
0_2_6D392A70 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then jmp eax |
0_2_6D38FABE |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then cmp dword ptr [ecx+ebx*8], 0850A6E6h |
0_2_6D3A82F0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 4x nop then mov ecx, edi |
0_2_6D375900 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then cmp dword ptr [edi+edx*8], B67AF9EBh |
3_2_004377D1 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then jmp eax |
3_2_00421857 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then add ebx, 02h |
3_2_00415822 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov word ptr [edx], cx |
3_2_00415822 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then movzx eax, dx |
3_2_004280C7 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then cmp dword ptr [edi+edx*8], B67AF9EBh |
3_2_004378CA |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov eax, ecx |
3_2_004238E3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then cmp byte ptr [ecx+eax], 00000000h |
3_2_004108E8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov dword ptr [esp+00000A98h], 00000000h |
3_2_004108E8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then cmp byte ptr [eax], 00000000h |
3_2_00438950 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then jmp eax |
3_2_00438950 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then test edi, edi |
3_2_00438950 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then movzx ebx, byte ptr [edx] |
3_2_00431120 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov eax, dword ptr [esp+04h] |
3_2_0040A130 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
3_2_004359E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
3_2_004359E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then test edi, edi |
3_2_004391F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov eax, dword ptr [esp+00000230h] |
3_2_00413980 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then cmp byte ptr [ebx+esi], 00000000h |
3_2_004221B9 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then cmp byte ptr [eax], 00000000h |
3_2_00438AB0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then jmp eax |
3_2_00438AB0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then test edi, edi |
3_2_00438AB0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov eax, dword ptr [esp+04h] |
3_2_00439B60 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then movsx eax, byte ptr [esi+ecx] |
3_2_0040D300 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov edx, dword ptr [esi] |
3_2_00438305 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov byte ptr [ecx], al |
3_2_00421B22 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov eax, dword ptr [esp+00000230h] |
3_2_00410324 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov word ptr [eax], cx |
3_2_00416B2B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov edi, ecx |
3_2_00416B2B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then cmp byte ptr [eax], 00000000h |
3_2_00438BD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then jmp eax |
3_2_00438BD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then test edi, edi |
3_2_00438BD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
3_2_004353F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov eax, dword ptr [004401D8h] |
3_2_0041241C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then cmp word ptr [eax+ebx+02h], 0000h |
3_2_00423C77 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov eax, dword ptr [004401D8h] |
3_2_0041441B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov eax, dword ptr [004401D8h] |
3_2_0041241C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov eax, dword ptr [004401D8h] |
3_2_0041241C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then jmp eax |
3_2_00421439 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov byte ptr [edx], al |
3_2_00409CD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov ecx, dword ptr [esp+04h] |
3_2_00422CF7 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov eax, dword ptr [esp+000000D8h] |
3_2_00411489 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then movzx edx, byte ptr [esi+edi] |
3_2_00402D60 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then cmp byte ptr [eax], 00000000h |
3_2_00438500 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then jmp eax |
3_2_00438500 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then test edi, edi |
3_2_00438500 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov eax, dword ptr [esp+04h] |
3_2_00439D30 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then xor eax, eax |
3_2_00420DD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov byte ptr [edi], al |
3_2_004255D8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then jmp ecx |
3_2_00426DF5 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then cmp byte ptr [ebp+00h], 00000000h |
3_2_00414D90 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov edx, dword ptr [esi] |
3_2_004365B5 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then xor eax, eax |
3_2_00420E4E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov ebx, dword ptr [edi+04h] |
3_2_00424670 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then cmp word ptr [eax+ebx+02h], 0000h |
3_2_00423E3F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then cmp word ptr [esi+eax+02h], 0000h |
3_2_00423E3F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then cmp byte ptr [eax], 00000000h |
3_2_004386D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then jmp eax |
3_2_004386D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then test edi, edi |
3_2_004386D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then cmp dword ptr [ecx+ebx*8], 0850A6E6h |
3_2_00439EF0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then movzx eax, dx |
3_2_00427F13 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov eax, ecx |
3_2_00427F13 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then push esi |
3_2_00417F20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then jmp eax |
3_2_00438F30 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then test edi, edi |
3_2_00438F30 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov dword ptr [esp+00000A98h], 00000000h |
3_2_00413FC0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then cmp dword ptr [edi+edx*8], B67AF9EBh |
3_2_004377D6 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov eax, dword ptr [esp+00000888h] |
3_2_0041DFF0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov eax, dword ptr [esp] |
3_2_0041EFFD |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then mov eax, dword ptr [esp+00000888h] |
3_2_0041DF8A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then cmp word ptr [eax], 0000h |
3_2_00412F99 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 4x nop then cmp byte ptr [ecx], 00000000h |
3_2_00410FA5 |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AD8000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://employeedscratshj.shop/api |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://falseaudiencekd.shop/api |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000B0E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://feighminoritsjda.shop/api1 |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000B0E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://feighminoritsjda.shop/apiK |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000B0E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://justifycanddidatewd.shop/ |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://justifycanddidatewd.shop/api |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000B0E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://pleasurenarrowsdla.shop/ |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000B0E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://pleasurenarrowsdla.shop/api? |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AD8000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://raiseboltskdlwpow.shop/B |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AD8000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://richardflorespoew.shop/ |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AD8000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://richardflorespoew.shop/0 |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://richardflorespoew.shop/api |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://richardflorespoew.shop/api7 |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://richardflorespoew.shop/apii |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000B0E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://richardflorespoew.shop/apiy |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AD8000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://richardflorespoew.shop/g |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AD8000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://strwawrunnygjwu.shop//l |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://strwawrunnygjwu.shop/api |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 0_2_6D3535D0 |
0_2_6D3535D0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 0_2_6D3530C0 |
0_2_6D3530C0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 0_2_6D3513F0 |
0_2_6D3513F0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 0_2_6D367125 |
0_2_6D367125 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 0_2_6D351010 |
0_2_6D351010 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 0_2_6D35B700 |
0_2_6D35B700 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 0_2_6D375530 |
0_2_6D375530 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 0_2_6D392DC0 |
0_2_6D392DC0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 0_2_6D37E410 |
0_2_6D37E410 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 0_2_6D372CE0 |
0_2_6D372CE0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 0_2_6D374F20 |
0_2_6D374F20 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 0_2_6D373710 |
0_2_6D373710 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 0_2_6D39079B |
0_2_6D39079B |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 0_2_6D3A86F0 |
0_2_6D3A86F0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 0_2_6D374190 |
0_2_6D374190 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 0_2_6D3939D8 |
0_2_6D3939D8 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 0_2_6D3769C0 |
0_2_6D3769C0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 0_2_6D38EB00 |
0_2_6D38EB00 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 0_2_6D38539C |
0_2_6D38539C |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 0_2_6D3A8A10 |
0_2_6D3A8A10 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 0_2_6D372250 |
0_2_6D372250 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Code function: 0_2_6D375900 |
0_2_6D375900 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_00410010 |
3_2_00410010 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_004280C7 |
3_2_004280C7 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_004048E0 |
3_2_004048E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_00420092 |
3_2_00420092 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_00438950 |
3_2_00438950 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_00407130 |
3_2_00407130 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_004249C0 |
3_2_004249C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_004221B9 |
3_2_004221B9 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_0043A2F0 |
3_2_0043A2F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_00438AB0 |
3_2_00438AB0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_00405310 |
3_2_00405310 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_00406B20 |
3_2_00406B20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_00421B22 |
3_2_00421B22 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_00438BD0 |
3_2_00438BD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_00420410 |
3_2_00420410 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_00421439 |
3_2_00421439 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_00438500 |
3_2_00438500 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_004085C0 |
3_2_004085C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_00420DD0 |
3_2_00420DD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_004255D8 |
3_2_004255D8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_00405D90 |
3_2_00405D90 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_0041FDA0 |
3_2_0041FDA0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_00420E4E |
3_2_00420E4E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_00403E50 |
3_2_00403E50 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_0042A652 |
3_2_0042A652 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_0043A610 |
3_2_0043A610 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_00401EC0 |
3_2_00401EC0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_004386D0 |
3_2_004386D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_00432F50 |
3_2_00432F50 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_00416F76 |
3_2_00416F76 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_00420700 |
3_2_00420700 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_00427F13 |
3_2_00427F13 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_00438F30 |
3_2_00438F30 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_0041C7EE |
3_2_0041C7EE |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Code function: 3_2_0041EFFD |
3_2_0041EFFD |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Section loaded: webio.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe |
Section loaded: msasn1.dll |
Jump to behavior |