Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov eax, dword ptr [esp+04h] | 0_2_6D378530 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov word ptr [eax], cx | 0_2_6D390D8C |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov eax, dword ptr [esp+00000230h] | 0_2_6D381D80 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov word ptr [edx], cx | 0_2_6D383DF8 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov eax, dword ptr [esp] | 0_2_6D3A3DE0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov eax, dword ptr [esp] | 0_2_6D3A3DE0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then add ebx, 02h | 0_2_6D383C39 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov eax, dword ptr [esp] | 0_2_6D38D470 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then jmp eax | 0_2_6D38FC57 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov eax, ecx | 0_2_6D391CE1 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then cmp byte ptr [ecx+eax], 00000000h | 0_2_6D37ECE8 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov dword ptr [esp+00000A98h], 00000000h | 0_2_6D37ECE8 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov eax, dword ptr [esp+00000230h] | 0_2_6D37E724 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov word ptr [eax], cx | 0_2_6D384F2B |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then movsx eax, byte ptr [esi+ecx] | 0_2_6D37B700 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov eax, dword ptr [esp+04h] | 0_2_6D3A7F60 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then cmp byte ptr [ebx+esi], 00000000h | 0_2_6D39079B |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov eax, dword ptr [esp] | 0_2_6D3A37F0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then xor eax, eax | 0_2_6D38F61A |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then xor eax, eax | 0_2_6D38F53A |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov eax, dword ptr [esp+04h] | 0_2_6D3A8130 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then movzx edx, byte ptr [esi+edi] | 0_2_6D371160 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then cmp byte ptr [ebp+00h], 00000000h | 0_2_6D383190 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov byte ptr [edi], al | 0_2_6D3939D8 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov eax, dword ptr [004401D8h] | 0_2_6D38081C |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov eax, dword ptr [004401D8h] | 0_2_6D38281B |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov eax, dword ptr [004401D8h] | 0_2_6D38081C |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then cmp word ptr [eax+ebx+02h], 0000h | 0_2_6D392070 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov eax, dword ptr [004401D8h] | 0_2_6D38081C |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov eax, dword ptr [esp+000000D8h] | 0_2_6D37F889 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov ecx, dword ptr [esp+04h] | 0_2_6D3910F7 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov byte ptr [edx], al | 0_2_6D3780D0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov byte ptr [ecx], al | 0_2_6D390310 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then cmp word ptr [esi+eax+02h], 0000h | 0_2_6D392300 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then cmp byte ptr [ecx], 00000000h | 0_2_6D37F3A5 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then cmp word ptr [eax], 0000h | 0_2_6D381399 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov eax, dword ptr [esp+00000888h] | 0_2_6D38C38A |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov eax, dword ptr [esp+00000888h] | 0_2_6D38C3F0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then push esi | 0_2_6D3863D3 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov dword ptr [esp+00000A98h], 00000000h | 0_2_6D3823C0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov edi, ecx | 0_2_6D385A1E |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov ebx, dword ptr [edi+04h] | 0_2_6D392A70 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then jmp eax | 0_2_6D38FABE |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then cmp dword ptr [ecx+ebx*8], 0850A6E6h | 0_2_6D3A82F0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 4x nop then mov ecx, edi | 0_2_6D375900 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then cmp dword ptr [edi+edx*8], B67AF9EBh | 3_2_004377D1 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then jmp eax | 3_2_00421857 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then add ebx, 02h | 3_2_00415822 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov word ptr [edx], cx | 3_2_00415822 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then movzx eax, dx | 3_2_004280C7 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then cmp dword ptr [edi+edx*8], B67AF9EBh | 3_2_004378CA |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov eax, ecx | 3_2_004238E3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then cmp byte ptr [ecx+eax], 00000000h | 3_2_004108E8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov dword ptr [esp+00000A98h], 00000000h | 3_2_004108E8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then cmp byte ptr [eax], 00000000h | 3_2_00438950 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then jmp eax | 3_2_00438950 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then test edi, edi | 3_2_00438950 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then movzx ebx, byte ptr [edx] | 3_2_00431120 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov eax, dword ptr [esp+04h] | 3_2_0040A130 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov eax, dword ptr [esp] | 3_2_004359E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov eax, dword ptr [esp] | 3_2_004359E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then test edi, edi | 3_2_004391F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov eax, dword ptr [esp+00000230h] | 3_2_00413980 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then cmp byte ptr [ebx+esi], 00000000h | 3_2_004221B9 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then cmp byte ptr [eax], 00000000h | 3_2_00438AB0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then jmp eax | 3_2_00438AB0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then test edi, edi | 3_2_00438AB0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov eax, dword ptr [esp+04h] | 3_2_00439B60 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then movsx eax, byte ptr [esi+ecx] | 3_2_0040D300 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov edx, dword ptr [esi] | 3_2_00438305 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov byte ptr [ecx], al | 3_2_00421B22 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov eax, dword ptr [esp+00000230h] | 3_2_00410324 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov word ptr [eax], cx | 3_2_00416B2B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov edi, ecx | 3_2_00416B2B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then cmp byte ptr [eax], 00000000h | 3_2_00438BD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then jmp eax | 3_2_00438BD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then test edi, edi | 3_2_00438BD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov eax, dword ptr [esp] | 3_2_004353F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov eax, dword ptr [004401D8h] | 3_2_0041241C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then cmp word ptr [eax+ebx+02h], 0000h | 3_2_00423C77 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov eax, dword ptr [004401D8h] | 3_2_0041441B |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov eax, dword ptr [004401D8h] | 3_2_0041241C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov eax, dword ptr [004401D8h] | 3_2_0041241C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then jmp eax | 3_2_00421439 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov byte ptr [edx], al | 3_2_00409CD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov ecx, dword ptr [esp+04h] | 3_2_00422CF7 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov eax, dword ptr [esp+000000D8h] | 3_2_00411489 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then movzx edx, byte ptr [esi+edi] | 3_2_00402D60 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then cmp byte ptr [eax], 00000000h | 3_2_00438500 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then jmp eax | 3_2_00438500 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then test edi, edi | 3_2_00438500 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov eax, dword ptr [esp+04h] | 3_2_00439D30 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then xor eax, eax | 3_2_00420DD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov byte ptr [edi], al | 3_2_004255D8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then jmp ecx | 3_2_00426DF5 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then cmp byte ptr [ebp+00h], 00000000h | 3_2_00414D90 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov edx, dword ptr [esi] | 3_2_004365B5 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then xor eax, eax | 3_2_00420E4E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov ebx, dword ptr [edi+04h] | 3_2_00424670 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then cmp word ptr [eax+ebx+02h], 0000h | 3_2_00423E3F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then cmp word ptr [esi+eax+02h], 0000h | 3_2_00423E3F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then cmp byte ptr [eax], 00000000h | 3_2_004386D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then jmp eax | 3_2_004386D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then test edi, edi | 3_2_004386D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then cmp dword ptr [ecx+ebx*8], 0850A6E6h | 3_2_00439EF0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then movzx eax, dx | 3_2_00427F13 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov eax, ecx | 3_2_00427F13 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then push esi | 3_2_00417F20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then jmp eax | 3_2_00438F30 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then test edi, edi | 3_2_00438F30 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov dword ptr [esp+00000A98h], 00000000h | 3_2_00413FC0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then cmp dword ptr [edi+edx*8], B67AF9EBh | 3_2_004377D6 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov eax, dword ptr [esp+00000888h] | 3_2_0041DFF0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov eax, dword ptr [esp] | 3_2_0041EFFD |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then mov eax, dword ptr [esp+00000888h] | 3_2_0041DF8A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then cmp word ptr [eax], 0000h | 3_2_00412F99 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 4x nop then cmp byte ptr [ecx], 00000000h | 3_2_00410FA5 |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AD8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://employeedscratshj.shop/api |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://falseaudiencekd.shop/api |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000B0E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://feighminoritsjda.shop/api1 |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000B0E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://feighminoritsjda.shop/apiK |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000B0E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://justifycanddidatewd.shop/ |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://justifycanddidatewd.shop/api |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000B0E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://pleasurenarrowsdla.shop/ |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000B0E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://pleasurenarrowsdla.shop/api? |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AD8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://raiseboltskdlwpow.shop/B |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AD8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://richardflorespoew.shop/ |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AD8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://richardflorespoew.shop/0 |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://richardflorespoew.shop/api |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://richardflorespoew.shop/api7 |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://richardflorespoew.shop/apii |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000B0E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://richardflorespoew.shop/apiy |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AD8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://richardflorespoew.shop/g |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AD8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://strwawrunnygjwu.shop//l |
Source: aspnet_regiis.exe, 00000003.00000002.1403267726.0000000000AFA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://strwawrunnygjwu.shop/api |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 0_2_6D3535D0 | 0_2_6D3535D0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 0_2_6D3530C0 | 0_2_6D3530C0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 0_2_6D3513F0 | 0_2_6D3513F0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 0_2_6D367125 | 0_2_6D367125 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 0_2_6D351010 | 0_2_6D351010 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 0_2_6D35B700 | 0_2_6D35B700 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 0_2_6D375530 | 0_2_6D375530 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 0_2_6D392DC0 | 0_2_6D392DC0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 0_2_6D37E410 | 0_2_6D37E410 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 0_2_6D372CE0 | 0_2_6D372CE0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 0_2_6D374F20 | 0_2_6D374F20 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 0_2_6D373710 | 0_2_6D373710 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 0_2_6D39079B | 0_2_6D39079B |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 0_2_6D3A86F0 | 0_2_6D3A86F0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 0_2_6D374190 | 0_2_6D374190 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 0_2_6D3939D8 | 0_2_6D3939D8 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 0_2_6D3769C0 | 0_2_6D3769C0 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 0_2_6D38EB00 | 0_2_6D38EB00 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 0_2_6D38539C | 0_2_6D38539C |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 0_2_6D3A8A10 | 0_2_6D3A8A10 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 0_2_6D372250 | 0_2_6D372250 |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Code function: 0_2_6D375900 | 0_2_6D375900 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_00410010 | 3_2_00410010 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_004280C7 | 3_2_004280C7 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_004048E0 | 3_2_004048E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_00420092 | 3_2_00420092 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_00438950 | 3_2_00438950 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_00407130 | 3_2_00407130 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_004249C0 | 3_2_004249C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_004221B9 | 3_2_004221B9 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_0043A2F0 | 3_2_0043A2F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_00438AB0 | 3_2_00438AB0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_00405310 | 3_2_00405310 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_00406B20 | 3_2_00406B20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_00421B22 | 3_2_00421B22 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_00438BD0 | 3_2_00438BD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_00420410 | 3_2_00420410 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_00421439 | 3_2_00421439 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_00438500 | 3_2_00438500 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_004085C0 | 3_2_004085C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_00420DD0 | 3_2_00420DD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_004255D8 | 3_2_004255D8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_00405D90 | 3_2_00405D90 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_0041FDA0 | 3_2_0041FDA0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_00420E4E | 3_2_00420E4E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_00403E50 | 3_2_00403E50 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_0042A652 | 3_2_0042A652 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_0043A610 | 3_2_0043A610 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_00401EC0 | 3_2_00401EC0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_004386D0 | 3_2_004386D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_00432F50 | 3_2_00432F50 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_00416F76 | 3_2_00416F76 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_00420700 | 3_2_00420700 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_00427F13 | 3_2_00427F13 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_00438F30 | 3_2_00438F30 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_0041C7EE | 3_2_0041C7EE |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Code function: 3_2_0041EFFD | 3_2_0041EFFD |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\tGm4SuP0sz.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Section loaded: webio.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe | Section loaded: msasn1.dll | Jump to behavior |