Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000D6170 |
0_2_000D6170 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000BE2A9 |
0_2_000BE2A9 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000D33A0 |
0_2_000D33A0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000D15F0 |
0_2_000D15F0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000EE690 |
0_2_000EE690 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000DC6D7 |
0_2_000DC6D7 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000B97B0 |
0_2_000B97B0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000B87F0 |
0_2_000B87F0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000BA960 |
0_2_000BA960 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000C6B7E |
0_2_000C6B7E |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000E9B90 |
0_2_000E9B90 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000E6C40 |
0_2_000E6C40 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000EDCF0 |
0_2_000EDCF0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000E6F90 |
0_2_000E6F90 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000DBFDA |
0_2_000DBFDA |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000C0FD6 |
0_2_000C0FD6 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000DBFD3 |
0_2_000DBFD3 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00274023 |
0_2_00274023 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0015D012 |
0_2_0015D012 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00146009 |
0_2_00146009 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00136030 |
0_2_00136030 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00137035 |
0_2_00137035 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0011E036 |
0_2_0011E036 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0016503F |
0_2_0016503F |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013F023 |
0_2_0013F023 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0012A02B |
0_2_0012A02B |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000EA030 |
0_2_000EA030 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0011A051 |
0_2_0011A051 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00160042 |
0_2_00160042 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000BE06A |
0_2_000BE06A |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000D5F7D |
0_2_000D5F7D |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000B9070 |
0_2_000B9070 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0027905B |
0_2_0027905B |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00118091 |
0_2_00118091 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000DD085 |
0_2_000DD085 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013D09A |
0_2_0013D09A |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0014A083 |
0_2_0014A083 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0015B08C |
0_2_0015B08C |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000D80B0 |
0_2_000D80B0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0014C0AB |
0_2_0014C0AB |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001240C4 |
0_2_001240C4 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000E80D9 |
0_2_000E80D9 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001530FC |
0_2_001530FC |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001390FD |
0_2_001390FD |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001500EA |
0_2_001500EA |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013B112 |
0_2_0013B112 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000DA100 |
0_2_000DA100 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00158103 |
0_2_00158103 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0016310B |
0_2_0016310B |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00134160 |
0_2_00134160 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013119B |
0_2_0013119B |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0012F19F |
0_2_0012F19F |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000C7190 |
0_2_000C7190 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001671AE |
0_2_001671AE |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001611C2 |
0_2_001611C2 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000E01D0 |
0_2_000E01D0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0011E1F6 |
0_2_0011E1F6 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001221FB |
0_2_001221FB |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0015D1E0 |
0_2_0015D1E0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0011F1EB |
0_2_0011F1EB |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000B81F0 |
0_2_000B81F0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0015A1EE |
0_2_0015A1EE |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013521B |
0_2_0013521B |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000B6200 |
0_2_000B6200 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00144238 |
0_2_00144238 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00138227 |
0_2_00138227 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00123276 |
0_2_00123276 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0012C276 |
0_2_0012C276 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000B4270 |
0_2_000B4270 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000D2270 |
0_2_000D2270 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00158295 |
0_2_00158295 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00164299 |
0_2_00164299 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001552B4 |
0_2_001552B4 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001492A7 |
0_2_001492A7 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000C92BA |
0_2_000C92BA |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000EE2C0 |
0_2_000EE2C0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001622C1 |
0_2_001622C1 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000D92D0 |
0_2_000D92D0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001482ED |
0_2_001482ED |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0012E305 |
0_2_0012E305 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000E533A |
0_2_000E533A |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00130326 |
0_2_00130326 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0011C341 |
0_2_0011C341 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_002DD37C |
0_2_002DD37C |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0014F341 |
0_2_0014F341 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000BB351 |
0_2_000BB351 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0014D37E |
0_2_0014D37E |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000B9360 |
0_2_000B9360 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000CC360 |
0_2_000CC360 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0015239B |
0_2_0015239B |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0012B380 |
0_2_0012B380 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013A385 |
0_2_0013A385 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0012D38A |
0_2_0012D38A |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013838A |
0_2_0013838A |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0014B3B0 |
0_2_0014B3B0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001233BE |
0_2_001233BE |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001403A1 |
0_2_001403A1 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0015C3AD |
0_2_0015C3AD |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000EA3F0 |
0_2_000EA3F0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0015640D |
0_2_0015640D |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0015943F |
0_2_0015943F |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000CD420 |
0_2_000CD420 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013C429 |
0_2_0013C429 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000E6430 |
0_2_000E6430 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000BD44C |
0_2_000BD44C |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00147473 |
0_2_00147473 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00157460 |
0_2_00157460 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000B7470 |
0_2_000B7470 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0012849F |
0_2_0012849F |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0011248A |
0_2_0011248A |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0012E4AF |
0_2_0012E4AF |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001464E8 |
0_2_001464E8 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001504E9 |
0_2_001504E9 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0012F51A |
0_2_0012F51A |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0016651D |
0_2_0016651D |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00139502 |
0_2_00139502 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0016753A |
0_2_0016753A |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00395505 |
0_2_00395505 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0011752F |
0_2_0011752F |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0011955D |
0_2_0011955D |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013154D |
0_2_0013154D |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0015F565 |
0_2_0015F565 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000C6571 |
0_2_000C6571 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_002775AB |
0_2_002775AB |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00161581 |
0_2_00161581 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0015658E |
0_2_0015658E |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0011D58C |
0_2_0011D58C |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013B5B4 |
0_2_0013B5B4 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0015A5BA |
0_2_0015A5BA |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001445AC |
0_2_001445AC |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001535D8 |
0_2_001535D8 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001485DB |
0_2_001485DB |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0011B5C3 |
0_2_0011B5C3 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001415C0 |
0_2_001415C0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001375EF |
0_2_001375EF |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00272634 |
0_2_00272634 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00127639 |
0_2_00127639 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013563E |
0_2_0013563E |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0012A640 |
0_2_0012A640 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0014E643 |
0_2_0014E643 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00110671 |
0_2_00110671 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0014B671 |
0_2_0014B671 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013F67A |
0_2_0013F67A |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0011467A |
0_2_0011467A |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00113663 |
0_2_00113663 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000C2670 |
0_2_000C2670 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000D5670 |
0_2_000D5670 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00151691 |
0_2_00151691 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0026E6B7 |
0_2_0026E6B7 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000B6690 |
0_2_000B6690 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000E6690 |
0_2_000E6690 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001556A6 |
0_2_001556A6 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001346A7 |
0_2_001346A7 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0015C6AD |
0_2_0015C6AD |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000E76B0 |
0_2_000E76B0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001426CD |
0_2_001426CD |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0012B6C9 |
0_2_0012B6C9 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000C56D0 |
0_2_000C56D0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001646F6 |
0_2_001646F6 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000D66E7 |
0_2_000D66E7 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00116709 |
0_2_00116709 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000D0717 |
0_2_000D0717 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0012C70D |
0_2_0012C70D |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00121724 |
0_2_00121724 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000C8731 |
0_2_000C8731 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0015875F |
0_2_0015875F |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00115748 |
0_2_00115748 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00138770 |
0_2_00138770 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00140770 |
0_2_00140770 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000DB763 |
0_2_000DB763 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013676A |
0_2_0013676A |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0014E76E |
0_2_0014E76E |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00133793 |
0_2_00133793 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001547B4 |
0_2_001547B4 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000C67A5 |
0_2_000C67A5 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0012D7BF |
0_2_0012D7BF |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001527A5 |
0_2_001527A5 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001427A3 |
0_2_001427A3 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0014B7A9 |
0_2_0014B7A9 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001437F5 |
0_2_001437F5 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001577F3 |
0_2_001577F3 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0011C7E6 |
0_2_0011C7E6 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001237EE |
0_2_001237EE |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001457E9 |
0_2_001457E9 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00160811 |
0_2_00160811 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00111800 |
0_2_00111800 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0015E828 |
0_2_0015E828 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0014A859 |
0_2_0014A859 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00125848 |
0_2_00125848 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0011784A |
0_2_0011784A |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013D87A |
0_2_0013D87A |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00147895 |
0_2_00147895 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_002818BC |
0_2_002818BC |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013C8B5 |
0_2_0013C8B5 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000B38C0 |
0_2_000B38C0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0026B8F0 |
0_2_0026B8F0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013A8F6 |
0_2_0013A8F6 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000CD8E0 |
0_2_000CD8E0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001128FE |
0_2_001128FE |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001198ED |
0_2_001198ED |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000C6E97 |
0_2_000C6E97 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000E7900 |
0_2_000E7900 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0015B905 |
0_2_0015B905 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000B5910 |
0_2_000B5910 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013F90F |
0_2_0013F90F |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000D5920 |
0_2_000D5920 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00152958 |
0_2_00152958 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00120942 |
0_2_00120942 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0011D976 |
0_2_0011D976 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000D297F |
0_2_000D297F |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00139981 |
0_2_00139981 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000B8990 |
0_2_000B8990 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0015F98A |
0_2_0015F98A |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001489B1 |
0_2_001489B1 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001419B8 |
0_2_001419B8 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001679B9 |
0_2_001679B9 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001569C9 |
0_2_001569C9 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_002639CC |
0_2_002639CC |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001229F8 |
0_2_001229F8 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001219F9 |
0_2_001219F9 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_002709D5 |
0_2_002709D5 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0014D9E7 |
0_2_0014D9E7 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001599E1 |
0_2_001599E1 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001279E7 |
0_2_001279E7 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0014A9EB |
0_2_0014A9EB |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000D3A00 |
0_2_000D3A00 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00130A3E |
0_2_00130A3E |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0011EA3F |
0_2_0011EA3F |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0011AA21 |
0_2_0011AA21 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000CBA48 |
0_2_000CBA48 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000C4A40 |
0_2_000C4A40 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00132A5C |
0_2_00132A5C |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000BCA54 |
0_2_000BCA54 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0024EA41 |
0_2_0024EA41 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00116A7F |
0_2_00116A7F |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0012AA6E |
0_2_0012AA6E |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000DBA8D |
0_2_000DBA8D |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00134A87 |
0_2_00134A87 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000ECAC0 |
0_2_000ECAC0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000C5ADC |
0_2_000C5ADC |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00110B18 |
0_2_00110B18 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00144B19 |
0_2_00144B19 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00275B35 |
0_2_00275B35 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000C1B1B |
0_2_000C1B1B |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013BB0B |
0_2_0013BB0B |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00151B0C |
0_2_00151B0C |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00131B08 |
0_2_00131B08 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00139B30 |
0_2_00139B30 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00111B52 |
0_2_00111B52 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013CB5E |
0_2_0013CB5E |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000CCB5A |
0_2_000CCB5A |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0012BB48 |
0_2_0012BB48 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0011AB7A |
0_2_0011AB7A |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0012DB6E |
0_2_0012DB6E |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0012CB95 |
0_2_0012CB95 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00160B84 |
0_2_00160B84 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0012FBA3 |
0_2_0012FBA3 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0015BBA6 |
0_2_0015BBA6 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00136BA4 |
0_2_00136BA4 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0014CBD0 |
0_2_0014CBD0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0014FBD9 |
0_2_0014FBD9 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0027ABF6 |
0_2_0027ABF6 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0011CBC0 |
0_2_0011CBC0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00115BCC |
0_2_00115BCC |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00129BF3 |
0_2_00129BF3 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000C8C1E |
0_2_000C8C1E |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00140C07 |
0_2_00140C07 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000C9C10 |
0_2_000C9C10 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00116C35 |
0_2_00116C35 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000CDC20 |
0_2_000CDC20 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013CC22 |
0_2_0013CC22 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00145C21 |
0_2_00145C21 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00165C2F |
0_2_00165C2F |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00132C28 |
0_2_00132C28 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000E4C4D |
0_2_000E4C4D |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00122C5D |
0_2_00122C5D |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00166C4C |
0_2_00166C4C |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0011BC4A |
0_2_0011BC4A |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013EC71 |
0_2_0013EC71 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00112C61 |
0_2_00112C61 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00155C67 |
0_2_00155C67 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000D7C9D |
0_2_000D7C9D |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0011DC8D |
0_2_0011DC8D |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013ACB6 |
0_2_0013ACB6 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001BECB1 |
0_2_001BECB1 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00164CA1 |
0_2_00164CA1 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001D2CFC |
0_2_001D2CFC |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000ECCE0 |
0_2_000ECCE0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00150CFB |
0_2_00150CFB |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00152CE5 |
0_2_00152CE5 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00120CE3 |
0_2_00120CE3 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000D2CF8 |
0_2_000D2CF8 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00157D13 |
0_2_00157D13 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00147D07 |
0_2_00147D07 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00162D37 |
0_2_00162D37 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013CD37 |
0_2_0013CD37 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000D3D30 |
0_2_000D3D30 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0011CD5C |
0_2_0011CD5C |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00125D74 |
0_2_00125D74 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000ECD60 |
0_2_000ECD60 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00143D65 |
0_2_00143D65 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000D4D70 |
0_2_000D4D70 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00149DB3 |
0_2_00149DB3 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00121DA5 |
0_2_00121DA5 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00130DAE |
0_2_00130DAE |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00122DC2 |
0_2_00122DC2 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00137DEC |
0_2_00137DEC |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000CAE00 |
0_2_000CAE00 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000ECE00 |
0_2_000ECE00 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0015DE38 |
0_2_0015DE38 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00141E2E |
0_2_00141E2E |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000D3E30 |
0_2_000D3E30 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0015CE56 |
0_2_0015CE56 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000D3E4B |
0_2_000D3E4B |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000CDE40 |
0_2_000CDE40 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0014EE59 |
0_2_0014EE59 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00161E59 |
0_2_00161E59 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00134E4E |
0_2_00134E4E |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0015FE4A |
0_2_0015FE4A |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013FE72 |
0_2_0013FE72 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000B5E60 |
0_2_000B5E60 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0012EE64 |
0_2_0012EE64 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0014DE68 |
0_2_0014DE68 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0015BE68 |
0_2_0015BE68 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00124E6D |
0_2_00124E6D |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_001F1E9F |
0_2_001F1E9F |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00114E95 |
0_2_00114E95 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00112E8B |
0_2_00112E8B |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000C6E97 |
0_2_000C6E97 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000B2EA0 |
0_2_000B2EA0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0014AEBF |
0_2_0014AEBF |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000D6EBE |
0_2_000D6EBE |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00136ED1 |
0_2_00136ED1 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00115ECD |
0_2_00115ECD |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00126EF8 |
0_2_00126EF8 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000C5EE0 |
0_2_000C5EE0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00160EE3 |
0_2_00160EE3 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0012FF11 |
0_2_0012FF11 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000C4F08 |
0_2_000C4F08 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0011AF01 |
0_2_0011AF01 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0012CF3F |
0_2_0012CF3F |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000CEF30 |
0_2_000CEF30 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0026EF1B |
0_2_0026EF1B |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0012DF50 |
0_2_0012DF50 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00111F59 |
0_2_00111F59 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00139F58 |
0_2_00139F58 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000D8F5D |
0_2_000D8F5D |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00131F7B |
0_2_00131F7B |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000D5F7D |
0_2_000D5F7D |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0011FF91 |
0_2_0011FF91 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00128F93 |
0_2_00128F93 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00132FB3 |
0_2_00132FB3 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000C8FAD |
0_2_000C8FAD |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0015EFB1 |
0_2_0015EFB1 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00154FA4 |
0_2_00154FA4 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00156FA3 |
0_2_00156FA3 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_000EDFB0 |
0_2_000EDFB0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00140FC4 |
0_2_00140FC4 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0012BFCA |
0_2_0012BFCA |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0013DFCC |
0_2_0013DFCC |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2864EE second address: 286512 instructions: 0x00000000 rdtsc 0x00000002 jnl 00007FA93CFE6D5Eh 0x00000008 push eax 0x00000009 push edx 0x0000000a jmp 00007FA93CFE6D62h 0x0000000f rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 26CE73 second address: 26CE87 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA93D08FA20h 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 26CE87 second address: 26CE8B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 26CE8B second address: 26CE91 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 26CE91 second address: 26CE9E instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pushad 0x00000004 popad 0x00000005 pop ebx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push edx 0x00000009 push eax 0x0000000a push edx 0x0000000b push ebx 0x0000000c pop ebx 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 285879 second address: 28587D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 28587D second address: 2858A0 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jl 00007FA93CFE6D69h 0x0000000c jmp 00007FA93CFE6D63h 0x00000011 push eax 0x00000012 push edx 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2858A0 second address: 2858A4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2858A4 second address: 2858A8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 285B82 second address: 285B86 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 285B86 second address: 285B98 instructions: 0x00000000 rdtsc 0x00000002 jne 00007FA93CFE6D56h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c jne 00007FA93CFE6D56h 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 28867A second address: 2886E7 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93D08FA20h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xor dword ptr [esp], 3D51D6D4h 0x00000010 pushad 0x00000011 jmp 00007FA93D08FA26h 0x00000016 sub dword ptr [ebp+122D35E7h], edx 0x0000001c popad 0x0000001d lea ebx, dword ptr [ebp+12453497h] 0x00000023 push 00000000h 0x00000025 push ebp 0x00000026 call 00007FA93D08FA18h 0x0000002b pop ebp 0x0000002c mov dword ptr [esp+04h], ebp 0x00000030 add dword ptr [esp+04h], 00000015h 0x00000038 inc ebp 0x00000039 push ebp 0x0000003a ret 0x0000003b pop ebp 0x0000003c ret 0x0000003d mov dh, bl 0x0000003f xchg eax, ebx 0x00000040 jng 00007FA93D08FA22h 0x00000046 jo 00007FA93D08FA1Ch 0x0000004c push eax 0x0000004d push edx 0x0000004e rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2887AA second address: 2887BA instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 push edi 0x00000006 pop edi 0x00000007 popad 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b pushad 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2887BA second address: 2887BE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 27F8A2 second address: 27F8A6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2A7938 second address: 2A793C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2A793C second address: 2A7940 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2A7940 second address: 2A7985 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jmp 00007FA93D08FA27h 0x0000000b pop eax 0x0000000c pushad 0x0000000d jmp 00007FA93D08FA27h 0x00000012 jl 00007FA93D08FA1Ch 0x00000018 je 00007FA93D08FA16h 0x0000001e pushad 0x0000001f push eax 0x00000020 push edx 0x00000021 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2A7C9E second address: 2A7CA9 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 ja 00007FA93CFE6D56h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2A7CA9 second address: 2A7CB2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 push ecx 0x00000008 pop ecx 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2A7DF8 second address: 2A7E19 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D67h 0x00000007 push ebx 0x00000008 pop ebx 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c push edx 0x0000000d pushad 0x0000000e popad 0x0000000f rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2A7E19 second address: 2A7E1D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2A7F7D second address: 2A7F81 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2A872E second address: 2A8762 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93D08FA21h 0x00000007 jg 00007FA93D08FA16h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f pushad 0x00000010 push eax 0x00000011 pop eax 0x00000012 push esi 0x00000013 pop esi 0x00000014 jns 00007FA93D08FA16h 0x0000001a jbe 00007FA93D08FA16h 0x00000020 popad 0x00000021 pop ebx 0x00000022 push eax 0x00000023 push edx 0x00000024 push eax 0x00000025 push edx 0x00000026 push eax 0x00000027 push edx 0x00000028 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2A8762 second address: 2A8775 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA93CFE6D5Fh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2A8775 second address: 2A877B instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2A877B second address: 2A8794 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FA93CFE6D64h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2A8794 second address: 2A879A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 29E94A second address: 29E951 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 27DDB8 second address: 27DDBC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 27DDBC second address: 27DDF6 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D69h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop esi 0x0000000a push eax 0x0000000b push edx 0x0000000c pushad 0x0000000d jmp 00007FA93CFE6D67h 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 27DDF6 second address: 27DE10 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edi 0x00000005 pop edi 0x00000006 jnc 00007FA93D08FA16h 0x0000000c popad 0x0000000d jmp 00007FA93D08FA1Dh 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2A88D8 second address: 2A88E0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 pushad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2A88E0 second address: 2A88E6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2A88E6 second address: 2A88EB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2A88EB second address: 2A8917 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93D08FA21h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pushad 0x0000000a pushad 0x0000000b jmp 00007FA93D08FA23h 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 272121 second address: 272125 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 272125 second address: 272136 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA93D08FA1Bh 0x00000009 pop edx 0x0000000a pop eax 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 272136 second address: 27213C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 27213C second address: 272140 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 272140 second address: 272159 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D5Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b jng 00007FA93CFE6D56h 0x00000011 push ecx 0x00000012 pop ecx 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 27C371 second address: 27C37C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 push eax 0x00000006 push edx 0x00000007 pushad 0x00000008 popad 0x00000009 push esi 0x0000000a pop esi 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B5ED5 second address: 2B5EE9 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jo 00007FA93CFE6D62h 0x0000000c jng 00007FA93CFE6D56h 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B6041 second address: 2B605B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA93D08FA25h 0x00000009 pop ebx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B605B second address: 2B6060 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B64C2 second address: 2B64CB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B64CB second address: 2B64D1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edi 0x00000005 pop edi 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B8D97 second address: 2B8E1C instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push edx 0x00000007 jmp 00007FA93D08FA25h 0x0000000c pop edx 0x0000000d popad 0x0000000e mov eax, dword ptr [esp+04h] 0x00000012 pushad 0x00000013 jns 00007FA93D08FA18h 0x00000019 pushad 0x0000001a jmp 00007FA93D08FA29h 0x0000001f jmp 00007FA93D08FA1Fh 0x00000024 popad 0x00000025 popad 0x00000026 mov eax, dword ptr [eax] 0x00000028 jmp 00007FA93D08FA1Dh 0x0000002d mov dword ptr [esp+04h], eax 0x00000031 push ebx 0x00000032 pushad 0x00000033 pushad 0x00000034 popad 0x00000035 pushad 0x00000036 popad 0x00000037 popad 0x00000038 pop ebx 0x00000039 pop eax 0x0000003a mov edi, 0E4A79C1h 0x0000003f push 3313B808h 0x00000044 push edx 0x00000045 push eax 0x00000046 push edx 0x00000047 jg 00007FA93D08FA16h 0x0000004d rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B988A second address: 2B9890 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B9B75 second address: 2B9B93 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93D08FA1Fh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e js 00007FA93D08FA16h 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B9B93 second address: 2B9B97 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B9B97 second address: 2B9B9D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B9C92 second address: 2B9C9C instructions: 0x00000000 rdtsc 0x00000002 je 00007FA93CFE6D5Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B9DDE second address: 2B9DE2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B9DE2 second address: 2B9E80 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 push eax 0x00000008 jmp 00007FA93CFE6D5Eh 0x0000000d nop 0x0000000e push 00000000h 0x00000010 push edi 0x00000011 call 00007FA93CFE6D58h 0x00000016 pop edi 0x00000017 mov dword ptr [esp+04h], edi 0x0000001b add dword ptr [esp+04h], 0000001Bh 0x00000023 inc edi 0x00000024 push edi 0x00000025 ret 0x00000026 pop edi 0x00000027 ret 0x00000028 jmp 00007FA93CFE6D60h 0x0000002d jmp 00007FA93CFE6D68h 0x00000032 xchg eax, ebx 0x00000033 pushad 0x00000034 pushad 0x00000035 jmp 00007FA93CFE6D63h 0x0000003a jmp 00007FA93CFE6D65h 0x0000003f popad 0x00000040 push eax 0x00000041 push edx 0x00000042 jmp 00007FA93CFE6D5Eh 0x00000047 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2BA4F7 second address: 2BA4FD instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2BAD99 second address: 2BAD9F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2BAD9F second address: 2BADA3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2BADA3 second address: 2BADA7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2BB6AC second address: 2BB6B2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2BB6B2 second address: 2BB6BF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop ebx 0x00000006 push eax 0x00000007 push eax 0x00000008 push edx 0x00000009 push ebx 0x0000000a push edi 0x0000000b pop edi 0x0000000c pop ebx 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2BD60A second address: 2BD610 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2BD610 second address: 2BD66C instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 nop 0x00000009 mov esi, 0E7B9B59h 0x0000000e push 00000000h 0x00000010 push 00000000h 0x00000012 push ebp 0x00000013 call 00007FA93CFE6D58h 0x00000018 pop ebp 0x00000019 mov dword ptr [esp+04h], ebp 0x0000001d add dword ptr [esp+04h], 0000001Ah 0x00000025 inc ebp 0x00000026 push ebp 0x00000027 ret 0x00000028 pop ebp 0x00000029 ret 0x0000002a call 00007FA93CFE6D68h 0x0000002f mov si, ax 0x00000032 pop esi 0x00000033 push 00000000h 0x00000035 and edi, 2D992A24h 0x0000003b xchg eax, ebx 0x0000003c pushad 0x0000003d push eax 0x0000003e push edx 0x0000003f pushad 0x00000040 popad 0x00000041 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2BD66C second address: 2BD670 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2BE15F second address: 2BE165 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2BE165 second address: 2BE169 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2BD3B0 second address: 2BD3B6 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2BD3B6 second address: 2BD3BC instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2BECF6 second address: 2BECFA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2BF8CE second address: 2BF8D9 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jnc 00007FA93D08FA16h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2BF645 second address: 2BF64B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push edx 0x00000005 pop edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C0103 second address: 2C0107 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C0107 second address: 2C010B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C214E second address: 2C2153 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C010B second address: 2C0115 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C2153 second address: 2C2163 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 pop esi 0x00000006 popad 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e pushad 0x0000000f popad 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C0115 second address: 2C0119 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C2163 second address: 2C2167 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C2167 second address: 2C216D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C372B second address: 2C3739 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop ecx 0x00000007 push eax 0x00000008 push eax 0x00000009 push edx 0x0000000a push eax 0x0000000b push edx 0x0000000c pushad 0x0000000d popad 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C3739 second address: 2C373D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C2953 second address: 2C2957 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C373D second address: 2C3743 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C39C4 second address: 2C39D2 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop ecx 0x00000007 push eax 0x00000008 push eax 0x00000009 push edx 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C39D2 second address: 2C39D6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C39D6 second address: 2C39E6 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93D08FA1Ch 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C5862 second address: 2C5875 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA93CFE6D5Eh 0x00000009 popad 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C39E6 second address: 2C39EB instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C5875 second address: 2C587B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C68C4 second address: 2C68C8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C68C8 second address: 2C68CE instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C59B6 second address: 2C59D4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 jo 00007FA93D08FA16h 0x0000000b jo 00007FA93D08FA16h 0x00000011 popad 0x00000012 popad 0x00000013 push eax 0x00000014 push eax 0x00000015 push edx 0x00000016 jbe 00007FA93D08FA18h 0x0000001c pushad 0x0000001d popad 0x0000001e rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C68CE second address: 2C68DD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA93CFE6D5Bh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C78C4 second address: 2C78D6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 push eax 0x00000006 push edx 0x00000007 jmp 00007FA93D08FA1Bh 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C888B second address: 2C88F4 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop eax 0x00000007 mov dword ptr [esp], eax 0x0000000a jmp 00007FA93CFE6D69h 0x0000000f push 00000000h 0x00000011 js 00007FA93CFE6D7Ch 0x00000017 call 00007FA93CFE6D62h 0x0000001c jmp 00007FA93CFE6D63h 0x00000021 pop ebx 0x00000022 push 00000000h 0x00000024 mov di, 953Dh 0x00000028 xchg eax, esi 0x00000029 jnp 00007FA93CFE6D5Ah 0x0000002f push edx 0x00000030 push edx 0x00000031 pop edx 0x00000032 pop edx 0x00000033 push eax 0x00000034 push eax 0x00000035 push edx 0x00000036 push ebx 0x00000037 push esi 0x00000038 pop esi 0x00000039 pop ebx 0x0000003a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C7ACD second address: 2C7B6C instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FA93D08FA1Ah 0x00000008 push esi 0x00000009 pop esi 0x0000000a popad 0x0000000b pop edx 0x0000000c pop eax 0x0000000d mov dword ptr [esp], eax 0x00000010 mov di, si 0x00000013 push dword ptr fs:[00000000h] 0x0000001a push 00000000h 0x0000001c push ecx 0x0000001d call 00007FA93D08FA18h 0x00000022 pop ecx 0x00000023 mov dword ptr [esp+04h], ecx 0x00000027 add dword ptr [esp+04h], 00000019h 0x0000002f inc ecx 0x00000030 push ecx 0x00000031 ret 0x00000032 pop ecx 0x00000033 ret 0x00000034 push esi 0x00000035 jmp 00007FA93D08FA28h 0x0000003a pop ebx 0x0000003b jmp 00007FA93D08FA20h 0x00000040 mov dword ptr fs:[00000000h], esp 0x00000047 mov dword ptr [ebp+1245830Fh], ecx 0x0000004d mov edi, eax 0x0000004f mov eax, dword ptr [ebp+122D01D1h] 0x00000055 stc 0x00000056 push FFFFFFFFh 0x00000058 jl 00007FA93D08FA1Ah 0x0000005e mov di, 2005h 0x00000062 push eax 0x00000063 push eax 0x00000064 push edx 0x00000065 jmp 00007FA93D08FA20h 0x0000006a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C992A second address: 2C9992 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA93CFE6D5Eh 0x00000009 popad 0x0000000a mov dword ptr [esp], eax 0x0000000d push 00000000h 0x0000000f push ecx 0x00000010 call 00007FA93CFE6D58h 0x00000015 pop ecx 0x00000016 mov dword ptr [esp+04h], ecx 0x0000001a add dword ptr [esp+04h], 00000015h 0x00000022 inc ecx 0x00000023 push ecx 0x00000024 ret 0x00000025 pop ecx 0x00000026 ret 0x00000027 mov dword ptr [ebp+122D2D8Fh], esi 0x0000002d push 00000000h 0x0000002f mov bx, F375h 0x00000033 push 00000000h 0x00000035 sub dword ptr [ebp+122D2FA4h], eax 0x0000003b xchg eax, esi 0x0000003c push esi 0x0000003d jmp 00007FA93CFE6D5Dh 0x00000042 pop esi 0x00000043 push eax 0x00000044 push eax 0x00000045 push edx 0x00000046 jmp 00007FA93CFE6D5Eh 0x0000004b rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C9992 second address: 2C99A5 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA93D08FA1Fh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C99A5 second address: 2C99A9 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C9B76 second address: 2C9BE4 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93D08FA1Eh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 popad 0x0000000a mov dword ptr [esp], eax 0x0000000d mov edi, dword ptr [ebp+122D35ACh] 0x00000013 push dword ptr fs:[00000000h] 0x0000001a mov di, 39F2h 0x0000001e add edi, 72ACCB4Ah 0x00000024 mov dword ptr fs:[00000000h], esp 0x0000002b mov dword ptr [ebp+122D35E7h], edi 0x00000031 mov eax, dword ptr [ebp+122D1741h] 0x00000037 push 00000000h 0x00000039 push edi 0x0000003a call 00007FA93D08FA18h 0x0000003f pop edi 0x00000040 mov dword ptr [esp+04h], edi 0x00000044 add dword ptr [esp+04h], 00000015h 0x0000004c inc edi 0x0000004d push edi 0x0000004e ret 0x0000004f pop edi 0x00000050 ret 0x00000051 movsx edi, bx 0x00000054 push FFFFFFFFh 0x00000056 mov ebx, dword ptr [ebp+122D3A21h] 0x0000005c push eax 0x0000005d push esi 0x0000005e push eax 0x0000005f push edx 0x00000060 push eax 0x00000061 push edx 0x00000062 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2C9BE4 second address: 2C9BE8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2CBABF second address: 2CBAC6 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push ebx 0x00000004 pop ebx 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2CEC44 second address: 2CEC54 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA93CFE6D5Ch 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2CF1BA second address: 2CF1BE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2CF1BE second address: 2CF1C4 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2CF1C4 second address: 2CF1E3 instructions: 0x00000000 rdtsc 0x00000002 jno 00007FA93D08FA25h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b pushad 0x0000000c push eax 0x0000000d push edx 0x0000000e pushad 0x0000000f popad 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2D11DB second address: 2D11EB instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D5Ch 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2D11EB second address: 2D11F5 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jc 00007FA93D08FA16h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2D03D9 second address: 2D03F5 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D60h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 jbe 00007FA93CFE6D5Ch 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2D11F5 second address: 2D1241 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov dword ptr [esp], eax 0x0000000b mov dword ptr [ebp+12457ED4h], ecx 0x00000011 push 00000000h 0x00000013 mov edi, edx 0x00000015 push 00000000h 0x00000017 jmp 00007FA93D08FA23h 0x0000001c xchg eax, esi 0x0000001d jnl 00007FA93D08FA22h 0x00000023 push eax 0x00000024 push eax 0x00000025 push edx 0x00000026 jne 00007FA93D08FA1Ch 0x0000002c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2D212D second address: 2D2132 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2DAE76 second address: 2DAE92 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 jmp 00007FA93D08FA26h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2DAE92 second address: 2DAE97 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2DB021 second address: 2DB039 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 jmp 00007FA93D08FA1Ch 0x0000000c pushad 0x0000000d pushad 0x0000000e popad 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2DB35A second address: 2DB366 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push edi 0x00000005 pop edi 0x00000006 jng 00007FA93CFE6D56h 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2DFADB second address: 2DFAE9 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA93D08FA1Ah 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2DFB8D second address: 2DFB9A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 jns 00007FA93CFE6D56h 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2DFC54 second address: 2DFC58 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2DFC58 second address: 2DFC5C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2DFC5C second address: 2DFC62 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2DFC62 second address: 2DFC82 instructions: 0x00000000 rdtsc 0x00000002 jno 00007FA93CFE6D5Ch 0x00000008 pop edx 0x00000009 pop eax 0x0000000a mov eax, dword ptr [eax] 0x0000000c push eax 0x0000000d push edx 0x0000000e je 00007FA93CFE6D5Ch 0x00000014 js 00007FA93CFE6D56h 0x0000001a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2DFD37 second address: 2DFD42 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 pushad 0x00000008 popad 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2DFD42 second address: 2DFD4E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 popad 0x00000006 push eax 0x00000007 push edi 0x00000008 push eax 0x00000009 push edx 0x0000000a push ecx 0x0000000b pop ecx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2DFD4E second address: 2DFDB1 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93D08FA28h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edi 0x0000000a mov eax, dword ptr [esp+04h] 0x0000000e push eax 0x0000000f jbe 00007FA93D08FA23h 0x00000015 pop eax 0x00000016 mov eax, dword ptr [eax] 0x00000018 jmp 00007FA93D08FA25h 0x0000001d mov dword ptr [esp+04h], eax 0x00000021 push ebx 0x00000022 push eax 0x00000023 push edx 0x00000024 jmp 00007FA93D08FA1Fh 0x00000029 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2DFDB1 second address: 2DFDB5 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2E5C9C second address: 2E5CA7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop eax 0x00000006 pushad 0x00000007 push eax 0x00000008 push edx 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2E5CA7 second address: 2E5CAB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2E5CAB second address: 2E5CCA instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 jnp 00007FA93D08FA16h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push esi 0x0000000d jmp 00007FA93D08FA1Eh 0x00000012 pop esi 0x00000013 pushad 0x00000014 push eax 0x00000015 push edx 0x00000016 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2E52CD second address: 2E52D1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2E56EC second address: 2E56F8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jl 00007FA93D08FA16h 0x0000000a pushad 0x0000000b popad 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2E56F8 second address: 2E5717 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D5Fh 0x00000007 pushad 0x00000008 popad 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c push edx 0x0000000d push ebx 0x0000000e pop ebx 0x0000000f jnc 00007FA93CFE6D56h 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2EB1DA second address: 2EB1F2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 jmp 00007FA93D08FA1Dh 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2EB1F2 second address: 2EB1F8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2EB1F8 second address: 2EB1FC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2EB1FC second address: 2EB219 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D60h 0x00000007 jg 00007FA93CFE6D56h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f pushad 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2EB219 second address: 2EB220 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 popad 0x00000007 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2E9E50 second address: 2E9E54 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2E9E54 second address: 2E9E5A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2EAB8E second address: 2EAB97 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 push esi 0x00000006 pop esi 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2EDF0E second address: 2EDF12 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2EDF12 second address: 2EDF30 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA93CFE6D65h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b pushad 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2EDF30 second address: 2EDF3C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jng 00007FA93D08FA16h 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2EDF3C second address: 2EDF42 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2813D8 second address: 2813E4 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push ebx 0x00000009 pushad 0x0000000a popad 0x0000000b pop ebx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2F38B9 second address: 2F38BF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2F38BF second address: 2F38C9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 pushad 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2F38C9 second address: 2F38CF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2F38CF second address: 2F38D5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2F2316 second address: 2F231A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2F231A second address: 2F231E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2F231E second address: 2F2340 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA93CFE6D5Dh 0x00000009 pop edx 0x0000000a pop eax 0x0000000b jmp 00007FA93CFE6D5Fh 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2F2687 second address: 2F268B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2F268B second address: 2F268F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2F268F second address: 2F26BE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA93D08FA24h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b jc 00007FA93D08FA29h 0x00000011 jmp 00007FA93D08FA1Dh 0x00000016 push eax 0x00000017 push edx 0x00000018 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2F2809 second address: 2F2815 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jns 00007FA93CFE6D56h 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2F2815 second address: 2F2829 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 push ecx 0x00000008 pop ecx 0x00000009 jmp 00007FA93D08FA1Bh 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2F2B49 second address: 2F2B4D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2F2CC9 second address: 2F2CD4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 pop esi 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 push ecx 0x0000000a pop ecx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 29F48B second address: 29F4A3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnp 00007FA93CFE6D58h 0x0000000a push edi 0x0000000b pop edi 0x0000000c popad 0x0000000d jl 00007FA93CFE6D6Eh 0x00000013 push esi 0x00000014 pushad 0x00000015 popad 0x00000016 push eax 0x00000017 push edx 0x00000018 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2704CA second address: 270522 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jng 00007FA93D08FA16h 0x0000000a popad 0x0000000b jmp 00007FA93D08FA29h 0x00000010 pushad 0x00000011 jno 00007FA93D08FA16h 0x00000017 jnc 00007FA93D08FA16h 0x0000001d pushad 0x0000001e popad 0x0000001f pushad 0x00000020 popad 0x00000021 popad 0x00000022 push eax 0x00000023 push edx 0x00000024 jmp 00007FA93D08FA1Ah 0x00000029 jmp 00007FA93D08FA26h 0x0000002e rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2F3731 second address: 2F3735 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2F3735 second address: 2F375D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FA93D08FA1Fh 0x00000008 jne 00007FA93D08FA16h 0x0000000e popad 0x0000000f pop edx 0x00000010 pop eax 0x00000011 push eax 0x00000012 push edx 0x00000013 pushad 0x00000014 jo 00007FA93D08FA16h 0x0000001a pushad 0x0000001b popad 0x0000001c push eax 0x0000001d push edx 0x0000001e rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2F375D second address: 2F3775 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jmp 00007FA93CFE6D63h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2F3775 second address: 2F377F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jno 00007FA93D08FA16h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2F1EA1 second address: 2F1EAD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 jbe 00007FA93CFE6D56h 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2FC38A second address: 2FC38F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2FB21F second address: 2FB234 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D5Eh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push ecx 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2FB234 second address: 2FB23F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnp 00007FA93D08FA16h 0x0000000a pop ecx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B7634 second address: 29E94A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 popad 0x00000007 pop edx 0x00000008 push eax 0x00000009 push edx 0x0000000a jmp 00007FA93CFE6D68h 0x0000000f pop edx 0x00000010 nop 0x00000011 push 00000000h 0x00000013 push eax 0x00000014 call 00007FA93CFE6D58h 0x00000019 pop eax 0x0000001a mov dword ptr [esp+04h], eax 0x0000001e add dword ptr [esp+04h], 00000016h 0x00000026 inc eax 0x00000027 push eax 0x00000028 ret 0x00000029 pop eax 0x0000002a ret 0x0000002b jmp 00007FA93CFE6D5Dh 0x00000030 lea eax, dword ptr [ebp+124823DAh] 0x00000036 mov dword ptr [ebp+122D198Fh], ecx 0x0000003c push eax 0x0000003d jmp 00007FA93CFE6D66h 0x00000042 mov dword ptr [esp], eax 0x00000045 mov ecx, dword ptr [ebp+12452676h] 0x0000004b call dword ptr [ebp+122D30C1h] 0x00000051 push eax 0x00000052 push edx 0x00000053 push eax 0x00000054 push edi 0x00000055 pop edi 0x00000056 pushad 0x00000057 popad 0x00000058 pop eax 0x00000059 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B7C4B second address: 2B7C51 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B7C51 second address: 108B50 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 nop 0x00000006 push 00000000h 0x00000008 push edi 0x00000009 call 00007FA93CFE6D58h 0x0000000e pop edi 0x0000000f mov dword ptr [esp+04h], edi 0x00000013 add dword ptr [esp+04h], 00000016h 0x0000001b inc edi 0x0000001c push edi 0x0000001d ret 0x0000001e pop edi 0x0000001f ret 0x00000020 mov edx, dword ptr [ebp+122D1807h] 0x00000026 push dword ptr [ebp+122D0611h] 0x0000002c call dword ptr [ebp+122D17F7h] 0x00000032 pushad 0x00000033 jmp 00007FA93CFE6D63h 0x00000038 xor eax, eax 0x0000003a stc 0x0000003b mov edx, dword ptr [esp+28h] 0x0000003f jbe 00007FA93CFE6D5Dh 0x00000045 jmp 00007FA93CFE6D67h 0x0000004a mov dword ptr [ebp+122D37B1h], eax 0x00000050 or dword ptr [ebp+122D3066h], ebx 0x00000056 mov esi, 0000003Ch 0x0000005b pushad 0x0000005c jno 00007FA93CFE6D5Ch 0x00000062 sub dword ptr [ebp+122D3066h], edx 0x00000068 popad 0x00000069 add esi, dword ptr [esp+24h] 0x0000006d pushad 0x0000006e clc 0x0000006f popad 0x00000070 lodsw 0x00000072 mov dword ptr [ebp+122D3101h], edx 0x00000078 add eax, dword ptr [esp+24h] 0x0000007c xor dword ptr [ebp+122D24F5h], ecx 0x00000082 mov ebx, dword ptr [esp+24h] 0x00000086 cmc 0x00000087 push eax 0x00000088 push eax 0x00000089 push edx 0x0000008a jmp 00007FA93CFE6D61h 0x0000008f rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B7CCD second address: 2B7CD3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B7CD3 second address: 2B7CF0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 jmp 00007FA93CFE6D66h 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B7F5F second address: 2B7F64 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B7F64 second address: 2B7F6A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B8103 second address: 2B8109 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B8109 second address: 2B810D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B810D second address: 2B8156 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov dword ptr [esp], eax 0x0000000b push 00000000h 0x0000000d push ebp 0x0000000e call 00007FA93D08FA18h 0x00000013 pop ebp 0x00000014 mov dword ptr [esp+04h], ebp 0x00000018 add dword ptr [esp+04h], 00000014h 0x00000020 inc ebp 0x00000021 push ebp 0x00000022 ret 0x00000023 pop ebp 0x00000024 ret 0x00000025 mov dword ptr [ebp+122D2518h], eax 0x0000002b push 00000004h 0x0000002d nop 0x0000002e jmp 00007FA93D08FA1Ch 0x00000033 push eax 0x00000034 push eax 0x00000035 push edx 0x00000036 jmp 00007FA93D08FA1Ah 0x0000003b rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B87B3 second address: 2B87BE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push eax 0x00000006 push edx 0x00000007 push eax 0x00000008 push edx 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B87BE second address: 2B87C2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B87C2 second address: 2B87D2 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D5Ch 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B87D2 second address: 2B87F3 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93D08FA24h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov eax, dword ptr [esp+04h] 0x0000000d pushad 0x0000000e push eax 0x0000000f push edx 0x00000010 pushad 0x00000011 popad 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B88EF second address: 2B8932 instructions: 0x00000000 rdtsc 0x00000002 jo 00007FA93CFE6D56h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a popad 0x0000000b push eax 0x0000000c jnc 00007FA93CFE6D5Ah 0x00000012 nop 0x00000013 mov ecx, eax 0x00000015 lea eax, dword ptr [ebp+1248241Eh] 0x0000001b push 00000000h 0x0000001d push eax 0x0000001e call 00007FA93CFE6D58h 0x00000023 pop eax 0x00000024 mov dword ptr [esp+04h], eax 0x00000028 add dword ptr [esp+04h], 00000016h 0x00000030 inc eax 0x00000031 push eax 0x00000032 ret 0x00000033 pop eax 0x00000034 ret 0x00000035 nop 0x00000036 pushad 0x00000037 push eax 0x00000038 push edx 0x00000039 pushad 0x0000003a popad 0x0000003b rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B8932 second address: 2B8965 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93D08FA28h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push ecx 0x0000000a push ebx 0x0000000b pop ebx 0x0000000c pop ecx 0x0000000d popad 0x0000000e push eax 0x0000000f push eax 0x00000010 push edx 0x00000011 jmp 00007FA93D08FA1Fh 0x00000016 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B8965 second address: 2B89B0 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D5Eh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 nop 0x0000000a movsx ecx, dx 0x0000000d lea eax, dword ptr [ebp+124823DAh] 0x00000013 push 00000000h 0x00000015 push ebp 0x00000016 call 00007FA93CFE6D58h 0x0000001b pop ebp 0x0000001c mov dword ptr [esp+04h], ebp 0x00000020 add dword ptr [esp+04h], 0000001Bh 0x00000028 inc ebp 0x00000029 push ebp 0x0000002a ret 0x0000002b pop ebp 0x0000002c ret 0x0000002d mov edx, dword ptr [ebp+122D2518h] 0x00000033 nop 0x00000034 pushad 0x00000035 push eax 0x00000036 push edx 0x00000037 pushad 0x00000038 popad 0x00000039 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B89B0 second address: 2B89B4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B89B4 second address: 2B89DE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jng 00007FA93CFE6D6Ch 0x0000000c jmp 00007FA93CFE6D66h 0x00000011 popad 0x00000012 push eax 0x00000013 push eax 0x00000014 push edx 0x00000015 push eax 0x00000016 push edx 0x00000017 push ecx 0x00000018 pop ecx 0x00000019 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B89DE second address: 2B89E2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B89E2 second address: 2B89E8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B89E8 second address: 29F48B instructions: 0x00000000 rdtsc 0x00000002 jng 00007FA93D08FA29h 0x00000008 jmp 00007FA93D08FA23h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f nop 0x00000010 push 00000000h 0x00000012 push edi 0x00000013 call 00007FA93D08FA18h 0x00000018 pop edi 0x00000019 mov dword ptr [esp+04h], edi 0x0000001d add dword ptr [esp+04h], 00000017h 0x00000025 inc edi 0x00000026 push edi 0x00000027 ret 0x00000028 pop edi 0x00000029 ret 0x0000002a xor dx, 680Dh 0x0000002f sub edx, dword ptr [ebp+122D17F7h] 0x00000035 call dword ptr [ebp+12451AD3h] 0x0000003b pushad 0x0000003c pushad 0x0000003d jne 00007FA93D08FA16h 0x00000043 push esi 0x00000044 pop esi 0x00000045 popad 0x00000046 js 00007FA93D08FA1Ch 0x0000004c push eax 0x0000004d push edx 0x0000004e rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2FB50B second address: 2FB524 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA93CFE6D63h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2FB524 second address: 2FB52A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2FB52A second address: 2FB55A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jnl 00007FA93CFE6D81h 0x0000000b push edi 0x0000000c pushad 0x0000000d popad 0x0000000e jmp 00007FA93CFE6D67h 0x00000013 pop edi 0x00000014 push eax 0x00000015 push edx 0x00000016 jng 00007FA93CFE6D56h 0x0000001c push ecx 0x0000001d pop ecx 0x0000001e rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2FB838 second address: 2FB83D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2FB9CD second address: 2FB9D7 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2FB9D7 second address: 2FB9DB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2FBB00 second address: 2FBB1A instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D64h 0x00000007 pushad 0x00000008 popad 0x00000009 pop edx 0x0000000a pop eax 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2FBC79 second address: 2FBC8B instructions: 0x00000000 rdtsc 0x00000002 js 00007FA93D08FA16h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a jbe 00007FA93D08FA1Ch 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2FF9FC second address: 2FFA0A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a pushad 0x0000000b popad 0x0000000c pushad 0x0000000d popad 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2FFB70 second address: 2FFB7A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edi 0x00000005 pop edi 0x00000006 pushad 0x00000007 popad 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 30231D second address: 302327 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 pushad 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 302327 second address: 30233C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 pushad 0x00000008 jmp 00007FA93D08FA1Bh 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 30201B second address: 30201F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 306FEF second address: 307014 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 pushad 0x00000006 push esi 0x00000007 pop esi 0x00000008 jmp 00007FA93D08FA29h 0x0000000d push ebx 0x0000000e pop ebx 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 30682E second address: 306843 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 jmp 00007FA93CFE6D5Fh 0x00000009 pop edx 0x0000000a pop eax 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 306843 second address: 306848 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 3069EC second address: 306A18 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D5Ch 0x00000007 pop edx 0x00000008 pop eax 0x00000009 jmp 00007FA93CFE6D68h 0x0000000e push eax 0x0000000f push edx 0x00000010 pushad 0x00000011 popad 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 306A18 second address: 306A1C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 306CEF second address: 306D21 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D5Ch 0x00000007 jmp 00007FA93CFE6D64h 0x0000000c pop edx 0x0000000d pop eax 0x0000000e push edx 0x0000000f push ebx 0x00000010 pop ebx 0x00000011 pushad 0x00000012 popad 0x00000013 pop edx 0x00000014 push eax 0x00000015 push edx 0x00000016 jg 00007FA93CFE6D56h 0x0000001c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 30AFC9 second address: 30AFCD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 30A26D second address: 30A271 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 30A408 second address: 30A40D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 30A40D second address: 30A42C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pushad 0x00000004 popad 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pushad 0x00000009 push eax 0x0000000a push edx 0x0000000b push ebx 0x0000000c pop ebx 0x0000000d jmp 00007FA93CFE6D62h 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 30A42C second address: 30A444 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jmp 00007FA93D08FA1Ah 0x0000000b push eax 0x0000000c push edx 0x0000000d ja 00007FA93D08FA16h 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 30A591 second address: 30A5AF instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D62h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 popad 0x0000000a push edx 0x0000000b push eax 0x0000000c push edx 0x0000000d push eax 0x0000000e pop eax 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 30A5AF second address: 30A5B3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 30A5B3 second address: 30A5B7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 30A9D3 second address: 30A9E4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 pop ebx 0x00000008 pushad 0x00000009 jo 00007FA93D08FA22h 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 30A9E4 second address: 30A9EA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 30A9EA second address: 30A9F1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ebx 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 30A9F1 second address: 30A9F9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 push esi 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 31085C second address: 310881 instructions: 0x00000000 rdtsc 0x00000002 jl 00007FA93D08FA16h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a jo 00007FA93D08FA2Bh 0x00000010 jmp 00007FA93D08FA25h 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 310881 second address: 310899 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 jmp 00007FA93CFE6D5Ah 0x00000008 jns 00007FA93CFE6D56h 0x0000000e pop edx 0x0000000f push eax 0x00000010 push edx 0x00000011 push eax 0x00000012 pop eax 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 310899 second address: 31089D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 30F237 second address: 30F25F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edi 0x00000006 pushad 0x00000007 push eax 0x00000008 push edx 0x00000009 jmp 00007FA93CFE6D69h 0x0000000e jno 00007FA93CFE6D56h 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 30F25F second address: 30F273 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93D08FA1Dh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push esi 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2813B2 second address: 2813D8 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D66h 0x00000007 ja 00007FA93CFE6D56h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f push eax 0x00000010 push edx 0x00000011 push eax 0x00000012 push edx 0x00000013 pushad 0x00000014 popad 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B8278 second address: 2B827C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B827C second address: 2B8286 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B8286 second address: 2B828A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B828A second address: 2B82E9 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 jl 00007FA93CFE6D60h 0x0000000e pushad 0x0000000f jnc 00007FA93CFE6D56h 0x00000015 pushad 0x00000016 popad 0x00000017 popad 0x00000018 nop 0x00000019 mov edi, dword ptr [ebp+122D37C5h] 0x0000001f mov ch, bl 0x00000021 mov ebx, dword ptr [ebp+12482419h] 0x00000027 mov edx, dword ptr [ebp+122D1B9Fh] 0x0000002d pushad 0x0000002e mov dword ptr [ebp+122D2DCEh], esi 0x00000034 pushad 0x00000035 push edi 0x00000036 pop ecx 0x00000037 mov cx, ax 0x0000003a popad 0x0000003b popad 0x0000003c add eax, ebx 0x0000003e push ebx 0x0000003f jmp 00007FA93CFE6D65h 0x00000044 pop edx 0x00000045 push eax 0x00000046 pushad 0x00000047 push eax 0x00000048 push edi 0x00000049 pop edi 0x0000004a pop eax 0x0000004b push eax 0x0000004c push edx 0x0000004d push eax 0x0000004e push edx 0x0000004f rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B82E9 second address: 2B82ED instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 2B82ED second address: 2B830C instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 mov dword ptr [esp], eax 0x0000000a mov edi, dword ptr [ebp+122D379Dh] 0x00000010 push 00000004h 0x00000012 jg 00007FA93CFE6D58h 0x00000018 push eax 0x00000019 push eax 0x0000001a pushad 0x0000001b push eax 0x0000001c push edx 0x0000001d rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 318C4E second address: 318C5D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jng 00007FA93D08FA16h 0x0000000a pushad 0x0000000b popad 0x0000000c pushad 0x0000000d popad 0x0000000e popad 0x0000000f rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 318C5D second address: 318C71 instructions: 0x00000000 rdtsc 0x00000002 jng 00007FA93CFE6D5Eh 0x00000008 push eax 0x00000009 push edx 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 318C71 second address: 318C75 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 318C75 second address: 318C79 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 316CA6 second address: 316CBA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA93D08FA20h 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 316CBA second address: 316CCC instructions: 0x00000000 rdtsc 0x00000002 jg 00007FA93CFE6D56h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c jl 00007FA93CFE6D56h 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 316CCC second address: 316CEA instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 js 00007FA93D08FA16h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007FA93D08FA1Eh 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 316CEA second address: 316CEE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 316CEE second address: 316CF2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 316CF2 second address: 316D00 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 pushad 0x00000008 push eax 0x00000009 push edx 0x0000000a push ebx 0x0000000b pop ebx 0x0000000c pushad 0x0000000d popad 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 316D00 second address: 316D3E instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 ja 00007FA93D08FA21h 0x0000000e jmp 00007FA93D08FA1Bh 0x00000013 pushad 0x00000014 push edi 0x00000015 pop edi 0x00000016 jng 00007FA93D08FA16h 0x0000001c jmp 00007FA93D08FA27h 0x00000021 popad 0x00000022 push eax 0x00000023 push edx 0x00000024 push eax 0x00000025 push edx 0x00000026 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 316D3E second address: 316D42 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 3170E9 second address: 317100 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA93D08FA23h 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 317100 second address: 31711E instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 jbe 00007FA93CFE6D56h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push ecx 0x0000000d js 00007FA93CFE6D56h 0x00000013 pop ecx 0x00000014 popad 0x00000015 pushad 0x00000016 jo 00007FA93CFE6D5Eh 0x0000001c push eax 0x0000001d push edx 0x0000001e rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 31744E second address: 3174B0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA93D08FA27h 0x00000009 push esi 0x0000000a pop esi 0x0000000b pushad 0x0000000c popad 0x0000000d popad 0x0000000e jmp 00007FA93D08FA25h 0x00000013 pushad 0x00000014 jmp 00007FA93D08FA21h 0x00000019 js 00007FA93D08FA16h 0x0000001f push ebx 0x00000020 pop ebx 0x00000021 popad 0x00000022 push eax 0x00000023 push edx 0x00000024 jmp 00007FA93D08FA20h 0x00000029 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 3174B0 second address: 3174B4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 3177A6 second address: 3177C4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 popad 0x00000007 jmp 00007FA93D08FA22h 0x0000000c pushad 0x0000000d pushad 0x0000000e popad 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 31836C second address: 318383 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D63h 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 318383 second address: 318389 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 321027 second address: 32102B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 32102B second address: 32102F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 32102F second address: 32103B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 32103B second address: 32103F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 32103F second address: 32105C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 jmp 00007FA93CFE6D5Ch 0x0000000e jp 00007FA93CFE6D58h 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 3201BC second address: 3201D0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 pop esi 0x00000006 pop edx 0x00000007 push edi 0x00000008 pushad 0x00000009 popad 0x0000000a pop edi 0x0000000b push esi 0x0000000c jg 00007FA93D08FA16h 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 320605 second address: 320624 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push edi 0x00000004 pop edi 0x00000005 push edi 0x00000006 pop edi 0x00000007 pushad 0x00000008 popad 0x00000009 popad 0x0000000a push eax 0x0000000b push edx 0x0000000c jmp 00007FA93CFE6D5Dh 0x00000011 jnp 00007FA93CFE6D56h 0x00000017 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 3285B4 second address: 3285C0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 pop edi 0x00000006 push eax 0x00000007 push edx 0x00000008 push eax 0x00000009 push edx 0x0000000a push edx 0x0000000b pop edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 3285C0 second address: 3285E7 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 js 00007FA93CFE6D71h 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 328A35 second address: 328A6C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93D08FA22h 0x00000007 jp 00007FA93D08FA16h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f jp 00007FA93D08FA22h 0x00000015 push edi 0x00000016 jp 00007FA93D08FA16h 0x0000001c push eax 0x0000001d push edx 0x0000001e rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 328BBE second address: 328BC4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 328BC4 second address: 328BC9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 328BC9 second address: 328BD3 instructions: 0x00000000 rdtsc 0x00000002 jbe 00007FA93CFE6D5Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 32919A second address: 3291B6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 push eax 0x00000006 push edx 0x00000007 jmp 00007FA93D08FA23h 0x0000000c pushad 0x0000000d popad 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 3291B6 second address: 3291C8 instructions: 0x00000000 rdtsc 0x00000002 jbe 00007FA93CFE6D56h 0x00000008 push eax 0x00000009 pop eax 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edx 0x0000000e pushad 0x0000000f popad 0x00000010 pushad 0x00000011 popad 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 3299C4 second address: 3299D2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 pop eax 0x00000006 je 00007FA93D08FA16h 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 328023 second address: 328027 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 328027 second address: 32803B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 jnl 00007FA93D08FA16h 0x0000000e jnc 00007FA93D08FA16h 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 275625 second address: 275650 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 jmp 00007FA93CFE6D66h 0x0000000b jmp 00007FA93CFE6D5Eh 0x00000010 popad 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 275650 second address: 27565B instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 jl 00007FA93D08FA16h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 27565B second address: 275685 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 jnl 00007FA93CFE6D5Eh 0x0000000b pop edx 0x0000000c pop eax 0x0000000d pushad 0x0000000e jmp 00007FA93CFE6D5Ah 0x00000013 push eax 0x00000014 push edx 0x00000015 pushad 0x00000016 popad 0x00000017 jns 00007FA93CFE6D56h 0x0000001d rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 32ED05 second address: 32ED0E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 push eax 0x00000006 push edx 0x00000007 push edx 0x00000008 pop edx 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 32ED0E second address: 32ED20 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D5Eh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 332DC2 second address: 332DCB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 push eax 0x00000006 push edx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 332DCB second address: 332DD5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jbe 00007FA93CFE6D56h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 332DD5 second address: 332E00 instructions: 0x00000000 rdtsc 0x00000002 jng 00007FA93D08FA16h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a popad 0x0000000b push eax 0x0000000c push edx 0x0000000d jo 00007FA93D08FA1Ah 0x00000013 pushad 0x00000014 popad 0x00000015 pushad 0x00000016 popad 0x00000017 push ebx 0x00000018 jmp 00007FA93D08FA20h 0x0000001d pushad 0x0000001e popad 0x0000001f pop ebx 0x00000020 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 332969 second address: 33296D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 33296D second address: 332981 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA93D08FA1Eh 0x00000009 pop edx 0x0000000a pop eax 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 332981 second address: 33299C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D61h 0x00000007 push eax 0x00000008 push edx 0x00000009 jns 00007FA93CFE6D56h 0x0000000f rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 33299C second address: 3329A0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 33438F second address: 334393 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 33F401 second address: 33F422 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 jmp 00007FA93D08FA23h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c push edx 0x0000000d js 00007FA93D08FA16h 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 34514D second address: 345151 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 27A766 second address: 27A78D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 popad 0x00000006 pushad 0x00000007 jmp 00007FA93D08FA25h 0x0000000c pushad 0x0000000d pushad 0x0000000e popad 0x0000000f js 00007FA93D08FA16h 0x00000015 push eax 0x00000016 push edx 0x00000017 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 344CCD second address: 344CE5 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D62h 0x00000007 push eax 0x00000008 push edx 0x00000009 pushad 0x0000000a popad 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 348B6C second address: 348B7B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 jnc 00007FA93D08FA16h 0x0000000d push ecx 0x0000000e pop ecx 0x0000000f rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 351DC1 second address: 351DC5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 35726B second address: 357275 instructions: 0x00000000 rdtsc 0x00000002 jp 00007FA93D08FA1Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 35CDD0 second address: 35CDD5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 35CF5B second address: 35CF77 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA93D08FA28h 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 35CF77 second address: 35CF87 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D5Ch 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 35CF87 second address: 35CFB2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 jmp 00007FA93D08FA27h 0x0000000c jmp 00007FA93D08FA1Bh 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 35CFB2 second address: 35CFBF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jne 00007FA93CFE6D62h 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 35CFBF second address: 35CFC5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 35D3CF second address: 35D3E3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jng 00007FA93CFE6D56h 0x0000000a pop eax 0x0000000b push esi 0x0000000c jns 00007FA93CFE6D56h 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 35D524 second address: 35D52A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 35D52A second address: 35D534 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 35D534 second address: 35D538 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 35D538 second address: 35D567 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D67h 0x00000007 jmp 00007FA93CFE6D64h 0x0000000c pop edx 0x0000000d pop eax 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 35D567 second address: 35D574 instructions: 0x00000000 rdtsc 0x00000002 jng 00007FA93D08FA18h 0x00000008 push edi 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 35D705 second address: 35D70C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edi 0x00000005 pop edi 0x00000006 popad 0x00000007 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 35D70C second address: 35D712 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 35D712 second address: 35D723 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA93CFE6D5Dh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 35D8EF second address: 35D8F3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 35D8F3 second address: 35D908 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a jmp 00007FA93CFE6D5Bh 0x0000000f rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 35E2D0 second address: 35E2E2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edi 0x00000005 jnc 00007FA93D08FA16h 0x0000000b jc 00007FA93D08FA16h 0x00000011 pop edi 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 361EA0 second address: 361EA4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 361B5F second address: 361B79 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 jmp 00007FA93D08FA23h 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 361B79 second address: 361B83 instructions: 0x00000000 rdtsc 0x00000002 je 00007FA93CFE6D56h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 36E469 second address: 36E46D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 36E46D second address: 36E473 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 36C265 second address: 36C26B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 36C26B second address: 36C26F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 37ECC6 second address: 37ECCC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 37ECCC second address: 37ECD6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 pushad 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 394A83 second address: 394A87 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 394D0A second address: 394D12 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 push ebx 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 394D12 second address: 394D27 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 pushad 0x00000006 pushad 0x00000007 popad 0x00000008 jp 00007FA93D08FA16h 0x0000000e pushad 0x0000000f popad 0x00000010 popad 0x00000011 push eax 0x00000012 push edx 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 394D27 second address: 394D2D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 394D2D second address: 394D31 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 394D31 second address: 394D56 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 popad 0x00000009 pushad 0x0000000a pushad 0x0000000b pushad 0x0000000c popad 0x0000000d js 00007FA93CFE6D56h 0x00000013 jnp 00007FA93CFE6D56h 0x00000019 push eax 0x0000001a pop eax 0x0000001b popad 0x0000001c push edi 0x0000001d jl 00007FA93CFE6D56h 0x00000023 push eax 0x00000024 push edx 0x00000025 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 394FD1 second address: 394FEF instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93D08FA27h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pushad 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 394FEF second address: 39500B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FA93CFE6D66h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 395476 second address: 39547D instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 push ebx 0x00000004 pop ebx 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 3984E2 second address: 3984E6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 3984E6 second address: 3984EC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 3984EC second address: 398511 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D5Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a pushad 0x0000000b pushad 0x0000000c jmp 00007FA93CFE6D61h 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 398511 second address: 398519 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 3987EB second address: 39883F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 jmp 00007FA93CFE6D5Ch 0x0000000a popad 0x0000000b mov dword ptr [esp], eax 0x0000000e push 00000000h 0x00000010 push ebx 0x00000011 call 00007FA93CFE6D58h 0x00000016 pop ebx 0x00000017 mov dword ptr [esp+04h], ebx 0x0000001b add dword ptr [esp+04h], 0000001Bh 0x00000023 inc ebx 0x00000024 push ebx 0x00000025 ret 0x00000026 pop ebx 0x00000027 ret 0x00000028 mov edx, dword ptr [ebp+122D1AD0h] 0x0000002e push 00000004h 0x00000030 or edx, 705D99F7h 0x00000036 call 00007FA93CFE6D59h 0x0000003b push esi 0x0000003c push eax 0x0000003d push edx 0x0000003e push eax 0x0000003f push edx 0x00000040 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 39883F second address: 398843 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 398843 second address: 398847 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 398847 second address: 398879 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop esi 0x00000007 push eax 0x00000008 jmp 00007FA93D08FA1Bh 0x0000000d mov eax, dword ptr [esp+04h] 0x00000011 push ebx 0x00000012 jo 00007FA93D08FA18h 0x00000018 pushad 0x00000019 popad 0x0000001a pop ebx 0x0000001b mov eax, dword ptr [eax] 0x0000001d push eax 0x0000001e push edx 0x0000001f pushad 0x00000020 jmp 00007FA93D08FA1Ah 0x00000025 push eax 0x00000026 push edx 0x00000027 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 398879 second address: 39887E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 39B4D9 second address: 39B4DD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 39B4DD second address: 39B4F2 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D5Ch 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push edx 0x0000000a pushad 0x0000000b popad 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F8032B second address: 4F80344 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93D08FA25h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F80344 second address: 4F80375 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 call 00007FA93CFE6D67h 0x00000008 pop esi 0x00000009 mov bx, 455Ch 0x0000000d popad 0x0000000e pop edx 0x0000000f pop eax 0x00000010 push esi 0x00000011 push eax 0x00000012 push edx 0x00000013 push eax 0x00000014 push edx 0x00000015 jmp 00007FA93CFE6D5Ah 0x0000001a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F80375 second address: 4F80379 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F80379 second address: 4F8037F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F8037F second address: 4F803C5 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 call 00007FA93D08FA1Ch 0x00000008 pop ecx 0x00000009 call 00007FA93D08FA1Bh 0x0000000e pop eax 0x0000000f popad 0x00000010 pop edx 0x00000011 pop eax 0x00000012 mov dword ptr [esp], ebp 0x00000015 push eax 0x00000016 push edx 0x00000017 pushad 0x00000018 pushad 0x00000019 popad 0x0000001a pushfd 0x0000001b jmp 00007FA93D08FA1Eh 0x00000020 xor cl, 00000008h 0x00000023 jmp 00007FA93D08FA1Bh 0x00000028 popfd 0x00000029 popad 0x0000002a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F803C5 second address: 4F80421 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D69h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov ebp, esp 0x0000000b pushad 0x0000000c movzx eax, dx 0x0000000f push edi 0x00000010 pushfd 0x00000011 jmp 00007FA93CFE6D64h 0x00000016 sub ah, FFFFFFC8h 0x00000019 jmp 00007FA93CFE6D5Bh 0x0000001e popfd 0x0000001f pop eax 0x00000020 popad 0x00000021 mov edx, dword ptr [ebp+0Ch] 0x00000024 pushad 0x00000025 mov ax, di 0x00000028 mov dh, D3h 0x0000002a popad 0x0000002b mov ecx, dword ptr [ebp+08h] 0x0000002e pushad 0x0000002f push eax 0x00000030 push edx 0x00000031 mov cl, 31h 0x00000033 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F80421 second address: 4F8045D instructions: 0x00000000 rdtsc 0x00000002 mov ax, dx 0x00000005 pop edx 0x00000006 pop eax 0x00000007 push eax 0x00000008 push edx 0x00000009 pushfd 0x0000000a jmp 00007FA93D08FA23h 0x0000000f xor ax, D06Eh 0x00000014 jmp 00007FA93D08FA29h 0x00000019 popfd 0x0000001a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0753 second address: 4FA07BB instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FA93CFE6D67h 0x00000009 sub ax, E9FEh 0x0000000e jmp 00007FA93CFE6D69h 0x00000013 popfd 0x00000014 mov ebx, ecx 0x00000016 popad 0x00000017 pop edx 0x00000018 pop eax 0x00000019 xchg eax, ebp 0x0000001a jmp 00007FA93CFE6D5Ah 0x0000001f mov ebp, esp 0x00000021 jmp 00007FA93CFE6D60h 0x00000026 xchg eax, ecx 0x00000027 pushad 0x00000028 mov ebx, ecx 0x0000002a popad 0x0000002b push eax 0x0000002c push eax 0x0000002d push edx 0x0000002e push eax 0x0000002f push edx 0x00000030 pushad 0x00000031 popad 0x00000032 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA07BB second address: 4FA07D6 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93D08FA27h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA07D6 second address: 4FA07EE instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA93CFE6D64h 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA07EE second address: 4FA085E instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93D08FA1Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b xchg eax, ecx 0x0000000c pushad 0x0000000d pushfd 0x0000000e jmp 00007FA93D08FA24h 0x00000013 adc ax, 6F48h 0x00000018 jmp 00007FA93D08FA1Bh 0x0000001d popfd 0x0000001e pushfd 0x0000001f jmp 00007FA93D08FA28h 0x00000024 sbb cl, FFFFFFA8h 0x00000027 jmp 00007FA93D08FA1Bh 0x0000002c popfd 0x0000002d popad 0x0000002e xchg eax, esi 0x0000002f pushad 0x00000030 movzx esi, di 0x00000033 mov dh, E6h 0x00000035 popad 0x00000036 push eax 0x00000037 push eax 0x00000038 push edx 0x00000039 pushad 0x0000003a push eax 0x0000003b push edx 0x0000003c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA085E second address: 4FA0865 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 pop edi 0x00000006 popad 0x00000007 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0865 second address: 4FA08A8 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 movsx edi, ax 0x00000006 pushfd 0x00000007 jmp 00007FA93D08FA26h 0x0000000c add esi, 4B26C668h 0x00000012 jmp 00007FA93D08FA1Bh 0x00000017 popfd 0x00000018 popad 0x00000019 pop edx 0x0000001a pop eax 0x0000001b xchg eax, esi 0x0000001c push eax 0x0000001d push edx 0x0000001e pushad 0x0000001f call 00007FA93D08FA1Bh 0x00000024 pop eax 0x00000025 popad 0x00000026 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA08A8 second address: 4FA08E0 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D65h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 lea eax, dword ptr [ebp-04h] 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 jmp 00007FA93CFE6D68h 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA08E0 second address: 4FA08EF instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93D08FA1Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA08EF second address: 4FA08F4 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0A7A second address: 4FA0AEA instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FA93D08FA1Fh 0x00000009 xor cx, 4ADEh 0x0000000e jmp 00007FA93D08FA29h 0x00000013 popfd 0x00000014 pushfd 0x00000015 jmp 00007FA93D08FA20h 0x0000001a xor si, 7AD8h 0x0000001f jmp 00007FA93D08FA1Bh 0x00000024 popfd 0x00000025 popad 0x00000026 pop edx 0x00000027 pop eax 0x00000028 mov eax, esi 0x0000002a push eax 0x0000002b push edx 0x0000002c jmp 00007FA93D08FA25h 0x00000031 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0AEA second address: 4FA0B12 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov dl, 78h 0x00000005 call 00007FA93CFE6D68h 0x0000000a pop esi 0x0000000b popad 0x0000000c pop edx 0x0000000d pop eax 0x0000000e pop esi 0x0000000f push eax 0x00000010 push edx 0x00000011 push eax 0x00000012 push edx 0x00000013 pushad 0x00000014 popad 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0B12 second address: 4FA0B2C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93D08FA26h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0B2C second address: 4FA0B32 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0B32 second address: 4FA0B36 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0B36 second address: 4FA0B3A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0B3A second address: 4FA0B4A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 leave 0x00000009 push eax 0x0000000a push edx 0x0000000b pushad 0x0000000c mov ah, 9Eh 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0B4A second address: 4FA0B4F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0B4F second address: 4FA003B instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93D08FA1Ah 0x00000007 pop edx 0x00000008 pop eax 0x00000009 retn 0004h 0x0000000c nop 0x0000000d sub esp, 04h 0x00000010 xor ebx, ebx 0x00000012 cmp eax, 00000000h 0x00000015 je 00007FA93D08FB63h 0x0000001b xor eax, eax 0x0000001d mov dword ptr [esp], 00000000h 0x00000024 mov dword ptr [esp+04h], 00000000h 0x0000002c call 00007FA941F4DFABh 0x00000031 mov edi, edi 0x00000033 jmp 00007FA93D08FA26h 0x00000038 xchg eax, ebp 0x00000039 pushad 0x0000003a push ecx 0x0000003b pop esi 0x0000003c push ebx 0x0000003d call 00007FA93D08FA24h 0x00000042 pop eax 0x00000043 pop edx 0x00000044 popad 0x00000045 push eax 0x00000046 push eax 0x00000047 push edx 0x00000048 push eax 0x00000049 push edx 0x0000004a pushad 0x0000004b popad 0x0000004c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA003B second address: 4FA0055 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D66h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0055 second address: 4FA007D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 movsx ebx, si 0x00000006 push eax 0x00000007 pop edx 0x00000008 popad 0x00000009 pop edx 0x0000000a pop eax 0x0000000b xchg eax, ebp 0x0000000c jmp 00007FA93D08FA24h 0x00000011 mov ebp, esp 0x00000013 push eax 0x00000014 push edx 0x00000015 push eax 0x00000016 push edx 0x00000017 push eax 0x00000018 push edx 0x00000019 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA007D second address: 4FA0081 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0081 second address: 4FA0087 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0087 second address: 4FA00C1 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D64h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push FFFFFFFEh 0x0000000b push eax 0x0000000c push edx 0x0000000d pushad 0x0000000e mov ecx, ebx 0x00000010 call 00007FA93CFE6D69h 0x00000015 pop esi 0x00000016 popad 0x00000017 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA00C1 second address: 4FA00D2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA93D08FA1Dh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA00D2 second address: 4FA00EC instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 call 00007FA93CFE6D59h 0x0000000d push eax 0x0000000e push edx 0x0000000f pushad 0x00000010 mov edx, esi 0x00000012 movzx ecx, di 0x00000015 popad 0x00000016 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA00EC second address: 4FA0110 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov ecx, 12B24219h 0x00000008 mov eax, 4D9BE6D5h 0x0000000d popad 0x0000000e pop edx 0x0000000f pop eax 0x00000010 push eax 0x00000011 push eax 0x00000012 push edx 0x00000013 pushad 0x00000014 jmp 00007FA93D08FA1Ch 0x00000019 movzx esi, bx 0x0000001c popad 0x0000001d rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0110 second address: 4FA0135 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D5Ch 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov eax, dword ptr [esp+04h] 0x0000000d push eax 0x0000000e push edx 0x0000000f push eax 0x00000010 push edx 0x00000011 jmp 00007FA93CFE6D5Dh 0x00000016 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0135 second address: 4FA013B instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA013B second address: 4FA0184 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D5Ch 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov eax, dword ptr [eax] 0x0000000b pushad 0x0000000c mov edi, 0D0164E4h 0x00000011 pushfd 0x00000012 jmp 00007FA93CFE6D5Dh 0x00000017 adc eax, 7BE8C526h 0x0000001d jmp 00007FA93CFE6D61h 0x00000022 popfd 0x00000023 popad 0x00000024 mov dword ptr [esp+04h], eax 0x00000028 push eax 0x00000029 push edx 0x0000002a push eax 0x0000002b push edx 0x0000002c push eax 0x0000002d push edx 0x0000002e rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0184 second address: 4FA0188 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0188 second address: 4FA018E instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA02A5 second address: 4FA02AA instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA02AA second address: 4FA02D8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edx 0x00000006 pop eax 0x00000007 nop 0x00000008 pushad 0x00000009 mov dx, D986h 0x0000000d mov di, 0812h 0x00000011 popad 0x00000012 sub esp, 18h 0x00000015 pushad 0x00000016 mov bx, 876Ah 0x0000001a call 00007FA93CFE6D5Bh 0x0000001f pop ebx 0x00000020 popad 0x00000021 xchg eax, ebx 0x00000022 push eax 0x00000023 push edx 0x00000024 push eax 0x00000025 push edx 0x00000026 pushad 0x00000027 popad 0x00000028 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA02D8 second address: 4FA02DE instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA02DE second address: 4FA036C instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FA93CFE6D64h 0x00000009 jmp 00007FA93CFE6D65h 0x0000000e popfd 0x0000000f pushad 0x00000010 popad 0x00000011 popad 0x00000012 pop edx 0x00000013 pop eax 0x00000014 push eax 0x00000015 push eax 0x00000016 push edx 0x00000017 pushad 0x00000018 pushfd 0x00000019 jmp 00007FA93CFE6D68h 0x0000001e sbb eax, 73388418h 0x00000024 jmp 00007FA93CFE6D5Bh 0x00000029 popfd 0x0000002a pushfd 0x0000002b jmp 00007FA93CFE6D68h 0x00000030 add esi, 2247EE78h 0x00000036 jmp 00007FA93CFE6D5Bh 0x0000003b popfd 0x0000003c popad 0x0000003d rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA036C second address: 4FA0372 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0372 second address: 4FA0376 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0376 second address: 4FA03A8 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 xchg eax, ebx 0x00000009 pushad 0x0000000a movsx edi, cx 0x0000000d push esi 0x0000000e pushad 0x0000000f popad 0x00000010 pop edx 0x00000011 popad 0x00000012 xchg eax, esi 0x00000013 jmp 00007FA93D08FA1Eh 0x00000018 push eax 0x00000019 pushad 0x0000001a mov al, dl 0x0000001c mov edi, ecx 0x0000001e popad 0x0000001f xchg eax, esi 0x00000020 push eax 0x00000021 push edx 0x00000022 pushad 0x00000023 movsx edi, ax 0x00000026 mov ebx, eax 0x00000028 popad 0x00000029 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA03A8 second address: 4FA03D8 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FA93CFE6D60h 0x00000008 popad 0x00000009 pop edx 0x0000000a pop eax 0x0000000b xchg eax, edi 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007FA93CFE6D67h 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA03D8 second address: 4FA03DE instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA03DE second address: 4FA03F6 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push eax 0x0000000a push edx 0x0000000b jmp 00007FA93CFE6D5Dh 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA03F6 second address: 4FA0465 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 pushad 0x00000006 popad 0x00000007 popad 0x00000008 pop edx 0x00000009 pop eax 0x0000000a xchg eax, edi 0x0000000b pushad 0x0000000c pushfd 0x0000000d jmp 00007FA93D08FA1Fh 0x00000012 or ecx, 42B5D86Eh 0x00000018 jmp 00007FA93D08FA29h 0x0000001d popfd 0x0000001e mov bl, ah 0x00000020 popad 0x00000021 mov eax, dword ptr [769B4538h] 0x00000026 pushad 0x00000027 pushfd 0x00000028 jmp 00007FA93D08FA29h 0x0000002d jmp 00007FA93D08FA1Bh 0x00000032 popfd 0x00000033 push eax 0x00000034 push edx 0x00000035 mov cl, 4Fh 0x00000037 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0465 second address: 4FA04B3 instructions: 0x00000000 rdtsc 0x00000002 pushfd 0x00000003 jmp 00007FA93CFE6D5Bh 0x00000008 or esi, 2CA233DEh 0x0000000e jmp 00007FA93CFE6D69h 0x00000013 popfd 0x00000014 pop edx 0x00000015 pop eax 0x00000016 popad 0x00000017 xor dword ptr [ebp-08h], eax 0x0000001a pushad 0x0000001b mov edi, ecx 0x0000001d mov cx, 339Fh 0x00000021 popad 0x00000022 xor eax, ebp 0x00000024 push eax 0x00000025 push edx 0x00000026 jmp 00007FA93CFE6D5Eh 0x0000002b rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA04B3 second address: 4FA04C5 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA93D08FA1Eh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA04C5 second address: 4FA04EE instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D5Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b nop 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007FA93CFE6D65h 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA04EE second address: 4FA055B instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov ebx, 1C033862h 0x00000008 pushfd 0x00000009 jmp 00007FA93D08FA23h 0x0000000e adc cx, 695Eh 0x00000013 jmp 00007FA93D08FA29h 0x00000018 popfd 0x00000019 popad 0x0000001a pop edx 0x0000001b pop eax 0x0000001c push eax 0x0000001d jmp 00007FA93D08FA21h 0x00000022 nop 0x00000023 push eax 0x00000024 push edx 0x00000025 push eax 0x00000026 push edx 0x00000027 jmp 00007FA93D08FA28h 0x0000002c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA055B second address: 4FA0561 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0561 second address: 4FA05B6 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 call 00007FA93D08FA1Ch 0x00000008 pop eax 0x00000009 jmp 00007FA93D08FA1Bh 0x0000000e popad 0x0000000f pop edx 0x00000010 pop eax 0x00000011 lea eax, dword ptr [ebp-10h] 0x00000014 pushad 0x00000015 mov dx, ax 0x00000018 pushfd 0x00000019 jmp 00007FA93D08FA20h 0x0000001e and ecx, 719FC948h 0x00000024 jmp 00007FA93D08FA1Bh 0x00000029 popfd 0x0000002a popad 0x0000002b mov dword ptr fs:[00000000h], eax 0x00000031 push eax 0x00000032 push edx 0x00000033 push eax 0x00000034 push edx 0x00000035 push eax 0x00000036 push edx 0x00000037 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA05B6 second address: 4FA05BA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA05BA second address: 4FA05C0 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA05C0 second address: 4FA05C6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA05C6 second address: 4FA05CA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA05CA second address: 4FA05CE instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA05CE second address: 4FA0634 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov dword ptr [ebp-18h], esp 0x0000000b pushad 0x0000000c mov si, 1DFDh 0x00000010 pushfd 0x00000011 jmp 00007FA93D08FA1Ah 0x00000016 and ah, FFFFFFD8h 0x00000019 jmp 00007FA93D08FA1Bh 0x0000001e popfd 0x0000001f popad 0x00000020 mov eax, dword ptr fs:[00000018h] 0x00000026 jmp 00007FA93D08FA26h 0x0000002b mov ecx, dword ptr [eax+00000FDCh] 0x00000031 push eax 0x00000032 push edx 0x00000033 jmp 00007FA93D08FA27h 0x00000038 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0634 second address: 4FA06AA instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FA93CFE6D5Fh 0x00000009 add ecx, 582923AEh 0x0000000f jmp 00007FA93CFE6D69h 0x00000014 popfd 0x00000015 mov edx, eax 0x00000017 popad 0x00000018 pop edx 0x00000019 pop eax 0x0000001a test ecx, ecx 0x0000001c jmp 00007FA93CFE6D5Ah 0x00000021 jns 00007FA93CFE6D78h 0x00000027 jmp 00007FA93CFE6D60h 0x0000002c add eax, ecx 0x0000002e jmp 00007FA93CFE6D60h 0x00000033 mov ecx, dword ptr [ebp+08h] 0x00000036 push eax 0x00000037 push edx 0x00000038 pushad 0x00000039 mov bl, DFh 0x0000003b push eax 0x0000003c push edx 0x0000003d rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA06AA second address: 4FA06AF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA06AF second address: 4FA06C3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA93CFE6D60h 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA06C3 second address: 4FA06C7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F901BF second address: 4F90210 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D69h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xchg eax, ebp 0x0000000a push eax 0x0000000b push edx 0x0000000c pushad 0x0000000d pushfd 0x0000000e jmp 00007FA93CFE6D5Fh 0x00000013 xor ax, CBCEh 0x00000018 jmp 00007FA93CFE6D69h 0x0000001d popfd 0x0000001e popad 0x0000001f rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F90210 second address: 4F90216 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F90216 second address: 4F9021A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F9021A second address: 4F9021E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F9021E second address: 4F9025B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 jmp 00007FA93CFE6D66h 0x0000000e xchg eax, ebp 0x0000000f pushad 0x00000010 movzx eax, bx 0x00000013 movsx edi, ax 0x00000016 popad 0x00000017 mov ebp, esp 0x00000019 push eax 0x0000001a push edx 0x0000001b jmp 00007FA93CFE6D61h 0x00000020 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F9025B second address: 4F90261 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F90261 second address: 4F90265 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F90265 second address: 4F90276 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 sub esp, 2Ch 0x0000000b push eax 0x0000000c push edx 0x0000000d pushad 0x0000000e push esi 0x0000000f pop edx 0x00000010 popad 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F90276 second address: 4F90289 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA93CFE6D5Fh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F90289 second address: 4F9028D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F9028D second address: 4F902D4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push edx 0x00000009 jmp 00007FA93CFE6D62h 0x0000000e mov dword ptr [esp], ebx 0x00000011 push eax 0x00000012 push edx 0x00000013 pushad 0x00000014 pushfd 0x00000015 jmp 00007FA93CFE6D5Dh 0x0000001a sbb si, 5586h 0x0000001f jmp 00007FA93CFE6D61h 0x00000024 popfd 0x00000025 popad 0x00000026 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F902D4 second address: 4F902D9 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F902D9 second address: 4F902F2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 movzx eax, dx 0x00000007 popad 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push edx 0x0000000b push eax 0x0000000c push edx 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007FA93CFE6D5Ah 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F902F2 second address: 4F902F8 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F90354 second address: 4F9036C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D5Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 sub ebx, ebx 0x0000000b push eax 0x0000000c push edx 0x0000000d pushad 0x0000000e mov edi, ecx 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F9036C second address: 4F90371 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F90371 second address: 4F90377 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F90377 second address: 4F9037B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F9037B second address: 4F903C7 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D65h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b sub edi, edi 0x0000000d jmp 00007FA93CFE6D67h 0x00000012 inc ebx 0x00000013 push eax 0x00000014 push edx 0x00000015 jmp 00007FA93CFE6D65h 0x0000001a rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F903C7 second address: 4F9041C instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FA93D08FA27h 0x00000009 xor al, FFFFFFAEh 0x0000000c jmp 00007FA93D08FA29h 0x00000011 popfd 0x00000012 mov edi, eax 0x00000014 popad 0x00000015 pop edx 0x00000016 pop eax 0x00000017 test al, al 0x00000019 pushad 0x0000001a push eax 0x0000001b push edx 0x0000001c call 00007FA93D08FA22h 0x00000021 pop eax 0x00000022 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F9041C second address: 4F90484 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 je 00007FA93CFE6F86h 0x0000000d jmp 00007FA93CFE6D5Dh 0x00000012 lea ecx, dword ptr [ebp-14h] 0x00000015 jmp 00007FA93CFE6D5Eh 0x0000001a mov dword ptr [ebp-14h], edi 0x0000001d pushad 0x0000001e pushfd 0x0000001f jmp 00007FA93CFE6D5Eh 0x00000024 and esi, 6C78FFE8h 0x0000002a jmp 00007FA93CFE6D5Bh 0x0000002f popfd 0x00000030 push eax 0x00000031 push edx 0x00000032 jmp 00007FA93CFE6D66h 0x00000037 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F90502 second address: 4F90589 instructions: 0x00000000 rdtsc 0x00000002 pushfd 0x00000003 jmp 00007FA93D08FA20h 0x00000008 sbb si, FC98h 0x0000000d jmp 00007FA93D08FA1Bh 0x00000012 popfd 0x00000013 pop edx 0x00000014 pop eax 0x00000015 jmp 00007FA93D08FA28h 0x0000001a popad 0x0000001b test eax, eax 0x0000001d pushad 0x0000001e mov cl, 20h 0x00000020 pushfd 0x00000021 jmp 00007FA93D08FA23h 0x00000026 jmp 00007FA93D08FA23h 0x0000002b popfd 0x0000002c popad 0x0000002d jg 00007FA9AEA5D933h 0x00000033 push eax 0x00000034 push edx 0x00000035 push eax 0x00000036 push edx 0x00000037 jmp 00007FA93D08FA20h 0x0000003c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F90589 second address: 4F90598 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D5Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F90598 second address: 4F90674 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93D08FA29h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 js 00007FA93D08FAB4h 0x0000000f pushad 0x00000010 pushfd 0x00000011 jmp 00007FA93D08FA1Ch 0x00000016 and esi, 4477E548h 0x0000001c jmp 00007FA93D08FA1Bh 0x00000021 popfd 0x00000022 mov edi, ecx 0x00000024 popad 0x00000025 cmp dword ptr [ebp-14h], edi 0x00000028 pushad 0x00000029 mov cx, 8CB7h 0x0000002d call 00007FA93D08FA1Ch 0x00000032 jmp 00007FA93D08FA22h 0x00000037 pop esi 0x00000038 popad 0x00000039 jne 00007FA9AEA5D8ABh 0x0000003f pushad 0x00000040 call 00007FA93D08FA27h 0x00000045 pushfd 0x00000046 jmp 00007FA93D08FA28h 0x0000004b jmp 00007FA93D08FA25h 0x00000050 popfd 0x00000051 pop esi 0x00000052 mov di, 0D44h 0x00000056 popad 0x00000057 mov ebx, dword ptr [ebp+08h] 0x0000005a push eax 0x0000005b push edx 0x0000005c jmp 00007FA93D08FA26h 0x00000061 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F90674 second address: 4F90686 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA93CFE6D5Eh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F90686 second address: 4F906BC instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 lea eax, dword ptr [ebp-2Ch] 0x0000000b pushad 0x0000000c mov bl, 5Dh 0x0000000e push eax 0x0000000f push edx 0x00000010 pushfd 0x00000011 jmp 00007FA93D08FA24h 0x00000016 adc si, C388h 0x0000001b jmp 00007FA93D08FA1Bh 0x00000020 popfd 0x00000021 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F906BC second address: 4F906FB instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D68h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 popad 0x0000000a xchg eax, esi 0x0000000b jmp 00007FA93CFE6D60h 0x00000010 push eax 0x00000011 push eax 0x00000012 push edx 0x00000013 jmp 00007FA93CFE6D5Eh 0x00000018 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F906FB second address: 4F9070D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA93D08FA1Eh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F9070D second address: 4F90725 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D5Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b xchg eax, esi 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 pushad 0x00000011 popad 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F90725 second address: 4F90740 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93D08FA27h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F90740 second address: 4F90746 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F90746 second address: 4F9074A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F9074A second address: 4F907F1 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push esi 0x00000009 pushad 0x0000000a pushad 0x0000000b mov ecx, 7613577Fh 0x00000010 pushfd 0x00000011 jmp 00007FA93CFE6D64h 0x00000016 sbb ecx, 69EB0F68h 0x0000001c jmp 00007FA93CFE6D5Bh 0x00000021 popfd 0x00000022 popad 0x00000023 call 00007FA93CFE6D68h 0x00000028 mov si, C261h 0x0000002c pop esi 0x0000002d popad 0x0000002e mov dword ptr [esp], eax 0x00000031 pushad 0x00000032 mov cl, dl 0x00000034 mov cx, 2C5Bh 0x00000038 popad 0x00000039 xchg eax, ebx 0x0000003a jmp 00007FA93CFE6D5Eh 0x0000003f push eax 0x00000040 pushad 0x00000041 mov di, 9AD4h 0x00000045 pushfd 0x00000046 jmp 00007FA93CFE6D5Dh 0x0000004b xor eax, 115A2996h 0x00000051 jmp 00007FA93CFE6D61h 0x00000056 popfd 0x00000057 popad 0x00000058 xchg eax, ebx 0x00000059 push eax 0x0000005a push edx 0x0000005b pushad 0x0000005c mov ax, di 0x0000005f mov eax, edi 0x00000061 popad 0x00000062 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F90070 second address: 4F900CE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 movsx ebx, ax 0x00000008 popad 0x00000009 mov ebp, esp 0x0000000b jmp 00007FA93D08FA28h 0x00000010 xchg eax, ecx 0x00000011 pushad 0x00000012 pushfd 0x00000013 jmp 00007FA93D08FA1Eh 0x00000018 or si, BFB8h 0x0000001d jmp 00007FA93D08FA1Bh 0x00000022 popfd 0x00000023 mov eax, 7ECF6BEFh 0x00000028 popad 0x00000029 push eax 0x0000002a push eax 0x0000002b push edx 0x0000002c jmp 00007FA93D08FA20h 0x00000031 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F900CE second address: 4F900D4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F900D4 second address: 4F900D8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F90D6E second address: 4F90D8B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 mov eax, edi 0x00000006 popad 0x00000007 popad 0x00000008 add dword ptr [esp], 66F56FBBh 0x0000000f push eax 0x00000010 push edx 0x00000011 jmp 00007FA93CFE6D5Ch 0x00000016 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F90D8B second address: 4F90DAE instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov bh, DEh 0x00000005 mov cx, D349h 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c call 00007FA9AEA547F1h 0x00000011 push 76952B70h 0x00000016 push dword ptr fs:[00000000h] 0x0000001d mov eax, dword ptr [esp+10h] 0x00000021 mov dword ptr [esp+10h], ebp 0x00000025 lea ebp, dword ptr [esp+10h] 0x00000029 sub esp, eax 0x0000002b push ebx 0x0000002c push esi 0x0000002d push edi 0x0000002e mov eax, dword ptr [769B4538h] 0x00000033 xor dword ptr [ebp-04h], eax 0x00000036 xor eax, ebp 0x00000038 push eax 0x00000039 mov dword ptr [ebp-18h], esp 0x0000003c push dword ptr [ebp-08h] 0x0000003f mov eax, dword ptr [ebp-04h] 0x00000042 mov dword ptr [ebp-04h], FFFFFFFEh 0x00000049 mov dword ptr [ebp-08h], eax 0x0000004c lea eax, dword ptr [ebp-10h] 0x0000004f mov dword ptr fs:[00000000h], eax 0x00000055 ret 0x00000056 push eax 0x00000057 push edx 0x00000058 push eax 0x00000059 push edx 0x0000005a jmp 00007FA93D08FA1Eh 0x0000005f rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F90DAE second address: 4F90DBD instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D5Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4F90E18 second address: 4F90E82 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FA93D08FA1Fh 0x00000009 sbb eax, 2DAD79CEh 0x0000000f jmp 00007FA93D08FA29h 0x00000014 popfd 0x00000015 pushad 0x00000016 popad 0x00000017 popad 0x00000018 pop edx 0x00000019 pop eax 0x0000001a je 00007FA9AEA4354Bh 0x00000020 jmp 00007FA93D08FA1Ch 0x00000025 cmp dword ptr [ebp+08h], 00002000h 0x0000002c push eax 0x0000002d push edx 0x0000002e jmp 00007FA93D08FA27h 0x00000033 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0B7B second address: 4FA0BA3 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov esi, edi 0x00000005 mov dx, 0FF6h 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push ecx 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007FA93CFE6D69h 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0BA3 second address: 4FA0BF7 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov edx, 64159CE2h 0x00000008 pushfd 0x00000009 jmp 00007FA93D08FA23h 0x0000000e jmp 00007FA93D08FA23h 0x00000013 popfd 0x00000014 popad 0x00000015 pop edx 0x00000016 pop eax 0x00000017 mov dword ptr [esp], ebp 0x0000001a jmp 00007FA93D08FA26h 0x0000001f mov ebp, esp 0x00000021 push eax 0x00000022 push edx 0x00000023 push eax 0x00000024 push edx 0x00000025 pushad 0x00000026 popad 0x00000027 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0BF7 second address: 4FA0BFD instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0BFD second address: 4FA0C0C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA93D08FA1Bh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0C0C second address: 4FA0C73 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93CFE6D69h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b xchg eax, esi 0x0000000c pushad 0x0000000d pushfd 0x0000000e jmp 00007FA93CFE6D5Ch 0x00000013 sub ax, 5298h 0x00000018 jmp 00007FA93CFE6D5Bh 0x0000001d popfd 0x0000001e movzx esi, dx 0x00000021 popad 0x00000022 push eax 0x00000023 pushad 0x00000024 push eax 0x00000025 push edx 0x00000026 pushfd 0x00000027 jmp 00007FA93CFE6D5Eh 0x0000002c adc ax, FCF8h 0x00000031 jmp 00007FA93CFE6D5Bh 0x00000036 popfd 0x00000037 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0C73 second address: 4FA0C9A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 mov esi, edx 0x00000007 mov bx, CAD4h 0x0000000b popad 0x0000000c popad 0x0000000d xchg eax, esi 0x0000000e push eax 0x0000000f push edx 0x00000010 push eax 0x00000011 push edx 0x00000012 jmp 00007FA93D08FA25h 0x00000017 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0C9A second address: 4FA0CA0 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0CA0 second address: 4FA0CB7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA93D08FA23h 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0CB7 second address: 4FA0CBB instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0CBB second address: 4FA0D0C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov esi, dword ptr [ebp+0Ch] 0x0000000b jmp 00007FA93D08FA25h 0x00000010 test esi, esi 0x00000012 pushad 0x00000013 pushfd 0x00000014 jmp 00007FA93D08FA1Ch 0x00000019 sbb eax, 457BBB48h 0x0000001f jmp 00007FA93D08FA1Bh 0x00000024 popfd 0x00000025 popad 0x00000026 je 00007FA9AEA3D0CFh 0x0000002c push eax 0x0000002d push edx 0x0000002e pushad 0x0000002f push esi 0x00000030 pop ebx 0x00000031 mov ah, 89h 0x00000033 popad 0x00000034 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0D0C second address: 4FA0D35 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 call 00007FA93CFE6D62h 0x00000008 pop eax 0x00000009 mov ax, di 0x0000000c popad 0x0000000d pop edx 0x0000000e pop eax 0x0000000f cmp dword ptr [769B459Ch], 05h 0x00000016 push eax 0x00000017 push edx 0x00000018 push eax 0x00000019 push edx 0x0000001a pushad 0x0000001b popad 0x0000001c rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0D35 second address: 4FA0D4B instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FA93D08FA22h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0D4B second address: 4FA0D51 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0D51 second address: 4FA0DDF instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 je 00007FA9AEA55154h 0x0000000e jmp 00007FA93D08FA29h 0x00000013 xchg eax, esi 0x00000014 pushad 0x00000015 mov dx, ax 0x00000018 mov ch, 3Fh 0x0000001a popad 0x0000001b push eax 0x0000001c push eax 0x0000001d push edx 0x0000001e pushad 0x0000001f pushfd 0x00000020 jmp 00007FA93D08FA27h 0x00000025 and cx, 130Eh 0x0000002a jmp 00007FA93D08FA29h 0x0000002f popfd 0x00000030 pushfd 0x00000031 jmp 00007FA93D08FA20h 0x00000036 xor ecx, 44369988h 0x0000003c jmp 00007FA93D08FA1Bh 0x00000041 popfd 0x00000042 popad 0x00000043 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0E20 second address: 4FA0E24 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0E24 second address: 4FA0E28 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0E28 second address: 4FA0E2E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0E2E second address: 4FA0E3D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA93D08FA1Bh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0E3D second address: 4FA0E41 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0E41 second address: 4FA0E6D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 jmp 00007FA93D08FA24h 0x0000000e xchg eax, esi 0x0000000f push eax 0x00000010 push edx 0x00000011 push eax 0x00000012 push edx 0x00000013 jmp 00007FA93D08FA1Ah 0x00000018 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0E6D second address: 4FA0E71 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0E71 second address: 4FA0E77 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\file.exe |
RDTSC instruction interceptor: First address: 4FA0E77 second address: 4FA0E88 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FA93CFE6D5Dh 0x00000009 rdtsc |