Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AD4B84 second address: AD4BA5 instructions: 0x00000000 rdtsc 0x00000002 je 00007FF3D0D81736h 0x00000008 jmp 00007FF3D0D81742h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f pushad 0x00000010 pushad 0x00000011 popad 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AD3BCE second address: AD3BD7 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push edi 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AD3BD7 second address: AD3BDC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AD7CFB second address: AD7D25 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jbe 00007FF3D0F68BBAh 0x0000000b jmp 00007FF3D0F68BB4h 0x00000010 popad 0x00000011 push eax 0x00000012 jl 00007FF3D0F68BAEh 0x00000018 push ecx 0x00000019 push eax 0x0000001a push edx 0x0000001b rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AD7D25 second address: AD7D33 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 mov eax, dword ptr [esp+04h] 0x00000009 pushad 0x0000000a push eax 0x0000000b push edx 0x0000000c pushad 0x0000000d popad 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AD7D33 second address: AD7D58 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0F68BACh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 jns 00007FF3D0F68BACh 0x0000000f popad 0x00000010 mov eax, dword ptr [eax] 0x00000012 push eax 0x00000013 push edx 0x00000014 push edx 0x00000015 push esi 0x00000016 pop esi 0x00000017 pop edx 0x00000018 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AD7F30 second address: AD7F34 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AD7F34 second address: AD7F38 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AD7F38 second address: AD7F3E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AD7F3E second address: AD7F7D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push edx 0x00000004 pop edx 0x00000005 push esi 0x00000006 pop esi 0x00000007 popad 0x00000008 pop edx 0x00000009 pop eax 0x0000000a mov eax, dword ptr [eax] 0x0000000c jmp 00007FF3D0F68BAEh 0x00000011 mov dword ptr [esp+04h], eax 0x00000015 jmp 00007FF3D0F68BAAh 0x0000001a pop eax 0x0000001b mov dword ptr [ebp+122D26F7h], ecx 0x00000021 lea ebx, dword ptr [ebp+12452C35h] 0x00000027 push eax 0x00000028 push esi 0x00000029 push eax 0x0000002a push edx 0x0000002b ja 00007FF3D0F68BA6h 0x00000031 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AD806F second address: AD8092 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop eax 0x00000007 add dword ptr [esp], 4BBAB99Ah 0x0000000e add edi, dword ptr [ebp+122D377Fh] 0x00000014 lea ebx, dword ptr [ebp+12452C3Eh] 0x0000001a and dh, FFFFFFF9h 0x0000001d push eax 0x0000001e pushad 0x0000001f push eax 0x00000020 push edx 0x00000021 pushad 0x00000022 popad 0x00000023 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AD8155 second address: AD8164 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FF3D0F68BAAh 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AD8164 second address: AD81D3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edx 0x00000006 pop eax 0x00000007 add dword ptr [esp], 44CCE901h 0x0000000e ja 00007FF3D0D81742h 0x00000014 jmp 00007FF3D0D8173Ch 0x00000019 push 00000003h 0x0000001b movzx ecx, bx 0x0000001e push 00000000h 0x00000020 mov dword ptr [ebp+122D1809h], ecx 0x00000026 push 00000003h 0x00000028 js 00007FF3D0D81738h 0x0000002e mov edi, ebx 0x00000030 push 6C2A7D8Ch 0x00000035 jmp 00007FF3D0D81740h 0x0000003a add dword ptr [esp], 53D58274h 0x00000041 adc ch, 0000007Ch 0x00000044 lea ebx, dword ptr [ebp+12452C49h] 0x0000004a pushad 0x0000004b mov ecx, dword ptr [ebp+122D38EFh] 0x00000051 or dword ptr [ebp+122D26F7h], edx 0x00000057 popad 0x00000058 push eax 0x00000059 pushad 0x0000005a push edx 0x0000005b push eax 0x0000005c push edx 0x0000005d rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AE8CCE second address: AE8CDF instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FF3D0F68BADh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AE8CDF second address: AE8CE3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AE8CE3 second address: AE8CF0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edi 0x0000000a pushad 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: ACE19B second address: ACE1B1 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 jng 00007FF3D0D81736h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edx 0x0000000e pushad 0x0000000f popad 0x00000010 js 00007FF3D0D81736h 0x00000016 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: ACE1B1 second address: ACE1BD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edi 0x00000007 push esi 0x00000008 push eax 0x00000009 push edx 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: ACE1BD second address: ACE1D1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FF3D0D81740h 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AF4FC0 second address: AF4FC4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AF4FC4 second address: AF4FCA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AF5417 second address: AF542F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FF3D0F68BB3h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AF542F second address: AF544F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FF3D0D81745h 0x00000009 push eax 0x0000000a pop eax 0x0000000b popad 0x0000000c push eax 0x0000000d push edx 0x0000000e push edi 0x0000000f pop edi 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AF5579 second address: AF557D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AF57E1 second address: AF57E5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AF57E5 second address: AF57EB instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AF57EB second address: AF580B instructions: 0x00000000 rdtsc 0x00000002 jno 00007FF3D0D81738h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push edi 0x0000000b pushad 0x0000000c jmp 00007FF3D0D81740h 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AF5D60 second address: AF5D78 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0F68BACh 0x00000007 pushad 0x00000008 popad 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c push edx 0x0000000d pushad 0x0000000e popad 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AF5D78 second address: AF5D7C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AF5D7C second address: AF5D80 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AF5D80 second address: AF5DA0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jng 00007FF3D0D81736h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push ecx 0x0000000d push eax 0x0000000e push edx 0x0000000f push ecx 0x00000010 pop ecx 0x00000011 jmp 00007FF3D0D8173Fh 0x00000016 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AF5EFF second address: AF5F03 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AF60A3 second address: AF60BB instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0D81744h 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AF60BB second address: AF60C9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push edx 0x00000007 jnl 00007FF3D0F68BA6h 0x0000000d pop edx 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AEB420 second address: AEB448 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0D81743h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 jmp 00007FF3D0D8173Bh 0x0000000e popad 0x0000000f push eax 0x00000010 push edx 0x00000011 pushad 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AEB448 second address: AEB453 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnp 00007FF3D0F68BA6h 0x0000000a popad 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AF6225 second address: AF622A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AF622A second address: AF6230 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AF924D second address: AF9251 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AFB23B second address: AFB242 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ebx 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AFB6B0 second address: AFB6B5 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AFA756 second address: AFA75A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AFA75A second address: AFA760 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AFA760 second address: AFA766 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B03452 second address: B0345C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jc 00007FF3D0D81736h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B0345C second address: B0348F instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0F68BB8h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push ecx 0x0000000a jmp 00007FF3D0F68BB5h 0x0000000f pop ecx 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B0348F second address: B03494 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B028A0 second address: B028B9 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0F68BB3h 0x00000007 push esi 0x00000008 pop esi 0x00000009 pop edx 0x0000000a pop eax 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B028B9 second address: B028DE instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FF3D0D81747h 0x00000009 jmp 00007FF3D0D8173Ah 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B028DE second address: B028E2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B03C12 second address: B03C16 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B04361 second address: B04366 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B04366 second address: B0436B instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B04A74 second address: B04A9B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jmp 00007FF3D0F68BB5h 0x0000000a popad 0x0000000b push eax 0x0000000c pushad 0x0000000d pushad 0x0000000e pushad 0x0000000f popad 0x00000010 push edi 0x00000011 pop edi 0x00000012 popad 0x00000013 push eax 0x00000014 push edx 0x00000015 push edi 0x00000016 pop edi 0x00000017 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B04BEC second address: B04BF8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 jg 00007FF3D0D81736h 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B04BF8 second address: B04C0B instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 push eax 0x00000009 push edx 0x0000000a pushad 0x0000000b jg 00007FF3D0F68BA6h 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B04C0B second address: B04C10 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B04DDA second address: B04DE4 instructions: 0x00000000 rdtsc 0x00000002 jne 00007FF3D0F68BA6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B04DE4 second address: B04DEA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push esi 0x00000005 pop esi 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B05CBD second address: B05D7D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jng 00007FF3D0F68BA8h 0x0000000a pushad 0x0000000b popad 0x0000000c popad 0x0000000d push eax 0x0000000e jmp 00007FF3D0F68BB9h 0x00000013 nop 0x00000014 jmp 00007FF3D0F68BB1h 0x00000019 push 00000000h 0x0000001b push 00000000h 0x0000001d push edi 0x0000001e call 00007FF3D0F68BA8h 0x00000023 pop edi 0x00000024 mov dword ptr [esp+04h], edi 0x00000028 add dword ptr [esp+04h], 0000001Dh 0x00000030 inc edi 0x00000031 push edi 0x00000032 ret 0x00000033 pop edi 0x00000034 ret 0x00000035 call 00007FF3D0F68BB9h 0x0000003a movzx esi, cx 0x0000003d pop edi 0x0000003e push 00000000h 0x00000040 push 00000000h 0x00000042 push ecx 0x00000043 call 00007FF3D0F68BA8h 0x00000048 pop ecx 0x00000049 mov dword ptr [esp+04h], ecx 0x0000004d add dword ptr [esp+04h], 0000001Dh 0x00000055 inc ecx 0x00000056 push ecx 0x00000057 ret 0x00000058 pop ecx 0x00000059 ret 0x0000005a xchg eax, ebx 0x0000005b push edx 0x0000005c push eax 0x0000005d push edx 0x0000005e jmp 00007FF3D0F68BB8h 0x00000063 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B06CAD second address: B06CB1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B06CB1 second address: B06CB5 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B088EB second address: B088F7 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pushad 0x00000009 push edi 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B09A5F second address: B09A69 instructions: 0x00000000 rdtsc 0x00000002 ja 00007FF3D0F68BACh 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B0A53F second address: B0A543 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B0A543 second address: B0A558 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0F68BB1h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B0A558 second address: B0A562 instructions: 0x00000000 rdtsc 0x00000002 jbe 00007FF3D0D8173Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B0A562 second address: B0A57F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push eax 0x00000008 push eax 0x00000009 push edx 0x0000000a jmp 00007FF3D0F68BB3h 0x0000000f rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B0B111 second address: B0B11B instructions: 0x00000000 rdtsc 0x00000002 jp 00007FF3D0D8173Ch 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B0AED6 second address: B0AEDC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: ACC5A5 second address: ACC5AF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 ja 00007FF3D0D81736h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: ACC5AF second address: ACC5C1 instructions: 0x00000000 rdtsc 0x00000002 jng 00007FF3D0F68BA6h 0x00000008 pushad 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edx 0x0000000e push ecx 0x0000000f pop ecx 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: ACC5C1 second address: ACC5C5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: ACC5C5 second address: ACC5C9 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B0DB29 second address: B0DB2D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: ACC5C9 second address: ACC5E3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 pushad 0x00000009 popad 0x0000000a jmp 00007FF3D0F68BB0h 0x0000000f rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B0DB2D second address: B0DB31 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B1480B second address: B14815 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jg 00007FF3D0F68BA6h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B12B3D second address: B12B4D instructions: 0x00000000 rdtsc 0x00000002 jns 00007FF3D0D81736h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push ebx 0x0000000c push eax 0x0000000d push edx 0x0000000e pushad 0x0000000f popad 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B14DBB second address: B14DC5 instructions: 0x00000000 rdtsc 0x00000002 jno 00007FF3D0F68BA6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B12B4D second address: B12BED instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0D81741h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop ebx 0x0000000a nop 0x0000000b movsx edi, bx 0x0000000e push dword ptr fs:[00000000h] 0x00000015 push 00000000h 0x00000017 push ebx 0x00000018 call 00007FF3D0D81738h 0x0000001d pop ebx 0x0000001e mov dword ptr [esp+04h], ebx 0x00000022 add dword ptr [esp+04h], 0000001Dh 0x0000002a inc ebx 0x0000002b push ebx 0x0000002c ret 0x0000002d pop ebx 0x0000002e ret 0x0000002f mov ebx, dword ptr [ebp+122D35E3h] 0x00000035 mov dword ptr fs:[00000000h], esp 0x0000003c sub ebx, dword ptr [ebp+122D3587h] 0x00000042 mov eax, dword ptr [ebp+122D0E59h] 0x00000048 jmp 00007FF3D0D8173Bh 0x0000004d push FFFFFFFFh 0x0000004f push 00000000h 0x00000051 push ebx 0x00000052 call 00007FF3D0D81738h 0x00000057 pop ebx 0x00000058 mov dword ptr [esp+04h], ebx 0x0000005c add dword ptr [esp+04h], 00000017h 0x00000064 inc ebx 0x00000065 push ebx 0x00000066 ret 0x00000067 pop ebx 0x00000068 ret 0x00000069 mov dword ptr [ebp+124537E6h], ecx 0x0000006f push eax 0x00000070 jp 00007FF3D0D81744h 0x00000076 push eax 0x00000077 push edx 0x00000078 jg 00007FF3D0D81736h 0x0000007e rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B14F80 second address: B14F86 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B14F86 second address: B14FA7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edi 0x00000006 push eax 0x00000007 push eax 0x00000008 push edx 0x00000009 jmp 00007FF3D0D81748h 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B17E62 second address: B17EDB instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0F68BAEh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop esi 0x0000000a nop 0x0000000b push 00000000h 0x0000000d push ebx 0x0000000e call 00007FF3D0F68BA8h 0x00000013 pop ebx 0x00000014 mov dword ptr [esp+04h], ebx 0x00000018 add dword ptr [esp+04h], 0000001Bh 0x00000020 inc ebx 0x00000021 push ebx 0x00000022 ret 0x00000023 pop ebx 0x00000024 ret 0x00000025 pushad 0x00000026 or dword ptr [ebp+122D18ECh], esi 0x0000002c or cx, AF14h 0x00000031 popad 0x00000032 push 00000000h 0x00000034 mov edi, dword ptr [ebp+122D376Fh] 0x0000003a push 00000000h 0x0000003c push 00000000h 0x0000003e push ebx 0x0000003f call 00007FF3D0F68BA8h 0x00000044 pop ebx 0x00000045 mov dword ptr [esp+04h], ebx 0x00000049 add dword ptr [esp+04h], 00000017h 0x00000051 inc ebx 0x00000052 push ebx 0x00000053 ret 0x00000054 pop ebx 0x00000055 ret 0x00000056 mov dword ptr [ebp+122D1C68h], esi 0x0000005c push eax 0x0000005d pushad 0x0000005e push eax 0x0000005f push edx 0x00000060 push eax 0x00000061 push edx 0x00000062 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B17EDB second address: B17EDF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B18E57 second address: B18E5B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B18E5B second address: B18E5F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B18055 second address: B1807C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 pop eax 0x00000006 popad 0x00000007 jmp 00007FF3D0F68BB6h 0x0000000c popad 0x0000000d push eax 0x0000000e push eax 0x0000000f push edx 0x00000010 pushad 0x00000011 pushad 0x00000012 popad 0x00000013 pushad 0x00000014 popad 0x00000015 popad 0x00000016 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B18E5F second address: B18EE5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 push eax 0x00000009 jmp 00007FF3D0D81747h 0x0000000e pop eax 0x0000000f nop 0x00000010 push 00000000h 0x00000012 push eax 0x00000013 call 00007FF3D0D81738h 0x00000018 pop eax 0x00000019 mov dword ptr [esp+04h], eax 0x0000001d add dword ptr [esp+04h], 0000001Dh 0x00000025 inc eax 0x00000026 push eax 0x00000027 ret 0x00000028 pop eax 0x00000029 ret 0x0000002a cld 0x0000002b push 00000000h 0x0000002d mov ebx, edi 0x0000002f push 00000000h 0x00000031 push 00000000h 0x00000033 push ecx 0x00000034 call 00007FF3D0D81738h 0x00000039 pop ecx 0x0000003a mov dword ptr [esp+04h], ecx 0x0000003e add dword ptr [esp+04h], 0000001Bh 0x00000046 inc ecx 0x00000047 push ecx 0x00000048 ret 0x00000049 pop ecx 0x0000004a ret 0x0000004b push ebx 0x0000004c add edi, dword ptr [ebp+122D38F7h] 0x00000052 pop edi 0x00000053 and edi, 1A69D771h 0x00000059 push eax 0x0000005a push eax 0x0000005b push edx 0x0000005c push ebx 0x0000005d pushad 0x0000005e popad 0x0000005f pop ebx 0x00000060 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B1814D second address: B18157 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jc 00007FF3D0F68BA6h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B18157 second address: B1815B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B19D7E second address: B19D93 instructions: 0x00000000 rdtsc 0x00000002 jc 00007FF3D0F68BACh 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b pushad 0x0000000c pushad 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B19FCD second address: B1A07C instructions: 0x00000000 rdtsc 0x00000002 jc 00007FF3D0D8173Ch 0x00000008 jnl 00007FF3D0D81736h 0x0000000e pop edx 0x0000000f pop eax 0x00000010 mov dword ptr [esp], eax 0x00000013 mov ebx, dword ptr [ebp+122D370Fh] 0x00000019 jng 00007FF3D0D8173Ch 0x0000001f mov dword ptr [ebp+1247E12Dh], eax 0x00000025 push dword ptr fs:[00000000h] 0x0000002c call 00007FF3D0D81745h 0x00000031 push esi 0x00000032 sbb di, C95Ah 0x00000037 pop edi 0x00000038 pop edi 0x00000039 mov dword ptr fs:[00000000h], esp 0x00000040 push 00000000h 0x00000042 push edx 0x00000043 call 00007FF3D0D81738h 0x00000048 pop edx 0x00000049 mov dword ptr [esp+04h], edx 0x0000004d add dword ptr [esp+04h], 00000019h 0x00000055 inc edx 0x00000056 push edx 0x00000057 ret 0x00000058 pop edx 0x00000059 ret 0x0000005a jc 00007FF3D0D81752h 0x00000060 call 00007FF3D0D81745h 0x00000065 mov dword ptr [ebp+1245335Eh], ecx 0x0000006b pop ebx 0x0000006c mov dword ptr [ebp+122D2FD0h], ecx 0x00000072 mov eax, dword ptr [ebp+122D1765h] 0x00000078 movsx edi, si 0x0000007b push FFFFFFFFh 0x0000007d mov edi, dword ptr [ebp+1247174Bh] 0x00000083 nop 0x00000084 pushad 0x00000085 pushad 0x00000086 push eax 0x00000087 push edx 0x00000088 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B204BE second address: B204C6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 pushad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B204C6 second address: B204D9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edi 0x00000005 pop edi 0x00000006 popad 0x00000007 popad 0x00000008 push eax 0x00000009 push eax 0x0000000a push edx 0x0000000b jnp 00007FF3D0D81738h 0x00000011 push esi 0x00000012 pop esi 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B204D9 second address: B204DF instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B204DF second address: B204E3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B204E3 second address: B20545 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 nop 0x00000009 push 00000000h 0x0000000b push edi 0x0000000c call 00007FF3D0F68BA8h 0x00000011 pop edi 0x00000012 mov dword ptr [esp+04h], edi 0x00000016 add dword ptr [esp+04h], 00000018h 0x0000001e inc edi 0x0000001f push edi 0x00000020 ret 0x00000021 pop edi 0x00000022 ret 0x00000023 mov dword ptr [ebp+12477BCCh], edi 0x00000029 push 00000000h 0x0000002b push 00000000h 0x0000002d push ecx 0x0000002e call 00007FF3D0F68BA8h 0x00000033 pop ecx 0x00000034 mov dword ptr [esp+04h], ecx 0x00000038 add dword ptr [esp+04h], 00000014h 0x00000040 inc ecx 0x00000041 push ecx 0x00000042 ret 0x00000043 pop ecx 0x00000044 ret 0x00000045 mov bh, 68h 0x00000047 push 00000000h 0x00000049 mov edi, dword ptr [ebp+122D1C68h] 0x0000004f push eax 0x00000050 push eax 0x00000051 push edx 0x00000052 push ecx 0x00000053 jns 00007FF3D0F68BA6h 0x00000059 pop ecx 0x0000005a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B1F6E7 second address: B1F6EB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B1E589 second address: B1E58F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B1F6EB second address: B1F70A instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop eax 0x00000007 push eax 0x00000008 pushad 0x00000009 push eax 0x0000000a push edx 0x0000000b jmp 00007FF3D0D81744h 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B23929 second address: B2392F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B2392F second address: B23936 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B2079F second address: B207B7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FF3D0F68BB4h 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B24F34 second address: B24F39 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B24F39 second address: B24F3F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B24F3F second address: B24F57 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edx 0x00000006 pop eax 0x00000007 push eax 0x00000008 push eax 0x00000009 push edx 0x0000000a push edx 0x0000000b jmp 00007FF3D0D8173Ch 0x00000010 pop edx 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B24F57 second address: B24FA9 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 jmp 00007FF3D0F68BAEh 0x00000008 pop ebx 0x00000009 pop edx 0x0000000a pop eax 0x0000000b nop 0x0000000c mov dword ptr [ebp+122D1CA1h], esi 0x00000012 push 00000000h 0x00000014 mov dword ptr [ebp+122D287Fh], edx 0x0000001a push 00000000h 0x0000001c push 00000000h 0x0000001e push edi 0x0000001f call 00007FF3D0F68BA8h 0x00000024 pop edi 0x00000025 mov dword ptr [esp+04h], edi 0x00000029 add dword ptr [esp+04h], 0000001Ch 0x00000031 inc edi 0x00000032 push edi 0x00000033 ret 0x00000034 pop edi 0x00000035 ret 0x00000036 sbb bh, FFFFFFA4h 0x00000039 push eax 0x0000003a pushad 0x0000003b push eax 0x0000003c push edx 0x0000003d push eax 0x0000003e push edx 0x0000003f rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B24FA9 second address: B24FAD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B25EEB second address: B25F58 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop eax 0x00000006 mov dword ptr [esp], eax 0x00000009 mov ebx, dword ptr [ebp+122D21E1h] 0x0000000f push 00000000h 0x00000011 push 00000000h 0x00000013 push ecx 0x00000014 call 00007FF3D0F68BA8h 0x00000019 pop ecx 0x0000001a mov dword ptr [esp+04h], ecx 0x0000001e add dword ptr [esp+04h], 00000018h 0x00000026 inc ecx 0x00000027 push ecx 0x00000028 ret 0x00000029 pop ecx 0x0000002a ret 0x0000002b mov edi, dword ptr [ebp+122D1D2Dh] 0x00000031 push 00000000h 0x00000033 push 00000000h 0x00000035 push esi 0x00000036 call 00007FF3D0F68BA8h 0x0000003b pop esi 0x0000003c mov dword ptr [esp+04h], esi 0x00000040 add dword ptr [esp+04h], 00000015h 0x00000048 inc esi 0x00000049 push esi 0x0000004a ret 0x0000004b pop esi 0x0000004c ret 0x0000004d mov ebx, dword ptr [ebp+12451F30h] 0x00000053 xchg eax, esi 0x00000054 jmp 00007FF3D0F68BABh 0x00000059 push eax 0x0000005a push edx 0x0000005b push ecx 0x0000005c push eax 0x0000005d push edx 0x0000005e rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B28E4F second address: B28E84 instructions: 0x00000000 rdtsc 0x00000002 jns 00007FF3D0D81742h 0x00000008 jmp 00007FF3D0D81741h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f je 00007FF3D0D81755h 0x00000015 push eax 0x00000016 push edx 0x00000017 jno 00007FF3D0D81736h 0x0000001d rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B2BCCE second address: B2BCD4 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B30524 second address: B3052A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B3052A second address: B3052E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B34C42 second address: B34C48 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B34C48 second address: B34C85 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 jmp 00007FF3D0F68BB3h 0x0000000b mov eax, dword ptr [esp+04h] 0x0000000f jc 00007FF3D0F68BBAh 0x00000015 mov eax, dword ptr [eax] 0x00000017 pushad 0x00000018 pushad 0x00000019 push eax 0x0000001a push edx 0x0000001b rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B34F20 second address: B34F38 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0D81744h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B3B336 second address: B3B33C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B3B33C second address: B3B348 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 popad 0x00000006 push eax 0x00000007 push edx 0x00000008 push eax 0x00000009 push edx 0x0000000a push esi 0x0000000b pop esi 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B3B348 second address: B3B366 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0F68BB4h 0x00000007 jns 00007FF3D0F68BA6h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B3B366 second address: B3B36E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 pushad 0x00000007 popad 0x00000008 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B3B36E second address: B3B380 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0F68BAEh 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B3A0C3 second address: B3A0CD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edi 0x00000005 pop edi 0x00000006 popad 0x00000007 pushad 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B3A0CD second address: B3A0D3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B3A800 second address: B3A804 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B3A804 second address: B3A82C instructions: 0x00000000 rdtsc 0x00000002 jns 00007FF3D0F68BA6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a jmp 00007FF3D0F68BB8h 0x0000000f push eax 0x00000010 push edx 0x00000011 push ebx 0x00000012 pop ebx 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B3A82C second address: B3A830 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B3FE35 second address: B3FE39 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B3FE39 second address: B3FE49 instructions: 0x00000000 rdtsc 0x00000002 ja 00007FF3D0D81736h 0x00000008 jc 00007FF3D0D81736h 0x0000000e pop edx 0x0000000f pop eax 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B3FE49 second address: B3FE5F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FF3D0F68BB1h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B3FE5F second address: B3FE6B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnc 00007FF3D0D81736h 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B3FE6B second address: B3FE92 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edx 0x00000006 pop eax 0x00000007 push eax 0x00000008 push edx 0x00000009 jp 00007FF3D0F68BBEh 0x0000000f jmp 00007FF3D0F68BB2h 0x00000014 jnp 00007FF3D0F68BA6h 0x0000001a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B3FE92 second address: B3FE9D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 je 00007FF3D0D81736h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B403EB second address: B40411 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 jmp 00007FF3D0F68BB0h 0x0000000a pushad 0x0000000b popad 0x0000000c jng 00007FF3D0F68BA6h 0x00000012 pushad 0x00000013 popad 0x00000014 popad 0x00000015 push eax 0x00000016 push edx 0x00000017 push eax 0x00000018 pop eax 0x00000019 push eax 0x0000001a push edx 0x0000001b rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B40411 second address: B40415 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B40807 second address: B40811 instructions: 0x00000000 rdtsc 0x00000002 jo 00007FF3D0F68BACh 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B409A0 second address: B409A6 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B409A6 second address: B409B4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 jbe 00007FF3D0F68BA6h 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B40B9A second address: B40BB0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 jne 00007FF3D0D81736h 0x0000000c je 00007FF3D0D81736h 0x00000012 pushad 0x00000013 popad 0x00000014 push eax 0x00000015 push edx 0x00000016 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B40EA6 second address: B40EB0 instructions: 0x00000000 rdtsc 0x00000002 js 00007FF3D0F68BACh 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B0F8E4 second address: AEB420 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0D81741h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov dword ptr [esp], eax 0x0000000c mov di, cx 0x0000000f lea eax, dword ptr [ebp+1248A63Dh] 0x00000015 push 00000000h 0x00000017 push ebx 0x00000018 call 00007FF3D0D81738h 0x0000001d pop ebx 0x0000001e mov dword ptr [esp+04h], ebx 0x00000022 add dword ptr [esp+04h], 00000014h 0x0000002a inc ebx 0x0000002b push ebx 0x0000002c ret 0x0000002d pop ebx 0x0000002e ret 0x0000002f add edx, dword ptr [ebp+122D360Bh] 0x00000035 nop 0x00000036 jmp 00007FF3D0D81740h 0x0000003b push eax 0x0000003c pushad 0x0000003d jmp 00007FF3D0D8173Fh 0x00000042 pushad 0x00000043 jmp 00007FF3D0D8173Bh 0x00000048 js 00007FF3D0D81736h 0x0000004e popad 0x0000004f popad 0x00000050 nop 0x00000051 pushad 0x00000052 mov dword ptr [ebp+122D358Ch], edx 0x00000058 mov ax, bx 0x0000005b popad 0x0000005c call dword ptr [ebp+122D25A8h] 0x00000062 pushad 0x00000063 push edx 0x00000064 pushad 0x00000065 popad 0x00000066 pop edx 0x00000067 push eax 0x00000068 push edx 0x00000069 jmp 00007FF3D0D8173Eh 0x0000006e rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B0FF16 second address: B0FF38 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop ebx 0x00000006 push eax 0x00000007 jmp 00007FF3D0F68BB2h 0x0000000c mov eax, dword ptr [esp+04h] 0x00000010 push ebx 0x00000011 push eax 0x00000012 push edx 0x00000013 pushad 0x00000014 popad 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B0FF38 second address: B0FF59 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop ebx 0x00000007 mov eax, dword ptr [eax] 0x00000009 push eax 0x0000000a push edx 0x0000000b jmp 00007FF3D0D81746h 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B0FF59 second address: B0FF5F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B10778 second address: B1077C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B1077C second address: B10782 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B10782 second address: B107A5 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0D81744h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push eax 0x0000000b push edx 0x0000000c push ebx 0x0000000d jng 00007FF3D0D81736h 0x00000013 pop ebx 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B108D6 second address: B108DC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B108DC second address: B108E1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B10B55 second address: B10B9D instructions: 0x00000000 rdtsc 0x00000002 jnp 00007FF3D0F68BA6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a jmp 00007FF3D0F68BAAh 0x0000000f popad 0x00000010 mov dword ptr [esp], eax 0x00000013 push 00000000h 0x00000015 push eax 0x00000016 call 00007FF3D0F68BA8h 0x0000001b pop eax 0x0000001c mov dword ptr [esp+04h], eax 0x00000020 add dword ptr [esp+04h], 00000017h 0x00000028 inc eax 0x00000029 push eax 0x0000002a ret 0x0000002b pop eax 0x0000002c ret 0x0000002d mov dx, si 0x00000030 lea eax, dword ptr [ebp+1248A681h] 0x00000036 clc 0x00000037 nop 0x00000038 push eax 0x00000039 push edx 0x0000003a push eax 0x0000003b push edx 0x0000003c pushad 0x0000003d popad 0x0000003e rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B10B9D second address: B10BAD instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0D8173Ch 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B10BAD second address: B10BFD instructions: 0x00000000 rdtsc 0x00000002 jne 00007FF3D0F68BA8h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b jp 00007FF3D0F68BB2h 0x00000011 js 00007FF3D0F68BACh 0x00000017 jns 00007FF3D0F68BA6h 0x0000001d nop 0x0000001e cld 0x0000001f lea eax, dword ptr [ebp+1248A63Dh] 0x00000025 push 00000000h 0x00000027 push edx 0x00000028 call 00007FF3D0F68BA8h 0x0000002d pop edx 0x0000002e mov dword ptr [esp+04h], edx 0x00000032 add dword ptr [esp+04h], 00000016h 0x0000003a inc edx 0x0000003b push edx 0x0000003c ret 0x0000003d pop edx 0x0000003e ret 0x0000003f nop 0x00000040 push eax 0x00000041 push edx 0x00000042 push ecx 0x00000043 jg 00007FF3D0F68BA6h 0x00000049 pop ecx 0x0000004a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B10BFD second address: B10C16 instructions: 0x00000000 rdtsc 0x00000002 jnc 00007FF3D0D81738h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push eax 0x0000000c push edx 0x0000000d pushad 0x0000000e pushad 0x0000000f popad 0x00000010 jl 00007FF3D0D81736h 0x00000016 popad 0x00000017 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B10C16 second address: B10C1C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B10C1C second address: AEBED1 instructions: 0x00000000 rdtsc 0x00000002 jnp 00007FF3D0D81736h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop edx 0x0000000b pop eax 0x0000000c nop 0x0000000d push 00000000h 0x0000000f push edx 0x00000010 call 00007FF3D0D81738h 0x00000015 pop edx 0x00000016 mov dword ptr [esp+04h], edx 0x0000001a add dword ptr [esp+04h], 00000017h 0x00000022 inc edx 0x00000023 push edx 0x00000024 ret 0x00000025 pop edx 0x00000026 ret 0x00000027 sub dword ptr [ebp+122D1F95h], ecx 0x0000002d mov dx, A74Ah 0x00000031 call dword ptr [ebp+122D1B42h] 0x00000037 push eax 0x00000038 push edx 0x00000039 push eax 0x0000003a push edx 0x0000003b jmp 00007FF3D0D81741h 0x00000040 pushad 0x00000041 popad 0x00000042 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AEBED1 second address: AEBEE5 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push esi 0x00000005 pop esi 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pushad 0x00000009 pushad 0x0000000a popad 0x0000000b jnp 00007FF3D0F68BA6h 0x00000011 push esi 0x00000012 pop esi 0x00000013 popad 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B448B1 second address: B448B7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B44A0C second address: B44A22 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 jmp 00007FF3D0F68BB0h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B44A22 second address: B44A27 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B44A27 second address: B44A52 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jg 00007FF3D0F68BA6h 0x0000000a pop eax 0x0000000b pop edx 0x0000000c pop eax 0x0000000d push eax 0x0000000e jmp 00007FF3D0F68BAAh 0x00000013 push eax 0x00000014 push edx 0x00000015 jmp 00007FF3D0F68BABh 0x0000001a js 00007FF3D0F68BA6h 0x00000020 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B44B64 second address: B44B68 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B44CC6 second address: B44CE7 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0F68BB9h 0x00000007 push eax 0x00000008 push edx 0x00000009 push ecx 0x0000000a pop ecx 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B44CE7 second address: B44CEB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B44E42 second address: B44E46 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B4A116 second address: B4A11C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B4A735 second address: B4A739 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B4A739 second address: B4A73F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B4A73F second address: B4A781 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 je 00007FF3D0F68BA6h 0x0000000d push ebx 0x0000000e pop ebx 0x0000000f jmp 00007FF3D0F68BB9h 0x00000014 jmp 00007FF3D0F68BB5h 0x00000019 popad 0x0000001a push eax 0x0000001b push edx 0x0000001c push eax 0x0000001d push edx 0x0000001e rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B4A781 second address: B4A785 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B4A785 second address: B4A789 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B4ABE9 second address: B4ABF3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 popad 0x00000006 pushad 0x00000007 push edx 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B4ABF3 second address: B4AC1D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 jmp 00007FF3D0F68BAAh 0x0000000a pushad 0x0000000b js 00007FF3D0F68BA6h 0x00000011 jmp 00007FF3D0F68BB2h 0x00000016 push eax 0x00000017 push edx 0x00000018 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B4AD45 second address: B4AD4B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B4AD4B second address: B4AD4F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B4AD4F second address: B4AD5B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 pushad 0x00000009 popad 0x0000000a pushad 0x0000000b popad 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B4B1CD second address: B4B1D2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B4FD95 second address: B4FDA0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 pushad 0x0000000a popad 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B5494C second address: B54963 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FF3D0F68BB2h 0x00000009 popad 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B54661 second address: B54673 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 pop eax 0x00000006 popad 0x00000007 pop ecx 0x00000008 je 00007FF3D0D81744h 0x0000000e push eax 0x0000000f push edx 0x00000010 pushad 0x00000011 popad 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B54673 second address: B54677 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B56F0B second address: B56F47 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FF3D0D81740h 0x00000008 push edi 0x00000009 pop edi 0x0000000a jo 00007FF3D0D81736h 0x00000010 popad 0x00000011 jng 00007FF3D0D8173Ah 0x00000017 push edx 0x00000018 pop edx 0x00000019 push ebx 0x0000001a pop ebx 0x0000001b pop edx 0x0000001c pop eax 0x0000001d push ecx 0x0000001e pushad 0x0000001f jmp 00007FF3D0D8173Eh 0x00000024 pushad 0x00000025 popad 0x00000026 push eax 0x00000027 push edx 0x00000028 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B5725A second address: B5727F instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a jmp 00007FF3D0F68BB9h 0x0000000f push ebx 0x00000010 pop ebx 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B5727F second address: B57283 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B573FA second address: B573FF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B5A777 second address: B5A78F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 push ebx 0x00000008 pop ebx 0x00000009 jmp 00007FF3D0D8173Fh 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B5A78F second address: B5A793 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B5A793 second address: B5A799 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B5AA6C second address: B5AA8F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 jmp 00007FF3D0F68BACh 0x00000009 pop edx 0x0000000a pop eax 0x0000000b pop edx 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 jmp 00007FF3D0F68BAAh 0x00000015 pushad 0x00000016 popad 0x00000017 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B5AA8F second address: B5AA93 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B5AA93 second address: B5AA99 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B5AD4A second address: B5AD65 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FF3D0D81747h 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AC7509 second address: AC7526 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0F68BB6h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pushad 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B5F01F second address: B5F023 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B5F2E7 second address: B5F2F6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FF3D0F68BABh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B5F2F6 second address: B5F309 instructions: 0x00000000 rdtsc 0x00000002 jo 00007FF3D0D8173Eh 0x00000008 jnc 00007FF3D0D81736h 0x0000000e pushad 0x0000000f popad 0x00000010 pushad 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B5F5D8 second address: B5F5DD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B10543 second address: B10547 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B10547 second address: B105D1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 nop 0x00000008 call 00007FF3D0F68BB8h 0x0000000d pushad 0x0000000e mov eax, 3D133BD3h 0x00000013 mov eax, esi 0x00000015 popad 0x00000016 pop edx 0x00000017 mov ebx, dword ptr [ebp+1248A67Ch] 0x0000001d push 00000000h 0x0000001f push ebp 0x00000020 call 00007FF3D0F68BA8h 0x00000025 pop ebp 0x00000026 mov dword ptr [esp+04h], ebp 0x0000002a add dword ptr [esp+04h], 0000001Ah 0x00000032 inc ebp 0x00000033 push ebp 0x00000034 ret 0x00000035 pop ebp 0x00000036 ret 0x00000037 mov dword ptr [ebp+122D2906h], ebx 0x0000003d mov dword ptr [ebp+122D2906h], esi 0x00000043 add eax, ebx 0x00000045 push 00000000h 0x00000047 push edi 0x00000048 call 00007FF3D0F68BA8h 0x0000004d pop edi 0x0000004e mov dword ptr [esp+04h], edi 0x00000052 add dword ptr [esp+04h], 00000015h 0x0000005a inc edi 0x0000005b push edi 0x0000005c ret 0x0000005d pop edi 0x0000005e ret 0x0000005f mov ch, 23h 0x00000061 nop 0x00000062 push eax 0x00000063 push edx 0x00000064 je 00007FF3D0F68BACh 0x0000006a push eax 0x0000006b push edx 0x0000006c rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B105D1 second address: B105D5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B105D5 second address: B10604 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 jmp 00007FF3D0F68BB3h 0x00000008 pop esi 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c push ecx 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007FF3D0F68BB2h 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B5F71C second address: B5F720 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B5F720 second address: B5F726 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B5F726 second address: B5F72D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B5F72D second address: B5F764 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FF3D0F68BB6h 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c pushad 0x0000000d pushad 0x0000000e jmp 00007FF3D0F68BAFh 0x00000013 push ebx 0x00000014 pop ebx 0x00000015 popad 0x00000016 push eax 0x00000017 push edx 0x00000018 pushad 0x00000019 popad 0x0000001a push edi 0x0000001b pop edi 0x0000001c rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B5F764 second address: B5F772 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 js 00007FF3D0D81754h 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B603BE second address: B603C4 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B64184 second address: B6418A instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B63D10 second address: B63D23 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 jnc 00007FF3D0F68BA6h 0x0000000d jc 00007FF3D0F68BA6h 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B6BEB1 second address: B6BEBB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jne 00007FF3D0D81736h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B69E01 second address: B69E2B instructions: 0x00000000 rdtsc 0x00000002 jnl 00007FF3D0F68BB4h 0x00000008 push ebx 0x00000009 jmp 00007FF3D0F68BB1h 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B69F63 second address: B69F92 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 jmp 00007FF3D0D8173Fh 0x0000000c popad 0x0000000d pushad 0x0000000e push eax 0x0000000f push edx 0x00000010 jmp 00007FF3D0D8173Ah 0x00000015 jmp 00007FF3D0D8173Bh 0x0000001a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B6B035 second address: B6B042 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 popad 0x00000007 pop esi 0x00000008 push edi 0x00000009 push eax 0x0000000a push edx 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B6B042 second address: B6B046 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B6B2DF second address: B6B2F9 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jnl 00007FF3D0F68BA6h 0x00000009 jl 00007FF3D0F68BA6h 0x0000000f popad 0x00000010 push eax 0x00000011 push edx 0x00000012 jp 00007FF3D0F68BA6h 0x00000018 push eax 0x00000019 push edx 0x0000001a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B6B2F9 second address: B6B2FD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B6B2FD second address: B6B319 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a pushad 0x0000000b jl 00007FF3D0F68BA6h 0x00000011 pushad 0x00000012 popad 0x00000013 jp 00007FF3D0F68BA6h 0x00000019 pushad 0x0000001a popad 0x0000001b popad 0x0000001c rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B6B319 second address: B6B32D instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0D8173Ch 0x00000007 push eax 0x00000008 push edx 0x00000009 push esi 0x0000000a pop esi 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B6B32D second address: B6B331 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B6B896 second address: B6B8B1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnc 00007FF3D0D81736h 0x0000000a jmp 00007FF3D0D8173Ah 0x0000000f popad 0x00000010 pop edi 0x00000011 push eax 0x00000012 push edx 0x00000013 push ebx 0x00000014 push eax 0x00000015 push edx 0x00000016 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B6B8B1 second address: B6B8B6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B6B8B6 second address: B6B8BB instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B6BBB0 second address: B6BBFC instructions: 0x00000000 rdtsc 0x00000002 jns 00007FF3D0F68BA6h 0x00000008 jmp 00007FF3D0F68BB0h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f jmp 00007FF3D0F68BAAh 0x00000014 jns 00007FF3D0F68BAAh 0x0000001a popad 0x0000001b jl 00007FF3D0F68BCFh 0x00000021 push eax 0x00000022 push edx 0x00000023 push esi 0x00000024 pop esi 0x00000025 jmp 00007FF3D0F68BB3h 0x0000002a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B704C5 second address: B704C9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B6F801 second address: B6F805 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B6F805 second address: B6F809 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B6F809 second address: B6F82B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FF3D0F68BB3h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b pushad 0x0000000c jp 00007FF3D0F68BA6h 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B6F82B second address: B6F84A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 jl 00007FF3D0D81736h 0x0000000c popad 0x0000000d popad 0x0000000e pushad 0x0000000f pushad 0x00000010 pushad 0x00000011 popad 0x00000012 jmp 00007FF3D0D8173Bh 0x00000017 push eax 0x00000018 push edx 0x00000019 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B6F84A second address: B6F855 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 pushad 0x00000008 popad 0x00000009 push esi 0x0000000a pop esi 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B6FB14 second address: B6FB18 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B6FE96 second address: B6FECD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 pushad 0x00000006 jne 00007FF3D0F68BA6h 0x0000000c jmp 00007FF3D0F68BAAh 0x00000011 push esi 0x00000012 pop esi 0x00000013 popad 0x00000014 jnp 00007FF3D0F68BAAh 0x0000001a popad 0x0000001b pushad 0x0000001c push eax 0x0000001d push edx 0x0000001e ja 00007FF3D0F68BA6h 0x00000024 jmp 00007FF3D0F68BAAh 0x00000029 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B70028 second address: B7002E instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B7002E second address: B70034 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B70175 second address: B701B0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 pushad 0x00000008 jnc 00007FF3D0D81736h 0x0000000e jmp 00007FF3D0D8173Ch 0x00000013 jmp 00007FF3D0D81746h 0x00000018 jmp 00007FF3D0D8173Ah 0x0000001d popad 0x0000001e rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B701B0 second address: B701B5 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B7D578 second address: B7D57C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B7B721 second address: B7B725 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B7B725 second address: B7B729 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B7B9BC second address: B7B9C9 instructions: 0x00000000 rdtsc 0x00000002 jc 00007FF3D0F68BA6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pushad 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B7BE41 second address: B7BE45 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B7BE45 second address: B7BE50 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 push eax 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B7BFE2 second address: B7BFF8 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FF3D0D81741h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B7BFF8 second address: B7BFFE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B7C189 second address: B7C199 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 jnc 00007FF3D0D81736h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f pop eax 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B7C2FE second address: B7C30D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 jc 00007FF3D0F68BA6h 0x0000000f rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B7C49E second address: B7C4A5 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B7CC87 second address: B7CC95 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pushad 0x00000004 popad 0x00000005 pop ecx 0x00000006 push eax 0x00000007 push edx 0x00000008 je 00007FF3D0F68BA6h 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B7CC95 second address: B7CC99 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B7CC99 second address: B7CC9F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B7B12B second address: B7B12F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B82A1A second address: B82A33 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FF3D0F68BB5h 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B82A33 second address: B82A37 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B82A37 second address: B82A5A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnl 00007FF3D0F68BA6h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edx 0x0000000e pushad 0x0000000f popad 0x00000010 jmp 00007FF3D0F68BB3h 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B82A5A second address: B82A87 instructions: 0x00000000 rdtsc 0x00000002 jng 00007FF3D0D81736h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop edx 0x0000000b pop eax 0x0000000c jp 00007FF3D0D81785h 0x00000012 push eax 0x00000013 push edx 0x00000014 jmp 00007FF3D0D8173Ch 0x00000019 jmp 00007FF3D0D8173Dh 0x0000001e rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B82BE2 second address: B82C07 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FF3D0F68BB7h 0x00000009 push eax 0x0000000a push edx 0x0000000b jc 00007FF3D0F68BA6h 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B82C07 second address: B82C0B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B82C0B second address: B82C0F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B82D5C second address: B82D65 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 push eax 0x00000006 push edx 0x00000007 pushad 0x00000008 popad 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B82D65 second address: B82D6D instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 push eax 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B85424 second address: B85428 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B85428 second address: B85434 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B85434 second address: B8543A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B90D67 second address: B90D6C instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B90D6C second address: B90D79 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 push eax 0x00000006 push edx 0x00000007 jg 00007FF3D0D81736h 0x0000000d rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B90D79 second address: B90DC3 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0F68BB0h 0x00000007 jne 00007FF3D0F68BA6h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f pop edx 0x00000010 pop eax 0x00000011 push eax 0x00000012 push edx 0x00000013 pushad 0x00000014 jmp 00007FF3D0F68BACh 0x00000019 jmp 00007FF3D0F68BB7h 0x0000001e jnc 00007FF3D0F68BA6h 0x00000024 push eax 0x00000025 push edx 0x00000026 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B90DC3 second address: B90DC8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B90DC8 second address: B90DCE instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B90DCE second address: B90DD2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B90890 second address: B9089A instructions: 0x00000000 rdtsc 0x00000002 jns 00007FF3D0F68BA6h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B9089A second address: B908A8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 jno 00007FF3D0D81736h 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B908A8 second address: B908B0 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B908B0 second address: B908D3 instructions: 0x00000000 rdtsc 0x00000002 ja 00007FF3D0D8173Ch 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push edx 0x0000000b jp 00007FF3D0D8173Eh 0x00000011 push eax 0x00000012 push edx 0x00000013 push eax 0x00000014 pop eax 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B90A76 second address: B90A8D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 jp 00007FF3D0F68BB2h 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B960CA second address: B960D4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jns 00007FF3D0D81736h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B960D4 second address: B960F5 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0F68BB4h 0x00000007 pushad 0x00000008 push edi 0x00000009 pop edi 0x0000000a je 00007FF3D0F68BA6h 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B98900 second address: B98906 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B98906 second address: B98923 instructions: 0x00000000 rdtsc 0x00000002 jg 00007FF3D0F68BA6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop edx 0x0000000b pop eax 0x0000000c pushad 0x0000000d jmp 00007FF3D0F68BADh 0x00000012 pushad 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B984FA second address: B98509 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 js 00007FF3D0D81736h 0x0000000a popad 0x0000000b push eax 0x0000000c push edx 0x0000000d push edi 0x0000000e pop edi 0x0000000f rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BA76A0 second address: BA76A5 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BA76A5 second address: BA76CC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FF3D0D81748h 0x00000009 jg 00007FF3D0D81736h 0x0000000f popad 0x00000010 push eax 0x00000011 push edx 0x00000012 push esi 0x00000013 pop esi 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: AC2492 second address: AC2497 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BAEEB3 second address: BAEEB7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BAF020 second address: BAF02B instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 je 00007FF3D0F68BA6h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BAF312 second address: BAF327 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jns 00007FF3D0D81736h 0x0000000a popad 0x0000000b push eax 0x0000000c push edx 0x0000000d pushad 0x0000000e popad 0x0000000f jo 00007FF3D0D81736h 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BAF327 second address: BAF32D instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BAF59D second address: BAF5BA instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push ebx 0x00000009 jmp 00007FF3D0D8173Fh 0x0000000e push edi 0x0000000f push eax 0x00000010 pop eax 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BB32B5 second address: BB32B9 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BB32B9 second address: BB32D7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jl 00007FF3D0D81736h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c pop edi 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007FF3D0D8173Fh 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BB2DBD second address: BB2DC7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jbe 00007FF3D0F68BA6h 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BB2DC7 second address: BB2DCB instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BB2DCB second address: BB2DD1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BB2F6D second address: BB2F71 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BB2F71 second address: BB2F75 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BB2F75 second address: BB2F7B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BBD1BD second address: BBD1C2 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BD3B38 second address: BD3B4E instructions: 0x00000000 rdtsc 0x00000002 jne 00007FF3D0D8173Ch 0x00000008 jnp 00007FF3D0D8173Ch 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BD3710 second address: BD371E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 pushad 0x00000007 popad 0x00000008 push edx 0x00000009 pop edx 0x0000000a popad 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BE9A40 second address: BE9A45 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BEA4CA second address: BEA4CE instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BEA4CE second address: BEA500 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FF3D0D8173Bh 0x00000009 pop edx 0x0000000a pop eax 0x0000000b pushad 0x0000000c jmp 00007FF3D0D8173Dh 0x00000011 push esi 0x00000012 pop esi 0x00000013 push ebx 0x00000014 pop ebx 0x00000015 popad 0x00000016 pushad 0x00000017 jmp 00007FF3D0D8173Bh 0x0000001c push eax 0x0000001d push edx 0x0000001e rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BEA500 second address: BEA506 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BED2B3 second address: BED2C7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jc 00007FF3D0D81738h 0x0000000b pushad 0x0000000c popad 0x0000000d popad 0x0000000e push eax 0x0000000f pushad 0x00000010 push eax 0x00000011 push edx 0x00000012 pushad 0x00000013 popad 0x00000014 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BED2C7 second address: BED2CB instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BED2CB second address: BED2D5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push edx 0x00000009 pop edx 0x0000000a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BEE837 second address: BEE83C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BEE83C second address: BEE84C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jc 00007FF3D0D81736h 0x0000000a jne 00007FF3D0D81736h 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BEE84C second address: BEE850 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BF02F6 second address: BF0322 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0D8173Dh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b push ebx 0x0000000c jmp 00007FF3D0D8173Ch 0x00000011 pop ebx 0x00000012 jmp 00007FF3D0D8173Bh 0x00000017 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BF0322 second address: BF0327 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: BF0327 second address: BF032D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B06A82 second address: B06A88 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: B06A88 second address: B06A8D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 49F041A second address: 49F0473 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 mov ebx, 3ADD68E8h 0x0000000a popad 0x0000000b pop edx 0x0000000c pop eax 0x0000000d push eax 0x0000000e pushad 0x0000000f mov bh, ah 0x00000011 mov ecx, edi 0x00000013 popad 0x00000014 xchg eax, ebp 0x00000015 pushad 0x00000016 movsx edx, si 0x00000019 pushfd 0x0000001a jmp 00007FF3D0F68BAAh 0x0000001f xor cl, 00000048h 0x00000022 jmp 00007FF3D0F68BABh 0x00000027 popfd 0x00000028 popad 0x00000029 mov ebp, esp 0x0000002b jmp 00007FF3D0F68BB6h 0x00000030 mov edx, dword ptr [ebp+0Ch] 0x00000033 push eax 0x00000034 push edx 0x00000035 pushad 0x00000036 movsx ebx, ax 0x00000039 movzx esi, dx 0x0000003c popad 0x0000003d rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 49F0473 second address: 49F0479 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 49F0479 second address: 49F047D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 49F047D second address: 49F0481 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 49F04AD second address: 49F04B1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 49F04B1 second address: 49F04B5 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 49F04B5 second address: 49F04BB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A10731 second address: 4A1076B instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 call 00007FF3D0D8173Fh 0x00000008 pop ecx 0x00000009 jmp 00007FF3D0D81749h 0x0000000e popad 0x0000000f pop edx 0x00000010 pop eax 0x00000011 xchg eax, ebp 0x00000012 push eax 0x00000013 push edx 0x00000014 pushad 0x00000015 mov bx, 43AEh 0x00000019 mov eax, ebx 0x0000001b popad 0x0000001c rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A1076B second address: 4A10786 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0F68BB0h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A10786 second address: 4A1078A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A1078A second address: 4A10790 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A10790 second address: 4A107A6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FF3D0D81742h 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A107A6 second address: 4A10836 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0F68BABh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b xchg eax, ebp 0x0000000c jmp 00007FF3D0F68BB6h 0x00000011 mov ebp, esp 0x00000013 pushad 0x00000014 jmp 00007FF3D0F68BAEh 0x00000019 mov ch, 38h 0x0000001b popad 0x0000001c push esp 0x0000001d pushad 0x0000001e pushfd 0x0000001f jmp 00007FF3D0F68BB8h 0x00000024 add ah, 00000048h 0x00000027 jmp 00007FF3D0F68BABh 0x0000002c popfd 0x0000002d call 00007FF3D0F68BB8h 0x00000032 mov esi, 40E34DC1h 0x00000037 pop eax 0x00000038 popad 0x00000039 mov dword ptr [esp], ecx 0x0000003c push eax 0x0000003d push edx 0x0000003e pushad 0x0000003f mov di, E1D8h 0x00000043 popad 0x00000044 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A10836 second address: 4A10876 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov di, ax 0x00000006 jmp 00007FF3D0D81748h 0x0000000b popad 0x0000000c pop edx 0x0000000d pop eax 0x0000000e xchg eax, esi 0x0000000f pushad 0x00000010 jmp 00007FF3D0D8173Eh 0x00000015 mov bl, ah 0x00000017 popad 0x00000018 push eax 0x00000019 push eax 0x0000001a push edx 0x0000001b pushad 0x0000001c mov di, FBACh 0x00000020 movsx ebx, si 0x00000023 popad 0x00000024 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A10876 second address: 4A10898 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0F68BB7h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xchg eax, esi 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A10898 second address: 4A1089C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A1089C second address: 4A108B7 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0F68BB7h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A108B7 second address: 4A10914 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0D81749h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 lea eax, dword ptr [ebp-04h] 0x0000000c pushad 0x0000000d movzx ecx, di 0x00000010 pushfd 0x00000011 jmp 00007FF3D0D81749h 0x00000016 jmp 00007FF3D0D8173Bh 0x0000001b popfd 0x0000001c popad 0x0000001d nop 0x0000001e pushad 0x0000001f mov esi, 0E9467FBh 0x00000024 mov bx, cx 0x00000027 popad 0x00000028 push eax 0x00000029 push eax 0x0000002a push edx 0x0000002b push eax 0x0000002c push edx 0x0000002d push eax 0x0000002e push edx 0x0000002f rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A10914 second address: 4A10918 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A10918 second address: 4A1092E instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0D81742h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A1092E second address: 4A10955 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0F68BABh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 nop 0x0000000a push eax 0x0000000b push edx 0x0000000c jmp 00007FF3D0F68BB5h 0x00000011 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A10955 second address: 4A1095B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A1095B second address: 4A1095F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A10A33 second address: 4A10A61 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0D81749h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov eax, esi 0x0000000b push eax 0x0000000c push edx 0x0000000d jmp 00007FF3D0D8173Dh 0x00000012 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A10A61 second address: 4A001A9 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0F68BB1h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop esi 0x0000000a pushad 0x0000000b mov eax, 68289243h 0x00000010 pushfd 0x00000011 jmp 00007FF3D0F68BB8h 0x00000016 and ah, 00000008h 0x00000019 jmp 00007FF3D0F68BABh 0x0000001e popfd 0x0000001f popad 0x00000020 leave 0x00000021 jmp 00007FF3D0F68BB6h 0x00000026 retn 0004h 0x00000029 nop 0x0000002a sub esp, 04h 0x0000002d xor ebx, ebx 0x0000002f cmp eax, 00000000h 0x00000032 je 00007FF3D0F68D0Ah 0x00000038 mov dword ptr [esp], 0000000Dh 0x0000003f call 00007FF3D5034EE3h 0x00000044 mov edi, edi 0x00000046 pushad 0x00000047 push eax 0x00000048 push edx 0x00000049 push eax 0x0000004a push edx 0x0000004b rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A001A9 second address: 4A001AD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A001AD second address: 4A0020F instructions: 0x00000000 rdtsc 0x00000002 mov di, cx 0x00000005 pop edx 0x00000006 pop eax 0x00000007 popad 0x00000008 push ebx 0x00000009 pushad 0x0000000a jmp 00007FF3D0F68BAEh 0x0000000f popad 0x00000010 mov dword ptr [esp], ebp 0x00000013 pushad 0x00000014 mov bx, F0F0h 0x00000018 movsx ebx, ax 0x0000001b popad 0x0000001c mov ebp, esp 0x0000001e pushad 0x0000001f mov edi, ecx 0x00000021 pushfd 0x00000022 jmp 00007FF3D0F68BAAh 0x00000027 and eax, 427BE938h 0x0000002d jmp 00007FF3D0F68BABh 0x00000032 popfd 0x00000033 popad 0x00000034 sub esp, 2Ch 0x00000037 push eax 0x00000038 push edx 0x00000039 jmp 00007FF3D0F68BB5h 0x0000003e rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A0020F second address: 4A00215 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A00215 second address: 4A00219 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A003C4 second address: 4A003CA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A003CA second address: 4A003CE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A003CE second address: 4A00453 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0D8173Dh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b inc ebx 0x0000000c jmp 00007FF3D0D8173Eh 0x00000011 test al, al 0x00000013 pushad 0x00000014 mov bx, cx 0x00000017 call 00007FF3D0D8173Ah 0x0000001c pushfd 0x0000001d jmp 00007FF3D0D81742h 0x00000022 and cl, FFFFFFA8h 0x00000025 jmp 00007FF3D0D8173Bh 0x0000002a popfd 0x0000002b pop eax 0x0000002c popad 0x0000002d je 00007FF3D0D818F7h 0x00000033 jmp 00007FF3D0D8173Fh 0x00000038 lea ecx, dword ptr [ebp-14h] 0x0000003b push eax 0x0000003c push edx 0x0000003d jmp 00007FF3D0D81745h 0x00000042 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A004FA second address: 4A00527 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0F68BB2h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 test eax, eax 0x0000000b push eax 0x0000000c push edx 0x0000000d pushad 0x0000000e call 00007FF3D0F68BADh 0x00000013 pop eax 0x00000014 movsx ebx, ax 0x00000017 popad 0x00000018 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A00527 second address: 4A0052C instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A0052C second address: 4A00568 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edx 0x00000006 pop eax 0x00000007 jg 00007FF441956AFFh 0x0000000d jmp 00007FF3D0F68BB0h 0x00000012 js 00007FF3D0F68C42h 0x00000018 push eax 0x00000019 push edx 0x0000001a jmp 00007FF3D0F68BB7h 0x0000001f rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A00568 second address: 4A005CE instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov dx, 16FAh 0x00000007 pushfd 0x00000008 jmp 00007FF3D0D8173Bh 0x0000000d or eax, 07680A9Eh 0x00000013 jmp 00007FF3D0D81749h 0x00000018 popfd 0x00000019 popad 0x0000001a pop edx 0x0000001b pop eax 0x0000001c cmp dword ptr [ebp-14h], edi 0x0000001f jmp 00007FF3D0D8173Eh 0x00000024 jne 00007FF44176F622h 0x0000002a push eax 0x0000002b push edx 0x0000002c jmp 00007FF3D0D81747h 0x00000031 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A005CE second address: 4A0060C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0F68BB9h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov ebx, dword ptr [ebp+08h] 0x0000000c pushad 0x0000000d mov cl, B1h 0x0000000f call 00007FF3D0F68BB9h 0x00000014 push eax 0x00000015 push edx 0x00000016 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A0060C second address: 4A0062F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 popad 0x00000006 lea eax, dword ptr [ebp-2Ch] 0x00000009 push eax 0x0000000a push edx 0x0000000b jmp 00007FF3D0D81748h 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A0062F second address: 4A00634 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A00634 second address: 4A006F3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 mov esi, edi 0x00000006 popad 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push ebx 0x0000000a pushad 0x0000000b pushad 0x0000000c pushfd 0x0000000d jmp 00007FF3D0D81742h 0x00000012 sbb esi, 7C060548h 0x00000018 jmp 00007FF3D0D8173Bh 0x0000001d popfd 0x0000001e pushfd 0x0000001f jmp 00007FF3D0D81748h 0x00000024 sbb si, C7A8h 0x00000029 jmp 00007FF3D0D8173Bh 0x0000002e popfd 0x0000002f popad 0x00000030 mov dx, si 0x00000033 popad 0x00000034 mov dword ptr [esp], esi 0x00000037 jmp 00007FF3D0D81742h 0x0000003c nop 0x0000003d jmp 00007FF3D0D81740h 0x00000042 push eax 0x00000043 push eax 0x00000044 push edx 0x00000045 pushad 0x00000046 mov al, 95h 0x00000048 pushfd 0x00000049 jmp 00007FF3D0D81749h 0x0000004e and eax, 19C38BD6h 0x00000054 jmp 00007FF3D0D81741h 0x00000059 popfd 0x0000005a popad 0x0000005b rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A006F3 second address: 4A00703 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FF3D0F68BACh 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A00703 second address: 4A00707 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A00707 second address: 4A00760 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 nop 0x00000009 pushad 0x0000000a pushfd 0x0000000b jmp 00007FF3D0F68BADh 0x00000010 sub ah, FFFFFFE6h 0x00000013 jmp 00007FF3D0F68BB1h 0x00000018 popfd 0x00000019 popad 0x0000001a xchg eax, ebx 0x0000001b jmp 00007FF3D0F68BAAh 0x00000020 push eax 0x00000021 jmp 00007FF3D0F68BABh 0x00000026 xchg eax, ebx 0x00000027 push eax 0x00000028 push edx 0x00000029 pushad 0x0000002a call 00007FF3D0F68BABh 0x0000002f pop ecx 0x00000030 mov cx, di 0x00000033 popad 0x00000034 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A00772 second address: 4A00778 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A00778 second address: 4A007B3 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 call 00007FF3D0F68BB3h 0x00000008 pop esi 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c mov esi, eax 0x0000000e pushad 0x0000000f mov ebx, ecx 0x00000011 mov edx, eax 0x00000013 popad 0x00000014 test esi, esi 0x00000016 push eax 0x00000017 push edx 0x00000018 jmp 00007FF3D0F68BB5h 0x0000001d rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A007B3 second address: 4A00025 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0D81741h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 je 00007FF44176F5C3h 0x0000000f xor eax, eax 0x00000011 jmp 00007FF3D0D5AE6Ah 0x00000016 pop esi 0x00000017 pop edi 0x00000018 pop ebx 0x00000019 leave 0x0000001a retn 0004h 0x0000001d nop 0x0000001e sub esp, 04h 0x00000021 mov esi, eax 0x00000023 xor ebx, ebx 0x00000025 cmp esi, 00000000h 0x00000028 je 00007FF3D0D81875h 0x0000002e call 00007FF3D4E4D77Ch 0x00000033 mov edi, edi 0x00000035 pushad 0x00000036 mov di, F746h 0x0000003a mov edx, 0CDB41D2h 0x0000003f popad 0x00000040 push ebx 0x00000041 push eax 0x00000042 push edx 0x00000043 jmp 00007FF3D0D81745h 0x00000048 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A00025 second address: 4A000EF instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0F68BB1h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov dword ptr [esp], ebp 0x0000000c pushad 0x0000000d pushfd 0x0000000e jmp 00007FF3D0F68BB3h 0x00000013 xor ecx, 4F1AA3DEh 0x00000019 jmp 00007FF3D0F68BB9h 0x0000001e popfd 0x0000001f popad 0x00000020 mov ebp, esp 0x00000022 pushad 0x00000023 jmp 00007FF3D0F68BACh 0x00000028 pushfd 0x00000029 jmp 00007FF3D0F68BB2h 0x0000002e xor cx, 9B08h 0x00000033 jmp 00007FF3D0F68BABh 0x00000038 popfd 0x00000039 popad 0x0000003a xchg eax, ecx 0x0000003b jmp 00007FF3D0F68BB6h 0x00000040 push eax 0x00000041 push eax 0x00000042 push edx 0x00000043 pushad 0x00000044 mov ax, 4E03h 0x00000048 pushfd 0x00000049 jmp 00007FF3D0F68BB8h 0x0000004e adc ah, FFFFFFC8h 0x00000051 jmp 00007FF3D0F68BABh 0x00000056 popfd 0x00000057 popad 0x00000058 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A000EF second address: 4A00107 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FF3D0D81744h 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A00107 second address: 4A0010B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A0010B second address: 4A0011A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 xchg eax, ecx 0x00000009 push eax 0x0000000a push edx 0x0000000b push eax 0x0000000c push edx 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A0011A second address: 4A0011E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A0011E second address: 4A00122 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A00122 second address: 4A00128 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A00BEA second address: 4A00C3E instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 mov ebp, esp 0x00000009 pushad 0x0000000a mov di, ax 0x0000000d jmp 00007FF3D0D81742h 0x00000012 popad 0x00000013 cmp dword ptr [7544459Ch], 05h 0x0000001a jmp 00007FF3D0D81740h 0x0000001f je 00007FF44175F514h 0x00000025 jmp 00007FF3D0D81740h 0x0000002a pop ebp 0x0000002b pushad 0x0000002c pushad 0x0000002d mov edi, esi 0x0000002f push eax 0x00000030 push edx 0x00000031 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A00C5D second address: 4A00C86 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0F68BB2h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push 33B9BD5Dh 0x0000000e push eax 0x0000000f push edx 0x00000010 jmp 00007FF3D0F68BACh 0x00000015 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A00D49 second address: 4A00DDC instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push ecx 0x00000004 pop edx 0x00000005 mov edi, eax 0x00000007 popad 0x00000008 pop edx 0x00000009 pop eax 0x0000000a test al, al 0x0000000c jmp 00007FF3D0D81748h 0x00000011 je 00007FF44175534Eh 0x00000017 pushad 0x00000018 call 00007FF3D0D8173Eh 0x0000001d mov bl, cl 0x0000001f pop ebx 0x00000020 pushfd 0x00000021 jmp 00007FF3D0D8173Ch 0x00000026 sub esi, 2845C278h 0x0000002c jmp 00007FF3D0D8173Bh 0x00000031 popfd 0x00000032 popad 0x00000033 cmp dword ptr [ebp+08h], 00002000h 0x0000003a pushad 0x0000003b pushfd 0x0000003c jmp 00007FF3D0D81744h 0x00000041 jmp 00007FF3D0D81745h 0x00000046 popfd 0x00000047 push eax 0x00000048 push edx 0x00000049 pushad 0x0000004a popad 0x0000004b rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A10AE1 second address: 4A10AE7 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A10AE7 second address: 4A10B00 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0D8173Eh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e pushad 0x0000000f popad 0x00000010 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A10B00 second address: 4A10B1C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0F68BB8h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A10B1C second address: 4A10B7B instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FF3D0D81741h 0x00000009 sbb ch, 00000046h 0x0000000c jmp 00007FF3D0D81741h 0x00000011 popfd 0x00000012 mov si, 20F7h 0x00000016 popad 0x00000017 pop edx 0x00000018 pop eax 0x00000019 xchg eax, ebp 0x0000001a pushad 0x0000001b call 00007FF3D0D81744h 0x00000020 movzx ecx, dx 0x00000023 pop edx 0x00000024 popad 0x00000025 mov ebp, esp 0x00000027 jmp 00007FF3D0D8173Ah 0x0000002c xchg eax, esi 0x0000002d pushad 0x0000002e push eax 0x0000002f push edx 0x00000030 mov di, ax 0x00000033 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A10B7B second address: 4A10BDE instructions: 0x00000000 rdtsc 0x00000002 mov dh, ch 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jmp 00007FF3D0F68BB5h 0x0000000b popad 0x0000000c push eax 0x0000000d jmp 00007FF3D0F68BB1h 0x00000012 xchg eax, esi 0x00000013 push eax 0x00000014 push edx 0x00000015 pushad 0x00000016 mov ax, dx 0x00000019 pushfd 0x0000001a jmp 00007FF3D0F68BAFh 0x0000001f and ah, FFFFFF9Eh 0x00000022 jmp 00007FF3D0F68BB9h 0x00000027 popfd 0x00000028 popad 0x00000029 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A10BDE second address: 4A10C51 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FF3D0D81741h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov esi, dword ptr [ebp+0Ch] 0x0000000c pushad 0x0000000d pushfd 0x0000000e jmp 00007FF3D0D8173Ch 0x00000013 or ecx, 0F7E5EC8h 0x00000019 jmp 00007FF3D0D8173Bh 0x0000001e popfd 0x0000001f mov ecx, 20DD1C3Fh 0x00000024 popad 0x00000025 test esi, esi 0x00000027 push eax 0x00000028 push edx 0x00000029 pushad 0x0000002a pushfd 0x0000002b jmp 00007FF3D0D81747h 0x00000030 jmp 00007FF3D0D81743h 0x00000035 popfd 0x00000036 mov di, cx 0x00000039 popad 0x0000003a rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A10C51 second address: 4A10C57 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A10C57 second address: 4A10C5B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A10C5B second address: 4A10C9A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 je 00007FF4419362FAh 0x0000000e jmp 00007FF3D0F68BB3h 0x00000013 cmp dword ptr [7544459Ch], 05h 0x0000001a push eax 0x0000001b push edx 0x0000001c jmp 00007FF3D0F68BB5h 0x00000021 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A10D08 second address: 4A10D47 instructions: 0x00000000 rdtsc 0x00000002 movzx esi, dx 0x00000005 pop edx 0x00000006 pop eax 0x00000007 mov ax, di 0x0000000a popad 0x0000000b push ebp 0x0000000c push eax 0x0000000d push edx 0x0000000e pushad 0x0000000f mov esi, ebx 0x00000011 pushfd 0x00000012 jmp 00007FF3D0D81745h 0x00000017 xor ax, 86D6h 0x0000001c jmp 00007FF3D0D81741h 0x00000021 popfd 0x00000022 popad 0x00000023 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | RDTSC instruction interceptor: First address: 4A10D47 second address: 4A10D4D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\phkbamefinggmakgklpkljjmgibohnba | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\3nxxd8pi.default-release\prefs.js | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\amkmjjmmflddogmhpjloimipbofnfjih | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\egjidjbpglichdcondbcbdnbeeppgdph | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\History | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\3nxxd8pi.default-release\places.sqlite | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\idnnbdplmphpflfnlkomgpfbpcgelopg | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\Cookies | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bhghoamapcdpbohphigoooaddinpkbai | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dngmlblcodfobpdpecaadgfbcggfjfnm | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cihmoadaighcejopammfbmddcmdekcje | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data For Account | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lgmpcpglpngdoalbgeoldeajfclnhafa | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\afbcbjpbpfadlkmhmclhkeeodmamcflc | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\efbglgofoippbgcjepnhiblaibcnclgk | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fcfcfllfndlomdhbehjjcoimbgofdncg | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\acmacodkjbdgmoleebolmdjonilkdbch | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\flpiciilemghbmfalicajoolhkkenfe | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ijmpgkjfkbfhoebgogflfebnmejmfbm | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejbalbakoplchlghecdalmeeeajnimhm | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\oeljdldpnmdbchonielidgobddfffla | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lkcjlnjfpbikmcmbachjpdbijejflpcm | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aeblfdkhhhdcdjpifhhbdiojplfjncoa | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mnfifefkajgofkcjkemidiaecocnkjeh | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nkddgncdjgjfcddamfgcmfnlhccnimig | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cnncmdhjacpkmjmkcafchppbnpnhdmon | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jbdaocneiiinmjbjlgalhcelgbejmnid | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejjladinnckdgjemekebdpeokbikhfci | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lpfcbjknijpeeillifnkikgncikgfhdo | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aflkmfhebedbjioipglgcbcmnbpgliof | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fijngjgcjhjmmpcmkeiomlglpeiijkld | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\ilgcnhelpchnceeipipijaljkblbcob | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fnjhmkhhmkbjkkabndcnnogagogbneec | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jiidiaalihmmhddjgbnbgdfflelocpak | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bcopgchhojmggmffilplmbdicgaihlkp | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fhmfendgdocmcbmfikdcogofphimnkno | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\abogmiocnneedmmepnohnhlijcjpcifd | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lodccjjbdhfakaekdiahmedfbieldgik | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cjelfplplebdjjenllpjcblmjkfcffne | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nlbmnnijcnlegkjjpcfjclmcfggfefdm | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nkbihfbeogaeaoehlefnkodbefgpgknn | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hpglfhgfnhbgpjdenjgmdgoeiappafln | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\infeboajgfhgbjpjbeppbkgnabfdkdaf | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dlcobpjiigpikoobohmabehhmhfoodbb | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jgaaimajipbpdogpdglhaphldakikgef | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jnlgamecbpmbajjfhmmmlhejkemejdma | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nlgbhdfgdhgbiamfdfmbikcdghidoadd | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cnmamaachppnkjgnildpdmkaakejnhae | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nknhiehlklippafakaeklbeglecifhad | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ocjdpmoallmgmjbbogfiiaofphbjgchh | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\opcgpfmipidbgpenhmajoajpbobppdil | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kkpllkodjeloidieedojogacfhpaihoh | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pioclpoplcdbaefihamjohnefbikjilc | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\3nxxd8pi.default-release\cookies.sqlite | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hifafgmccdpekplomjjkcfgodnhcellj | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gaedmjdfmmahhbjefcbgaolhhanlaolb | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mcohilncbfahbmgdjkbpemcciiolgcge | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cphhlgmgameodnhkjdmkpanlelnlohao | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\onhogfjeacnfoofkfgppdlbmlmnplgbn | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fihkakfobkmkjojpchpfgcmhfjnmnfpi | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aiifbnbfobpmeekipheeijimdpnlpgpp | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hnfanknocfeofbddgcijnmhnfnkdnaad | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\blnieiiffboillknjnepogjhkgnoapac | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data For Account | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\onofpnbbkehpmmoabgpcpmigafmmnjh | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\3nxxd8pi.default-release\logins.json | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\3nxxd8pi.default-release\formhistory.sqlite | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fhbohimaelbohpjbbldcngcnapndodjp | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\3nxxd8pi.default-release\cert9.db | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\bhghoamapcdpbohphigoooaddinpkbai | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nngceckbapebfimnlniiiahkandclblb | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\loinekcabhlmhjjbocijdoimmejangoa | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dmkamcknogkgcdfhhbddcghachkejeap | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\imloifkgjagghnncjkhggdhalmcnfklk | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\heefohaffomkkkphnlpohglngmbcclhi | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bhhhlbepdkbapadjdnnojkbgioiodbic | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kjmoohlgokccodicjjfebfomlbljgfhk | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ppbibelpcjmhbdihakflkdcoccbgbkpo | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mopnmbcafieddcagagdcbnhejhlodfdd | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aholpfdialjgjfhomihkjbmgjidlcdno | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nanjmdknhkinifnkgdcggcfnhdaammmj | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ojggmchlghnjlapmfbnjholfjkiidbch | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jojhfeoedkpkglbfimdfabpdfjaoolaf | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kncchdigobghenbbaddojjnnaogfppfj | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\klnaejjgbibmhlephnhpmaofohgkpgkd | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\3nxxd8pi.default-release\key4.db | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ookjlbkiijinhpmnjffcofjonbfbgaoc | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dkdedlpgdmmkkfjabffeganieamfklkm | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\Cookies | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\anokgmphncpekkhclmingpimjmcooifb | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\oeljdldpnmdbchonielidgobddfffla | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mkpegjkblkkefacfnmkajcjmabijhclg | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mmmjbcfofconkannjonfmjjajpllddbg | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kppfdiipphfccemcignhifpjkapfbihd | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ibnejdfjmmkpcnlpebklmnkoeoihofec | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cpojfbodiccabbabgimdeohkkpjfpbnf | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bfnaelmomeimhlpmgjnjophhpkkoljpa | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nhnkbkgjikgcigadomkphalanndcapjk | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hdokiejnpimakedhajhdlcegeplioahd | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aeachknmefphepccionboohckonoeemg | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Data | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hcflpincpppdclinealmandijcmnkbgn | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ffnbelfdoeiohenkjibnmadjiehjhajb | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ilgcnhelpchnceeipipijaljkblbcob | Jump to behavior |
Source: C:\Users\user\Desktop\onaUtwpiyq.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kpfopkelmapcoipemfendmdcghnegimn | Jump to behavior |