Windows Analysis Report
7950COPY.exe

Overview

General Information

Sample name: 7950COPY.exe
Analysis ID: 1542909
MD5: 366019444461914c99eca593e71a9a02
SHA1: 5b5f155953bbc13bf852a673e4be088afc57dda9
SHA256: 369c60a89a3351e62008c3f8014ebe5424a67ef020767f0d37b7939243d6e808
Tags: exeFormbookuser-threatcat_ch
Infos:

Detection

FormBook
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Yara detected AntiVM3
Yara detected FormBook
Yara detected UAC Bypass using CMSTP
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
AI detected suspicious sample
Adds a directory exclusion to Windows Defender
Allocates memory in foreign processes
Disables UAC (registry)
Found direct / indirect Syscall (likely to bypass EDR)
Injects a PE file into a foreign processes
Loading BitLocker PowerShell Module
Machine Learning detection for sample
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Switches to a custom stack to bypass stack traces
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Uses regedit.exe to modify the Windows registry
Writes to foreign memory regions
AV process strings found (often used to terminate AV products)
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if the current process is being debugged
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to read the PEB
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
May sleep (evasive loops) to hinder dynamic analysis
One or more processes crash
PE file does not import any functions
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: Powershell Defender Exclusion
Uses code obfuscation techniques (call, push, ret)

Classification

AV Detection

barindex
Source: 7950COPY.exe Avira: detected
Source: 7950COPY.exe ReversingLabs: Detection: 63%
Source: Yara match File source: 5.2.ilasm.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.ilasm.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 0000000F.00000002.3601048120.0000000000C50000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.2188258196.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000F.00000002.3601268503.0000000003110000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000F.00000002.3601299719.0000000003160000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.2188485814.0000000005DB0000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
Source: Submited Sample Integrated Neural Analysis Model: Matched 100.0% probability
Source: 7950COPY.exe Joe Sandbox ML: detected

Exploits

barindex
Source: Yara match File source: 00000000.00000002.2314358721.0000017097B34000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: 7950COPY.exe PID: 6908, type: MEMORYSTR
Source: 7950COPY.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: System.Windows.Forms.pdb source: WER40CA.tmp.dmp.9.dr
Source: Binary string: fltMC.pdb source: ilasm.exe, 00000005.00000002.2188442822.0000000005BB8000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: mscorlib.pdb source: WER40CA.tmp.dmp.9.dr
Source: Binary string: System.ni.pdbRSDS source: WER40CA.tmp.dmp.9.dr
Source: Binary string: .pdbError: CoCreateInstance(IID_ISymUnmanagedWriter) returns %X source: 7950COPY.exe, 00000000.00000002.2311713328.0000000015DDC000.00000004.80000000.00040000.00000000.sdmp, fltMC.exe, 0000000F.00000002.3601098295.0000000002E90000.00000004.00000020.00020000.00000000.sdmp, fltMC.exe, 0000000F.00000002.3601717977.00000000039AC000.00000004.10000000.00040000.00000000.sdmp
Source: Binary string: System.Windows.Forms.ni.pdbRSDS source: WER40CA.tmp.dmp.9.dr
Source: Binary string: System.Windows.Forms.ni.pdb source: WER40CA.tmp.dmp.9.dr
Source: Binary string: System.Drawing.pdb source: WER40CA.tmp.dmp.9.dr
Source: Binary string: mscorlib.ni.pdb source: WER40CA.tmp.dmp.9.dr
Source: Binary string: wntdll.pdbUGP source: ilasm.exe, 00000005.00000002.2188520319.0000000005E60000.00000040.00001000.00020000.00000000.sdmp, fltMC.exe, 0000000F.00000002.3601401909.00000000034DE000.00000040.00001000.00020000.00000000.sdmp, fltMC.exe, 0000000F.00000003.2188880100.0000000002FE3000.00000004.00000020.00020000.00000000.sdmp, fltMC.exe, 0000000F.00000003.2190926695.0000000003199000.00000004.00000020.00020000.00000000.sdmp, fltMC.exe, 0000000F.00000002.3601401909.0000000003340000.00000040.00001000.00020000.00000000.sdmp
Source: Binary string: System.Drawing.ni.pdb source: WER40CA.tmp.dmp.9.dr
Source: Binary string: wntdll.pdb source: ilasm.exe, ilasm.exe, 00000005.00000002.2188520319.0000000005E60000.00000040.00001000.00020000.00000000.sdmp, fltMC.exe, fltMC.exe, 0000000F.00000002.3601401909.00000000034DE000.00000040.00001000.00020000.00000000.sdmp, fltMC.exe, 0000000F.00000003.2188880100.0000000002FE3000.00000004.00000020.00020000.00000000.sdmp, fltMC.exe, 0000000F.00000003.2190926695.0000000003199000.00000004.00000020.00020000.00000000.sdmp, fltMC.exe, 0000000F.00000002.3601401909.0000000003340000.00000040.00001000.00020000.00000000.sdmp
Source: Binary string: System.Core.pdb source: WER40CA.tmp.dmp.9.dr
Source: Binary string: mscorlib.ni.pdbRSDS7^3l source: WER40CA.tmp.dmp.9.dr
Source: Binary string: System.Drawing.pdb source: WER40CA.tmp.dmp.9.dr
Source: Binary string: ilasm.pdb source: 7950COPY.exe, 00000000.00000002.2311713328.0000000015DDC000.00000004.80000000.00040000.00000000.sdmp, fltMC.exe, 0000000F.00000002.3601098295.0000000002E90000.00000004.00000020.00020000.00000000.sdmp, fltMC.exe, 0000000F.00000002.3601717977.00000000039AC000.00000004.10000000.00040000.00000000.sdmp
Source: Binary string: System.Drawing.ni.pdbRSDS source: WER40CA.tmp.dmp.9.dr
Source: Binary string: fltMC.pdbGCTL source: ilasm.exe, 00000005.00000002.2188442822.0000000005BB8000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: System.Windows.Forms.pdb source: WER40CA.tmp.dmp.9.dr
Source: Binary string: System.ni.pdb source: WER40CA.tmp.dmp.9.dr
Source: Binary string: System.pdb source: WER40CA.tmp.dmp.9.dr
Source: Binary string: System.Core.ni.pdbRSDS source: WER40CA.tmp.dmp.9.dr
Source: Binary string: System.Core.ni.pdb source: WER40CA.tmp.dmp.9.dr
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 4x nop then xor eax, eax 15_2_00C59DD0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 4x nop then mov ebx, 00000004h 15_2_032604E1
Source: Amcache.hve.9.dr String found in binary or memory: http://upx.sf.net

E-Banking Fraud

barindex
Source: Yara match File source: 5.2.ilasm.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.ilasm.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 0000000F.00000002.3601048120.0000000000C50000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.2188258196.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000F.00000002.3601268503.0000000003110000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000F.00000002.3601299719.0000000003160000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.2188485814.0000000005DB0000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY

System Summary

barindex
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\regedit.exe "C:\Windows\regedit.exe"
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_0042C3D3 NtClose, 5_2_0042C3D3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED35C0 NtCreateMutant,LdrInitializeThunk, 5_2_05ED35C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2DF0 NtQuerySystemInformation,LdrInitializeThunk, 5_2_05ED2DF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2CA0 NtQueryInformationToken,LdrInitializeThunk, 5_2_05ED2CA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2C70 NtFreeVirtualMemory,LdrInitializeThunk, 5_2_05ED2C70
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2F90 NtProtectVirtualMemory,LdrInitializeThunk, 5_2_05ED2F90
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2B60 NtClose,LdrInitializeThunk, 5_2_05ED2B60
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED4650 NtSuspendThread, 5_2_05ED4650
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED3090 NtSetValueKey, 5_2_05ED3090
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED3010 NtOpenDirectoryObject, 5_2_05ED3010
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED4340 NtSetContextThread, 5_2_05ED4340
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2DD0 NtDelayExecution, 5_2_05ED2DD0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2DB0 NtEnumerateKey, 5_2_05ED2DB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED3D70 NtOpenThread, 5_2_05ED3D70
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2D30 NtUnmapViewOfSection, 5_2_05ED2D30
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2D00 NtSetInformationFile, 5_2_05ED2D00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2D10 NtMapViewOfSection, 5_2_05ED2D10
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED3D10 NtOpenProcessToken, 5_2_05ED3D10
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2CF0 NtOpenProcess, 5_2_05ED2CF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2CC0 NtQueryVirtualMemory, 5_2_05ED2CC0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2C60 NtCreateKey, 5_2_05ED2C60
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2C00 NtQueryInformationProcess, 5_2_05ED2C00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2FE0 NtCreateFile, 5_2_05ED2FE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2FA0 NtQuerySection, 5_2_05ED2FA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2FB0 NtResumeThread, 5_2_05ED2FB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2F60 NtCreateProcessEx, 5_2_05ED2F60
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2F30 NtCreateSection, 5_2_05ED2F30
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2EE0 NtQueueApcThread, 5_2_05ED2EE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2EA0 NtAdjustPrivilegesToken, 5_2_05ED2EA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2E80 NtReadVirtualMemory, 5_2_05ED2E80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2E30 NtWriteVirtualMemory, 5_2_05ED2E30
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED39B0 NtGetContextThread, 5_2_05ED39B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2BE0 NtQueryValueKey, 5_2_05ED2BE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2BF0 NtAllocateVirtualMemory, 5_2_05ED2BF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2BA0 NtEnumerateValueKey, 5_2_05ED2BA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2B80 NtQueryInformationFile, 5_2_05ED2B80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2AF0 NtWriteFile, 5_2_05ED2AF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2AD0 NtReadFile, 5_2_05ED2AD0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2AB0 NtWaitForSingleObject, 5_2_05ED2AB0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B35C0 NtCreateMutant,LdrInitializeThunk, 15_2_033B35C0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2B60 NtClose,LdrInitializeThunk, 15_2_033B2B60
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2BF0 NtAllocateVirtualMemory,LdrInitializeThunk, 15_2_033B2BF0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2BE0 NtQueryValueKey,LdrInitializeThunk, 15_2_033B2BE0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2AD0 NtReadFile,LdrInitializeThunk, 15_2_033B2AD0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2F30 NtCreateSection,LdrInitializeThunk, 15_2_033B2F30
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2FE0 NtCreateFile,LdrInitializeThunk, 15_2_033B2FE0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2D10 NtMapViewOfSection,LdrInitializeThunk, 15_2_033B2D10
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2DF0 NtQuerySystemInformation,LdrInitializeThunk, 15_2_033B2DF0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2DD0 NtDelayExecution,LdrInitializeThunk, 15_2_033B2DD0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2C70 NtFreeVirtualMemory,LdrInitializeThunk, 15_2_033B2C70
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2C60 NtCreateKey,LdrInitializeThunk, 15_2_033B2C60
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2CA0 NtQueryInformationToken,LdrInitializeThunk, 15_2_033B2CA0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B4340 NtSetContextThread, 15_2_033B4340
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B3010 NtOpenDirectoryObject, 15_2_033B3010
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B3090 NtSetValueKey, 15_2_033B3090
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B4650 NtSuspendThread, 15_2_033B4650
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2BA0 NtEnumerateValueKey, 15_2_033B2BA0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2B80 NtQueryInformationFile, 15_2_033B2B80
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2AB0 NtWaitForSingleObject, 15_2_033B2AB0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2AF0 NtWriteFile, 15_2_033B2AF0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B39B0 NtGetContextThread, 15_2_033B39B0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2F60 NtCreateProcessEx, 15_2_033B2F60
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2FB0 NtResumeThread, 15_2_033B2FB0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2FA0 NtQuerySection, 15_2_033B2FA0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2F90 NtProtectVirtualMemory, 15_2_033B2F90
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2E30 NtWriteVirtualMemory, 15_2_033B2E30
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2EA0 NtAdjustPrivilegesToken, 15_2_033B2EA0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2E80 NtReadVirtualMemory, 15_2_033B2E80
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2EE0 NtQueueApcThread, 15_2_033B2EE0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2D30 NtUnmapViewOfSection, 15_2_033B2D30
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B3D10 NtOpenProcessToken, 15_2_033B3D10
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2D00 NtSetInformationFile, 15_2_033B2D00
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B3D70 NtOpenThread, 15_2_033B3D70
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2DB0 NtEnumerateKey, 15_2_033B2DB0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2C00 NtQueryInformationProcess, 15_2_033B2C00
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2CF0 NtOpenProcess, 15_2_033B2CF0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B2CC0 NtQueryVirtualMemory, 15_2_033B2CC0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C79070 NtReadFile, 15_2_00C79070
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C79200 NtClose, 15_2_00C79200
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C79370 NtAllocateVirtualMemory, 15_2_00C79370
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C78F00 NtCreateFile, 15_2_00C78F00
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03273520 NtSetContextThread, 15_2_03273520
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0327453D NtMapViewOfSection, 15_2_0327453D
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03273B42 NtResumeThread, 15_2_03273B42
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03274908 NtUnmapViewOfSection, 15_2_03274908
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03273830 NtSuspendThread, 15_2_03273830
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03273E50 NtQueueApcThread, 15_2_03273E50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_00418383 5_2_00418383
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_004029EB 5_2_004029EB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_004029F0 5_2_004029F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_0042E9F3 5_2_0042E9F3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_004011A0 5_2_004011A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_00402240 5_2_00402240
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_0040FC5B 5_2_0040FC5B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_0040FC63 5_2_0040FC63
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_00402CD0 5_2_00402CD0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_00402560 5_2_00402560
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_004165C3 5_2_004165C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_004165BE 5_2_004165BE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_0040FE83 5_2_0040FE83
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_00402F50 5_2_00402F50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_0040DF03 5_2_0040DF03
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F3D5B0 5_2_05F3D5B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F60591 5_2_05F60591
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F57571 5_2_05F57571
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA0535 5_2_05EA0535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F4E4F6 5_2_05F4E4F6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E91460 5_2_05E91460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F52446 5_2_05F52446
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F5F43F 5_2_05F5F43F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9C7C0 5_2_05E9C7C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F5F7B0 5_2_05F5F7B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA0770 5_2_05EA0770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC4750 5_2_05EC4750
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBC6E0 5_2_05EBC6E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F516CC 5_2_05F516CC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F581CC 5_2_05F581CC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EAB1B0 5_2_05EAB1B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F601AA 5_2_05F601AA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED516C 5_2_05ED516C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F172 5_2_05E8F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F6B16B 5_2_05F6B16B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E90100 5_2_05E90100
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F3A118 5_2_05F3A118
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F5F0E0 5_2_05F5F0E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F570E9 5_2_05F570E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA70C0 5_2_05EA70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F4F0CC 5_2_05F4F0CC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F603E6 5_2_05F603E6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EAE3F0 5_2_05EAE3F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EE739A 5_2_05EE739A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8D34C 5_2_05E8D34C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F5A352 5_2_05F5A352
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F5132D 5_2_05F5132D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F412ED 5_2_05F412ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBD2F0 5_2_05EBD2F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBB2C0 5_2_05EBB2C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA52A0 5_2_05EA52A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F40274 5_2_05F40274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9ADE0 5_2_05E9ADE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBFDC0 5_2_05EBFDC0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB8DBF 5_2_05EB8DBF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F57D73 5_2_05F57D73
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA3D40 5_2_05EA3D40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F51D5A 5_2_05F51D5A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EAAD00 5_2_05EAAD00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F5FCF2 5_2_05F5FCF2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E90CF2 5_2_05E90CF2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F40CB5 5_2_05F40CB5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F19C32 5_2_05F19C32
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA0C00 5_2_05EA0C00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E92FC8 5_2_05E92FC8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F5FFB1 5_2_05F5FFB1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA1F92 5_2_05EA1F92
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F14F40 5_2_05F14F40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EE2F28 5_2_05EE2F28
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC0F30 5_2_05EC0F30
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F5FF09 5_2_05F5FF09
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F5EEDB 5_2_05F5EEDB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA9EB0 5_2_05EA9EB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F5CE93 5_2_05F5CE93
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB2E90 5_2_05EB2E90
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA0E59 5_2_05EA0E59
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F5EE26 5_2_05F5EE26
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA29A0 5_2_05EA29A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F6A9A6 5_2_05F6A9A6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB6962 5_2_05EB6962
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA9950 5_2_05EA9950
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBB950 5_2_05EBB950
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA38E0 5_2_05EA38E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECE8F0 5_2_05ECE8F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E868B8 5_2_05E868B8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA2840 5_2_05EA2840
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EAA840 5_2_05EAA840
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F0D800 5_2_05F0D800
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EDDBF9 5_2_05EDDBF9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F56BD7 5_2_05F56BD7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBFB80 5_2_05EBFB80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F5FB76 5_2_05F5FB76
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F5AB40 5_2_05F5AB40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F4DAC6 5_2_05F4DAC6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EE5AA0 5_2_05EE5AA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F3DAAC 5_2_05F3DAAC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9EA80 5_2_05E9EA80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F13A6C 5_2_05F13A6C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F57A46 5_2_05F57A46
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F5FA49 5_2_05F5FA49
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0343A352 15_2_0343A352
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0343132D 15_2_0343132D
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0336D34C 15_2_0336D34C
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_034403E6 15_2_034403E6
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033C739A 15_2_033C739A
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0338E3F0 15_2_0338E3F0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03420274 15_2_03420274
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033852A0 15_2_033852A0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_034212ED 15_2_034212ED
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0339D2F0 15_2_0339D2F0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0339B2C0 15_2_0339B2C0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03408158 15_2_03408158
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0344B16B 15_2_0344B16B
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03370100 15_2_03370100
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0336F172 15_2_0336F172
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033B516C 15_2_033B516C
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0341A118 15_2_0341A118
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0338B1B0 15_2_0338B1B0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_034381CC 15_2_034381CC
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_034401AA 15_2_034401AA
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0342F0CC 15_2_0342F0CC
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0343F0E0 15_2_0343F0E0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_034370E9 15_2_034370E9
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033870C0 15_2_033870C0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03380770 15_2_03380770
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033A4750 15_2_033A4750
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0343F7B0 15_2_0343F7B0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0337C7C0 15_2_0337C7C0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_034316CC 15_2_034316CC
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0339C6E0 15_2_0339C6E0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03380535 15_2_03380535
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03437571 15_2_03437571
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03440591 15_2_03440591
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0341D5B0 15_2_0341D5B0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03432446 15_2_03432446
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03371460 15_2_03371460
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0343F43F 15_2_0343F43F
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0342E4F6 15_2_0342E4F6
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0343AB40 15_2_0343AB40
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0343FB76 15_2_0343FB76
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03436BD7 15_2_03436BD7
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0339FB80 15_2_0339FB80
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033BDBF9 15_2_033BDBF9
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033F5BF0 15_2_033F5BF0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03437A46 15_2_03437A46
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0343FA49 15_2_0343FA49
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033F3A6C 15_2_033F3A6C
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0342DAC6 15_2_0342DAC6
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033C5AA0 15_2_033C5AA0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0337EA80 15_2_0337EA80
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0341DAAC 15_2_0341DAAC
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03396962 15_2_03396962
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03389950 15_2_03389950
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0339B950 15_2_0339B950
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033829A0 15_2_033829A0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0344A9A6 15_2_0344A9A6
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033ED800 15_2_033ED800
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0338A840 15_2_0338A840
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03382840 15_2_03382840
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033668B8 15_2_033668B8
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033AE8F0 15_2_033AE8F0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033838E0 15_2_033838E0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033A0F30 15_2_033A0F30
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033C2F28 15_2_033C2F28
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0343FF09 15_2_0343FF09
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033F4F40 15_2_033F4F40
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03381F92 15_2_03381F92
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0343FFB1 15_2_0343FFB1
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03372FC8 15_2_03372FC8
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03380E59 15_2_03380E59
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0343EE26 15_2_0343EE26
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03389EB0 15_2_03389EB0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0343EEDB 15_2_0343EEDB
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03392E90 15_2_03392E90
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0343CE93 15_2_0343CE93
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03431D5A 15_2_03431D5A
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03437D73 15_2_03437D73
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0338AD00 15_2_0338AD00
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03383D40 15_2_03383D40
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03398DBF 15_2_03398DBF
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0337ADE0 15_2_0337ADE0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0339FDC0 15_2_0339FDC0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033F9C32 15_2_033F9C32
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03380C00 15_2_03380C00
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0343FCF2 15_2_0343FCF2
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03370CF2 15_2_03370CF2
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_03420CB5 15_2_03420CB5
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C61B50 15_2_00C61B50
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C651B0 15_2_00C651B0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C633EB 15_2_00C633EB
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C633F0 15_2_00C633F0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C7B820 15_2_00C7B820
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C5CA88 15_2_00C5CA88
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C5CA90 15_2_00C5CA90
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C5CCB0 15_2_00C5CCB0
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C5AD30 15_2_00C5AD30
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0326E353 15_2_0326E353
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0326E238 15_2_0326E238
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0326D7B8 15_2_0326D7B8
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0326E6EC 15_2_0326E6EC
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_0326CA68 15_2_0326CA68
Source: C:\Windows\SysWOW64\fltMC.exe Code function: String function: 033FF290 appears 103 times
Source: C:\Windows\SysWOW64\fltMC.exe Code function: String function: 033B5130 appears 36 times
Source: C:\Windows\SysWOW64\fltMC.exe Code function: String function: 033C7E54 appears 93 times
Source: C:\Windows\SysWOW64\fltMC.exe Code function: String function: 0336B970 appears 250 times
Source: C:\Windows\SysWOW64\fltMC.exe Code function: String function: 033EEA12 appears 86 times
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: String function: 05F1F290 appears 103 times
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: String function: 05ED5130 appears 36 times
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: String function: 05F0EA12 appears 84 times
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: String function: 05EE7E54 appears 85 times
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: String function: 05E8B970 appears 248 times
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 6908 -s 1532
Source: 7950COPY.exe Static PE information: No import functions for PE file found
Source: 7950COPY.exe, 00000000.00000002.2311713328.0000000015DDC000.00000004.80000000.00040000.00000000.sdmp Binary or memory string: OriginalFilenameilasm.exeT vs 7950COPY.exe
Source: 7950COPY.exe, 00000000.00000000.1738544482.0000017095B06000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilenameNewStb.exe4 vs 7950COPY.exe
Source: 7950COPY.exe Binary or memory string: OriginalFilenameNewStb.exe4 vs 7950COPY.exe
Source: classification engine Classification label: mal100.troj.expl.evad.winEXE@18/10@0/0
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Mutant created: NULL
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4228:120:WilError_03
Source: C:\Windows\System32\WerFault.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess6908
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File created: C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_3mwi2efp.lkh.ps1 Jump to behavior
Source: 7950COPY.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\7950COPY.exe File read: C:\Users\user\Desktop\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: 7950COPY.exe ReversingLabs: Detection: 63%
Source: C:\Users\user\Desktop\7950COPY.exe File read: C:\Users\user\Desktop\7950COPY.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\7950COPY.exe "C:\Users\user\Desktop\7950COPY.exe"
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\7950COPY.exe" -Force
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\regedit.exe "C:\Windows\regedit.exe"
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe"
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe"
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe"
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 6908 -s 1532
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\System32\wbem\WmiPrvSE.exe C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\SysWOW64\psr.exe "C:\Windows\SysWOW64\psr.exe"
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\SysWOW64\fltMC.exe "C:\Windows\SysWOW64\fltMC.exe"
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\7950COPY.exe" -Force Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\regedit.exe "C:\Windows\regedit.exe" Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe" Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe" Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\SysWOW64\psr.exe "C:\Windows\SysWOW64\psr.exe" Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\SysWOW64\fltMC.exe "C:\Windows\SysWOW64\fltMC.exe" Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: slc.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: atl.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: msisip.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wshext.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: appxsip.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: opcservices.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: microsoft.management.infrastructure.native.unmanaged.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: mi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: miutils.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wmidcom.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: dpapi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: fastprox.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: ncobjapi.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: mpclient.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: wmitomi.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: mi.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: miutils.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: miutils.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\fltMC.exe Section loaded: fltlib.dll Jump to behavior
Source: C:\Windows\SysWOW64\fltMC.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32 Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\Desktop\7950COPY.exe File opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dll Jump to behavior
Source: 7950COPY.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
Source: 7950COPY.exe Static file information: File size 2238495 > 1048576
Source: 7950COPY.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: System.Windows.Forms.pdb source: WER40CA.tmp.dmp.9.dr
Source: Binary string: fltMC.pdb source: ilasm.exe, 00000005.00000002.2188442822.0000000005BB8000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: mscorlib.pdb source: WER40CA.tmp.dmp.9.dr
Source: Binary string: System.ni.pdbRSDS source: WER40CA.tmp.dmp.9.dr
Source: Binary string: .pdbError: CoCreateInstance(IID_ISymUnmanagedWriter) returns %X source: 7950COPY.exe, 00000000.00000002.2311713328.0000000015DDC000.00000004.80000000.00040000.00000000.sdmp, fltMC.exe, 0000000F.00000002.3601098295.0000000002E90000.00000004.00000020.00020000.00000000.sdmp, fltMC.exe, 0000000F.00000002.3601717977.00000000039AC000.00000004.10000000.00040000.00000000.sdmp
Source: Binary string: System.Windows.Forms.ni.pdbRSDS source: WER40CA.tmp.dmp.9.dr
Source: Binary string: System.Windows.Forms.ni.pdb source: WER40CA.tmp.dmp.9.dr
Source: Binary string: System.Drawing.pdb source: WER40CA.tmp.dmp.9.dr
Source: Binary string: mscorlib.ni.pdb source: WER40CA.tmp.dmp.9.dr
Source: Binary string: wntdll.pdbUGP source: ilasm.exe, 00000005.00000002.2188520319.0000000005E60000.00000040.00001000.00020000.00000000.sdmp, fltMC.exe, 0000000F.00000002.3601401909.00000000034DE000.00000040.00001000.00020000.00000000.sdmp, fltMC.exe, 0000000F.00000003.2188880100.0000000002FE3000.00000004.00000020.00020000.00000000.sdmp, fltMC.exe, 0000000F.00000003.2190926695.0000000003199000.00000004.00000020.00020000.00000000.sdmp, fltMC.exe, 0000000F.00000002.3601401909.0000000003340000.00000040.00001000.00020000.00000000.sdmp
Source: Binary string: System.Drawing.ni.pdb source: WER40CA.tmp.dmp.9.dr
Source: Binary string: wntdll.pdb source: ilasm.exe, ilasm.exe, 00000005.00000002.2188520319.0000000005E60000.00000040.00001000.00020000.00000000.sdmp, fltMC.exe, fltMC.exe, 0000000F.00000002.3601401909.00000000034DE000.00000040.00001000.00020000.00000000.sdmp, fltMC.exe, 0000000F.00000003.2188880100.0000000002FE3000.00000004.00000020.00020000.00000000.sdmp, fltMC.exe, 0000000F.00000003.2190926695.0000000003199000.00000004.00000020.00020000.00000000.sdmp, fltMC.exe, 0000000F.00000002.3601401909.0000000003340000.00000040.00001000.00020000.00000000.sdmp
Source: Binary string: System.Core.pdb source: WER40CA.tmp.dmp.9.dr
Source: Binary string: mscorlib.ni.pdbRSDS7^3l source: WER40CA.tmp.dmp.9.dr
Source: Binary string: System.Drawing.pdb source: WER40CA.tmp.dmp.9.dr
Source: Binary string: ilasm.pdb source: 7950COPY.exe, 00000000.00000002.2311713328.0000000015DDC000.00000004.80000000.00040000.00000000.sdmp, fltMC.exe, 0000000F.00000002.3601098295.0000000002E90000.00000004.00000020.00020000.00000000.sdmp, fltMC.exe, 0000000F.00000002.3601717977.00000000039AC000.00000004.10000000.00040000.00000000.sdmp
Source: Binary string: System.Drawing.ni.pdbRSDS source: WER40CA.tmp.dmp.9.dr
Source: Binary string: fltMC.pdbGCTL source: ilasm.exe, 00000005.00000002.2188442822.0000000005BB8000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: System.Windows.Forms.pdb source: WER40CA.tmp.dmp.9.dr
Source: Binary string: System.ni.pdb source: WER40CA.tmp.dmp.9.dr
Source: Binary string: System.pdb source: WER40CA.tmp.dmp.9.dr
Source: Binary string: System.Core.ni.pdbRSDS source: WER40CA.tmp.dmp.9.dr
Source: Binary string: System.Core.ni.pdb source: WER40CA.tmp.dmp.9.dr

Data Obfuscation

barindex
Source: 7950COPY.exe, .cs .Net Code: System.AppDomain.Load(byte[])
Source: 7950COPY.exe, .cs .Net Code: System.AppDomain.Load(byte[])
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_0041480E pushad ; ret 5_2_0041481C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_0040D14B push ss; iretd 5_2_0040D14C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_00407105 push ds; iretd 5_2_00407108
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_004031D0 push eax; ret 5_2_004031D2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_0040D1A0 push 00000043h; ret 5_2_0040D1A5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_0040BAFD push es; ret 5_2_0040BB00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_0041A383 push ebp; ret 5_2_0041A3BB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_0041645F pushad ; iretd 5_2_0041645E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_0041643E pushad ; iretd 5_2_0041645E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_00418D0B pushfd ; retf 5_2_00418D14
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_004235E3 push edi; retf 5_2_004235EC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_00417E6B push edx; ret 5_2_00417E6C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_00401602 push ebx; ret 5_2_00401603
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_00417E1F push F4118F09h; iretd 5_2_00417E26
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_00404FE0 push esi; retf 5_2_00404FE5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E909AD push ecx; mov dword ptr [esp], ecx 5_2_05E909B6
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_033709AD push ecx; mov dword ptr [esp], ecx 15_2_033709B6
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C671B0 push ebp; ret 15_2_00C671E8
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C6328C pushad ; iretd 15_2_00C6328B
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C6F2BF push esi; retn 0000h 15_2_00C6F2C7
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C6326B pushad ; iretd 15_2_00C6328B
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C7040D push edi; retf 15_2_00C70419
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C70410 push edi; retf 15_2_00C70419
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C6163B pushad ; ret 15_2_00C61649
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C709D1 push esp; retf 15_2_00C709DD
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C709B6 push ebx; retf 15_2_00C709B7
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C5892A push es; ret 15_2_00C5892D
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C65B38 pushfd ; retf 15_2_00C65B41
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C64C98 push edx; ret 15_2_00C64C99
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C64C4C push F4118F09h; iretd 15_2_00C64C53
Source: C:\Windows\SysWOW64\fltMC.exe Code function: 15_2_00C51E0D push esi; retf 15_2_00C51E12

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\fltMC.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior

Malware Analysis System Evasion

barindex
Source: Yara match File source: Process Memory Space: 7950COPY.exe PID: 6908, type: MEMORYSTR
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe API/Special instruction interceptor: Address: 7FFE2220D324
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe API/Special instruction interceptor: Address: 7FFE22210774
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe API/Special instruction interceptor: Address: 7FFE22210154
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe API/Special instruction interceptor: Address: 7FFE2220D8A4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe API/Special instruction interceptor: Address: 7FFE2220DA44
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe API/Special instruction interceptor: Address: 7FFE2220D1E4
Source: C:\Windows\SysWOW64\fltMC.exe API/Special instruction interceptor: Address: 7FFE2220D324
Source: C:\Windows\SysWOW64\fltMC.exe API/Special instruction interceptor: Address: 7FFE22210774
Source: C:\Windows\SysWOW64\fltMC.exe API/Special instruction interceptor: Address: 7FFE2220D944
Source: C:\Windows\SysWOW64\fltMC.exe API/Special instruction interceptor: Address: 7FFE2220D504
Source: C:\Windows\SysWOW64\fltMC.exe API/Special instruction interceptor: Address: 7FFE2220D544
Source: C:\Windows\SysWOW64\fltMC.exe API/Special instruction interceptor: Address: 7FFE2220D1E4
Source: C:\Windows\SysWOW64\fltMC.exe API/Special instruction interceptor: Address: 7FFE22210154
Source: C:\Windows\SysWOW64\fltMC.exe API/Special instruction interceptor: Address: 7FFE2220D8A4
Source: C:\Windows\SysWOW64\fltMC.exe API/Special instruction interceptor: Address: 7FFE2220DA44
Source: 7950COPY.exe, 00000000.00000002.2314358721.0000017097B34000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: WINE_GET_UNIX_FILE_NAME
Source: 7950COPY.exe, 00000000.00000002.2314358721.0000017097B34000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: SBIEDLL.DLL
Source: C:\Users\user\Desktop\7950COPY.exe Memory allocated: 17095E40000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Memory allocated: 170AF800000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Memory allocated: 170B7EC0000 memory reserve | memory write watch Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F0D1C0 rdtsc 5_2_05F0D1C0
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 5747 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 3158 Jump to behavior
Source: C:\Windows\SysWOW64\fltMC.exe Window / User API: threadDelayed 3370 Jump to behavior
Source: C:\Windows\SysWOW64\fltMC.exe Window / User API: threadDelayed 6605 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe API coverage: 1.0 %
Source: C:\Windows\SysWOW64\fltMC.exe API coverage: 1.9 %
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 5288 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 6012 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Windows\SysWOW64\fltMC.exe TID: 1364 Thread sleep count: 3370 > 30 Jump to behavior
Source: C:\Windows\SysWOW64\fltMC.exe TID: 1364 Thread sleep time: -6740000s >= -30000s Jump to behavior
Source: C:\Windows\SysWOW64\fltMC.exe TID: 1364 Thread sleep count: 6605 > 30 Jump to behavior
Source: C:\Windows\SysWOW64\fltMC.exe TID: 1364 Thread sleep time: -13210000s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Last function: Thread delayed
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Last function: Thread delayed
Source: C:\Windows\SysWOW64\fltMC.exe Last function: Thread delayed
Source: C:\Windows\SysWOW64\fltMC.exe Last function: Thread delayed
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: Amcache.hve.9.dr Binary or memory string: VMware
Source: Amcache.hve.9.dr Binary or memory string: VMware Virtual USB Mouse
Source: Amcache.hve.9.dr Binary or memory string: vmci.syshbin
Source: Amcache.hve.9.dr Binary or memory string: VMware, Inc.
Source: 7950COPY.exe, 00000000.00000002.2314358721.0000017097B34000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\
Source: Amcache.hve.9.dr Binary or memory string: VMware20,1hbin@
Source: Amcache.hve.9.dr Binary or memory string: c:\windows\system32\driverstore\filerepository\vmci.inf_amd64_68ed49469341f563
Source: Amcache.hve.9.dr Binary or memory string: Ascsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000
Source: Amcache.hve.9.dr Binary or memory string: .Z$c:/windows/system32/drivers/vmci.sys
Source: Amcache.hve.9.dr Binary or memory string: :scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000
Source: 7950COPY.exe, 00000000.00000002.2314358721.0000017097B34000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: VMWARE
Source: 7950COPY.exe, 00000000.00000002.2314358721.0000017097B34000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: InstallPath%C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\'C:\WINDOWS\system32\drivers\vmmouse.sys&C:\WINDOWS\system32\drivers\vmhgfs.sys
Source: Amcache.hve.9.dr Binary or memory string: pci\ven_15ad&dev_0740&subsys_074015ad,pci\ven_15ad&dev_0740,root\vmwvmcihostdev
Source: 7950COPY.exe, 00000000.00000002.2314358721.0000017097B34000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: VMWARE"SOFTWARE\VMware, Inc.\VMware ToolsLHARDWARE\DEVICEMAP\Scsi\Scsi Port 1\Scsi Bus 0\Target Id 0\Logical Unit Id 0LHARDWARE\DEVICEMAP\Scsi\Scsi Port 2\Scsi Bus 0\Target Id 0\Logical Unit Id 0'SYSTEM\ControlSet001\Services\Disk\Enum
Source: 7950COPY.exe, 00000000.00000002.2314358721.0000017097B34000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: VMware SVGA II
Source: Amcache.hve.9.dr Binary or memory string: c:/windows/system32/drivers/vmci.sys
Source: Amcache.hve.9.dr Binary or memory string: scsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000
Source: 7950COPY.exe, 00000000.00000002.2313369865.0000017095CDB000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: Amcache.hve.9.dr Binary or memory string: vmci.sys
Source: Amcache.hve.9.dr Binary or memory string: VMware-56 4d 43 71 48 15 3d ed-ae e6 c7 5a ec d9 3b f0
Source: 7950COPY.exe, 00000000.00000002.2314358721.0000017097B34000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: C:\WINDOWS\system32\drivers\vmmouse.sys
Source: fltMC.exe, 0000000F.00000002.3601098295.0000000002E90000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll;
Source: Amcache.hve.9.dr Binary or memory string: vmci.syshbin`
Source: 7950COPY.exe, 00000000.00000002.2314358721.0000017097B34000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: vmware
Source: Amcache.hve.9.dr Binary or memory string: \driver\vmci,\driver\pci
Source: 7950COPY.exe, 00000000.00000002.2314358721.0000017097B34000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: C:\WINDOWS\system32\drivers\vmhgfs.sys
Source: 7950COPY.exe, 00000000.00000002.2314358721.0000017097B34000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: SOFTWARE\VMware, Inc.\VMware Tools
Source: Amcache.hve.9.dr Binary or memory string: scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000
Source: Amcache.hve.9.dr Binary or memory string: VMware20,1
Source: Amcache.hve.9.dr Binary or memory string: Microsoft Hyper-V Generation Counter
Source: Amcache.hve.9.dr Binary or memory string: NECVMWar VMware SATA CD00
Source: Amcache.hve.9.dr Binary or memory string: VMware Virtual disk SCSI Disk Device
Source: Amcache.hve.9.dr Binary or memory string: scsi\cdromnecvmwarvmware_sata_cd001.00,scsi\cdromnecvmwarvmware_sata_cd00,scsi\cdromnecvmwar,scsi\necvmwarvmware_sata_cd001,necvmwarvmware_sata_cd001,gencdrom
Source: Amcache.hve.9.dr Binary or memory string: scsi\diskvmware__virtual_disk____2.0_,scsi\diskvmware__virtual_disk____,scsi\diskvmware__,scsi\vmware__virtual_disk____2,vmware__virtual_disk____2,gendisk
Source: Amcache.hve.9.dr Binary or memory string: Microsoft Hyper-V Virtualization Infrastructure Driver
Source: Amcache.hve.9.dr Binary or memory string: VMware PCI VMCI Bus Device
Source: 7950COPY.exe, 00000000.00000002.2314358721.0000017097B34000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: noValueButYesKey)C:\WINDOWS\system32\drivers\VBoxMouse.sys
Source: 7950COPY.exe, 00000000.00000002.2314358721.0000017097B34000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: C:\WINDOWS\system32\drivers\VBoxMouse.sys
Source: Amcache.hve.9.dr Binary or memory string: VMware VMCI Bus Device
Source: Amcache.hve.9.dr Binary or memory string: VMware Virtual RAM
Source: Amcache.hve.9.dr Binary or memory string: BiosVendor:VMware, Inc.,BiosVersion:VMW201.00V.20829224.B64.2211211842,BiosReleaseDate:11/21/2022,BiosMajorRelease:0xff,BiosMinorRelease:0xff,SystemManufacturer:VMware, Inc.,SystemProduct:VMware20,1,SystemFamily:,SystemSKUNumber:,BaseboardManufacturer:,BaseboardProduct:,BaseboardVersion:,EnclosureType:0x1
Source: Amcache.hve.9.dr Binary or memory string: vmci.inf_amd64_68ed49469341f563
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process queried: DebugPort Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Process queried: DebugPort Jump to behavior
Source: C:\Windows\SysWOW64\fltMC.exe Process queried: DebugPort Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F0D1C0 rdtsc 5_2_05F0D1C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_00417513 LdrLoadDll, 5_2_00417513
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECC5ED mov eax, dword ptr fs:[00000030h] 5_2_05ECC5ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECC5ED mov eax, dword ptr fs:[00000030h] 5_2_05ECC5ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E925E0 mov eax, dword ptr fs:[00000030h] 5_2_05E925E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBE5E7 mov eax, dword ptr fs:[00000030h] 5_2_05EBE5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBE5E7 mov eax, dword ptr fs:[00000030h] 5_2_05EBE5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBE5E7 mov eax, dword ptr fs:[00000030h] 5_2_05EBE5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBE5E7 mov eax, dword ptr fs:[00000030h] 5_2_05EBE5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBE5E7 mov eax, dword ptr fs:[00000030h] 5_2_05EBE5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBE5E7 mov eax, dword ptr fs:[00000030h] 5_2_05EBE5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBE5E7 mov eax, dword ptr fs:[00000030h] 5_2_05EBE5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBE5E7 mov eax, dword ptr fs:[00000030h] 5_2_05EBE5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB15F4 mov eax, dword ptr fs:[00000030h] 5_2_05EB15F4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB15F4 mov eax, dword ptr fs:[00000030h] 5_2_05EB15F4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB15F4 mov eax, dword ptr fs:[00000030h] 5_2_05EB15F4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB15F4 mov eax, dword ptr fs:[00000030h] 5_2_05EB15F4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB15F4 mov eax, dword ptr fs:[00000030h] 5_2_05EB15F4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB15F4 mov eax, dword ptr fs:[00000030h] 5_2_05EB15F4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F0D5D0 mov eax, dword ptr fs:[00000030h] 5_2_05F0D5D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F0D5D0 mov ecx, dword ptr fs:[00000030h] 5_2_05F0D5D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F635D7 mov eax, dword ptr fs:[00000030h] 5_2_05F635D7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F635D7 mov eax, dword ptr fs:[00000030h] 5_2_05F635D7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F635D7 mov eax, dword ptr fs:[00000030h] 5_2_05F635D7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECE5CF mov eax, dword ptr fs:[00000030h] 5_2_05ECE5CF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECE5CF mov eax, dword ptr fs:[00000030h] 5_2_05ECE5CF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC55C0 mov eax, dword ptr fs:[00000030h] 5_2_05EC55C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB95DA mov eax, dword ptr fs:[00000030h] 5_2_05EB95DA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E965D0 mov eax, dword ptr fs:[00000030h] 5_2_05E965D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECA5D0 mov eax, dword ptr fs:[00000030h] 5_2_05ECA5D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECA5D0 mov eax, dword ptr fs:[00000030h] 5_2_05ECA5D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F655C9 mov eax, dword ptr fs:[00000030h] 5_2_05F655C9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB15A9 mov eax, dword ptr fs:[00000030h] 5_2_05EB15A9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB15A9 mov eax, dword ptr fs:[00000030h] 5_2_05EB15A9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB15A9 mov eax, dword ptr fs:[00000030h] 5_2_05EB15A9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB15A9 mov eax, dword ptr fs:[00000030h] 5_2_05EB15A9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB15A9 mov eax, dword ptr fs:[00000030h] 5_2_05EB15A9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F235BA mov eax, dword ptr fs:[00000030h] 5_2_05F235BA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F235BA mov eax, dword ptr fs:[00000030h] 5_2_05F235BA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F235BA mov eax, dword ptr fs:[00000030h] 5_2_05F235BA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F235BA mov eax, dword ptr fs:[00000030h] 5_2_05F235BA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F4F5BE mov eax, dword ptr fs:[00000030h] 5_2_05F4F5BE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F105A7 mov eax, dword ptr fs:[00000030h] 5_2_05F105A7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F105A7 mov eax, dword ptr fs:[00000030h] 5_2_05F105A7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F105A7 mov eax, dword ptr fs:[00000030h] 5_2_05F105A7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB45B1 mov eax, dword ptr fs:[00000030h] 5_2_05EB45B1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB45B1 mov eax, dword ptr fs:[00000030h] 5_2_05EB45B1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBF5B0 mov eax, dword ptr fs:[00000030h] 5_2_05EBF5B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBF5B0 mov eax, dword ptr fs:[00000030h] 5_2_05EBF5B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBF5B0 mov eax, dword ptr fs:[00000030h] 5_2_05EBF5B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBF5B0 mov eax, dword ptr fs:[00000030h] 5_2_05EBF5B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBF5B0 mov eax, dword ptr fs:[00000030h] 5_2_05EBF5B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBF5B0 mov eax, dword ptr fs:[00000030h] 5_2_05EBF5B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBF5B0 mov eax, dword ptr fs:[00000030h] 5_2_05EBF5B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBF5B0 mov eax, dword ptr fs:[00000030h] 5_2_05EBF5B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBF5B0 mov eax, dword ptr fs:[00000030h] 5_2_05EBF5B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC4588 mov eax, dword ptr fs:[00000030h] 5_2_05EC4588
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F1B594 mov eax, dword ptr fs:[00000030h] 5_2_05F1B594
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F1B594 mov eax, dword ptr fs:[00000030h] 5_2_05F1B594
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8758F mov eax, dword ptr fs:[00000030h] 5_2_05E8758F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8758F mov eax, dword ptr fs:[00000030h] 5_2_05E8758F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8758F mov eax, dword ptr fs:[00000030h] 5_2_05E8758F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E92582 mov eax, dword ptr fs:[00000030h] 5_2_05E92582
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E92582 mov ecx, dword ptr fs:[00000030h] 5_2_05E92582
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECE59C mov eax, dword ptr fs:[00000030h] 5_2_05ECE59C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC656A mov eax, dword ptr fs:[00000030h] 5_2_05EC656A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC656A mov eax, dword ptr fs:[00000030h] 5_2_05EC656A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC656A mov eax, dword ptr fs:[00000030h] 5_2_05EC656A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8B562 mov eax, dword ptr fs:[00000030h] 5_2_05E8B562
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECB570 mov eax, dword ptr fs:[00000030h] 5_2_05ECB570
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECB570 mov eax, dword ptr fs:[00000030h] 5_2_05ECB570
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E98550 mov eax, dword ptr fs:[00000030h] 5_2_05E98550
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E98550 mov eax, dword ptr fs:[00000030h] 5_2_05E98550
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F65537 mov eax, dword ptr fs:[00000030h] 5_2_05F65537
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBE53E mov eax, dword ptr fs:[00000030h] 5_2_05EBE53E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBE53E mov eax, dword ptr fs:[00000030h] 5_2_05EBE53E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBE53E mov eax, dword ptr fs:[00000030h] 5_2_05EBE53E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBE53E mov eax, dword ptr fs:[00000030h] 5_2_05EBE53E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBE53E mov eax, dword ptr fs:[00000030h] 5_2_05EBE53E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F3F525 mov eax, dword ptr fs:[00000030h] 5_2_05F3F525
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F3F525 mov eax, dword ptr fs:[00000030h] 5_2_05F3F525
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F3F525 mov eax, dword ptr fs:[00000030h] 5_2_05F3F525
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F3F525 mov eax, dword ptr fs:[00000030h] 5_2_05F3F525
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F3F525 mov eax, dword ptr fs:[00000030h] 5_2_05F3F525
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F3F525 mov eax, dword ptr fs:[00000030h] 5_2_05F3F525
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F3F525 mov eax, dword ptr fs:[00000030h] 5_2_05F3F525
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F4B52F mov eax, dword ptr fs:[00000030h] 5_2_05F4B52F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECD530 mov eax, dword ptr fs:[00000030h] 5_2_05ECD530
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECD530 mov eax, dword ptr fs:[00000030h] 5_2_05ECD530
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9D534 mov eax, dword ptr fs:[00000030h] 5_2_05E9D534
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9D534 mov eax, dword ptr fs:[00000030h] 5_2_05E9D534
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9D534 mov eax, dword ptr fs:[00000030h] 5_2_05E9D534
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9D534 mov eax, dword ptr fs:[00000030h] 5_2_05E9D534
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9D534 mov eax, dword ptr fs:[00000030h] 5_2_05E9D534
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9D534 mov eax, dword ptr fs:[00000030h] 5_2_05E9D534
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA0535 mov eax, dword ptr fs:[00000030h] 5_2_05EA0535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA0535 mov eax, dword ptr fs:[00000030h] 5_2_05EA0535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA0535 mov eax, dword ptr fs:[00000030h] 5_2_05EA0535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA0535 mov eax, dword ptr fs:[00000030h] 5_2_05EA0535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA0535 mov eax, dword ptr fs:[00000030h] 5_2_05EA0535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA0535 mov eax, dword ptr fs:[00000030h] 5_2_05EA0535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC7505 mov eax, dword ptr fs:[00000030h] 5_2_05EC7505
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC7505 mov ecx, dword ptr fs:[00000030h] 5_2_05EC7505
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F64500 mov eax, dword ptr fs:[00000030h] 5_2_05F64500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F64500 mov eax, dword ptr fs:[00000030h] 5_2_05F64500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F64500 mov eax, dword ptr fs:[00000030h] 5_2_05F64500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F64500 mov eax, dword ptr fs:[00000030h] 5_2_05F64500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F64500 mov eax, dword ptr fs:[00000030h] 5_2_05F64500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F64500 mov eax, dword ptr fs:[00000030h] 5_2_05F64500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F64500 mov eax, dword ptr fs:[00000030h] 5_2_05F64500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E904E5 mov ecx, dword ptr fs:[00000030h] 5_2_05E904E5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F394E0 mov eax, dword ptr fs:[00000030h] 5_2_05F394E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F654DB mov eax, dword ptr fs:[00000030h] 5_2_05F654DB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F1A4B0 mov eax, dword ptr fs:[00000030h] 5_2_05F1A4B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E964AB mov eax, dword ptr fs:[00000030h] 5_2_05E964AB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC34B0 mov eax, dword ptr fs:[00000030h] 5_2_05EC34B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC44B0 mov ecx, dword ptr fs:[00000030h] 5_2_05EC44B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8B480 mov eax, dword ptr fs:[00000030h] 5_2_05E8B480
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E99486 mov eax, dword ptr fs:[00000030h] 5_2_05E99486
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E99486 mov eax, dword ptr fs:[00000030h] 5_2_05E99486
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E91460 mov eax, dword ptr fs:[00000030h] 5_2_05E91460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E91460 mov eax, dword ptr fs:[00000030h] 5_2_05E91460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E91460 mov eax, dword ptr fs:[00000030h] 5_2_05E91460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E91460 mov eax, dword ptr fs:[00000030h] 5_2_05E91460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E91460 mov eax, dword ptr fs:[00000030h] 5_2_05E91460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F6547F mov eax, dword ptr fs:[00000030h] 5_2_05F6547F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EAF460 mov eax, dword ptr fs:[00000030h] 5_2_05EAF460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EAF460 mov eax, dword ptr fs:[00000030h] 5_2_05EAF460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EAF460 mov eax, dword ptr fs:[00000030h] 5_2_05EAF460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EAF460 mov eax, dword ptr fs:[00000030h] 5_2_05EAF460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EAF460 mov eax, dword ptr fs:[00000030h] 5_2_05EAF460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EAF460 mov eax, dword ptr fs:[00000030h] 5_2_05EAF460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBA470 mov eax, dword ptr fs:[00000030h] 5_2_05EBA470
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBA470 mov eax, dword ptr fs:[00000030h] 5_2_05EBA470
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBA470 mov eax, dword ptr fs:[00000030h] 5_2_05EBA470
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F4F453 mov eax, dword ptr fs:[00000030h] 5_2_05F4F453
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9B440 mov eax, dword ptr fs:[00000030h] 5_2_05E9B440
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9B440 mov eax, dword ptr fs:[00000030h] 5_2_05E9B440
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9B440 mov eax, dword ptr fs:[00000030h] 5_2_05E9B440
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9B440 mov eax, dword ptr fs:[00000030h] 5_2_05E9B440
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9B440 mov eax, dword ptr fs:[00000030h] 5_2_05E9B440
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9B440 mov eax, dword ptr fs:[00000030h] 5_2_05E9B440
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECE443 mov eax, dword ptr fs:[00000030h] 5_2_05ECE443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECE443 mov eax, dword ptr fs:[00000030h] 5_2_05ECE443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECE443 mov eax, dword ptr fs:[00000030h] 5_2_05ECE443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECE443 mov eax, dword ptr fs:[00000030h] 5_2_05ECE443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECE443 mov eax, dword ptr fs:[00000030h] 5_2_05ECE443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECE443 mov eax, dword ptr fs:[00000030h] 5_2_05ECE443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECE443 mov eax, dword ptr fs:[00000030h] 5_2_05ECE443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECE443 mov eax, dword ptr fs:[00000030h] 5_2_05ECE443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB245A mov eax, dword ptr fs:[00000030h] 5_2_05EB245A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8645D mov eax, dword ptr fs:[00000030h] 5_2_05E8645D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8E420 mov eax, dword ptr fs:[00000030h] 5_2_05E8E420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8E420 mov eax, dword ptr fs:[00000030h] 5_2_05E8E420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8E420 mov eax, dword ptr fs:[00000030h] 5_2_05E8E420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8C427 mov eax, dword ptr fs:[00000030h] 5_2_05E8C427
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB340D mov eax, dword ptr fs:[00000030h] 5_2_05EB340D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC8402 mov eax, dword ptr fs:[00000030h] 5_2_05EC8402
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC8402 mov eax, dword ptr fs:[00000030h] 5_2_05EC8402
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC8402 mov eax, dword ptr fs:[00000030h] 5_2_05EC8402
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB27ED mov eax, dword ptr fs:[00000030h] 5_2_05EB27ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB27ED mov eax, dword ptr fs:[00000030h] 5_2_05EB27ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB27ED mov eax, dword ptr fs:[00000030h] 5_2_05EB27ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9D7E0 mov ecx, dword ptr fs:[00000030h] 5_2_05E9D7E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E947FB mov eax, dword ptr fs:[00000030h] 5_2_05E947FB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E947FB mov eax, dword ptr fs:[00000030h] 5_2_05E947FB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9C7C0 mov eax, dword ptr fs:[00000030h] 5_2_05E9C7C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E957C0 mov eax, dword ptr fs:[00000030h] 5_2_05E957C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E957C0 mov eax, dword ptr fs:[00000030h] 5_2_05E957C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E957C0 mov eax, dword ptr fs:[00000030h] 5_2_05E957C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F637B6 mov eax, dword ptr fs:[00000030h] 5_2_05F637B6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E907AF mov eax, dword ptr fs:[00000030h] 5_2_05E907AF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F7BA mov eax, dword ptr fs:[00000030h] 5_2_05E8F7BA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F7BA mov eax, dword ptr fs:[00000030h] 5_2_05E8F7BA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F7BA mov eax, dword ptr fs:[00000030h] 5_2_05E8F7BA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F7BA mov eax, dword ptr fs:[00000030h] 5_2_05E8F7BA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F7BA mov eax, dword ptr fs:[00000030h] 5_2_05E8F7BA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F7BA mov eax, dword ptr fs:[00000030h] 5_2_05E8F7BA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F7BA mov eax, dword ptr fs:[00000030h] 5_2_05E8F7BA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F7BA mov eax, dword ptr fs:[00000030h] 5_2_05E8F7BA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F7BA mov eax, dword ptr fs:[00000030h] 5_2_05E8F7BA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F197A9 mov eax, dword ptr fs:[00000030h] 5_2_05F197A9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBD7B0 mov eax, dword ptr fs:[00000030h] 5_2_05EBD7B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F1F7AF mov eax, dword ptr fs:[00000030h] 5_2_05F1F7AF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F1F7AF mov eax, dword ptr fs:[00000030h] 5_2_05F1F7AF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F1F7AF mov eax, dword ptr fs:[00000030h] 5_2_05F1F7AF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F1F7AF mov eax, dword ptr fs:[00000030h] 5_2_05F1F7AF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F1F7AF mov eax, dword ptr fs:[00000030h] 5_2_05F1F7AF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F4F78A mov eax, dword ptr fs:[00000030h] 5_2_05F4F78A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8B765 mov eax, dword ptr fs:[00000030h] 5_2_05E8B765
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8B765 mov eax, dword ptr fs:[00000030h] 5_2_05E8B765
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8B765 mov eax, dword ptr fs:[00000030h] 5_2_05E8B765
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8B765 mov eax, dword ptr fs:[00000030h] 5_2_05E8B765
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E98770 mov eax, dword ptr fs:[00000030h] 5_2_05E98770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA0770 mov eax, dword ptr fs:[00000030h] 5_2_05EA0770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA0770 mov eax, dword ptr fs:[00000030h] 5_2_05EA0770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA0770 mov eax, dword ptr fs:[00000030h] 5_2_05EA0770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA0770 mov eax, dword ptr fs:[00000030h] 5_2_05EA0770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA0770 mov eax, dword ptr fs:[00000030h] 5_2_05EA0770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA0770 mov eax, dword ptr fs:[00000030h] 5_2_05EA0770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA0770 mov eax, dword ptr fs:[00000030h] 5_2_05EA0770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA0770 mov eax, dword ptr fs:[00000030h] 5_2_05EA0770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA0770 mov eax, dword ptr fs:[00000030h] 5_2_05EA0770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA0770 mov eax, dword ptr fs:[00000030h] 5_2_05EA0770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA0770 mov eax, dword ptr fs:[00000030h] 5_2_05EA0770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA0770 mov eax, dword ptr fs:[00000030h] 5_2_05EA0770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC674D mov esi, dword ptr fs:[00000030h] 5_2_05EC674D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC674D mov eax, dword ptr fs:[00000030h] 5_2_05EC674D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC674D mov eax, dword ptr fs:[00000030h] 5_2_05EC674D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F14755 mov eax, dword ptr fs:[00000030h] 5_2_05F14755
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA3740 mov eax, dword ptr fs:[00000030h] 5_2_05EA3740
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA3740 mov eax, dword ptr fs:[00000030h] 5_2_05EA3740
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA3740 mov eax, dword ptr fs:[00000030h] 5_2_05EA3740
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E90750 mov eax, dword ptr fs:[00000030h] 5_2_05E90750
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2750 mov eax, dword ptr fs:[00000030h] 5_2_05ED2750
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2750 mov eax, dword ptr fs:[00000030h] 5_2_05ED2750
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F63749 mov eax, dword ptr fs:[00000030h] 5_2_05F63749
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F0C730 mov eax, dword ptr fs:[00000030h] 5_2_05F0C730
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E93720 mov eax, dword ptr fs:[00000030h] 5_2_05E93720
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F6B73C mov eax, dword ptr fs:[00000030h] 5_2_05F6B73C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F6B73C mov eax, dword ptr fs:[00000030h] 5_2_05F6B73C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F6B73C mov eax, dword ptr fs:[00000030h] 5_2_05F6B73C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F6B73C mov eax, dword ptr fs:[00000030h] 5_2_05F6B73C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EAF720 mov eax, dword ptr fs:[00000030h] 5_2_05EAF720
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EAF720 mov eax, dword ptr fs:[00000030h] 5_2_05EAF720
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EAF720 mov eax, dword ptr fs:[00000030h] 5_2_05EAF720
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECC720 mov eax, dword ptr fs:[00000030h] 5_2_05ECC720
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECC720 mov eax, dword ptr fs:[00000030h] 5_2_05ECC720
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC273C mov eax, dword ptr fs:[00000030h] 5_2_05EC273C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC273C mov ecx, dword ptr fs:[00000030h] 5_2_05EC273C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC273C mov eax, dword ptr fs:[00000030h] 5_2_05EC273C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9973A mov eax, dword ptr fs:[00000030h] 5_2_05E9973A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9973A mov eax, dword ptr fs:[00000030h] 5_2_05E9973A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E89730 mov eax, dword ptr fs:[00000030h] 5_2_05E89730
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E89730 mov eax, dword ptr fs:[00000030h] 5_2_05E89730
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC5734 mov eax, dword ptr fs:[00000030h] 5_2_05EC5734
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F4F72E mov eax, dword ptr fs:[00000030h] 5_2_05F4F72E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F5972B mov eax, dword ptr fs:[00000030h] 5_2_05F5972B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E97703 mov eax, dword ptr fs:[00000030h] 5_2_05E97703
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E95702 mov eax, dword ptr fs:[00000030h] 5_2_05E95702
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E95702 mov eax, dword ptr fs:[00000030h] 5_2_05E95702
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECC700 mov eax, dword ptr fs:[00000030h] 5_2_05ECC700
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECF71F mov eax, dword ptr fs:[00000030h] 5_2_05ECF71F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECF71F mov eax, dword ptr fs:[00000030h] 5_2_05ECF71F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E90710 mov eax, dword ptr fs:[00000030h] 5_2_05E90710
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC0710 mov eax, dword ptr fs:[00000030h] 5_2_05EC0710
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F106F1 mov eax, dword ptr fs:[00000030h] 5_2_05F106F1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F106F1 mov eax, dword ptr fs:[00000030h] 5_2_05F106F1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F0E6F2 mov eax, dword ptr fs:[00000030h] 5_2_05F0E6F2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F0E6F2 mov eax, dword ptr fs:[00000030h] 5_2_05F0E6F2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F0E6F2 mov eax, dword ptr fs:[00000030h] 5_2_05F0E6F2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F0E6F2 mov eax, dword ptr fs:[00000030h] 5_2_05F0E6F2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F4D6F0 mov eax, dword ptr fs:[00000030h] 5_2_05F4D6F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBD6E0 mov eax, dword ptr fs:[00000030h] 5_2_05EBD6E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBD6E0 mov eax, dword ptr fs:[00000030h] 5_2_05EBD6E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F236EE mov eax, dword ptr fs:[00000030h] 5_2_05F236EE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F236EE mov eax, dword ptr fs:[00000030h] 5_2_05F236EE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F236EE mov eax, dword ptr fs:[00000030h] 5_2_05F236EE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F236EE mov eax, dword ptr fs:[00000030h] 5_2_05F236EE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F236EE mov eax, dword ptr fs:[00000030h] 5_2_05F236EE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F236EE mov eax, dword ptr fs:[00000030h] 5_2_05F236EE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC16CF mov eax, dword ptr fs:[00000030h] 5_2_05EC16CF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9B6C0 mov eax, dword ptr fs:[00000030h] 5_2_05E9B6C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9B6C0 mov eax, dword ptr fs:[00000030h] 5_2_05E9B6C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9B6C0 mov eax, dword ptr fs:[00000030h] 5_2_05E9B6C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9B6C0 mov eax, dword ptr fs:[00000030h] 5_2_05E9B6C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9B6C0 mov eax, dword ptr fs:[00000030h] 5_2_05E9B6C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9B6C0 mov eax, dword ptr fs:[00000030h] 5_2_05E9B6C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECA6C7 mov ebx, dword ptr fs:[00000030h] 5_2_05ECA6C7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECA6C7 mov eax, dword ptr fs:[00000030h] 5_2_05ECA6C7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F4F6C7 mov eax, dword ptr fs:[00000030h] 5_2_05F4F6C7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F516CC mov eax, dword ptr fs:[00000030h] 5_2_05F516CC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F516CC mov eax, dword ptr fs:[00000030h] 5_2_05F516CC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F516CC mov eax, dword ptr fs:[00000030h] 5_2_05F516CC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F516CC mov eax, dword ptr fs:[00000030h] 5_2_05F516CC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8D6AA mov eax, dword ptr fs:[00000030h] 5_2_05E8D6AA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8D6AA mov eax, dword ptr fs:[00000030h] 5_2_05E8D6AA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECC6A6 mov eax, dword ptr fs:[00000030h] 5_2_05ECC6A6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E876B2 mov eax, dword ptr fs:[00000030h] 5_2_05E876B2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E876B2 mov eax, dword ptr fs:[00000030h] 5_2_05E876B2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E876B2 mov eax, dword ptr fs:[00000030h] 5_2_05E876B2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC66B0 mov eax, dword ptr fs:[00000030h] 5_2_05EC66B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E94690 mov eax, dword ptr fs:[00000030h] 5_2_05E94690
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E94690 mov eax, dword ptr fs:[00000030h] 5_2_05E94690
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F1368C mov eax, dword ptr fs:[00000030h] 5_2_05F1368C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F1368C mov eax, dword ptr fs:[00000030h] 5_2_05F1368C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F1368C mov eax, dword ptr fs:[00000030h] 5_2_05F1368C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F1368C mov eax, dword ptr fs:[00000030h] 5_2_05F1368C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECA660 mov eax, dword ptr fs:[00000030h] 5_2_05ECA660
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECA660 mov eax, dword ptr fs:[00000030h] 5_2_05ECA660
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC9660 mov eax, dword ptr fs:[00000030h] 5_2_05EC9660
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC9660 mov eax, dword ptr fs:[00000030h] 5_2_05EC9660
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC2674 mov eax, dword ptr fs:[00000030h] 5_2_05EC2674
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F5866E mov eax, dword ptr fs:[00000030h] 5_2_05F5866E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F5866E mov eax, dword ptr fs:[00000030h] 5_2_05F5866E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EAC640 mov eax, dword ptr fs:[00000030h] 5_2_05EAC640
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F65636 mov eax, dword ptr fs:[00000030h] 5_2_05F65636
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9262C mov eax, dword ptr fs:[00000030h] 5_2_05E9262C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC6620 mov eax, dword ptr fs:[00000030h] 5_2_05EC6620
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC8620 mov eax, dword ptr fs:[00000030h] 5_2_05EC8620
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EAE627 mov eax, dword ptr fs:[00000030h] 5_2_05EAE627
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F626 mov eax, dword ptr fs:[00000030h] 5_2_05E8F626
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F626 mov eax, dword ptr fs:[00000030h] 5_2_05E8F626
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F626 mov eax, dword ptr fs:[00000030h] 5_2_05E8F626
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F626 mov eax, dword ptr fs:[00000030h] 5_2_05E8F626
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F626 mov eax, dword ptr fs:[00000030h] 5_2_05E8F626
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F626 mov eax, dword ptr fs:[00000030h] 5_2_05E8F626
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F626 mov eax, dword ptr fs:[00000030h] 5_2_05E8F626
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F626 mov eax, dword ptr fs:[00000030h] 5_2_05E8F626
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F626 mov eax, dword ptr fs:[00000030h] 5_2_05E8F626
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA260B mov eax, dword ptr fs:[00000030h] 5_2_05EA260B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA260B mov eax, dword ptr fs:[00000030h] 5_2_05EA260B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA260B mov eax, dword ptr fs:[00000030h] 5_2_05EA260B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA260B mov eax, dword ptr fs:[00000030h] 5_2_05EA260B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA260B mov eax, dword ptr fs:[00000030h] 5_2_05EA260B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA260B mov eax, dword ptr fs:[00000030h] 5_2_05EA260B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA260B mov eax, dword ptr fs:[00000030h] 5_2_05EA260B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC1607 mov eax, dword ptr fs:[00000030h] 5_2_05EC1607
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECF603 mov eax, dword ptr fs:[00000030h] 5_2_05ECF603
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED2619 mov eax, dword ptr fs:[00000030h] 5_2_05ED2619
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F0E609 mov eax, dword ptr fs:[00000030h] 5_2_05F0E609
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E93616 mov eax, dword ptr fs:[00000030h] 5_2_05E93616
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E93616 mov eax, dword ptr fs:[00000030h] 5_2_05E93616
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB51EF mov eax, dword ptr fs:[00000030h] 5_2_05EB51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB51EF mov eax, dword ptr fs:[00000030h] 5_2_05EB51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB51EF mov eax, dword ptr fs:[00000030h] 5_2_05EB51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB51EF mov eax, dword ptr fs:[00000030h] 5_2_05EB51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB51EF mov eax, dword ptr fs:[00000030h] 5_2_05EB51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB51EF mov eax, dword ptr fs:[00000030h] 5_2_05EB51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB51EF mov eax, dword ptr fs:[00000030h] 5_2_05EB51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB51EF mov eax, dword ptr fs:[00000030h] 5_2_05EB51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB51EF mov eax, dword ptr fs:[00000030h] 5_2_05EB51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB51EF mov eax, dword ptr fs:[00000030h] 5_2_05EB51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB51EF mov eax, dword ptr fs:[00000030h] 5_2_05EB51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB51EF mov eax, dword ptr fs:[00000030h] 5_2_05EB51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB51EF mov eax, dword ptr fs:[00000030h] 5_2_05EB51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E951ED mov eax, dword ptr fs:[00000030h] 5_2_05E951ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F661E5 mov eax, dword ptr fs:[00000030h] 5_2_05F661E5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC01F8 mov eax, dword ptr fs:[00000030h] 5_2_05EC01F8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F0E1D0 mov eax, dword ptr fs:[00000030h] 5_2_05F0E1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F0E1D0 mov eax, dword ptr fs:[00000030h] 5_2_05F0E1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F0E1D0 mov ecx, dword ptr fs:[00000030h] 5_2_05F0E1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F0E1D0 mov eax, dword ptr fs:[00000030h] 5_2_05F0E1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F0E1D0 mov eax, dword ptr fs:[00000030h] 5_2_05F0E1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F561C3 mov eax, dword ptr fs:[00000030h] 5_2_05F561C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F561C3 mov eax, dword ptr fs:[00000030h] 5_2_05F561C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECD1D0 mov eax, dword ptr fs:[00000030h] 5_2_05ECD1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ECD1D0 mov ecx, dword ptr fs:[00000030h] 5_2_05ECD1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F651CB mov eax, dword ptr fs:[00000030h] 5_2_05F651CB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F411A4 mov eax, dword ptr fs:[00000030h] 5_2_05F411A4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F411A4 mov eax, dword ptr fs:[00000030h] 5_2_05F411A4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F411A4 mov eax, dword ptr fs:[00000030h] 5_2_05F411A4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F411A4 mov eax, dword ptr fs:[00000030h] 5_2_05F411A4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EAB1B0 mov eax, dword ptr fs:[00000030h] 5_2_05EAB1B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED0185 mov eax, dword ptr fs:[00000030h] 5_2_05ED0185
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F1019F mov eax, dword ptr fs:[00000030h] 5_2_05F1019F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F1019F mov eax, dword ptr fs:[00000030h] 5_2_05F1019F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F1019F mov eax, dword ptr fs:[00000030h] 5_2_05F1019F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F1019F mov eax, dword ptr fs:[00000030h] 5_2_05F1019F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F4C188 mov eax, dword ptr fs:[00000030h] 5_2_05F4C188
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F4C188 mov eax, dword ptr fs:[00000030h] 5_2_05F4C188
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EE7190 mov eax, dword ptr fs:[00000030h] 5_2_05EE7190
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8A197 mov eax, dword ptr fs:[00000030h] 5_2_05E8A197
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8A197 mov eax, dword ptr fs:[00000030h] 5_2_05E8A197
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8A197 mov eax, dword ptr fs:[00000030h] 5_2_05E8A197
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F29179 mov eax, dword ptr fs:[00000030h] 5_2_05F29179
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F172 mov eax, dword ptr fs:[00000030h] 5_2_05E8F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F172 mov eax, dword ptr fs:[00000030h] 5_2_05E8F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F172 mov eax, dword ptr fs:[00000030h] 5_2_05E8F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F172 mov eax, dword ptr fs:[00000030h] 5_2_05E8F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F172 mov eax, dword ptr fs:[00000030h] 5_2_05E8F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F172 mov eax, dword ptr fs:[00000030h] 5_2_05E8F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F172 mov eax, dword ptr fs:[00000030h] 5_2_05E8F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F172 mov eax, dword ptr fs:[00000030h] 5_2_05E8F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F172 mov eax, dword ptr fs:[00000030h] 5_2_05E8F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F172 mov eax, dword ptr fs:[00000030h] 5_2_05E8F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F172 mov eax, dword ptr fs:[00000030h] 5_2_05E8F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F172 mov eax, dword ptr fs:[00000030h] 5_2_05E8F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F172 mov eax, dword ptr fs:[00000030h] 5_2_05E8F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F172 mov eax, dword ptr fs:[00000030h] 5_2_05E8F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F172 mov eax, dword ptr fs:[00000030h] 5_2_05E8F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F172 mov eax, dword ptr fs:[00000030h] 5_2_05E8F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F172 mov eax, dword ptr fs:[00000030h] 5_2_05E8F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F172 mov eax, dword ptr fs:[00000030h] 5_2_05E8F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F172 mov eax, dword ptr fs:[00000030h] 5_2_05E8F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F172 mov eax, dword ptr fs:[00000030h] 5_2_05E8F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8F172 mov eax, dword ptr fs:[00000030h] 5_2_05E8F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E89148 mov eax, dword ptr fs:[00000030h] 5_2_05E89148
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E89148 mov eax, dword ptr fs:[00000030h] 5_2_05E89148
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E89148 mov eax, dword ptr fs:[00000030h] 5_2_05E89148
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E89148 mov eax, dword ptr fs:[00000030h] 5_2_05E89148
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F65152 mov eax, dword ptr fs:[00000030h] 5_2_05F65152
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F24144 mov eax, dword ptr fs:[00000030h] 5_2_05F24144
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F24144 mov eax, dword ptr fs:[00000030h] 5_2_05F24144
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F24144 mov ecx, dword ptr fs:[00000030h] 5_2_05F24144
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F24144 mov eax, dword ptr fs:[00000030h] 5_2_05F24144
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F24144 mov eax, dword ptr fs:[00000030h] 5_2_05F24144
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E97152 mov eax, dword ptr fs:[00000030h] 5_2_05E97152
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E96154 mov eax, dword ptr fs:[00000030h] 5_2_05E96154
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E96154 mov eax, dword ptr fs:[00000030h] 5_2_05E96154
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8C156 mov eax, dword ptr fs:[00000030h] 5_2_05E8C156
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC0124 mov eax, dword ptr fs:[00000030h] 5_2_05EC0124
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E91131 mov eax, dword ptr fs:[00000030h] 5_2_05E91131
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E91131 mov eax, dword ptr fs:[00000030h] 5_2_05E91131
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8B136 mov eax, dword ptr fs:[00000030h] 5_2_05E8B136
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8B136 mov eax, dword ptr fs:[00000030h] 5_2_05E8B136
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8B136 mov eax, dword ptr fs:[00000030h] 5_2_05E8B136
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8B136 mov eax, dword ptr fs:[00000030h] 5_2_05E8B136
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F50115 mov eax, dword ptr fs:[00000030h] 5_2_05F50115
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F3A118 mov ecx, dword ptr fs:[00000030h] 5_2_05F3A118
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F3A118 mov eax, dword ptr fs:[00000030h] 5_2_05F3A118
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F3A118 mov eax, dword ptr fs:[00000030h] 5_2_05F3A118
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F3A118 mov eax, dword ptr fs:[00000030h] 5_2_05F3A118
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E980E9 mov eax, dword ptr fs:[00000030h] 5_2_05E980E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8A0E3 mov ecx, dword ptr fs:[00000030h] 5_2_05E8A0E3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB50E4 mov eax, dword ptr fs:[00000030h] 5_2_05EB50E4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB50E4 mov ecx, dword ptr fs:[00000030h] 5_2_05EB50E4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8C0F0 mov eax, dword ptr fs:[00000030h] 5_2_05E8C0F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05ED20F0 mov ecx, dword ptr fs:[00000030h] 5_2_05ED20F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA70C0 mov eax, dword ptr fs:[00000030h] 5_2_05EA70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA70C0 mov ecx, dword ptr fs:[00000030h] 5_2_05EA70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA70C0 mov ecx, dword ptr fs:[00000030h] 5_2_05EA70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA70C0 mov eax, dword ptr fs:[00000030h] 5_2_05EA70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA70C0 mov ecx, dword ptr fs:[00000030h] 5_2_05EA70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA70C0 mov ecx, dword ptr fs:[00000030h] 5_2_05EA70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA70C0 mov eax, dword ptr fs:[00000030h] 5_2_05EA70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA70C0 mov eax, dword ptr fs:[00000030h] 5_2_05EA70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA70C0 mov eax, dword ptr fs:[00000030h] 5_2_05EA70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA70C0 mov eax, dword ptr fs:[00000030h] 5_2_05EA70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA70C0 mov eax, dword ptr fs:[00000030h] 5_2_05EA70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA70C0 mov eax, dword ptr fs:[00000030h] 5_2_05EA70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA70C0 mov eax, dword ptr fs:[00000030h] 5_2_05EA70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA70C0 mov eax, dword ptr fs:[00000030h] 5_2_05EA70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA70C0 mov eax, dword ptr fs:[00000030h] 5_2_05EA70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA70C0 mov eax, dword ptr fs:[00000030h] 5_2_05EA70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA70C0 mov eax, dword ptr fs:[00000030h] 5_2_05EA70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA70C0 mov eax, dword ptr fs:[00000030h] 5_2_05EA70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F120DE mov eax, dword ptr fs:[00000030h] 5_2_05F120DE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F650D9 mov eax, dword ptr fs:[00000030h] 5_2_05F650D9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EB90DB mov eax, dword ptr fs:[00000030h] 5_2_05EB90DB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F0D0C0 mov eax, dword ptr fs:[00000030h] 5_2_05F0D0C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F0D0C0 mov eax, dword ptr fs:[00000030h] 5_2_05F0D0C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F560B8 mov eax, dword ptr fs:[00000030h] 5_2_05F560B8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F560B8 mov ecx, dword ptr fs:[00000030h] 5_2_05F560B8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9208A mov eax, dword ptr fs:[00000030h] 5_2_05E9208A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8D08D mov eax, dword ptr fs:[00000030h] 5_2_05E8D08D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC909C mov eax, dword ptr fs:[00000030h] 5_2_05EC909C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBD090 mov eax, dword ptr fs:[00000030h] 5_2_05EBD090
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBD090 mov eax, dword ptr fs:[00000030h] 5_2_05EBD090
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E95096 mov eax, dword ptr fs:[00000030h] 5_2_05E95096
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F0D070 mov ecx, dword ptr fs:[00000030h] 5_2_05F0D070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F65060 mov eax, dword ptr fs:[00000030h] 5_2_05F65060
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBC073 mov eax, dword ptr fs:[00000030h] 5_2_05EBC073
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA1070 mov eax, dword ptr fs:[00000030h] 5_2_05EA1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA1070 mov ecx, dword ptr fs:[00000030h] 5_2_05EA1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA1070 mov eax, dword ptr fs:[00000030h] 5_2_05EA1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA1070 mov eax, dword ptr fs:[00000030h] 5_2_05EA1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA1070 mov eax, dword ptr fs:[00000030h] 5_2_05EA1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA1070 mov eax, dword ptr fs:[00000030h] 5_2_05EA1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA1070 mov eax, dword ptr fs:[00000030h] 5_2_05EA1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA1070 mov eax, dword ptr fs:[00000030h] 5_2_05EA1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA1070 mov eax, dword ptr fs:[00000030h] 5_2_05EA1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA1070 mov eax, dword ptr fs:[00000030h] 5_2_05EA1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA1070 mov eax, dword ptr fs:[00000030h] 5_2_05EA1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA1070 mov eax, dword ptr fs:[00000030h] 5_2_05EA1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA1070 mov eax, dword ptr fs:[00000030h] 5_2_05EA1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F3705E mov ebx, dword ptr fs:[00000030h] 5_2_05F3705E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F3705E mov eax, dword ptr fs:[00000030h] 5_2_05F3705E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E92050 mov eax, dword ptr fs:[00000030h] 5_2_05E92050
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EBB052 mov eax, dword ptr fs:[00000030h] 5_2_05EBB052
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8A020 mov eax, dword ptr fs:[00000030h] 5_2_05E8A020
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E8C020 mov eax, dword ptr fs:[00000030h] 5_2_05E8C020
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F5903E mov eax, dword ptr fs:[00000030h] 5_2_05F5903E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F5903E mov eax, dword ptr fs:[00000030h] 5_2_05F5903E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F5903E mov eax, dword ptr fs:[00000030h] 5_2_05F5903E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F5903E mov eax, dword ptr fs:[00000030h] 5_2_05F5903E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EAE016 mov eax, dword ptr fs:[00000030h] 5_2_05EAE016
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EAE016 mov eax, dword ptr fs:[00000030h] 5_2_05EAE016
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EAE016 mov eax, dword ptr fs:[00000030h] 5_2_05EAE016
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EAE016 mov eax, dword ptr fs:[00000030h] 5_2_05EAE016
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA03E9 mov eax, dword ptr fs:[00000030h] 5_2_05EA03E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA03E9 mov eax, dword ptr fs:[00000030h] 5_2_05EA03E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA03E9 mov eax, dword ptr fs:[00000030h] 5_2_05EA03E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA03E9 mov eax, dword ptr fs:[00000030h] 5_2_05EA03E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA03E9 mov eax, dword ptr fs:[00000030h] 5_2_05EA03E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA03E9 mov eax, dword ptr fs:[00000030h] 5_2_05EA03E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA03E9 mov eax, dword ptr fs:[00000030h] 5_2_05EA03E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EA03E9 mov eax, dword ptr fs:[00000030h] 5_2_05EA03E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F653FC mov eax, dword ptr fs:[00000030h] 5_2_05F653FC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F4F3E6 mov eax, dword ptr fs:[00000030h] 5_2_05F4F3E6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EC63FF mov eax, dword ptr fs:[00000030h] 5_2_05EC63FF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EAE3F0 mov eax, dword ptr fs:[00000030h] 5_2_05EAE3F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EAE3F0 mov eax, dword ptr fs:[00000030h] 5_2_05EAE3F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05EAE3F0 mov eax, dword ptr fs:[00000030h] 5_2_05EAE3F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05F4B3D0 mov ecx, dword ptr fs:[00000030h] 5_2_05F4B3D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9A3C0 mov eax, dword ptr fs:[00000030h] 5_2_05E9A3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9A3C0 mov eax, dword ptr fs:[00000030h] 5_2_05E9A3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9A3C0 mov eax, dword ptr fs:[00000030h] 5_2_05E9A3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9A3C0 mov eax, dword ptr fs:[00000030h] 5_2_05E9A3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9A3C0 mov eax, dword ptr fs:[00000030h] 5_2_05E9A3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E9A3C0 mov eax, dword ptr fs:[00000030h] 5_2_05E9A3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Code function: 5_2_05E983C0 mov eax, dword ptr fs:[00000030h] 5_2_05E983C0
Source: C:\Users\user\Desktop\7950COPY.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process token adjusted: Debug Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Memory allocated: page read and write | page guard Jump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: 7950COPY.exe, .cs Reference to suspicious API methods: GetProcAddress(, )
Source: 7950COPY.exe, .cs Reference to suspicious API methods: VirtualProtect(procAddress, (UIntPtr)(ulong)array.Length, ., out var )
Source: 7950COPY.exe, .cs Reference to suspicious API methods: LoadLibrary([.])
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\7950COPY.exe" -Force
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\7950COPY.exe" -Force Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Memory allocated: C:\Windows\regedit.exe base: 400000 protect: page execute and read and write Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Memory allocated: C:\Windows\System32\cmd.exe base: 400000 protect: page execute and read and write Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Memory allocated: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe base: 400000 protect: page execute and read and write Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe NtResumeThread: Indirect: 0x12122B7 Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe NtMapViewOfSection: Indirect: 0x12121B0 Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe NtMapViewOfSection: Indirect: 0x121216C Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Memory written: C:\Windows\regedit.exe base: 400000 value starts with: 4D5A Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Memory written: C:\Windows\System32\cmd.exe base: 400000 value starts with: 4D5A Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe base: 400000 value starts with: 4D5A Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: NULL target: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe protection: execute and read and write Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Section loaded: NULL target: C:\Windows\SysWOW64\fltMC.exe protection: execute and read and write Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Section loaded: NULL target: C:\Users\user\Desktop\7950COPY.exe protection: execute and read and write Jump to behavior
Source: C:\Windows\SysWOW64\fltMC.exe Section loaded: NULL target: C:\Users\user\Desktop\7950COPY.exe protection: read write Jump to behavior
Source: C:\Windows\SysWOW64\fltMC.exe Section loaded: NULL target: C:\Users\user\Desktop\7950COPY.exe protection: execute and read and write Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe Thread register set: target process: 6908 Jump to behavior
Source: C:\Windows\SysWOW64\fltMC.exe Thread register set: target process: 6908 Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Memory written: C:\Windows\regedit.exe base: 400000 Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Memory written: C:\Windows\regedit.exe base: 401000 Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Memory written: C:\Windows\System32\cmd.exe base: 400000 Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Memory written: C:\Windows\System32\cmd.exe base: 401000 Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe base: 400000 Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe base: 401000 Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe base: 5368008 Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\7950COPY.exe" -Force Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\regedit.exe "C:\Windows\regedit.exe" Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe" Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\ilasm.exe" Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\SysWOW64\psr.exe "C:\Windows\SysWOW64\psr.exe" Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Process created: C:\Windows\SysWOW64\fltMC.exe "C:\Windows\SysWOW64\fltMC.exe" Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Queries volume information: C:\Users\user\Desktop\7950COPY.exe VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\7950COPY.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior

Lowering of HIPS / PFW / Operating System Security Settings

barindex
Source: C:\Users\user\Desktop\7950COPY.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System EnableLUA Jump to behavior
Source: Amcache.hve.9.dr Binary or memory string: c:\programdata\microsoft\windows defender\platform\4.18.23080.2006-0\msmpeng.exe
Source: Amcache.hve.9.dr Binary or memory string: msmpeng.exe
Source: Amcache.hve.9.dr Binary or memory string: c:\program files\windows defender\msmpeng.exe
Source: Amcache.hve.9.dr Binary or memory string: MsMpEng.exe

Stealing of Sensitive Information

barindex
Source: Yara match File source: 5.2.ilasm.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.ilasm.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 0000000F.00000002.3601048120.0000000000C50000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.2188258196.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000F.00000002.3601268503.0000000003110000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000F.00000002.3601299719.0000000003160000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.2188485814.0000000005DB0000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY

Remote Access Functionality

barindex
Source: Yara match File source: 5.2.ilasm.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.ilasm.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 0000000F.00000002.3601048120.0000000000C50000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.2188258196.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000F.00000002.3601268503.0000000003110000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000F.00000002.3601299719.0000000003160000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.2188485814.0000000005DB0000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
No contacted IP infos