Windows Analysis Report
rTransferenciarealizada451236.exe

Overview

General Information

Sample name: rTransferenciarealizada451236.exe
Analysis ID: 1545014
MD5: 12f32dc32a25a48db3aca40758745e80
SHA1: 41f2c89b8c83b279633c641d1e266a3a2487294d
SHA256: 8085c17ea9441ff19ee1d021408ce2b159bdf4d53704a9afd180e76033c74415
Tags: exeuser-Porcupine
Infos:

Detection

GuLoader
Score: 76
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Yara detected GuLoader
AI detected suspicious sample
Switches to a custom stack to bypass stack traces
Tries to detect virtualization through RDTSC time measurements
Abnormal high CPU Usage
Contains functionality for execution timing, often used to detect debuggers
Contains functionality for read data from the clipboard
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to dynamically determine API calls
Contains functionality to read the PEB
Contains functionality to shutdown / reboot the system
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Detected potential crypto function
Drops PE files
Found dropped PE file which has not been started or loaded
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
JA3 SSL client fingerprint seen in connection with other malware
PE / OLE file has an invalid certificate
Sample file is different than original file name gathered from version info
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)

Classification

AV Detection

barindex
Source: rTransferenciarealizada451236.exe Avira: detected
Source: rTransferenciarealizada451236.exe ReversingLabs: Detection: 15%
Source: rTransferenciarealizada451236.exe Virustotal: Detection: 32% Perma Link
Source: Submited Sample Integrated Neural Analysis Model: Matched 100.0% probability
Source: rTransferenciarealizada451236.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: unknown HTTPS traffic detected: 142.250.186.142:443 -> 192.168.2.4:56106 version: TLS 1.2
Source: unknown HTTPS traffic detected: 142.250.185.193:443 -> 192.168.2.4:56116 version: TLS 1.2
Source: rTransferenciarealizada451236.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: mshtml.pdb source: rTransferenciarealizada451236.exe, 00000005.00000001.2676520137.0000000000649000.00000008.00000001.01000000.00000007.sdmp
Source: Binary string: wntdll.pdbUGP source: rTransferenciarealizada451236.exe, 00000005.00000002.4182804414.0000000033AC0000.00000040.00001000.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2918854405.0000000033913000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000002.4182804414.0000000033C5E000.00000040.00001000.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2916882802.0000000033769000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: wntdll.pdb source: rTransferenciarealizada451236.exe, rTransferenciarealizada451236.exe, 00000005.00000002.4182804414.0000000033AC0000.00000040.00001000.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2918854405.0000000033913000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000002.4182804414.0000000033C5E000.00000040.00001000.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2916882802.0000000033769000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: mshtml.pdbUGP source: rTransferenciarealizada451236.exe, 00000005.00000001.2676520137.0000000000649000.00000008.00000001.01000000.00000007.sdmp
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 0_2_00406232 FindFirstFileA,FindClose, 0_2_00406232
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 0_2_004056F7 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, 0_2_004056F7
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 0_2_004026F8 FindFirstFileA, 0_2_004026F8
Source: Joe Sandbox View JA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
Source: Network traffic Suricata IDS: 2803270 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UHCa : 192.168.2.4:56106 -> 142.250.186.142:443
Source: global traffic HTTP traffic detected: GET /uc?export=download&id=1nMPhNN-2GjI3FUIqU_EPUgHeeK8mihQO HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:131.0) Gecko/20100101 Firefox/131.0Host: drive.google.comCache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /download?id=1nMPhNN-2GjI3FUIqU_EPUgHeeK8mihQO&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:131.0) Gecko/20100101 Firefox/131.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-Alive
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /uc?export=download&id=1nMPhNN-2GjI3FUIqU_EPUgHeeK8mihQO HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:131.0) Gecko/20100101 Firefox/131.0Host: drive.google.comCache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /download?id=1nMPhNN-2GjI3FUIqU_EPUgHeeK8mihQO&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:131.0) Gecko/20100101 Firefox/131.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-Alive
Source: global traffic DNS traffic detected: DNS query: drive.google.com
Source: global traffic DNS traffic detected: DNS query: drive.usercontent.google.com
Source: rTransferenciarealizada451236.exe String found in binary or memory: http://nsis.sf.net/NSIS_Error
Source: rTransferenciarealizada451236.exe String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
Source: rTransferenciarealizada451236.exe, 00000005.00000001.2676520137.0000000000649000.00000008.00000001.01000000.00000007.sdmp String found in binary or memory: http://www.ftp.ftp://ftp.gopher.
Source: rTransferenciarealizada451236.exe, 00000005.00000001.2676520137.00000000005F2000.00000008.00000001.01000000.00000007.sdmp String found in binary or memory: http://www.w3c.org/TR/1999/REC-html401-19991224/frameset.dtd
Source: rTransferenciarealizada451236.exe, 00000005.00000001.2676520137.00000000005F2000.00000008.00000001.01000000.00000007.sdmp String found in binary or memory: http://www.w3c.org/TR/1999/REC-html401-19991224/loose.dtd
Source: rTransferenciarealizada451236.exe, 00000005.00000003.2725645535.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2725724585.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://apis.google.com
Source: rTransferenciarealizada451236.exe, 00000005.00000002.4155197056.0000000003A18000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/
Source: rTransferenciarealizada451236.exe, 00000005.00000002.4155197056.0000000003A55000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000002.4155460060.0000000003B30000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1nMPhNN-2GjI3FUIqU_EPUgHeeK8mihQO
Source: rTransferenciarealizada451236.exe, 00000005.00000002.4155197056.0000000003A18000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1nMPhNN-2GjI3FUIqU_EPUgHeeK8mihQO8D
Source: rTransferenciarealizada451236.exe, 00000005.00000002.4155197056.0000000003A18000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1nMPhNN-2GjI3FUIqU_EPUgHeeK8mihQONDs
Source: rTransferenciarealizada451236.exe, 00000005.00000002.4155197056.0000000003A18000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1nMPhNN-2GjI3FUIqU_EPUgHeeK8mihQOdD
Source: rTransferenciarealizada451236.exe, 00000005.00000003.2917130489.0000000003A7F000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2917338648.0000000003A88000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2763596938.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000002.4155375280.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://drive.usercontent.google.com/
Source: rTransferenciarealizada451236.exe, 00000005.00000003.2917130489.0000000003A7F000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2917338648.0000000003A88000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2763596938.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000002.4155375280.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://drive.usercontent.google.com/d
Source: rTransferenciarealizada451236.exe, 00000005.00000003.2917130489.0000000003A7F000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2725645535.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2725724585.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2917365230.0000000003A6F000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000002.4155268080.0000000003A6F000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2917338648.0000000003A88000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2763596938.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000002.4155375280.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://drive.usercontent.google.com/download?id=1nMPhNN-2GjI3FUIqU_EPUgHeeK8mihQO&export=download
Source: rTransferenciarealizada451236.exe, 00000005.00000003.2917130489.0000000003A7F000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2917338648.0000000003A88000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2763596938.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000002.4155375280.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://drive.usercontent.google.com/download?id=1nMPhNN-2GjI3FUIqU_EPUgHeeK8mihQO&export=download.c
Source: rTransferenciarealizada451236.exe, 00000005.00000003.2917130489.0000000003A7F000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2917338648.0000000003A88000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2763596938.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000002.4155375280.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://drive.usercontent.google.com/download?id=1nMPhNN-2GjI3FUIqU_EPUgHeeK8mihQO&export=download1A
Source: rTransferenciarealizada451236.exe, 00000005.00000001.2676520137.0000000000649000.00000008.00000001.01000000.00000007.sdmp String found in binary or memory: https://inference.location.live.net/inferenceservice/v21/Pox/GetLocationUsingFingerprinte1e71f6b-214
Source: rTransferenciarealizada451236.exe, 00000005.00000003.2725645535.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2725724585.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://ssl.gstatic.com
Source: rTransferenciarealizada451236.exe, 00000005.00000003.2725645535.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2725724585.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.google-analytics.com;report-uri
Source: rTransferenciarealizada451236.exe, 00000005.00000003.2725645535.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2725724585.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.google.com
Source: rTransferenciarealizada451236.exe, 00000005.00000003.2725645535.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2725724585.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.googletagmanager.com
Source: rTransferenciarealizada451236.exe, 00000005.00000003.2725645535.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2725724585.0000000003A8B000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.gstatic.com
Source: unknown Network traffic detected: HTTP traffic on port 56116 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56116
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56106
Source: unknown Network traffic detected: HTTP traffic on port 56106 -> 443
Source: unknown HTTPS traffic detected: 142.250.186.142:443 -> 192.168.2.4:56106 version: TLS 1.2
Source: unknown HTTPS traffic detected: 142.250.185.193:443 -> 192.168.2.4:56116 version: TLS 1.2
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 0_2_00405194 GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,ShowWindow,ShowWindow,GetDlgItem,SendMessageA,SendMessageA,SendMessageA,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,ShowWindow,ShowWindow,SendMessageA,CreatePopupMenu,AppendMenuA,GetWindowRect,TrackPopupMenu,SendMessageA,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageA,GlobalUnlock,SetClipboardData,CloseClipboard, 0_2_00405194
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Process Stats: CPU usage > 49%
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32DF0 NtQuerySystemInformation,LdrInitializeThunk, 5_2_33B32DF0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B33090 NtSetValueKey, 5_2_33B33090
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B33010 NtOpenDirectoryObject, 5_2_33B33010
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B335C0 NtCreateMutant, 5_2_33B335C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B339B0 NtGetContextThread, 5_2_33B339B0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B33D10 NtOpenProcessToken, 5_2_33B33D10
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B33D70 NtOpenThread, 5_2_33B33D70
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B34340 NtSetContextThread, 5_2_33B34340
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B34650 NtSuspendThread, 5_2_33B34650
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32BA0 NtEnumerateValueKey, 5_2_33B32BA0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32B80 NtQueryInformationFile, 5_2_33B32B80
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32BF0 NtAllocateVirtualMemory, 5_2_33B32BF0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32BE0 NtQueryValueKey, 5_2_33B32BE0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32B60 NtClose, 5_2_33B32B60
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32AB0 NtWaitForSingleObject, 5_2_33B32AB0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32AF0 NtWriteFile, 5_2_33B32AF0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32AD0 NtReadFile, 5_2_33B32AD0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32FB0 NtResumeThread, 5_2_33B32FB0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32FA0 NtQuerySection, 5_2_33B32FA0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32F90 NtProtectVirtualMemory, 5_2_33B32F90
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32FE0 NtCreateFile, 5_2_33B32FE0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32F30 NtCreateSection, 5_2_33B32F30
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32F60 NtCreateProcessEx, 5_2_33B32F60
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32EA0 NtAdjustPrivilegesToken, 5_2_33B32EA0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32E80 NtReadVirtualMemory, 5_2_33B32E80
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32EE0 NtQueueApcThread, 5_2_33B32EE0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32E30 NtWriteVirtualMemory, 5_2_33B32E30
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32DB0 NtEnumerateKey, 5_2_33B32DB0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32DD0 NtDelayExecution, 5_2_33B32DD0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32D30 NtUnmapViewOfSection, 5_2_33B32D30
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32D10 NtMapViewOfSection, 5_2_33B32D10
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32D00 NtSetInformationFile, 5_2_33B32D00
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32CA0 NtQueryInformationToken, 5_2_33B32CA0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32CF0 NtOpenProcess, 5_2_33B32CF0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32CC0 NtQueryVirtualMemory, 5_2_33B32CC0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32C00 NtQueryInformationProcess, 5_2_33B32C00
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32C70 NtFreeVirtualMemory, 5_2_33B32C70
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B32C60 NtCreateKey, 5_2_33B32C60
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 0_2_004031BB EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, 0_2_004031BB
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe File created: C:\Windows\resources\nringsmiddelet.ini Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe File created: C:\Windows\terzetters Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe File created: C:\Windows\Fonts\karrooers.ini Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 0_2_004049D3 0_2_004049D3
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 0_2_004065BB 0_2_004065BB
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B4739A 5_2_33B4739A
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB132D 5_2_33BB132D
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AED34C 5_2_33AED34C
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B052A0 5_2_33B052A0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1D2F0 5_2_33B1D2F0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA12ED 5_2_33BA12ED
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1B2C0 5_2_33B1B2C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B0B1B0 5_2_33B0B1B0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BCB16B 5_2_33BCB16B
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF172 5_2_33AEF172
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B3516C 5_2_33B3516C
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB70E9 5_2_33BB70E9
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BBF0E0 5_2_33BBF0E0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B070C0 5_2_33B070C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BAF0CC 5_2_33BAF0CC
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BBF7B0 5_2_33BBF7B0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB16CC 5_2_33BB16CC
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9D5B0 5_2_33B9D5B0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB7571 5_2_33BB7571
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BBF43F 5_2_33BBF43F
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF1460 5_2_33AF1460
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1FB80 5_2_33B1FB80
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B75BF0 5_2_33B75BF0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B3DBF9 5_2_33B3DBF9
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BBFB76 5_2_33BBFB76
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B45AA0 5_2_33B45AA0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9DAAC 5_2_33B9DAAC
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA1AA3 5_2_33BA1AA3
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BADAC6 5_2_33BADAC6
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B73A6C 5_2_33B73A6C
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BBFA49 5_2_33BBFA49
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB7A46 5_2_33BB7A46
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B95910 5_2_33B95910
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B09950 5_2_33B09950
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1B950 5_2_33B1B950
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B038E0 5_2_33B038E0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B6D800 5_2_33B6D800
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BBFFB1 5_2_33BBFFB1
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B01F92 5_2_33B01F92
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BBFF09 5_2_33BBFF09
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B09EB0 5_2_33B09EB0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1FDC0 5_2_33B1FDC0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB7D73 5_2_33BB7D73
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB1D5A 5_2_33BB1D5A
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B03D40 5_2_33B03D40
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BBFCF2 5_2_33BBFCF2
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B79C32 5_2_33B79C32
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B0E3F0 5_2_33B0E3F0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BC03E6 5_2_33BC03E6
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BBA352 5_2_33BBA352
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B802C0 5_2_33B802C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA0274 5_2_33BA0274
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BC01AA 5_2_33BC01AA
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB81CC 5_2_33BB81CC
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9A118 5_2_33B9A118
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF0100 5_2_33AF0100
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B88158 5_2_33B88158
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B92000 5_2_33B92000
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFC7C0 5_2_33AFC7C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B00770 5_2_33B00770
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B24750 5_2_33B24750
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1C6E0 5_2_33B1C6E0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BC0591 5_2_33BC0591
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B00535 5_2_33B00535
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BAE4F6 5_2_33BAE4F6
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA4420 5_2_33BA4420
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB2446 5_2_33BB2446
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB6BD7 5_2_33BB6BD7
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BBAB40 5_2_33BBAB40
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFEA80 5_2_33AFEA80
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B029A0 5_2_33B029A0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BCA9A6 5_2_33BCA9A6
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B16962 5_2_33B16962
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE68B8 5_2_33AE68B8
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B2E8F0 5_2_33B2E8F0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B0A840 5_2_33B0A840
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B02840 5_2_33B02840
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B7EFA0 5_2_33B7EFA0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B0CFE0 5_2_33B0CFE0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF2FC8 5_2_33AF2FC8
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B20F30 5_2_33B20F30
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA2F30 5_2_33BA2F30
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B42F28 5_2_33B42F28
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B74F40 5_2_33B74F40
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B12E90 5_2_33B12E90
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BBCE93 5_2_33BBCE93
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BBEEDB 5_2_33BBEEDB
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BBEE26 5_2_33BBEE26
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B00E59 5_2_33B00E59
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B18DBF 5_2_33B18DBF
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFADE0 5_2_33AFADE0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9CD1F 5_2_33B9CD1F
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B0AD00 5_2_33B0AD00
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA0CB5 5_2_33BA0CB5
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF0CF2 5_2_33AF0CF2
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B00C00 5_2_33B00C00
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: String function: 33B6EA12 appears 86 times
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: String function: 33B35130 appears 58 times
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: String function: 33B7F290 appears 105 times
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: String function: 33AEB970 appears 262 times
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: String function: 33B47E54 appears 100 times
Source: rTransferenciarealizada451236.exe Static PE information: invalid certificate
Source: rTransferenciarealizada451236.exe, 00000005.00000003.2916882802.000000003388C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamentdll.dllj% vs rTransferenciarealizada451236.exe
Source: rTransferenciarealizada451236.exe, 00000005.00000002.4182804414.0000000033D91000.00000040.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamentdll.dllj% vs rTransferenciarealizada451236.exe
Source: rTransferenciarealizada451236.exe, 00000005.00000003.2918854405.0000000033A40000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamentdll.dllj% vs rTransferenciarealizada451236.exe
Source: rTransferenciarealizada451236.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: classification engine Classification label: mal76.troj.evad.winEXE@3/12@2/2
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 0_2_004031BB EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, 0_2_004031BB
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 0_2_00404460 GetDlgItem,SetWindowTextA,SHBrowseForFolderA,CoTaskMemFree,lstrcmpiA,lstrcatA,SetDlgItemTextA,GetDiskFreeSpaceA,MulDiv,SetDlgItemTextA, 0_2_00404460
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 0_2_004020CB CoCreateInstance,MultiByteToWideChar, 0_2_004020CB
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe File created: C:\Users\user\entomostraca Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe File created: C:\Users\user\AppData\Local\Temp\nsv8C3F.tmp Jump to behavior
Source: rTransferenciarealizada451236.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: rTransferenciarealizada451236.exe ReversingLabs: Detection: 15%
Source: rTransferenciarealizada451236.exe Virustotal: Detection: 32%
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe File read: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\rTransferenciarealizada451236.exe "C:\Users\user\Desktop\rTransferenciarealizada451236.exe"
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Process created: C:\Users\user\Desktop\rTransferenciarealizada451236.exe "C:\Users\user\Desktop\rTransferenciarealizada451236.exe"
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Process created: C:\Users\user\Desktop\rTransferenciarealizada451236.exe "C:\Users\user\Desktop\rTransferenciarealizada451236.exe" Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: oleacc.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: shfolder.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: schannel.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: mskeyprotect.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: dpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Section loaded: ncryptsslp.dll Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32 Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe File written: C:\Windows\Resources\nringsmiddelet.ini Jump to behavior
Source: rTransferenciarealizada451236.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: mshtml.pdb source: rTransferenciarealizada451236.exe, 00000005.00000001.2676520137.0000000000649000.00000008.00000001.01000000.00000007.sdmp
Source: Binary string: wntdll.pdbUGP source: rTransferenciarealizada451236.exe, 00000005.00000002.4182804414.0000000033AC0000.00000040.00001000.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2918854405.0000000033913000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000002.4182804414.0000000033C5E000.00000040.00001000.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2916882802.0000000033769000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: wntdll.pdb source: rTransferenciarealizada451236.exe, rTransferenciarealizada451236.exe, 00000005.00000002.4182804414.0000000033AC0000.00000040.00001000.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2918854405.0000000033913000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000002.4182804414.0000000033C5E000.00000040.00001000.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000003.2916882802.0000000033769000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: mshtml.pdbUGP source: rTransferenciarealizada451236.exe, 00000005.00000001.2676520137.0000000000649000.00000008.00000001.01000000.00000007.sdmp

Data Obfuscation

barindex
Source: Yara match File source: 00000000.00000002.2677672856.0000000003B5D000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 0_2_10001A5D GlobalAlloc,lstrcpyA,lstrcpyA,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,LdrInitializeThunk,LdrInitializeThunk,lstrcpyA,GetModuleHandleA,LoadLibraryA,GetProcAddress,lstrlenA, 0_2_10001A5D
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 0_2_10002D20 push eax; ret 0_2_10002D4E
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF09AD push ecx; mov dword ptr [esp], ecx 5_2_33AF09B6
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe File created: C:\Users\user\AppData\Local\Temp\nso93F1.tmp\System.dll Jump to dropped file
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Process information set: NOOPENFILEERRORBOX Jump to behavior

Malware Analysis System Evasion

barindex
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe API/Special instruction interceptor: Address: 41CD978
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe API/Special instruction interceptor: Address: 27DD978
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe RDTSC instruction interceptor: First address: 41A8A8A second address: 41A8A8A instructions: 0x00000000 rdtsc 0x00000002 test bh, dh 0x00000004 cmp ebx, ecx 0x00000006 jc 00007EFE284F73F8h 0x00000008 inc ebp 0x00000009 inc ebx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe RDTSC instruction interceptor: First address: 27B8A8A second address: 27B8A8A instructions: 0x00000000 rdtsc 0x00000002 test bh, dh 0x00000004 cmp ebx, ecx 0x00000006 jc 00007EFE293475A8h 0x00000008 inc ebp 0x00000009 inc ebx 0x0000000a rdtsc
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B6D1C0 rdtsc 5_2_33B6D1C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nso93F1.tmp\System.dll Jump to dropped file
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe API coverage: 0.1 %
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 0_2_00406232 FindFirstFileA,FindClose, 0_2_00406232
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 0_2_004056F7 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose, 0_2_004056F7
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 0_2_004026F8 FindFirstFileA, 0_2_004026F8
Source: rTransferenciarealizada451236.exe, 00000005.00000003.2917189084.0000000003A77000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000002.4155197056.0000000003A18000.00000004.00000020.00020000.00000000.sdmp, rTransferenciarealizada451236.exe, 00000005.00000002.4155268080.0000000003A77000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B6D1C0 rdtsc 5_2_33B6D1C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 0_2_00402D48 GetTempPathA,GetTickCount,GetModuleFileNameA,LdrInitializeThunk,GetFileSize,GlobalAlloc,SetFilePointer, 0_2_00402D48
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 0_2_10001A5D GlobalAlloc,lstrcpyA,lstrcpyA,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,LdrInitializeThunk,LdrInitializeThunk,lstrcpyA,GetModuleHandleA,LoadLibraryA,GetProcAddress,lstrlenA, 0_2_10001A5D
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B913B9 mov eax, dword ptr fs:[00000030h] 5_2_33B913B9
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B913B9 mov eax, dword ptr fs:[00000030h] 5_2_33B913B9
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B913B9 mov eax, dword ptr fs:[00000030h] 5_2_33B913B9
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B233A0 mov eax, dword ptr fs:[00000030h] 5_2_33B233A0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B233A0 mov eax, dword ptr fs:[00000030h] 5_2_33B233A0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B133A5 mov eax, dword ptr fs:[00000030h] 5_2_33B133A5
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BC539D mov eax, dword ptr fs:[00000030h] 5_2_33BC539D
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B4739A mov eax, dword ptr fs:[00000030h] 5_2_33B4739A
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B4739A mov eax, dword ptr fs:[00000030h] 5_2_33B4739A
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BC53FC mov eax, dword ptr fs:[00000030h] 5_2_33BC53FC
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BAF3E6 mov eax, dword ptr fs:[00000030h] 5_2_33BAF3E6
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BAB3D0 mov ecx, dword ptr fs:[00000030h] 5_2_33BAB3D0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB132D mov eax, dword ptr fs:[00000030h] 5_2_33BB132D
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB132D mov eax, dword ptr fs:[00000030h] 5_2_33BB132D
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1F32A mov eax, dword ptr fs:[00000030h] 5_2_33B1F32A
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE7330 mov eax, dword ptr fs:[00000030h] 5_2_33AE7330
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B7930B mov eax, dword ptr fs:[00000030h] 5_2_33B7930B
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B7930B mov eax, dword ptr fs:[00000030h] 5_2_33B7930B
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B7930B mov eax, dword ptr fs:[00000030h] 5_2_33B7930B
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B93370 mov eax, dword ptr fs:[00000030h] 5_2_33B93370
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BAF367 mov eax, dword ptr fs:[00000030h] 5_2_33BAF367
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF7370 mov eax, dword ptr fs:[00000030h] 5_2_33AF7370
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF7370 mov eax, dword ptr fs:[00000030h] 5_2_33AF7370
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF7370 mov eax, dword ptr fs:[00000030h] 5_2_33AF7370
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AED34C mov eax, dword ptr fs:[00000030h] 5_2_33AED34C
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AED34C mov eax, dword ptr fs:[00000030h] 5_2_33AED34C
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BC5341 mov eax, dword ptr fs:[00000030h] 5_2_33BC5341
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE9353 mov eax, dword ptr fs:[00000030h] 5_2_33AE9353
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE9353 mov eax, dword ptr fs:[00000030h] 5_2_33AE9353
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B792BC mov eax, dword ptr fs:[00000030h] 5_2_33B792BC
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B792BC mov eax, dword ptr fs:[00000030h] 5_2_33B792BC
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B792BC mov ecx, dword ptr fs:[00000030h] 5_2_33B792BC
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B792BC mov ecx, dword ptr fs:[00000030h] 5_2_33B792BC
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B052A0 mov eax, dword ptr fs:[00000030h] 5_2_33B052A0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B052A0 mov eax, dword ptr fs:[00000030h] 5_2_33B052A0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B052A0 mov eax, dword ptr fs:[00000030h] 5_2_33B052A0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B052A0 mov eax, dword ptr fs:[00000030h] 5_2_33B052A0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B872A0 mov eax, dword ptr fs:[00000030h] 5_2_33B872A0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B872A0 mov eax, dword ptr fs:[00000030h] 5_2_33B872A0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB92A6 mov eax, dword ptr fs:[00000030h] 5_2_33BB92A6
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB92A6 mov eax, dword ptr fs:[00000030h] 5_2_33BB92A6
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB92A6 mov eax, dword ptr fs:[00000030h] 5_2_33BB92A6
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB92A6 mov eax, dword ptr fs:[00000030h] 5_2_33BB92A6
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B2329E mov eax, dword ptr fs:[00000030h] 5_2_33B2329E
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B2329E mov eax, dword ptr fs:[00000030h] 5_2_33B2329E
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BC5283 mov eax, dword ptr fs:[00000030h] 5_2_33BC5283
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BAF2F8 mov eax, dword ptr fs:[00000030h] 5_2_33BAF2F8
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9B2F0 mov eax, dword ptr fs:[00000030h] 5_2_33B9B2F0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9B2F0 mov eax, dword ptr fs:[00000030h] 5_2_33B9B2F0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE92FF mov eax, dword ptr fs:[00000030h] 5_2_33AE92FF
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA12ED mov eax, dword ptr fs:[00000030h] 5_2_33BA12ED
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA12ED mov eax, dword ptr fs:[00000030h] 5_2_33BA12ED
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA12ED mov eax, dword ptr fs:[00000030h] 5_2_33BA12ED
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA12ED mov eax, dword ptr fs:[00000030h] 5_2_33BA12ED
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA12ED mov eax, dword ptr fs:[00000030h] 5_2_33BA12ED
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA12ED mov eax, dword ptr fs:[00000030h] 5_2_33BA12ED
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA12ED mov eax, dword ptr fs:[00000030h] 5_2_33BA12ED
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA12ED mov eax, dword ptr fs:[00000030h] 5_2_33BA12ED
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA12ED mov eax, dword ptr fs:[00000030h] 5_2_33BA12ED
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA12ED mov eax, dword ptr fs:[00000030h] 5_2_33BA12ED
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA12ED mov eax, dword ptr fs:[00000030h] 5_2_33BA12ED
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA12ED mov eax, dword ptr fs:[00000030h] 5_2_33BA12ED
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA12ED mov eax, dword ptr fs:[00000030h] 5_2_33BA12ED
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA12ED mov eax, dword ptr fs:[00000030h] 5_2_33BA12ED
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BC52E2 mov eax, dword ptr fs:[00000030h] 5_2_33BC52E2
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1F2D0 mov eax, dword ptr fs:[00000030h] 5_2_33B1F2D0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1F2D0 mov eax, dword ptr fs:[00000030h] 5_2_33B1F2D0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF92C5 mov eax, dword ptr fs:[00000030h] 5_2_33AF92C5
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF92C5 mov eax, dword ptr fs:[00000030h] 5_2_33AF92C5
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1B2C0 mov eax, dword ptr fs:[00000030h] 5_2_33B1B2C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1B2C0 mov eax, dword ptr fs:[00000030h] 5_2_33B1B2C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1B2C0 mov eax, dword ptr fs:[00000030h] 5_2_33B1B2C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1B2C0 mov eax, dword ptr fs:[00000030h] 5_2_33B1B2C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1B2C0 mov eax, dword ptr fs:[00000030h] 5_2_33B1B2C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1B2C0 mov eax, dword ptr fs:[00000030h] 5_2_33B1B2C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1B2C0 mov eax, dword ptr fs:[00000030h] 5_2_33B1B2C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEB2D3 mov eax, dword ptr fs:[00000030h] 5_2_33AEB2D3
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEB2D3 mov eax, dword ptr fs:[00000030h] 5_2_33AEB2D3
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEB2D3 mov eax, dword ptr fs:[00000030h] 5_2_33AEB2D3
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BC5227 mov eax, dword ptr fs:[00000030h] 5_2_33BC5227
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B27208 mov eax, dword ptr fs:[00000030h] 5_2_33B27208
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B27208 mov eax, dword ptr fs:[00000030h] 5_2_33B27208
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B31270 mov eax, dword ptr fs:[00000030h] 5_2_33B31270
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B31270 mov eax, dword ptr fs:[00000030h] 5_2_33B31270
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B19274 mov eax, dword ptr fs:[00000030h] 5_2_33B19274
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BBD26B mov eax, dword ptr fs:[00000030h] 5_2_33BBD26B
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BBD26B mov eax, dword ptr fs:[00000030h] 5_2_33BBD26B
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BAB256 mov eax, dword ptr fs:[00000030h] 5_2_33BAB256
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BAB256 mov eax, dword ptr fs:[00000030h] 5_2_33BAB256
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE9240 mov eax, dword ptr fs:[00000030h] 5_2_33AE9240
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE9240 mov eax, dword ptr fs:[00000030h] 5_2_33AE9240
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B2724D mov eax, dword ptr fs:[00000030h] 5_2_33B2724D
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B0B1B0 mov eax, dword ptr fs:[00000030h] 5_2_33B0B1B0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA11A4 mov eax, dword ptr fs:[00000030h] 5_2_33BA11A4
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA11A4 mov eax, dword ptr fs:[00000030h] 5_2_33BA11A4
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA11A4 mov eax, dword ptr fs:[00000030h] 5_2_33BA11A4
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA11A4 mov eax, dword ptr fs:[00000030h] 5_2_33BA11A4
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B47190 mov eax, dword ptr fs:[00000030h] 5_2_33B47190
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA5180 mov eax, dword ptr fs:[00000030h] 5_2_33BA5180
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA5180 mov eax, dword ptr fs:[00000030h] 5_2_33BA5180
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B971F9 mov esi, dword ptr fs:[00000030h] 5_2_33B971F9
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF51ED mov eax, dword ptr fs:[00000030h] 5_2_33AF51ED
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B151EF mov eax, dword ptr fs:[00000030h] 5_2_33B151EF
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B151EF mov eax, dword ptr fs:[00000030h] 5_2_33B151EF
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B151EF mov eax, dword ptr fs:[00000030h] 5_2_33B151EF
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B151EF mov eax, dword ptr fs:[00000030h] 5_2_33B151EF
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B151EF mov eax, dword ptr fs:[00000030h] 5_2_33B151EF
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B151EF mov eax, dword ptr fs:[00000030h] 5_2_33B151EF
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B151EF mov eax, dword ptr fs:[00000030h] 5_2_33B151EF
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B151EF mov eax, dword ptr fs:[00000030h] 5_2_33B151EF
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B151EF mov eax, dword ptr fs:[00000030h] 5_2_33B151EF
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B151EF mov eax, dword ptr fs:[00000030h] 5_2_33B151EF
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B151EF mov eax, dword ptr fs:[00000030h] 5_2_33B151EF
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B151EF mov eax, dword ptr fs:[00000030h] 5_2_33B151EF
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B151EF mov eax, dword ptr fs:[00000030h] 5_2_33B151EF
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B2D1D0 mov eax, dword ptr fs:[00000030h] 5_2_33B2D1D0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B2D1D0 mov ecx, dword ptr fs:[00000030h] 5_2_33B2D1D0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BC51CB mov eax, dword ptr fs:[00000030h] 5_2_33BC51CB
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEB136 mov eax, dword ptr fs:[00000030h] 5_2_33AEB136
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEB136 mov eax, dword ptr fs:[00000030h] 5_2_33AEB136
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEB136 mov eax, dword ptr fs:[00000030h] 5_2_33AEB136
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEB136 mov eax, dword ptr fs:[00000030h] 5_2_33AEB136
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF1131 mov eax, dword ptr fs:[00000030h] 5_2_33AF1131
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF1131 mov eax, dword ptr fs:[00000030h] 5_2_33AF1131
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B89179 mov eax, dword ptr fs:[00000030h] 5_2_33B89179
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF172 mov eax, dword ptr fs:[00000030h] 5_2_33AEF172
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF172 mov eax, dword ptr fs:[00000030h] 5_2_33AEF172
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF172 mov eax, dword ptr fs:[00000030h] 5_2_33AEF172
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF172 mov eax, dword ptr fs:[00000030h] 5_2_33AEF172
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF172 mov eax, dword ptr fs:[00000030h] 5_2_33AEF172
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF172 mov eax, dword ptr fs:[00000030h] 5_2_33AEF172
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF172 mov eax, dword ptr fs:[00000030h] 5_2_33AEF172
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF172 mov eax, dword ptr fs:[00000030h] 5_2_33AEF172
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF172 mov eax, dword ptr fs:[00000030h] 5_2_33AEF172
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF172 mov eax, dword ptr fs:[00000030h] 5_2_33AEF172
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF172 mov eax, dword ptr fs:[00000030h] 5_2_33AEF172
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF172 mov eax, dword ptr fs:[00000030h] 5_2_33AEF172
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF172 mov eax, dword ptr fs:[00000030h] 5_2_33AEF172
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF172 mov eax, dword ptr fs:[00000030h] 5_2_33AEF172
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF172 mov eax, dword ptr fs:[00000030h] 5_2_33AEF172
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF172 mov eax, dword ptr fs:[00000030h] 5_2_33AEF172
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF172 mov eax, dword ptr fs:[00000030h] 5_2_33AEF172
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF172 mov eax, dword ptr fs:[00000030h] 5_2_33AEF172
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF172 mov eax, dword ptr fs:[00000030h] 5_2_33AEF172
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF172 mov eax, dword ptr fs:[00000030h] 5_2_33AEF172
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF172 mov eax, dword ptr fs:[00000030h] 5_2_33AEF172
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE9148 mov eax, dword ptr fs:[00000030h] 5_2_33AE9148
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE9148 mov eax, dword ptr fs:[00000030h] 5_2_33AE9148
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE9148 mov eax, dword ptr fs:[00000030h] 5_2_33AE9148
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE9148 mov eax, dword ptr fs:[00000030h] 5_2_33AE9148
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BC5152 mov eax, dword ptr fs:[00000030h] 5_2_33BC5152
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B83140 mov eax, dword ptr fs:[00000030h] 5_2_33B83140
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B83140 mov eax, dword ptr fs:[00000030h] 5_2_33B83140
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B83140 mov eax, dword ptr fs:[00000030h] 5_2_33B83140
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF7152 mov eax, dword ptr fs:[00000030h] 5_2_33AF7152
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1D090 mov eax, dword ptr fs:[00000030h] 5_2_33B1D090
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1D090 mov eax, dword ptr fs:[00000030h] 5_2_33B1D090
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AED08D mov eax, dword ptr fs:[00000030h] 5_2_33AED08D
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B2909C mov eax, dword ptr fs:[00000030h] 5_2_33B2909C
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B7D080 mov eax, dword ptr fs:[00000030h] 5_2_33B7D080
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B7D080 mov eax, dword ptr fs:[00000030h] 5_2_33B7D080
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF5096 mov eax, dword ptr fs:[00000030h] 5_2_33AF5096
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B150E4 mov eax, dword ptr fs:[00000030h] 5_2_33B150E4
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B150E4 mov ecx, dword ptr fs:[00000030h] 5_2_33B150E4
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BC50D9 mov eax, dword ptr fs:[00000030h] 5_2_33BC50D9
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B190DB mov eax, dword ptr fs:[00000030h] 5_2_33B190DB
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B070C0 mov eax, dword ptr fs:[00000030h] 5_2_33B070C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B070C0 mov ecx, dword ptr fs:[00000030h] 5_2_33B070C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B070C0 mov ecx, dword ptr fs:[00000030h] 5_2_33B070C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B070C0 mov eax, dword ptr fs:[00000030h] 5_2_33B070C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B070C0 mov ecx, dword ptr fs:[00000030h] 5_2_33B070C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B070C0 mov ecx, dword ptr fs:[00000030h] 5_2_33B070C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B070C0 mov eax, dword ptr fs:[00000030h] 5_2_33B070C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B070C0 mov eax, dword ptr fs:[00000030h] 5_2_33B070C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B070C0 mov eax, dword ptr fs:[00000030h] 5_2_33B070C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B070C0 mov eax, dword ptr fs:[00000030h] 5_2_33B070C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B070C0 mov eax, dword ptr fs:[00000030h] 5_2_33B070C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B070C0 mov eax, dword ptr fs:[00000030h] 5_2_33B070C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B070C0 mov eax, dword ptr fs:[00000030h] 5_2_33B070C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B070C0 mov eax, dword ptr fs:[00000030h] 5_2_33B070C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B070C0 mov eax, dword ptr fs:[00000030h] 5_2_33B070C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B070C0 mov eax, dword ptr fs:[00000030h] 5_2_33B070C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B070C0 mov eax, dword ptr fs:[00000030h] 5_2_33B070C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B070C0 mov eax, dword ptr fs:[00000030h] 5_2_33B070C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B6D0C0 mov eax, dword ptr fs:[00000030h] 5_2_33B6D0C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B6D0C0 mov eax, dword ptr fs:[00000030h] 5_2_33B6D0C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB903E mov eax, dword ptr fs:[00000030h] 5_2_33BB903E
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB903E mov eax, dword ptr fs:[00000030h] 5_2_33BB903E
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB903E mov eax, dword ptr fs:[00000030h] 5_2_33BB903E
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB903E mov eax, dword ptr fs:[00000030h] 5_2_33BB903E
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B01070 mov eax, dword ptr fs:[00000030h] 5_2_33B01070
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B01070 mov ecx, dword ptr fs:[00000030h] 5_2_33B01070
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B01070 mov eax, dword ptr fs:[00000030h] 5_2_33B01070
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B01070 mov eax, dword ptr fs:[00000030h] 5_2_33B01070
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B01070 mov eax, dword ptr fs:[00000030h] 5_2_33B01070
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B01070 mov eax, dword ptr fs:[00000030h] 5_2_33B01070
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B01070 mov eax, dword ptr fs:[00000030h] 5_2_33B01070
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B01070 mov eax, dword ptr fs:[00000030h] 5_2_33B01070
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B01070 mov eax, dword ptr fs:[00000030h] 5_2_33B01070
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B01070 mov eax, dword ptr fs:[00000030h] 5_2_33B01070
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B01070 mov eax, dword ptr fs:[00000030h] 5_2_33B01070
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B01070 mov eax, dword ptr fs:[00000030h] 5_2_33B01070
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B01070 mov eax, dword ptr fs:[00000030h] 5_2_33B01070
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B6D070 mov ecx, dword ptr fs:[00000030h] 5_2_33B6D070
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B7106E mov eax, dword ptr fs:[00000030h] 5_2_33B7106E
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BC5060 mov eax, dword ptr fs:[00000030h] 5_2_33BC5060
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1B052 mov eax, dword ptr fs:[00000030h] 5_2_33B1B052
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9705E mov ebx, dword ptr fs:[00000030h] 5_2_33B9705E
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9705E mov eax, dword ptr fs:[00000030h] 5_2_33B9705E
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1D7B0 mov eax, dword ptr fs:[00000030h] 5_2_33B1D7B0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BC37B6 mov eax, dword ptr fs:[00000030h] 5_2_33BC37B6
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BAD7B0 mov eax, dword ptr fs:[00000030h] 5_2_33BAD7B0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BAD7B0 mov eax, dword ptr fs:[00000030h] 5_2_33BAD7B0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF7BA mov eax, dword ptr fs:[00000030h] 5_2_33AEF7BA
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF7BA mov eax, dword ptr fs:[00000030h] 5_2_33AEF7BA
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF7BA mov eax, dword ptr fs:[00000030h] 5_2_33AEF7BA
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF7BA mov eax, dword ptr fs:[00000030h] 5_2_33AEF7BA
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF7BA mov eax, dword ptr fs:[00000030h] 5_2_33AEF7BA
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF7BA mov eax, dword ptr fs:[00000030h] 5_2_33AEF7BA
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF7BA mov eax, dword ptr fs:[00000030h] 5_2_33AEF7BA
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF7BA mov eax, dword ptr fs:[00000030h] 5_2_33AEF7BA
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF7BA mov eax, dword ptr fs:[00000030h] 5_2_33AEF7BA
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B7F7AF mov eax, dword ptr fs:[00000030h] 5_2_33B7F7AF
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B7F7AF mov eax, dword ptr fs:[00000030h] 5_2_33B7F7AF
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B7F7AF mov eax, dword ptr fs:[00000030h] 5_2_33B7F7AF
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B7F7AF mov eax, dword ptr fs:[00000030h] 5_2_33B7F7AF
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B7F7AF mov eax, dword ptr fs:[00000030h] 5_2_33B7F7AF
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B797A9 mov eax, dword ptr fs:[00000030h] 5_2_33B797A9
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BAF78A mov eax, dword ptr fs:[00000030h] 5_2_33BAF78A
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFD7E0 mov ecx, dword ptr fs:[00000030h] 5_2_33AFD7E0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF57C0 mov eax, dword ptr fs:[00000030h] 5_2_33AF57C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF57C0 mov eax, dword ptr fs:[00000030h] 5_2_33AF57C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF57C0 mov eax, dword ptr fs:[00000030h] 5_2_33AF57C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BCB73C mov eax, dword ptr fs:[00000030h] 5_2_33BCB73C
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BCB73C mov eax, dword ptr fs:[00000030h] 5_2_33BCB73C
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BCB73C mov eax, dword ptr fs:[00000030h] 5_2_33BCB73C
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BCB73C mov eax, dword ptr fs:[00000030h] 5_2_33BCB73C
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B25734 mov eax, dword ptr fs:[00000030h] 5_2_33B25734
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF3720 mov eax, dword ptr fs:[00000030h] 5_2_33AF3720
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B0F720 mov eax, dword ptr fs:[00000030h] 5_2_33B0F720
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B0F720 mov eax, dword ptr fs:[00000030h] 5_2_33B0F720
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B0F720 mov eax, dword ptr fs:[00000030h] 5_2_33B0F720
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB972B mov eax, dword ptr fs:[00000030h] 5_2_33BB972B
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BAF72E mov eax, dword ptr fs:[00000030h] 5_2_33BAF72E
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF973A mov eax, dword ptr fs:[00000030h] 5_2_33AF973A
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF973A mov eax, dword ptr fs:[00000030h] 5_2_33AF973A
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE9730 mov eax, dword ptr fs:[00000030h] 5_2_33AE9730
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE9730 mov eax, dword ptr fs:[00000030h] 5_2_33AE9730
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF7703 mov eax, dword ptr fs:[00000030h] 5_2_33AF7703
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF5702 mov eax, dword ptr fs:[00000030h] 5_2_33AF5702
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF5702 mov eax, dword ptr fs:[00000030h] 5_2_33AF5702
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B2F71F mov eax, dword ptr fs:[00000030h] 5_2_33B2F71F
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B2F71F mov eax, dword ptr fs:[00000030h] 5_2_33B2F71F
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEB765 mov eax, dword ptr fs:[00000030h] 5_2_33AEB765
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEB765 mov eax, dword ptr fs:[00000030h] 5_2_33AEB765
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEB765 mov eax, dword ptr fs:[00000030h] 5_2_33AEB765
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEB765 mov eax, dword ptr fs:[00000030h] 5_2_33AEB765
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9375F mov eax, dword ptr fs:[00000030h] 5_2_33B9375F
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9375F mov eax, dword ptr fs:[00000030h] 5_2_33B9375F
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9375F mov eax, dword ptr fs:[00000030h] 5_2_33B9375F
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9375F mov eax, dword ptr fs:[00000030h] 5_2_33B9375F
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9375F mov eax, dword ptr fs:[00000030h] 5_2_33B9375F
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B03740 mov eax, dword ptr fs:[00000030h] 5_2_33B03740
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B03740 mov eax, dword ptr fs:[00000030h] 5_2_33B03740
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B03740 mov eax, dword ptr fs:[00000030h] 5_2_33B03740
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BC3749 mov eax, dword ptr fs:[00000030h] 5_2_33BC3749
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AED6AA mov eax, dword ptr fs:[00000030h] 5_2_33AED6AA
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AED6AA mov eax, dword ptr fs:[00000030h] 5_2_33AED6AA
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE76B2 mov eax, dword ptr fs:[00000030h] 5_2_33AE76B2
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE76B2 mov eax, dword ptr fs:[00000030h] 5_2_33AE76B2
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE76B2 mov eax, dword ptr fs:[00000030h] 5_2_33AE76B2
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B7368C mov eax, dword ptr fs:[00000030h] 5_2_33B7368C
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B7368C mov eax, dword ptr fs:[00000030h] 5_2_33B7368C
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B7368C mov eax, dword ptr fs:[00000030h] 5_2_33B7368C
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B7368C mov eax, dword ptr fs:[00000030h] 5_2_33B7368C
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BAD6F0 mov eax, dword ptr fs:[00000030h] 5_2_33BAD6F0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1D6E0 mov eax, dword ptr fs:[00000030h] 5_2_33B1D6E0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1D6E0 mov eax, dword ptr fs:[00000030h] 5_2_33B1D6E0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B836EE mov eax, dword ptr fs:[00000030h] 5_2_33B836EE
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B836EE mov eax, dword ptr fs:[00000030h] 5_2_33B836EE
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B836EE mov eax, dword ptr fs:[00000030h] 5_2_33B836EE
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B836EE mov eax, dword ptr fs:[00000030h] 5_2_33B836EE
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B836EE mov eax, dword ptr fs:[00000030h] 5_2_33B836EE
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B836EE mov eax, dword ptr fs:[00000030h] 5_2_33B836EE
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFB6C0 mov eax, dword ptr fs:[00000030h] 5_2_33AFB6C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFB6C0 mov eax, dword ptr fs:[00000030h] 5_2_33AFB6C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFB6C0 mov eax, dword ptr fs:[00000030h] 5_2_33AFB6C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFB6C0 mov eax, dword ptr fs:[00000030h] 5_2_33AFB6C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFB6C0 mov eax, dword ptr fs:[00000030h] 5_2_33AFB6C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFB6C0 mov eax, dword ptr fs:[00000030h] 5_2_33AFB6C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB16CC mov eax, dword ptr fs:[00000030h] 5_2_33BB16CC
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB16CC mov eax, dword ptr fs:[00000030h] 5_2_33BB16CC
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB16CC mov eax, dword ptr fs:[00000030h] 5_2_33BB16CC
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB16CC mov eax, dword ptr fs:[00000030h] 5_2_33BB16CC
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BAF6C7 mov eax, dword ptr fs:[00000030h] 5_2_33BAF6C7
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B216CF mov eax, dword ptr fs:[00000030h] 5_2_33B216CF
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF626 mov eax, dword ptr fs:[00000030h] 5_2_33AEF626
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF626 mov eax, dword ptr fs:[00000030h] 5_2_33AEF626
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF626 mov eax, dword ptr fs:[00000030h] 5_2_33AEF626
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF626 mov eax, dword ptr fs:[00000030h] 5_2_33AEF626
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF626 mov eax, dword ptr fs:[00000030h] 5_2_33AEF626
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF626 mov eax, dword ptr fs:[00000030h] 5_2_33AEF626
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF626 mov eax, dword ptr fs:[00000030h] 5_2_33AEF626
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF626 mov eax, dword ptr fs:[00000030h] 5_2_33AEF626
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEF626 mov eax, dword ptr fs:[00000030h] 5_2_33AEF626
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BC5636 mov eax, dword ptr fs:[00000030h] 5_2_33BC5636
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B2F603 mov eax, dword ptr fs:[00000030h] 5_2_33B2F603
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B21607 mov eax, dword ptr fs:[00000030h] 5_2_33B21607
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF3616 mov eax, dword ptr fs:[00000030h] 5_2_33AF3616
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF3616 mov eax, dword ptr fs:[00000030h] 5_2_33AF3616
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B29660 mov eax, dword ptr fs:[00000030h] 5_2_33B29660
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B29660 mov eax, dword ptr fs:[00000030h] 5_2_33B29660
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B8D660 mov eax, dword ptr fs:[00000030h] 5_2_33B8D660
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1F5B0 mov eax, dword ptr fs:[00000030h] 5_2_33B1F5B0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1F5B0 mov eax, dword ptr fs:[00000030h] 5_2_33B1F5B0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1F5B0 mov eax, dword ptr fs:[00000030h] 5_2_33B1F5B0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1F5B0 mov eax, dword ptr fs:[00000030h] 5_2_33B1F5B0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1F5B0 mov eax, dword ptr fs:[00000030h] 5_2_33B1F5B0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1F5B0 mov eax, dword ptr fs:[00000030h] 5_2_33B1F5B0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1F5B0 mov eax, dword ptr fs:[00000030h] 5_2_33B1F5B0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1F5B0 mov eax, dword ptr fs:[00000030h] 5_2_33B1F5B0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1F5B0 mov eax, dword ptr fs:[00000030h] 5_2_33B1F5B0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B835BA mov eax, dword ptr fs:[00000030h] 5_2_33B835BA
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B835BA mov eax, dword ptr fs:[00000030h] 5_2_33B835BA
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B835BA mov eax, dword ptr fs:[00000030h] 5_2_33B835BA
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B835BA mov eax, dword ptr fs:[00000030h] 5_2_33B835BA
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BAF5BE mov eax, dword ptr fs:[00000030h] 5_2_33BAF5BE
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B8D5B0 mov eax, dword ptr fs:[00000030h] 5_2_33B8D5B0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B8D5B0 mov eax, dword ptr fs:[00000030h] 5_2_33B8D5B0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B115A9 mov eax, dword ptr fs:[00000030h] 5_2_33B115A9
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B115A9 mov eax, dword ptr fs:[00000030h] 5_2_33B115A9
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B115A9 mov eax, dword ptr fs:[00000030h] 5_2_33B115A9
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B115A9 mov eax, dword ptr fs:[00000030h] 5_2_33B115A9
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B115A9 mov eax, dword ptr fs:[00000030h] 5_2_33B115A9
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE758F mov eax, dword ptr fs:[00000030h] 5_2_33AE758F
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE758F mov eax, dword ptr fs:[00000030h] 5_2_33AE758F
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE758F mov eax, dword ptr fs:[00000030h] 5_2_33AE758F
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B7B594 mov eax, dword ptr fs:[00000030h] 5_2_33B7B594
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B7B594 mov eax, dword ptr fs:[00000030h] 5_2_33B7B594
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B115F4 mov eax, dword ptr fs:[00000030h] 5_2_33B115F4
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B115F4 mov eax, dword ptr fs:[00000030h] 5_2_33B115F4
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B115F4 mov eax, dword ptr fs:[00000030h] 5_2_33B115F4
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B115F4 mov eax, dword ptr fs:[00000030h] 5_2_33B115F4
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B115F4 mov eax, dword ptr fs:[00000030h] 5_2_33B115F4
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B115F4 mov eax, dword ptr fs:[00000030h] 5_2_33B115F4
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B6D5D0 mov eax, dword ptr fs:[00000030h] 5_2_33B6D5D0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B6D5D0 mov ecx, dword ptr fs:[00000030h] 5_2_33B6D5D0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BC35D7 mov eax, dword ptr fs:[00000030h] 5_2_33BC35D7
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BC35D7 mov eax, dword ptr fs:[00000030h] 5_2_33BC35D7
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BC35D7 mov eax, dword ptr fs:[00000030h] 5_2_33BC35D7
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B195DA mov eax, dword ptr fs:[00000030h] 5_2_33B195DA
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B255C0 mov eax, dword ptr fs:[00000030h] 5_2_33B255C0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BC55C9 mov eax, dword ptr fs:[00000030h] 5_2_33BC55C9
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B2D530 mov eax, dword ptr fs:[00000030h] 5_2_33B2D530
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B2D530 mov eax, dword ptr fs:[00000030h] 5_2_33B2D530
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BC5537 mov eax, dword ptr fs:[00000030h] 5_2_33BC5537
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BAB52F mov eax, dword ptr fs:[00000030h] 5_2_33BAB52F
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFD534 mov eax, dword ptr fs:[00000030h] 5_2_33AFD534
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFD534 mov eax, dword ptr fs:[00000030h] 5_2_33AFD534
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFD534 mov eax, dword ptr fs:[00000030h] 5_2_33AFD534
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFD534 mov eax, dword ptr fs:[00000030h] 5_2_33AFD534
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFD534 mov eax, dword ptr fs:[00000030h] 5_2_33AFD534
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFD534 mov eax, dword ptr fs:[00000030h] 5_2_33AFD534
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9F525 mov eax, dword ptr fs:[00000030h] 5_2_33B9F525
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9F525 mov eax, dword ptr fs:[00000030h] 5_2_33B9F525
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9F525 mov eax, dword ptr fs:[00000030h] 5_2_33B9F525
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9F525 mov eax, dword ptr fs:[00000030h] 5_2_33B9F525
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9F525 mov eax, dword ptr fs:[00000030h] 5_2_33B9F525
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9F525 mov eax, dword ptr fs:[00000030h] 5_2_33B9F525
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9F525 mov eax, dword ptr fs:[00000030h] 5_2_33B9F525
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B27505 mov eax, dword ptr fs:[00000030h] 5_2_33B27505
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B27505 mov ecx, dword ptr fs:[00000030h] 5_2_33B27505
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B2B570 mov eax, dword ptr fs:[00000030h] 5_2_33B2B570
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B2B570 mov eax, dword ptr fs:[00000030h] 5_2_33B2B570
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEB562 mov eax, dword ptr fs:[00000030h] 5_2_33AEB562
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9B550 mov eax, dword ptr fs:[00000030h] 5_2_33B9B550
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9B550 mov eax, dword ptr fs:[00000030h] 5_2_33B9B550
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9B550 mov eax, dword ptr fs:[00000030h] 5_2_33B9B550
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B234B0 mov eax, dword ptr fs:[00000030h] 5_2_33B234B0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE74B0 mov eax, dword ptr fs:[00000030h] 5_2_33AE74B0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE74B0 mov eax, dword ptr fs:[00000030h] 5_2_33AE74B0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF9486 mov eax, dword ptr fs:[00000030h] 5_2_33AF9486
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF9486 mov eax, dword ptr fs:[00000030h] 5_2_33AF9486
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEB480 mov eax, dword ptr fs:[00000030h] 5_2_33AEB480
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B994E0 mov eax, dword ptr fs:[00000030h] 5_2_33B994E0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BC54DB mov eax, dword ptr fs:[00000030h] 5_2_33BC54DB
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B77410 mov eax, dword ptr fs:[00000030h] 5_2_33B77410
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1340D mov eax, dword ptr fs:[00000030h] 5_2_33B1340D
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BC547F mov eax, dword ptr fs:[00000030h] 5_2_33BC547F
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF1460 mov eax, dword ptr fs:[00000030h] 5_2_33AF1460
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF1460 mov eax, dword ptr fs:[00000030h] 5_2_33AF1460
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF1460 mov eax, dword ptr fs:[00000030h] 5_2_33AF1460
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF1460 mov eax, dword ptr fs:[00000030h] 5_2_33AF1460
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF1460 mov eax, dword ptr fs:[00000030h] 5_2_33AF1460
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B0F460 mov eax, dword ptr fs:[00000030h] 5_2_33B0F460
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B0F460 mov eax, dword ptr fs:[00000030h] 5_2_33B0F460
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B0F460 mov eax, dword ptr fs:[00000030h] 5_2_33B0F460
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B0F460 mov eax, dword ptr fs:[00000030h] 5_2_33B0F460
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B0F460 mov eax, dword ptr fs:[00000030h] 5_2_33B0F460
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B0F460 mov eax, dword ptr fs:[00000030h] 5_2_33B0F460
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BAF453 mov eax, dword ptr fs:[00000030h] 5_2_33BAF453
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9B450 mov eax, dword ptr fs:[00000030h] 5_2_33B9B450
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9B450 mov eax, dword ptr fs:[00000030h] 5_2_33B9B450
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9B450 mov eax, dword ptr fs:[00000030h] 5_2_33B9B450
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9B450 mov eax, dword ptr fs:[00000030h] 5_2_33B9B450
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFB440 mov eax, dword ptr fs:[00000030h] 5_2_33AFB440
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFB440 mov eax, dword ptr fs:[00000030h] 5_2_33AFB440
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFB440 mov eax, dword ptr fs:[00000030h] 5_2_33AFB440
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFB440 mov eax, dword ptr fs:[00000030h] 5_2_33AFB440
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFB440 mov eax, dword ptr fs:[00000030h] 5_2_33AFB440
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFB440 mov eax, dword ptr fs:[00000030h] 5_2_33AFB440
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1DBA0 mov eax, dword ptr fs:[00000030h] 5_2_33B1DBA0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1DBA0 mov eax, dword ptr fs:[00000030h] 5_2_33B1DBA0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1DBA0 mov eax, dword ptr fs:[00000030h] 5_2_33B1DBA0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1DBA0 mov eax, dword ptr fs:[00000030h] 5_2_33B1DBA0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1DBA0 mov eax, dword ptr fs:[00000030h] 5_2_33B1DBA0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1DBA0 mov eax, dword ptr fs:[00000030h] 5_2_33B1DBA0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B29B9F mov eax, dword ptr fs:[00000030h] 5_2_33B29B9F
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B29B9F mov eax, dword ptr fs:[00000030h] 5_2_33B29B9F
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B29B9F mov eax, dword ptr fs:[00000030h] 5_2_33B29B9F
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BAFB97 mov eax, dword ptr fs:[00000030h] 5_2_33BAFB97
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB9B8B mov eax, dword ptr fs:[00000030h] 5_2_33BB9B8B
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BB9B8B mov eax, dword ptr fs:[00000030h] 5_2_33BB9B8B
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BAFBF3 mov eax, dword ptr fs:[00000030h] 5_2_33BAFBF3
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B31BEF mov eax, dword ptr fs:[00000030h] 5_2_33B31BEF
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B31BEF mov eax, dword ptr fs:[00000030h] 5_2_33B31BEF
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE7BCD mov eax, dword ptr fs:[00000030h] 5_2_33AE7BCD
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE7BCD mov ecx, dword ptr fs:[00000030h] 5_2_33AE7BCD
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B03BD6 mov eax, dword ptr fs:[00000030h] 5_2_33B03BD6
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B03BD6 mov eax, dword ptr fs:[00000030h] 5_2_33B03BD6
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B03BD6 mov eax, dword ptr fs:[00000030h] 5_2_33B03BD6
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B03BD6 mov eax, dword ptr fs:[00000030h] 5_2_33B03BD6
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B03BD6 mov eax, dword ptr fs:[00000030h] 5_2_33B03BD6
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF9BC4 mov eax, dword ptr fs:[00000030h] 5_2_33AF9BC4
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B7FBDC mov eax, dword ptr fs:[00000030h] 5_2_33B7FBDC
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B7FBDC mov eax, dword ptr fs:[00000030h] 5_2_33B7FBDC
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B7FBDC mov eax, dword ptr fs:[00000030h] 5_2_33B7FBDC
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B29B28 mov eax, dword ptr fs:[00000030h] 5_2_33B29B28
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B29B28 mov eax, dword ptr fs:[00000030h] 5_2_33B29B28
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF1B04 mov eax, dword ptr fs:[00000030h] 5_2_33AF1B04
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AF1B04 mov eax, dword ptr fs:[00000030h] 5_2_33AF1B04
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1DB00 mov eax, dword ptr fs:[00000030h] 5_2_33B1DB00
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1DB00 mov eax, dword ptr fs:[00000030h] 5_2_33B1DB00
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1DB00 mov eax, dword ptr fs:[00000030h] 5_2_33B1DB00
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1DB00 mov eax, dword ptr fs:[00000030h] 5_2_33B1DB00
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1DB00 mov eax, dword ptr fs:[00000030h] 5_2_33B1DB00
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1DB00 mov edx, dword ptr fs:[00000030h] 5_2_33B1DB00
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BAFB0C mov eax, dword ptr fs:[00000030h] 5_2_33BAFB0C
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B93B60 mov eax, dword ptr fs:[00000030h] 5_2_33B93B60
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B93B60 mov eax, dword ptr fs:[00000030h] 5_2_33B93B60
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B93B60 mov eax, dword ptr fs:[00000030h] 5_2_33B93B60
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B93B60 mov eax, dword ptr fs:[00000030h] 5_2_33B93B60
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B93B60 mov eax, dword ptr fs:[00000030h] 5_2_33B93B60
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEFB4C mov edi, dword ptr fs:[00000030h] 5_2_33AEFB4C
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B85B50 mov eax, dword ptr fs:[00000030h] 5_2_33B85B50
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B85B50 mov eax, dword ptr fs:[00000030h] 5_2_33B85B50
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEFAA4 mov ecx, dword ptr fs:[00000030h] 5_2_33AEFAA4
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFBAA0 mov eax, dword ptr fs:[00000030h] 5_2_33AFBAA0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFBAA0 mov eax, dword ptr fs:[00000030h] 5_2_33AFBAA0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9DAAC mov ecx, dword ptr fs:[00000030h] 5_2_33B9DAAC
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9DAAC mov ecx, dword ptr fs:[00000030h] 5_2_33B9DAAC
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9DAAC mov eax, dword ptr fs:[00000030h] 5_2_33B9DAAC
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA1AA3 mov eax, dword ptr fs:[00000030h] 5_2_33BA1AA3
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA1AA3 mov eax, dword ptr fs:[00000030h] 5_2_33BA1AA3
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BA1AA3 mov eax, dword ptr fs:[00000030h] 5_2_33BA1AA3
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1DAAE mov eax, dword ptr fs:[00000030h] 5_2_33B1DAAE
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE7A80 mov eax, dword ptr fs:[00000030h] 5_2_33AE7A80
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE7A80 mov eax, dword ptr fs:[00000030h] 5_2_33AE7A80
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AE7A80 mov eax, dword ptr fs:[00000030h] 5_2_33AE7A80
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BAFA87 mov eax, dword ptr fs:[00000030h] 5_2_33BAFA87
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEBAE0 mov eax, dword ptr fs:[00000030h] 5_2_33AEBAE0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B85AD0 mov eax, dword ptr fs:[00000030h] 5_2_33B85AD0
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1BADA mov eax, dword ptr fs:[00000030h] 5_2_33B1BADA
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B71ACB mov eax, dword ptr fs:[00000030h] 5_2_33B71ACB
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B71ACB mov ecx, dword ptr fs:[00000030h] 5_2_33B71ACB
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1DA20 mov eax, dword ptr fs:[00000030h] 5_2_33B1DA20
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B1DA20 mov eax, dword ptr fs:[00000030h] 5_2_33B1DA20
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFBA30 mov eax, dword ptr fs:[00000030h] 5_2_33AFBA30
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFBA30 mov ecx, dword ptr fs:[00000030h] 5_2_33AFBA30
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFBA30 mov eax, dword ptr fs:[00000030h] 5_2_33AFBA30
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFBA30 mov eax, dword ptr fs:[00000030h] 5_2_33AFBA30
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFBA30 mov eax, dword ptr fs:[00000030h] 5_2_33AFBA30
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AFBA30 mov eax, dword ptr fs:[00000030h] 5_2_33AFBA30
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B97A11 mov edi, dword ptr fs:[00000030h] 5_2_33B97A11
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B19A18 mov ecx, dword ptr fs:[00000030h] 5_2_33B19A18
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B6DA1D mov eax, dword ptr fs:[00000030h] 5_2_33B6DA1D
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9BA0B mov eax, dword ptr fs:[00000030h] 5_2_33B9BA0B
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9BA0B mov eax, dword ptr fs:[00000030h] 5_2_33B9BA0B
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9BA0B mov eax, dword ptr fs:[00000030h] 5_2_33B9BA0B
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B9BA0B mov eax, dword ptr fs:[00000030h] 5_2_33B9BA0B
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B25A01 mov eax, dword ptr fs:[00000030h] 5_2_33B25A01
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B25A01 mov ecx, dword ptr fs:[00000030h] 5_2_33B25A01
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B25A01 mov eax, dword ptr fs:[00000030h] 5_2_33B25A01
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B25A01 mov eax, dword ptr fs:[00000030h] 5_2_33B25A01
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33BAFA02 mov eax, dword ptr fs:[00000030h] 5_2_33BAFA02
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33AEBA10 mov eax, dword ptr fs:[00000030h] 5_2_33AEBA10
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B83A78 mov eax, dword ptr fs:[00000030h] 5_2_33B83A78
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B83A78 mov eax, dword ptr fs:[00000030h] 5_2_33B83A78
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B83A78 mov eax, dword ptr fs:[00000030h] 5_2_33B83A78
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 5_2_33B83A78 mov eax, dword ptr fs:[00000030h] 5_2_33B83A78
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Process created: C:\Users\user\Desktop\rTransferenciarealizada451236.exe "C:\Users\user\Desktop\rTransferenciarealizada451236.exe" Jump to behavior
Source: C:\Users\user\Desktop\rTransferenciarealizada451236.exe Code function: 0_2_004031BB EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, 0_2_004031BB
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs