Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then cmp dword ptr [edi+edx*8], 4C697C35h |
0_2_00AE1050 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then mov word ptr [ebx], dx |
0_2_00AB8890 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then cmp dword ptr [ebx+edi*8], 1B6183F2h |
0_2_00AC68D0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then mov dword ptr [esi+04h], eax |
0_2_00ACE03F |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then movzx esi, byte ptr [esp+eax-2FEE79D7h] |
0_2_00AAD80D |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then mov byte ptr [edi], cl |
0_2_00ACC81E |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then movzx ecx, byte ptr [esp+esi+04h] |
0_2_00AC3850 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then mov byte ptr [edi], bl |
0_2_00AA91B0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then cmp dword ptr [edi+edx*8], 4C697C35h |
0_2_00AE11E0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then movzx edx, byte ptr [esi+ecx+5F30FA22h] |
0_2_00AAB1D0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then jmp eax |
0_2_00AC51D0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then movzx edi, byte ptr [esp+eax+000001ADh] |
0_2_00AB990C |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then movsx eax, byte ptr [esi] |
0_2_00AE02F0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then mov ebx, edx |
0_2_00ABC225 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then movsx eax, byte ptr [esi] |
0_2_00AE0210 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then mov byte ptr [edx], al |
0_2_00ACE3BE |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then mov ecx, eax |
0_2_00ABEB80 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then mov word ptr [esi], ax |
0_2_00ABEB80 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then mov word ptr [esi], ax |
0_2_00ABEB80 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then movzx edx, byte ptr [esp+eax-42FFC5DBh] |
0_2_00AAD392 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then movzx eax, byte ptr [esi+edx+00000420h] |
0_2_00ACC3D0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then mov byte ptr [ebx], dl |
0_2_00ACC3D0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then movzx edx, byte ptr [esp+ecx-5B418B08h] |
0_2_00ADC3D0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then cmp dword ptr [esi+edx*8], 98D5A07Fh |
0_2_00ADC3D0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then mov ecx, eax |
0_2_00ABD330 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then movzx edi, byte ptr [esp+edx+000000E8h] |
0_2_00AAE4AF |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then movzx ecx, byte ptr [esp+eax] |
0_2_00AE1480 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then mov ecx, eax |
0_2_00AC6C90 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then mov ebx, dword ptr [edi+04h] |
0_2_00ACB4E0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then movzx ebx, byte ptr [edx] |
0_2_00AD5CC0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then jmp eax |
0_2_00AC5440 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then movzx ebx, bx |
0_2_00AC55A4 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then mov dword ptr [ebp-10h], edx |
0_2_00AC4DA1 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then movzx edi, byte ptr [esp+eax-0CA2BA0Eh] |
0_2_00AACDB0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then movzx eax, byte ptr [edi] |
0_2_00ADFDE0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then movsx eax, byte ptr [esi] |
0_2_00ADFDE0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then cmp word ptr [ebp+edi+02h], 0000h |
0_2_00AC35F0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then mov dword ptr [esi+04h], eax |
0_2_00ACEDCA |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then jmp eax |
0_2_00AC55D0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then movzx edx, byte ptr [eax+ecx] |
0_2_00AAAD20 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then mov dword ptr [esi+04h], eax |
0_2_00ACED09 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then movzx edi, byte ptr [esp+eax-7269D38Fh] |
0_2_00AB8E83 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then cmp dword ptr [ebx+edi*8], 32F24C0Bh |
0_2_00ADBE60 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then cmp dword ptr [ebx+edi*8], 1B6183F2h |
0_2_00ADBFA0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then mov byte ptr [edi], al |
0_2_00ABFF90 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then mov edx, ecx |
0_2_00AAC795 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then mov ebx, ecx |
0_2_00AA77D0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then movzx edx, word ptr [eax] |
0_2_00AE1720 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then mov dword ptr [ecx], edi |
0_2_00AAB769 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then cmp dword ptr [ecx+ebx*8], 9C142CDAh |
0_2_00AE0F70 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 4x nop then jmp dword ptr [00AE6898h] |
0_2_00AB9744 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AA8A70 |
0_2_00AA8A70 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AD88B0 |
0_2_00AD88B0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AC90B1 |
0_2_00AC90B1 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AA4880 |
0_2_00AA4880 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AD0082 |
0_2_00AD0082 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AC88F8 |
0_2_00AC88F8 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ACE0CB |
0_2_00ACE0CB |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AA98C0 |
0_2_00AA98C0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AC88DD |
0_2_00AC88DD |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AD3820 |
0_2_00AD3820 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ACE03F |
0_2_00ACE03F |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AA6830 |
0_2_00AA6830 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AA6180 |
0_2_00AA6180 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ACC9E3 |
0_2_00ACC9E3 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ABB1FA |
0_2_00ABB1FA |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ACC1F0 |
0_2_00ACC1F0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AC51D0 |
0_2_00AC51D0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AB990C |
0_2_00AB990C |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AAE911 |
0_2_00AAE911 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AA5917 |
0_2_00AA5917 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AA5917 |
0_2_00AA5917 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AC4957 |
0_2_00AC4957 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AE02F0 |
0_2_00AE02F0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ACFAD8 |
0_2_00ACFAD8 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AACA3F |
0_2_00AACA3F |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ACA235 |
0_2_00ACA235 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AE0210 |
0_2_00AE0210 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AA2A70 |
0_2_00AA2A70 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ACAA59 |
0_2_00ACAA59 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AD9250 |
0_2_00AD9250 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AC13AD |
0_2_00AC13AD |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ACE3BE |
0_2_00ACE3BE |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ABEB80 |
0_2_00ABEB80 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ADCB80 |
0_2_00ADCB80 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ACAB83 |
0_2_00ACAB83 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ACD304 |
0_2_00ACD304 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ABF3C0 |
0_2_00ABF3C0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ACC3D0 |
0_2_00ACC3D0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ADC3D0 |
0_2_00ADC3D0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ABE304 |
0_2_00ABE304 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ABC4BC |
0_2_00ABC4BC |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AE1CB0 |
0_2_00AE1CB0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AA3490 |
0_2_00AA3490 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AA6CC0 |
0_2_00AA6CC0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AA5CC0 |
0_2_00AA5CC0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AA9410 |
0_2_00AA9410 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AD0C61 |
0_2_00AD0C61 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AC5440 |
0_2_00AC5440 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AC55A4 |
0_2_00AC55A4 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AD35B0 |
0_2_00AD35B0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ACB580 |
0_2_00ACB580 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ABCDE0 |
0_2_00ABCDE0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ADFDE0 |
0_2_00ADFDE0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ACEDCA |
0_2_00ACEDCA |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AC55D0 |
0_2_00AC55D0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AAAD20 |
0_2_00AAAD20 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ACED09 |
0_2_00ACED09 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AC2D10 |
0_2_00AC2D10 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AC7D61 |
0_2_00AC7D61 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AC8D61 |
0_2_00AC8D61 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ABFD50 |
0_2_00ABFD50 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ABDEB6 |
0_2_00ABDEB6 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AB8E83 |
0_2_00AB8E83 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AC0EF0 |
0_2_00AC0EF0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AB9ECF |
0_2_00AB9ECF |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AD8ED0 |
0_2_00AD8ED0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AA9E21 |
0_2_00AA9E21 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AA8670 |
0_2_00AA8670 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AA3E70 |
0_2_00AA3E70 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AD8650 |
0_2_00AD8650 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ABA783 |
0_2_00ABA783 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AC6F9E |
0_2_00AC6F9E |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ABFF90 |
0_2_00ABFF90 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AD1790 |
0_2_00AD1790 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ABAFC2 |
0_2_00ABAFC2 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00ACC7C6 |
0_2_00ACC7C6 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AC77C0 |
0_2_00AC77C0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AA77D0 |
0_2_00AA77D0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AC97D0 |
0_2_00AC97D0 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AC3F26 |
0_2_00AC3F26 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AE1720 |
0_2_00AE1720 |
Source: C:\Users\user\Desktop\XTN21MDFrg.exe |
Code function: 0_2_00AAB769 |
0_2_00AAB769 |
Source: XTN21MDFrg.exe, 00000000.00000000.2114730785.0000000000AE2000.00000002.00000001.01000000.00000003.sdmp |
String found in binary or memory: faintbl0w.sbs |
Source: XTN21MDFrg.exe, 00000000.00000000.2114730785.0000000000AE2000.00000002.00000001.01000000.00000003.sdmp |
String found in binary or memory: 300snails.sbs |
Source: XTN21MDFrg.exe, 00000000.00000000.2114730785.0000000000AE2000.00000002.00000001.01000000.00000003.sdmp |
String found in binary or memory: 3xc1aimbl0w.sbs |
Source: XTN21MDFrg.exe, 00000000.00000000.2114730785.0000000000AE2000.00000002.00000001.01000000.00000003.sdmp |
String found in binary or memory: thicktoys.sbs |