Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 0x0000000000000000: FC cld
- 0x0000000000000001: 48 83 E4 F0 and rsp, 0xfffffffffffffff0
- 0x0000000000000005: E8 C0 00 00 00 call 0xca
- 0x000000000000000a: 41 51 push r9
- 0x000000000000000c: 41 50 push r8
- 0x000000000000000e: 52 push rdx
- 0x000000000000000f: 51 push rcx
- 0x0000000000000010: 56 push rsi
- 0x0000000000000011: 48 31 D2 xor rdx, rdx
- 0x0000000000000014: 65 48 8B 52 60 mov rdx, qword ptr gs:[rdx + 0x60]
- 0x0000000000000019: 48 8B 52 18 mov rdx, qword ptr [rdx + 0x18]
- 0x000000000000001d: 48 8B 52 20 mov rdx, qword ptr [rdx + 0x20]
- 0x0000000000000021: 48 8B 72 50 mov rsi, qword ptr [rdx + 0x50]
- 0x0000000000000025: 48 0F B7 4A 4A movzx rcx, word ptr [rdx + 0x4a]
- 0x000000000000002a: 4D 31 C9 xor r9, r9
- 0x000000000000002d: 48 31 C0 xor rax, rax
- 0x0000000000000030: AC lodsb al, byte ptr [rsi]
- 0x0000000000000031: 3C 61 cmp al, 0x61
- 0x0000000000000033: 7C 02 jl 0x37
- 0x0000000000000035: 2C 20 sub al, 0x20
- 0x0000000000000037: 41 C1 C9 0D ror r9d, 0xd
- 0x000000000000003b: 41 01 C1 add r9d, eax
- 0x000000000000003e: E2 ED loop 0x2d
- 0x0000000000000040: 52 push rdx
- 0x0000000000000041: 41 51 push r9
- 0x0000000000000043: 48 8B 52 20 mov rdx, qword ptr [rdx + 0x20]
- 0x0000000000000047: 8B 42 3C mov eax, dword ptr [rdx + 0x3c]
- 0x000000000000004a: 48 01 D0 add rax, rdx
- 0x000000000000004d: 8B 80 88 00 00 00 mov eax, dword ptr [rax + 0x88]
- 0x0000000000000053: 48 85 C0 test rax, rax
- 0x0000000000000056: 74 67 je 0xbf
- 0x0000000000000058: 48 01 D0 add rax, rdx
- 0x000000000000005b: 50 push rax
- 0x000000000000005c: 8B 48 18 mov ecx, dword ptr [rax + 0x18]
- 0x000000000000005f: 44 8B 40 20 mov r8d, dword ptr [rax + 0x20]
- 0x0000000000000063: 49 01 D0 add r8, rdx
- 0x0000000000000066: E3 56 jrcxz 0xbe
- 0x0000000000000068: 48 FF C9 dec rcx
- 0x000000000000006b: 41 8B 34 88 mov esi, dword ptr [r8 + rcx*4]
- 0x000000000000006f: 48 01 D6 add rsi, rdx
- 0x0000000000000072: 4D 31 C9 xor r9, r9
- 0x0000000000000075: 48 31 C0 xor rax, rax
- 0x0000000000000078: AC lodsb al, byte ptr [rsi]
- 0x0000000000000079: 41 C1 C9 0D ror r9d, 0xd
- 0x000000000000007d: 41 01 C1 add r9d, eax
- 0x0000000000000080: 38 E0 cmp al, ah
- 0x0000000000000082: 75 F1 jne 0x75
- 0x0000000000000084: 4C 03 4C 24 08 add r9, qword ptr [rsp + 8]
- 0x0000000000000089: 45 39 D1 cmp r9d, r10d
- 0x000000000000008c: 75 D8 jne 0x66
- 0x000000000000008e: 58 pop rax
- 0x000000000000008f: 44 8B 40 24 mov r8d, dword ptr [rax + 0x24]
- 0x0000000000000093: 49 01 D0 add r8, rdx
- 0x0000000000000096: 66 41 8B 0C 48 mov cx, word ptr [r8 + rcx*2]
- 0x000000000000009b: 44 8B 40 1C mov r8d, dword ptr [rax + 0x1c]
- 0x000000000000009f: 49 01 D0 add r8, rdx
- 0x00000000000000a2: 41 8B 04 88 mov eax, dword ptr [r8 + rcx*4]
- 0x00000000000000a6: 48 01 D0 add rax, rdx
- 0x00000000000000a9: 41 58 pop r8
- 0x00000000000000ab: 41 58 pop r8
- 0x00000000000000ad: 5E pop rsi
- 0x00000000000000ae: 59 pop rcx
- 0x00000000000000af: 5A pop rdx
- 0x00000000000000b0: 41 58 pop r8
- 0x00000000000000b2: 41 59 pop r9
- 0x00000000000000b4: 41 5A pop r10
- 0x00000000000000b6: 48 83 EC 20 sub rsp, 0x20
- 0x00000000000000ba: 41 52 push r10
- 0x00000000000000bc: FF E0 jmp rax
- 0x00000000000000be: 58 pop rax
- 0x00000000000000bf: 41 59 pop r9
- 0x00000000000000c1: 5A pop rdx
- 0x00000000000000c2: 48 8B 12 mov rdx, qword ptr [rdx]
- 0x00000000000000c5: E9 57 FF FF FF jmp 0x21
- 0x00000000000000ca: 5D pop rbp
- 0x00000000000000cb: 49 BE 77 73 32 5F 33 32 00 00 movabs r14, 0x32335f327377
- 0x00000000000000d5: 41 56 push r14
- 0x00000000000000d7: 49 89 E6 mov r14, rsp
- 0x00000000000000da: 48 81 EC A0 01 00 00 sub rsp, 0x1a0
- 0x00000000000000e1: 49 89 E5 mov r13, rsp
- 0x00000000000000e4: 49 BC 02 00 01 BB C0 A8 38 66 movabs r12, 0x6638a8c0bb010002
- 0x00000000000000ee: 41 54 push r12
- 0x00000000000000f0: 49 89 E4 mov r12, rsp
- 0x00000000000000f3: 4C 89 F1 mov rcx, r14
- 0x00000000000000f6: 41 BA 4C 77 26 07 mov r10d, 0x726774c
- 0x00000000000000fc: FF D5 call rbp
- 0x00000000000000fe: 4C 89 EA mov rdx, r13
- 0x0000000000000101: 68 01 01 00 00 push 0x101
- 0x0000000000000106: 59 pop rcx
- 0x0000000000000107: 41 BA 29 80 6B 00 mov r10d, 0x6b8029
- 0x000000000000010d: FF D5 call rbp
- 0x000000000000010f: 50 push rax
- 0x0000000000000110: 50 push rax
- 0x0000000000000111: 4D 31 C9 xor r9, r9
- 0x0000000000000114: 4D 31 C0 xor r8, r8
- 0x0000000000000117: 48 FF C0 inc rax
- 0x000000000000011a: 48 89 C2 mov rdx, rax
- 0x000000000000011d: 48 FF C0 inc rax
- 0x0000000000000120: 48 89 C1 mov rcx, rax
- 0x0000000000000123: 41 BA EA 0F DF E0 mov r10d, 0xe0df0fea
- 0x0000000000000129: FF D5 call rbp
- 0x000000000000012b: 48 89 C7 mov rdi, rax
- 0x000000000000012e: 6A 10 push 0x10
- 0x0000000000000130: 41 58 pop r8
- 0x0000000000000132: 4C 89 E2 mov rdx, r12
- 0x0000000000000135: 48 89 F9 mov rcx, rdi
- 0x0000000000000138: 41 BA 99 A5 74 61 mov r10d, 0x6174a599
- 0x000000000000013e: FF D5 call rbp
- 0x0000000000000140: 48 81 C4 40 02 00 00 add rsp, 0x240
- 0x0000000000000147: 49 B8 63 6D 64 00 00 00 00 00 movabs r8, 0x646d63
- 0x0000000000000151: 41 50 push r8
- 0x0000000000000153: 41 50 push r8
- 0x0000000000000155: 48 89 E2 mov rdx, rsp
- 0x0000000000000158: 57 push rdi
- 0x0000000000000159: 57 push rdi
- 0x000000000000015a: 57 push rdi
- 0x000000000000015b: 4D 31 C0 xor r8, r8
- 0x000000000000015e: 6A 0D push 0xd
- 0x0000000000000160: 59 pop rcx
- 0x0000000000000161: 41 50 push r8
- 0x0000000000000163: E2 FC loop 0x161
- 0x0000000000000165: 66 C7 44 24 54 01 01 mov word ptr [rsp + 0x54], 0x101
- 0x000000000000016c: 48 8D 44 24 18 lea rax, [rsp + 0x18]
- 0x0000000000000171: C6 00 68 mov byte ptr [rax], 0x68
- 0x0000000000000174: 48 89 E6 mov rsi, rsp
- 0x0000000000000177: 56 push rsi
- 0x0000000000000178: 50 push rax
- 0x0000000000000179: 41 50 push r8
- 0x000000000000017b: 41 50 push r8
- 0x000000000000017d: 41 50 push r8
- 0x000000000000017f: 49 FF C0 inc r8
- 0x0000000000000182: 41 50 push r8
- 0x0000000000000184: 49 FF C8 dec r8
- 0x0000000000000187: 4D 89 C1 mov r9, r8
- 0x000000000000018a: 4C 89 C1 mov rcx, r8
- 0x000000000000018d: 41 BA 79 CC 3F 86 mov r10d, 0x863fcc79
- 0x0000000000000193: FF D5 call rbp
- 0x0000000000000195: 48 31 D2 xor rdx, rdx
- 0x0000000000000198: 48 FF CA dec rdx
- 0x000000000000019b: 8B 0E mov ecx, dword ptr [rsi]
- 0x000000000000019d: 41 BA 08 87 1D 60 mov r10d, 0x601d8708
- 0x00000000000001a3: FF D5 call rbp
- 0x00000000000001a5: BB F0 B5 A2 56 mov ebx, 0x56a2b5f0
- 0x00000000000001aa: 41 BA A6 95 BD 9D mov r10d, 0x9dbd95a6
- 0x00000000000001b0: FF D5 call rbp
- 0x00000000000001b2: 48 83 C4 28 add rsp, 0x28
- 0x00000000000001b6: 3C 06 cmp al, 6
- 0x00000000000001b8: 7C 0A jl 0x1c4
- 0x00000000000001ba: 80 FB E0 cmp bl, 0xe0
- 0x00000000000001bd: 75 05 jne 0x1c4
- 0x00000000000001bf: BB 47 13 72 6F mov ebx, 0x6f721347
- 0x00000000000001c4: 6A 00 push 0
- 0x00000000000001c6: 59 pop rcx
- 0x00000000000001c7: 41 89 DA mov r10d, ebx
- 0x00000000000001ca: FF D5 call rbp
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement