2020-07-21 08:19:18 +00:00
|
|
|
RAX = 0x0000000000000000 RCX = 0x0000000000000000 RDX = 0x0000000000000000 RBX = 0x0000000000000000
|
|
|
|
RSP = 0x0000000000101000 RBP = 0x0000000000000000 RSI = 0x0000000000000000 RDI = 0x0000000000000000
|
|
|
|
R8 = 0x0000000000000000 R9 = 0x0000000000000000 R10 = 0x0000000000000000 R11 = 0x0000000000000000
|
|
|
|
R12 = 0x0000000000000000 R13 = 0x0000000000000000 R14 = 0x0000000000000000 R15 = 0x0000000000000000
|
|
|
|
RIP = 0x0000000000200000 RFLAGS = 0x0000000000000202
|
|
|
|
Emulating: 0x0000000000200000 MOV eax, 0xffffffff
|
|
|
|
RAX = 0x00000000ffffffff RCX = 0x0000000000000000 RDX = 0x0000000000000000 RBX = 0x0000000000000000
|
|
|
|
RSP = 0x0000000000101000 RBP = 0x0000000000000000 RSI = 0x0000000000000000 RDI = 0x0000000000000000
|
|
|
|
R8 = 0x0000000000000000 R9 = 0x0000000000000000 R10 = 0x0000000000000000 R11 = 0x0000000000000000
|
|
|
|
R12 = 0x0000000000000000 R13 = 0x0000000000000000 R14 = 0x0000000000000000 R15 = 0x0000000000000000
|
|
|
|
RIP = 0x0000000000200005 RFLAGS = 0x0000000000000202
|
2020-07-23 11:08:01 +00:00
|
|
|
Emulating: 0x0000000000200005 ADD eax, 0x00000001
|
2020-07-21 08:19:18 +00:00
|
|
|
RAX = 0x0000000000000000 RCX = 0x0000000000000000 RDX = 0x0000000000000000 RBX = 0x0000000000000000
|
|
|
|
RSP = 0x0000000000101000 RBP = 0x0000000000000000 RSI = 0x0000000000000000 RDI = 0x0000000000000000
|
|
|
|
R8 = 0x0000000000000000 R9 = 0x0000000000000000 R10 = 0x0000000000000000 R11 = 0x0000000000000000
|
|
|
|
R12 = 0x0000000000000000 R13 = 0x0000000000000000 R14 = 0x0000000000000000 R15 = 0x0000000000000000
|
|
|
|
RIP = 0x0000000000200008 RFLAGS = 0x0000000000000247
|
|
|
|
Emulating: 0x0000000000200008 JNC 0x200014
|
|
|
|
RAX = 0x0000000000000000 RCX = 0x0000000000000000 RDX = 0x0000000000000000 RBX = 0x0000000000000000
|
|
|
|
RSP = 0x0000000000101000 RBP = 0x0000000000000000 RSI = 0x0000000000000000 RDI = 0x0000000000000000
|
|
|
|
R8 = 0x0000000000000000 R9 = 0x0000000000000000 R10 = 0x0000000000000000 R11 = 0x0000000000000000
|
|
|
|
R12 = 0x0000000000000000 R13 = 0x0000000000000000 R14 = 0x0000000000000000 R15 = 0x0000000000000000
|
|
|
|
RIP = 0x000000000020000a RFLAGS = 0x0000000000000247
|
|
|
|
Emulating: 0x000000000020000a LEA rsi, [rel 0x200014]
|
|
|
|
RAX = 0x0000000000000000 RCX = 0x0000000000000000 RDX = 0x0000000000000000 RBX = 0x0000000000000000
|
|
|
|
RSP = 0x0000000000101000 RBP = 0x0000000000000000 RSI = 0x0000000000200014 RDI = 0x0000000000000000
|
|
|
|
R8 = 0x0000000000000000 R9 = 0x0000000000000000 R10 = 0x0000000000000000 R11 = 0x0000000000000000
|
|
|
|
R12 = 0x0000000000000000 R13 = 0x0000000000000000 R14 = 0x0000000000000000 R15 = 0x0000000000000000
|
|
|
|
RIP = 0x0000000000200011 RFLAGS = 0x0000000000000247
|
|
|
|
Emulating: 0x0000000000200011 MOV byte ptr [rsi], 0xcc
|
|
|
|
RAX = 0x0000000000000000 RCX = 0x0000000000000000 RDX = 0x0000000000000000 RBX = 0x0000000000000000
|
|
|
|
RSP = 0x0000000000101000 RBP = 0x0000000000000000 RSI = 0x0000000000200014 RDI = 0x0000000000000000
|
|
|
|
R8 = 0x0000000000000000 R9 = 0x0000000000000000 R10 = 0x0000000000000000 R11 = 0x0000000000000000
|
|
|
|
R12 = 0x0000000000000000 R13 = 0x0000000000000000 R14 = 0x0000000000000000 R15 = 0x0000000000000000
|
|
|
|
RIP = 0x0000000000200014 RFLAGS = 0x0000000000000247
|
|
|
|
Emulating: 0x0000000000200014 INT3
|
|
|
|
Emulation terminated with status 0x00000003, flags: 0x4, 0 NOPs
|
|
|
|
SHEMU_FLAG_WRITE_SELF
|