Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE237BA0 CryptUnprotectData,LocalFree, | 0_2_0000020AAE237BA0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE238020 BCryptDecrypt,BCryptDecrypt, | 0_2_0000020AAE238020 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE237EC0 CryptProtectData,LocalFree, | 0_2_0000020AAE237EC0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1F7C20 CryptUnprotectData,LocalFree, | 0_2_0000020AAE1F7C20 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1F3A30 BCryptDestroyKey, | 0_2_0000020AAE1F3A30 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE2383C0 BCryptCloseAlgorithmProvider, | 0_2_0000020AAE2383C0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE238440 BCryptOpenAlgorithmProvider,BCryptSetProperty,BCryptGenerateSymmetricKey,Concurrency::cancel_current_task, | 0_2_0000020AAE238440 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE27B500 FindClose,FindFirstFileExW,GetLastError, | 0_2_0000020AAE27B500 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE27B5B0 GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,__std_fs_open_handle,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,CloseHandle,CloseHandle, | 0_2_0000020AAE27B5B0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE295100 FindFirstFileW, | 0_2_0000020AAE295100 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE245B70 GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetDC,GetDeviceCaps,GetDeviceCaps,CreateCompatibleDC,CreateCompatibleBitmap,SelectObject,BitBlt,SHCreateMemStream,SelectObject,DeleteDC,ReleaseDC,DeleteObject,EnterCriticalSection,LeaveCriticalSection,IStream_Size,IStream_Reset,IStream_Read,SelectObject,DeleteDC,ReleaseDC,DeleteObject, | 0_2_0000020AAE245B70 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE249D30 GetModuleHandleA,GetProcAddress,OpenProcess,NtQuerySystemInformation,NtQuerySystemInformation,GetCurrentProcess,NtQueryObject,GetFinalPathNameByHandleA,CloseHandle,CloseHandle, | 0_2_0000020AAE249D30 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE2956F8 NtQuerySystemInformation, | 0_2_0000020AAE2956F8 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE24A430 RtlAcquirePebLock,NtAllocateVirtualMemory,lstrcpyW,lstrcatW,NtAllocateVirtualMemory,lstrcpyW,RtlInitUnicodeString,RtlInitUnicodeString,LdrEnumerateLoadedModules,RtlReleasePebLock,CoInitializeEx,lstrcpyW,lstrcatW,CoGetObject,lstrcpyW,lstrcatW,CoGetObject,CoUninitialize, | 0_2_0000020AAE24A430 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE209F80 | 0_2_0000020AAE209F80 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE248030 | 0_2_0000020AAE248030 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE23F020 | 0_2_0000020AAE23F020 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE22D080 | 0_2_0000020AAE22D080 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE24D050 | 0_2_0000020AAE24D050 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1F20B0 | 0_2_0000020AAE1F20B0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1EFE20 | 0_2_0000020AAE1EFE20 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE262E3C | 0_2_0000020AAE262E3C |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE245B70 | 0_2_0000020AAE245B70 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1F4B70 | 0_2_0000020AAE1F4B70 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1F1B90 | 0_2_0000020AAE1F1B90 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1FECB0 | 0_2_0000020AAE1FECB0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1F2CA0 | 0_2_0000020AAE1F2CA0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE225970 | 0_2_0000020AAE225970 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1FCA10 | 0_2_0000020AAE1FCA10 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1EF730 | 0_2_0000020AAE1EF730 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE246860 | 0_2_0000020AAE246860 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1FD570 | 0_2_0000020AAE1FD570 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE27B5B0 | 0_2_0000020AAE27B5B0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE24C5CB | 0_2_0000020AAE24C5CB |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1FE610 | 0_2_0000020AAE1FE610 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE280658 | 0_2_0000020AAE280658 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE2476A0 | 0_2_0000020AAE2476A0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE205310 | 0_2_0000020AAE205310 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE226350 | 0_2_0000020AAE226350 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1F0450 | 0_2_0000020AAE1F0450 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE2120F6 | 0_2_0000020AAE2120F6 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE25918C | 0_2_0000020AAE25918C |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE245240 | 0_2_0000020AAE245240 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE235EF0 | 0_2_0000020AAE235EF0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1FBF40 | 0_2_0000020AAE1FBF40 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE27FFBC | 0_2_0000020AAE27FFBC |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE2630B8 | 0_2_0000020AAE2630B8 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE217CEB | 0_2_0000020AAE217CEB |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE234D40 | 0_2_0000020AAE234D40 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE250D14 | 0_2_0000020AAE250D14 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE258D50 | 0_2_0000020AAE258D50 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1C5DB0 | 0_2_0000020AAE1C5DB0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1FADD0 | 0_2_0000020AAE1FADD0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE21BDD0 | 0_2_0000020AAE21BDD0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1F0E80 | 0_2_0000020AAE1F0E80 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1F7E70 | 0_2_0000020AAE1F7E70 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE240E90 | 0_2_0000020AAE240E90 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE211AF0 | 0_2_0000020AAE211AF0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE238B00 | 0_2_0000020AAE238B00 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE26BB90 | 0_2_0000020AAE26BB90 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1F98CD | 0_2_0000020AAE1F98CD |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE23C8E0 | 0_2_0000020AAE23C8E0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE25A924 | 0_2_0000020AAE25A924 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1F3A30 | 0_2_0000020AAE1F3A30 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1F0A80 | 0_2_0000020AAE1F0A80 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE266A68 | 0_2_0000020AAE266A68 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE235AB0 | 0_2_0000020AAE235AB0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE21BAB0 | 0_2_0000020AAE21BAB0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE220AC0 | 0_2_0000020AAE220AC0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE2646E4 | 0_2_0000020AAE2646E4 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE214720 | 0_2_0000020AAE214720 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE24A780 | 0_2_0000020AAE24A780 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE21B780 | 0_2_0000020AAE21B780 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE222750 | 0_2_0000020AAE222750 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE25579C | 0_2_0000020AAE25579C |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE25F7E6 | 0_2_0000020AAE25F7E6 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE2614E4 | 0_2_0000020AAE2614E4 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1E5520 | 0_2_0000020AAE1E5520 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE246540 | 0_2_0000020AAE246540 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1E6510 | 0_2_0000020AAE1E6510 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE255598 | 0_2_0000020AAE255598 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1C6610 | 0_2_0000020AAE1C6610 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE25666C | 0_2_0000020AAE25666C |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE268674 | 0_2_0000020AAE268674 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE2636A8 | 0_2_0000020AAE2636A8 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE23E2F0 | 0_2_0000020AAE23E2F0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE26A3C8 | 0_2_0000020AAE26A3C8 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE255394 | 0_2_0000020AAE255394 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE2363A6 | 0_2_0000020AAE2363A6 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1E83D0 | 0_2_0000020AAE1E83D0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE24A430 | 0_2_0000020AAE24A430 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE21C420 | 0_2_0000020AAE21C420 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE23B420 | 0_2_0000020AAE23B420 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE21B480 | 0_2_0000020AAE21B480 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE26A44F | 0_2_0000020AAE26A44F |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE21C0F0 | 0_2_0000020AAE21C0F0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1C70E0 | 0_2_0000020AAE1C70E0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE25F0D8 | 0_2_0000020AAE25F0D8 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE26C128 | 0_2_0000020AAE26C128 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE253150 | 0_2_0000020AAE253150 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE1C6180 | 0_2_0000020AAE1C6180 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE256164 | 0_2_0000020AAE256164 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE2671D8 | 0_2_0000020AAE2671D8 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE251220 | 0_2_0000020AAE251220 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE2302C0 | 0_2_0000020AAE2302C0 |
Source: 0.2.ZIOpctBE0o.exe.20aae1c0000.0.raw.unpack, type: UNPACKEDPE | Matched rule: infostealer_win_meduzastealer author = Sekoia.io, description = Finds MeduzaStealer samples based on specific strings, creation_date = 2023-06-20, classification = TLP:CLEAR, version = 1.0, id = 1276f485-aa5d-491b-89d8-77f98dc496e1 |
Source: 0.2.ZIOpctBE0o.exe.20aae1c0000.0.unpack, type: UNPACKEDPE | Matched rule: infostealer_win_meduzastealer author = Sekoia.io, description = Finds MeduzaStealer samples based on specific strings, creation_date = 2023-06-20, classification = TLP:CLEAR, version = 1.0, id = 1276f485-aa5d-491b-89d8-77f98dc496e1 |
Source: 00000000.00000002.2061153206.0000020AAE1C0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: infostealer_win_meduzastealer author = Sekoia.io, description = Finds MeduzaStealer samples based on specific strings, creation_date = 2023-06-20, classification = TLP:CLEAR, version = 1.0, id = 1276f485-aa5d-491b-89d8-77f98dc496e1 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: vaultcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE27B500 FindClose,FindFirstFileExW,GetLastError, | 0_2_0000020AAE27B500 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE27B5B0 GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,__std_fs_open_handle,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,CloseHandle,CloseHandle, | 0_2_0000020AAE27B5B0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE295100 FindFirstFileW, | 0_2_0000020AAE295100 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE257F68 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 0_2_0000020AAE257F68 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE2952E0 SetUnhandledExceptionFilter, | 0_2_0000020AAE2952E0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE26F498 SetUnhandledExceptionFilter, | 0_2_0000020AAE26F498 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: 0_2_0000020AAE26F2B8 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 0_2_0000020AAE26F2B8 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: EnumSystemLocalesW, | 0_2_0000020AAE268F60 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: EnumSystemLocalesW, | 0_2_0000020AAE269030 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: GetLocaleInfoW, | 0_2_0000020AAE25E020 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, | 0_2_0000020AAE2690C8 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: EnumSystemLocalesW, | 0_2_0000020AAE25DAE0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: TranslateName,TranslateName,GetACP,IsValidCodePage,GetLocaleInfoW, | 0_2_0000020AAE268C04 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: GetLocaleInfoW, | 0_2_0000020AAE269518 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, | 0_2_0000020AAE26964C |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: GetLocaleInfoW, | 0_2_0000020AAE269310 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: EnumSystemLocalesW, | 0_2_0000020AAE2953B8 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: GetLocaleInfoW,EnumSystemLocalesW,RaiseException, | 0_2_0000020AAE2953A0 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, | 0_2_0000020AAE269468 |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | Code function: GetLocaleInfoEx,FormatMessageA, | 0_2_0000020AAE27B170 |
Source: ZIOpctBE0o.exe, 00000000.00000002.2060727680.0000020AAC68C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: Electrum\wallets |
Source: ZIOpctBE0o.exe, 00000000.00000002.2060727680.0000020AAC68C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: ElectronCash\wallets |
Source: ZIOpctBE0o.exe, 00000000.00000002.2060727680.0000020AAC68C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb |
Source: ZIOpctBE0o.exe, 00000000.00000002.2060727680.0000020AAC68C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: Exodus\exodus.wallet |
Source: ZIOpctBE0o.exe, 00000000.00000002.2060727680.0000020AAC68C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: Ethereum\keystore |
Source: ZIOpctBE0o.exe, 00000000.00000002.2060727680.0000020AAC68C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: Ethereum\keystore |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\CURRENT | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cookies.sqlite | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\MANIFEST-000001 | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Cookies | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\places.sqlite | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\prefs.js | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\History | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\Cookies | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Data | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data For Account | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOCK | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\key4.db | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log | Jump to behavior |
Source: C:\Users\user\Desktop\ZIOpctBE0o.exe | File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\Cookies | Jump to behavior |