Loading ...

Play interactive tourEdit tour

Analysis Report zeus 1_1.2.1.5.vir

Overview

General Information

Sample Name:zeus 1_1.2.1.5.vir (renamed file extension from vir to exe)
Analysis ID:247337
MD5:11b83ace7722358a7172e55c8c896cd7
SHA1:4151d739f6a42adbd4d3a138142e10690cc7413c
SHA256:84cd847f2f244fc4f45d9ea1615018fd478f601e455236b6c662aeb94064004a

Most interesting Screenshot:

Detection

Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Detected unpacking (changes PE section rights)
Multi AV Scanner detection for submitted file
Allocates memory in foreign processes
Changes memory attributes in foreign processes to executable or writable
Contains functionality to change the desktop window for a process (likely to hide graphical interactions)
Creates an undocumented autostart registry key
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Writes to foreign memory regions
AV process strings found (often used to terminate AV products)
Antivirus or Machine Learning detection for unpacked file
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to dynamically determine API calls
Contains functionality to launch a process as a different user
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to read the clipboard data
Contains functionality to retrieve information about pressed keystrokes
Contains functionality to shutdown / reboot the system
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates files inside the system directory
Detected potential crypto function
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Enables debug privileges
Extensive use of GetProcAddress (often used to hide API calls)
Found dropped PE file which has not been started or loaded
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)

Classification

Startup

  • System is w10x64
  • zeus 1_1.2.1.5.exe (PID: 5436 cmdline: 'C:\Users\user\Desktop\zeus 1_1.2.1.5.exe' MD5: 11B83ACE7722358A7172E55C8C896CD7)
    • winlogon.exe (PID: 548 cmdline: MD5: 3E56F9D58EBBB1B33E31B86267DBECFC)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

System Summary:

barindex
Sigma detected: Windows Processes Suspicious Parent DirectoryShow sources
Source: Process startedAuthor: vburov: Data: Command: , CommandLine: , CommandLine|base64offset|contains: , Image: C:\Windows\System32\winlogon.exe, NewProcessName: C:\Windows\System32\winlogon.exe, OriginalFileName: C:\Windows\System32\winlogon.exe, ParentCommandLine: 'C:\Users\user\Desktop\zeus 1_1.2.1.5.exe' , ParentImage: C:\Users\user\Desktop\zeus 1_1.2.1.5.exe, ParentProcessId: 5436, ProcessCommandLine: , ProcessId: 548

Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Antivirus / Scanner detection for submitted sampleShow sources
Source: zeus 1_1.2.1.5.exeAvira: detected
Antivirus detection for dropped fileShow sources
Source: C:\Windows\SysWOW64\twex.exeAvira: detection malicious, Label: TR/Dropper.Gen
Multi AV Scanner detection for submitted fileShow sources
Source: zeus 1_1.2.1.5.exeVirustotal: Detection: 84%Perma Link
Source: zeus 1_1.2.1.5.exeMetadefender: Detection: 77%Perma Link
Source: zeus 1_1.2.1.5.exeReversingLabs: Detection: 86%
Machine Learning detection for dropped fileShow sources
Source: C:\Windows\SysWOW64\twex.exeJoe Sandbox ML: detected
Machine Learning detection for sampleShow sources
Source: zeus 1_1.2.1.5.exeJoe Sandbox ML: detected
Source: 0.0.zeus 1_1.2.1.5.exe.400000.0.unpackAvira: Label: TR/Crypt.ZPACK.Gen
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_0040D7E8 CryptAcquireContextW,CryptCreateHash,CryptHashData,CryptGetHashParam,CryptDestroyHash,CryptReleaseContext,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_00409C59 PathCombineW,FindFirstFileW,PathMatchSpecW,PathCombineW,FindNextFileW,FindClose,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_0041095C FindFirstFileW,FindClose,FindFirstFileW,FindClose,CreateMutexW,MoveFileExW,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_00406BDC ExpandEnvironmentStringsW,FindFirstFileW,PathRemoveFileSpecW,PathCombineW,FindNextFileW,FindClose,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_00403DF0 PathCombineW,FindFirstFileW,PathCombineW,WaitForSingleObject,RtlEnterCriticalSection,PathMatchSpecW,PathCombineW,wnsprintfW,WaitForSingleObject,RtlLeaveCriticalSection,Sleep,FindNextFileW,FindClose,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_0040F193 PathCombineW,FindFirstFileW,PathCombineW,PathCombineW,FindNextFileW,FindClose,
Source: Joe Sandbox ViewASN Name: CLOUDFLARENETUS CLOUDFLARENETUS
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_0040BC58 RtlEnterCriticalSection,RtlLeaveCriticalSection,InternetQueryOptionA,InternetSetOptionA,RtlLeaveCriticalSection,InternetReadFile,InternetReadFileExA,InternetReadFileExW,InternetQueryDataAvailable,
Source: zeus 1_1.2.1.5.exe, 00000000.00000002.1211320945.0000000000A03000.00000004.00000040.sdmpString found in binary or memory: https://onlineeast#.bankofamerica.com/cgi-bin/ias/
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_00405257 GetClipboardData,GlobalFix,GlobalUnWire,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_004053C3 GetTickCount,GetCurrentProcessId,wnsprintfW,GetKeyState,GetKeyState,GetKeyboardState,ToUnicode,WideCharToMultiByte,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_00409346 CreateFileW,NtQueryObject,lstrcpyW,CloseHandle,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_0040692C NtQueryInformationProcess,CreateToolhelp32Snapshot,Thread32First,Thread32Next,CloseHandle,NtCreateThread,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_00404F9E NtQueryDirectoryFile,NtQueryObject,lstrcmpiW,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_004099A7 GetForegroundWindow,GetWindowThreadProcessId,OpenProcess,OpenProcessToken,DuplicateTokenEx,CloseHandle,CloseHandle,CreateProcessAsUserW,CloseHandle,CreateProcessW,CloseHandle,CloseHandle,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_00409D4D OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeFile created: C:\Windows\SysWOW64\twex.exeJump to behavior
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_0040D6F5
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_0040D95C
Source: zeus 1_1.2.1.5.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Source: twex.exe.0.drStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Source: classification engineClassification label: mal100.evad.winEXE@1/2@0/1
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_00403AE5 CertOpenSystemStoreW,PFXExportCertStore,PFXExportCertStore,GetSystemTime,wnsprintfW,CertDuplicateCertificateContext,CertDeleteCRLFromStore,CertEnumCertificatesInStore,CertCloseStore,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_004090ED HeapCreate,GetProcessHeap,GetCurrentProcessId,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,FindCloseChangeNotification,GetUserDefaultUILanguage,GetUserNameW,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_00409D4D OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_00409616 CreateToolhelp32Snapshot,GetUserNameW,lstrcpyW,SHGetSpecialFolderPathW,Process32FirstW,lstrcmpiW,OpenProcess,K32GetModuleFileNameExW,PathCombineW,lstrcmpiW,lstrcmpiW,CloseHandle,Process32NextW,CloseHandle,FindCloseChangeNotification,FindCloseChangeNotification,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMutant created: \Sessions\1\BaseNamedObjects\_H_91C38905_
Source: zeus 1_1.2.1.5.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: zeus 1_1.2.1.5.exeVirustotal: Detection: 84%
Source: zeus 1_1.2.1.5.exeMetadefender: Detection: 77%
Source: zeus 1_1.2.1.5.exeReversingLabs: Detection: 86%
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeFile read: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeJump to behavior

Data Obfuscation:

barindex
Detected unpacking (changes PE section rights)Show sources
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeUnpacked PE file: 0.2.zeus 1_1.2.1.5.exe.400000.0.unpack .text:ER;.data:W; vs .text:ER;.data:W;.reloc:R;.data1:W;
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_00409041 LoadLibraryA,GetProcAddress,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_004112ED push eax; ret
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeFile created: C:\Windows\SysWOW64\twex.exeJump to dropped file
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeFile created: C:\Windows\SysWOW64\twex.exeJump to dropped file

Boot Survival:

barindex
Creates an undocumented autostart registry key Show sources
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon userinitJump to behavior
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_004079CF LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,LoadCursorW,GetIconInfo,GetCursorPos,DrawIcon,lstrcmpiW,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeDropped PE file which has not been started: C:\Windows\SysWOW64\twex.exeJump to dropped file
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exe TID: 5440Thread sleep count: 241 > 30
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_00409C59 PathCombineW,FindFirstFileW,PathMatchSpecW,PathCombineW,FindNextFileW,FindClose,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_0041095C FindFirstFileW,FindClose,FindFirstFileW,FindClose,CreateMutexW,MoveFileExW,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_00406BDC ExpandEnvironmentStringsW,FindFirstFileW,PathRemoveFileSpecW,PathCombineW,FindNextFileW,FindClose,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_00403DF0 PathCombineW,FindFirstFileW,PathCombineW,WaitForSingleObject,RtlEnterCriticalSection,PathMatchSpecW,PathCombineW,wnsprintfW,WaitForSingleObject,RtlLeaveCriticalSection,Sleep,FindNextFileW,FindClose,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_0040F193 PathCombineW,FindFirstFileW,PathCombineW,PathCombineW,FindNextFileW,FindClose,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeProcess information queried: ProcessInformation
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_00404EEA LdrGetDllHandle,LdrLoadDll,RtlEnterCriticalSection,RtlLeaveCriticalSection,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_00409041 LoadLibraryA,GetProcAddress,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeCode function: 0_2_004090ED HeapCreate,GetProcessHeap,GetCurrentProcessId,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,FindCloseChangeNotification,GetUserDefaultUILanguage,GetUserNameW,
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeProcess token adjusted: Debug

HIPS / PFW / Operating System Protection Evasion:

barindex
Allocates memory in foreign processesShow sources
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 400000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 400000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 401000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 411000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 413000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 415000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12270000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12270000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12271000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12281000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12283000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12285000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12290000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12290000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12291000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 122A1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 122A3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 122A5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 122B0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 122B0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 122B1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 122C1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 122C3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 122C5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 122D0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 122D0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 122D1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 122E1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 122E3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 122E5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 122F0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 122F0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 122F1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12301000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12303000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12305000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12310000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12310000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12311000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12321000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12323000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12325000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12330000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12330000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12331000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12341000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12343000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12345000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12350000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12350000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12351000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12361000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12363000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12365000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12370000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12370000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12371000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12381000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12383000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12385000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12390000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12390000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12391000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 123A1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 123A3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 123A5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 123B0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 123B0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 123B1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 123C1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 123C3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 123C5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 123D0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 123D0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 123D1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 123E1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 123E3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 123E5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 123F0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 123F0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 123F1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12401000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12403000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12405000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12410000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12410000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12411000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12421000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12423000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12425000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12430000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12430000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12431000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12441000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12443000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12445000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12450000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12450000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12451000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12461000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12463000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12465000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12470000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12470000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12471000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12481000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12483000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12485000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12490000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12490000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12491000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 124A1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 124A3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 124A5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 124B0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 124B0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 124B1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 124C1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 124C3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 124C5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 124D0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 124D0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 124D1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 124E1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 124E3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 124E5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 124F0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 124F0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 124F1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12501000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12503000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12505000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12510000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12510000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12511000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12521000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12523000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12525000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12530000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12530000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12531000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12541000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12543000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12545000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12550000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12550000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12551000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12561000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12563000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12565000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12570000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12570000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12571000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12581000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12583000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12585000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12590000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12590000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12591000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 125A1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 125A3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 125A5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 125B0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 125B0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 125B1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 125C1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 125C3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 125C5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 125D0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 125D0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 125D1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 125E1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 125E3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 125E5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 125F0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 125F0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 125F1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12601000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12603000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12605000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12610000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12610000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12611000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12621000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12623000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12625000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12630000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12630000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12631000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12641000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12643000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12645000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12650000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12650000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12651000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12661000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12663000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12665000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12670000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12670000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12671000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12681000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12683000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12685000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12690000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12690000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12691000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 126A1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 126A3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 126A5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 126B0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 126B0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 126B1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 126C1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 126C3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 126C5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 126D0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 126D0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 126D1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 126E1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 126E3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 126E5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 126F0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 126F0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 126F1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12701000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12703000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12705000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12710000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12710000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12711000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12721000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12723000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12725000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12730000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12730000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12731000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12741000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12743000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12745000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12750000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12750000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12751000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12761000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12763000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12765000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12770000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12770000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12771000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12781000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12783000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12785000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12790000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12790000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12791000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 127A1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 127A3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 127A5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 127B0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 127B0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 127B1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 127C1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 127C3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 127C5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 127D0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 127D0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 127D1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 127E1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 127E3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 127E5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 127F0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 127F0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 127F1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12801000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12803000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12805000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12810000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12810000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12811000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12821000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12823000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12825000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12830000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12830000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12831000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12841000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12843000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12845000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12850000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12850000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12851000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12861000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12863000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12865000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12870000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12870000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12871000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12881000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12883000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12885000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12890000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12890000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12891000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 128A1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 128A3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 128A5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 128B0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 128B0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 128B1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 128C1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 128C3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 128C5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 128D0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 128D0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 128D1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 128E1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 128E3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 128E5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 128F0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 128F0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 128F1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12901000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12903000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12905000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12910000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12910000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12911000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12921000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12923000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12925000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12930000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12930000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12931000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12941000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12943000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12945000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12950000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12950000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12951000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12961000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12963000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12965000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12970000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12970000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12971000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12981000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12983000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12985000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12990000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12990000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12991000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 129A1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 129A3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 129A5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 129B0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 129B0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 129B1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 129C1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 129C3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 129C5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 129D0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 129D0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 129D1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 129E1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 129E3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 129E5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 129F0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 129F0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 129F1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A01000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A03000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A05000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A10000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A10000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A11000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A21000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A23000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A25000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A30000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A30000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A31000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A41000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A43000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A45000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A50000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A50000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A51000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A61000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A63000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A65000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A70000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A70000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A71000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A81000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A83000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A85000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A90000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A90000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12A91000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12AA1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12AA3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12AA5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12AB0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12AB0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12AB1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12AC1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12AC3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12AC5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12AD0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12AD0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12AD1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12AE1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12AE3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12AE5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12AF0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12AF0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12AF1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B01000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B03000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B05000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B10000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B10000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B11000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B21000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B23000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B25000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B30000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B30000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B31000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B41000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B43000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B45000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B50000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B50000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B51000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B61000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B63000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B65000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B70000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B70000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B71000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B81000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B83000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B85000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B90000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B90000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12B91000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12BA1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12BA3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12BA5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12BB0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12BB0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12BB1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12BC1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12BC3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12BC5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12BD0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12BD0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12BD1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12BE1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12BE3000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12BE5000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12BF0000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12BF0000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12BF1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C01000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C03000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C05000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C10000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C10000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C11000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C21000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C23000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C25000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C30000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C30000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C31000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C41000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C43000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C45000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C50000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C50000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C51000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C61000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C63000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C65000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C70000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C70000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C71000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C81000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C83000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C85000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C90000 protect: page no access
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C90000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12C91000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12CA1000 protect: page read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory allocated: C:\Windows\System32\winlogon.exe base: 12CA3000 protect: page read and write
Changes memory attributes in foreign processes to executable or writableShow sources
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 400000 protect: page readonly
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 401000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 411000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 413000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 415000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12270000 protect: page readonly
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12271000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12281000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12283000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12285000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12290000 protect: page readonly
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12291000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 122A1000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 122A3000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 122A5000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 122B0000 protect: page readonly
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 122B1000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 122C1000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 122C3000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 122C5000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 122D0000 protect: page readonly
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 122D1000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 122E1000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 122E3000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 122E5000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 122F0000 protect: page readonly
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 122F1000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12301000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12303000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12305000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12310000 protect: page readonly
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12311000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12321000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12323000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12325000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12330000 protect: page readonly
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12331000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12341000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12343000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12345000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12350000 protect: page readonly
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12351000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12361000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12363000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12365000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12370000 protect: page readonly
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12371000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12381000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12383000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12385000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12390000 protect: page readonly
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12391000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 123A1000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 123A3000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 123A5000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 123B0000 protect: page readonly
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 123B1000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 123C1000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 123C3000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 123C5000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 123D0000 protect: page readonly
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 123D1000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 123E1000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 123E3000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 123E5000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 123F0000 protect: page readonly
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 123F1000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12401000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12403000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12405000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12410000 protect: page readonly
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12411000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12421000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12423000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12425000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12430000 protect: page readonly
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12431000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12441000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12443000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12445000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12450000 protect: page readonly
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12451000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12461000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12463000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12465000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12470000 protect: page readonly
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12471000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12481000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12483000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12485000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12490000 protect: page readonly
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 12491000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 124A1000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 124A3000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 124A5000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 124B0000 protect: page readonly
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 124B1000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 124C1000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 124C3000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 124C5000 protect: page execute and read and write
Source: C:\Users\user\Desktop\zeus 1_1.2.1.5.exeMemory protected: C:\Windows\System32\winlogon.exe base: 124D0000 protect: page