Windows Analysis Report
4OVYJHCTFA.exe

Overview

General Information

Sample name: 4OVYJHCTFA.exe
renamed because original name is a hash value
Original sample name: 30772bcce9852eb58cf05a75bcdce2f9.exe
Analysis ID: 1465836
MD5: 30772bcce9852eb58cf05a75bcdce2f9
SHA1: b43da7a9785fb47cc1174bb4a896866fbb1a0df0
SHA256: 584945fbd2076bc151184065a72373f87405136be7b0131d36ded7d986b968fc
Tags: 32exetrojan
Infos:

Detection

LummaC
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus detection for URL or domain
Antivirus detection for dropped file
Found malware configuration
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Yara detected LummaC Stealer
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Found direct / indirect Syscall (likely to bypass EDR)
Found hidden mapped module (file has been removed from disk)
Injects code into the Windows Explorer (explorer.exe)
LummaC encrypted strings found
Machine Learning detection for dropped file
Maps a DLL or memory area into another process
Sample uses string decryption to hide its real strings
Switches to a custom stack to bypass stack traces
Writes to foreign memory regions
Binary contains a suspicious time stamp
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to dynamically determine API calls
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
Drops files with a non-matching file extension (content does not match file extension)
Found dropped PE file which has not been started or loaded
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
PE file contains an invalid checksum
PE file contains sections with non-standard names
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)

Classification

Name Description Attribution Blogpost URLs Link
Lumma Stealer, LummaC2 Stealer Lumma Stealer (aka LummaC2 Stealer) is an information stealer written in C language that has been available through a Malware-as-a-Service (MaaS) model on Russian-speaking forums since at least August 2022. It is believed to have been developed by the threat actor "Shamel", who goes by the alias "Lumma". Lumma Stealer primarily targets cryptocurrency wallets and two-factor authentication (2FA) browser extensions, before ultimately stealing sensitive information from the victim's machine. Once the targeted data is obtained, it is exfiltrated to a C2 server via HTTP POST requests using the user agent "TeslaBrowser/5.5"." The stealer also features a non-resident loader that is capable of delivering additional payloads via EXE, DLL, and PowerShell. No Attribution https://malpedia.caad.fkie.fraunhofer.de/details/win.lumma

AV Detection

barindex
Source: facilitycoursedw.shop Avira URL Cloud: Label: malware
Source: computerexcudesp.shop Avira URL Cloud: Label: malware
Source: doughtdrillyksow.shop Avira URL Cloud: Label: malware
Source: disappointcredisotw.shop Avira URL Cloud: Label: malware
Source: leafcalfconflcitw.shop Avira URL Cloud: Label: malware
Source: periodicroytewrsn.shop Avira URL Cloud: Label: malware
Source: publicitycharetew.shop Avira URL Cloud: Label: malware
Source: bargainnygroandjwk.shop Avira URL Cloud: Label: malware
Source: injurypiggyoewirog.shop Avira URL Cloud: Label: malware
Source: C:\Users\user\AppData\Local\Temp\gqnmaqicmbds Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\Users\user\AppData\Local\Temp\tbh Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: cmd.exe.4588.3.memstrmin Malware Configuration Extractor: LummaC {"C2 url": ["facilitycoursedw.shop", "doughtdrillyksow.shop", "disappointcredisotw.shop", "bargainnygroandjwk.shop", "injurypiggyoewirog.shop", "leafcalfconflcitw.shop", "computerexcudesp.shop", "publicitycharetew.shop", "periodicroytewrsn.shop"], "Build id": "Fe0z0o--Batman"}
Source: facilitycoursedw.shop Virustotal: Detection: 17% Perma Link
Source: computerexcudesp.shop Virustotal: Detection: 17% Perma Link
Source: disappointcredisotw.shop Virustotal: Detection: 17% Perma Link
Source: doughtdrillyksow.shop Virustotal: Detection: 17% Perma Link
Source: publicitycharetew.shop Virustotal: Detection: 18% Perma Link
Source: leafcalfconflcitw.shop Virustotal: Detection: 17% Perma Link
Source: injurypiggyoewirog.shop Virustotal: Detection: 16% Perma Link
Source: bargainnygroandjwk.shop Virustotal: Detection: 17% Perma Link
Source: C:\Users\user\AppData\Local\Temp\Qt5Network.dll ReversingLabs: Detection: 54%
Source: C:\Users\user\AppData\Local\Temp\Qt5Network.dll Virustotal: Detection: 8% Perma Link
Source: C:\Users\user\AppData\Local\Temp\gqnmaqicmbds ReversingLabs: Detection: 79%
Source: C:\Users\user\AppData\Local\Temp\gqnmaqicmbds Virustotal: Detection: 78% Perma Link
Source: C:\Users\user\AppData\Local\Temp\tbh ReversingLabs: Detection: 79%
Source: C:\Users\user\AppData\Local\Temp\tbh Virustotal: Detection: 78% Perma Link
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\Qt5Network.dll ReversingLabs: Detection: 54%
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\Qt5Network.dll Virustotal: Detection: 8% Perma Link
Source: 4OVYJHCTFA.exe ReversingLabs: Detection: 70%
Source: 4OVYJHCTFA.exe Virustotal: Detection: 58% Perma Link
Source: Submited Sample Integrated Neural Analysis Model: Matched 100.0% probability
Source: C:\Users\user\AppData\Local\Temp\gqnmaqicmbds Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Temp\tbh Joe Sandbox ML: detected
Source: 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String decryptor: facilitycoursedw.shop
Source: 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String decryptor: doughtdrillyksow.shop
Source: 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String decryptor: disappointcredisotw.shop
Source: 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String decryptor: bargainnygroandjwk.shop
Source: 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String decryptor: injurypiggyoewirog.shop
Source: 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String decryptor: leafcalfconflcitw.shop
Source: 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String decryptor: computerexcudesp.shop
Source: 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String decryptor: publicitycharetew.shop
Source: 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String decryptor: periodicroytewrsn.shop
Source: 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String decryptor: lid=%s&j=%s&ver=4.0
Source: 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String decryptor: TeslaBrowser/5.5
Source: 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String decryptor: - Screen Resoluton:
Source: 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String decryptor: - Physical Installed Memory:
Source: 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String decryptor: Workgroup: -
Source: 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String decryptor: Fe0z0o--Batman
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEA5B40 CRYPTO_free,OPENSSL_sk_pop_free,CRYPTO_free,CRYPTO_clear_free,CRYPTO_free,CRYPTO_free,EVP_PKEY_free,EVP_PKEY_free,CRYPTO_free,CRYPTO_free,memset,CRYPTO_free, 1_2_00007FFDFAEA5B40
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE97B20 CRYPTO_free, 1_2_00007FFDFAE97B20
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91CD5 CRYPTO_malloc,COMP_expand_block, 1_2_00007FFDFAE91CD5
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE916E5 CRYPTO_zalloc, 1_2_00007FFDFAE916E5
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91104 EVP_PKEY_free,X509_free,EVP_PKEY_free,OPENSSL_sk_pop_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,X509_STORE_free,X509_STORE_free,CRYPTO_free,CRYPTO_THREAD_lock_free,CRYPTO_free, 1_2_00007FFDFAE91104
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91253 CRYPTO_free, 1_2_00007FFDFAE91253
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEE1AD0 CRYPTO_free, 1_2_00007FFDFAEE1AD0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE922CA ERR_put_error,CRYPTO_free,CRYPTO_strdup, 1_2_00007FFDFAE922CA
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEAFAA0 strncmp,strncmp,strncmp,strncmp,ERR_put_error,CRYPTO_malloc,CRYPTO_malloc,CRYPTO_free,ERR_put_error,strncmp,CRYPTO_free,OPENSSL_sk_new_null,CRYPTO_free,OPENSSL_sk_num,OPENSSL_sk_value,OPENSSL_sk_push,OPENSSL_sk_num,OPENSSL_sk_push,CRYPTO_free,OPENSSL_sk_free,CRYPTO_free,OPENSSL_sk_free, 1_2_00007FFDFAEAFAA0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEEFA70 CRYPTO_free,CRYPTO_strndup,CRYPTO_free,CRYPTO_memdup,OPENSSL_cleanse, 1_2_00007FFDFAEEFA70
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9DC20 CRYPTO_free, 1_2_00007FFDFAE9DC20
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEADBC0 CRYPTO_mem_ctrl,OPENSSL_sk_new,COMP_get_type,CRYPTO_malloc,OPENSSL_sk_push,OPENSSL_sk_sort,CRYPTO_mem_ctrl, 1_2_00007FFDFAEADBC0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91686 CRYPTO_free,CRYPTO_memdup, 1_2_00007FFDFAE91686
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91028 EVP_PKEY_free,CRYPTO_free,CRYPTO_free,EVP_MD_CTX_new,RSA_pkey_ctx_ctrl,CRYPTO_free,EVP_MD_CTX_free,EVP_MD_CTX_free, 1_2_00007FFDFAE91028
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91F6E CRYPTO_free,CRYPTO_memdup, 1_2_00007FFDFAE91F6E
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9193D CRYPTO_free,CRYPTO_memdup, 1_2_00007FFDFAE9193D
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9141F EVP_PKEY_get1_tls_encodedpoint,EVP_PKEY_free,CRYPTO_free,EVP_PKEY_free,CRYPTO_free, 1_2_00007FFDFAE9141F
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEB18D0 CRYPTO_free,CRYPTO_strdup, 1_2_00007FFDFAEB18D0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEC7870 CRYPTO_free, 1_2_00007FFDFAEC7870
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91870 CRYPTO_free,CRYPTO_malloc,CRYPTO_free,CRYPTO_free,CRYPTO_memdup, 1_2_00007FFDFAE91870
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEB3A20 CRYPTO_free,CRYPTO_memdup, 1_2_00007FFDFAEB3A20
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9207C CRYPTO_free,CRYPTO_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,memset, 1_2_00007FFDFAE9207C
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91C12 CRYPTO_free,CRYPTO_strdup, 1_2_00007FFDFAE91C12
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEED9C0 OPENSSL_sk_free,OPENSSL_sk_free,CRYPTO_free,CRYPTO_free,memcmp,OPENSSL_sk_num,OPENSSL_sk_value,OPENSSL_sk_num,memcpy,OPENSSL_sk_num,OPENSSL_sk_value,OPENSSL_sk_num,CRYPTO_memcmp,OPENSSL_sk_free,OPENSSL_sk_dup,OPENSSL_sk_free,OPENSSL_sk_dup,OPENSSL_sk_num,OPENSSL_sk_value,OPENSSL_sk_num,OPENSSL_sk_num,OPENSSL_sk_value,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_free,CRYPTO_free,CRYPTO_free, 1_2_00007FFDFAEED9C0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE92144 EVP_MD_CTX_new,EVP_MD_CTX_copy_ex,EVP_MD_CTX_free,CRYPTO_memcmp,memcpy,memcpy, 1_2_00007FFDFAE92144
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE924DC CRYPTO_malloc,ERR_put_error,memcpy,CRYPTO_free,CRYPTO_free, 1_2_00007FFDFAE924DC
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEE3980 CRYPTO_malloc,memcpy, 1_2_00007FFDFAEE3980
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE99F50 CRYPTO_malloc,memset,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free, 1_2_00007FFDFAE99F50
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEB5F20 ERR_put_error,CRYPTO_free,ERR_put_error,BUF_MEM_free,EVP_MD_CTX_free,X509_free,X509_VERIFY_PARAM_move_peername,CRYPTO_free, 1_2_00007FFDFAEB5F20
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91861 CRYPTO_free,CRYPTO_strndup,CRYPTO_free,OPENSSL_cleanse,_time64,memcpy,OPENSSL_cleanse,OPENSSL_cleanse,EVP_MD_size, 1_2_00007FFDFAE91861
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEADEF0 CRYPTO_THREAD_run_once, 1_2_00007FFDFAEADEF0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEA7EE0 CRYPTO_free,CRYPTO_memdup, 1_2_00007FFDFAEA7EE0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE97ED0 CRYPTO_zalloc,ERR_put_error, 1_2_00007FFDFAE97ED0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9150A CRYPTO_free,CRYPTO_malloc,ERR_put_error,memcpy, 1_2_00007FFDFAE9150A
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9FEA0 EVP_CIPHER_CTX_cipher,EVP_CIPHER_flags,EVP_MD_CTX_md,EVP_MD_size,CRYPTO_memcmp,EVP_MD_CTX_md,EVP_MD_CTX_md,EVP_MD_size,EVP_CIPHER_CTX_cipher,EVP_CIPHER_flags,EVP_CIPHER_CTX_cipher,EVP_CIPHER_flags,CRYPTO_memcmp,strncmp,strncmp,strncmp,strncmp,strncmp, 1_2_00007FFDFAE9FEA0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9101E EVP_PKEY_free,BN_num_bits,BN_bn2bin,EVP_PKEY_free,CRYPTO_free,EVP_PKEY_free,CRYPTO_free,CRYPTO_clear_free,CRYPTO_clear_free, 1_2_00007FFDFAE9101E
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE92095 CRYPTO_free,_time64,CRYPTO_free,CRYPTO_malloc,EVP_sha256,EVP_Digest,EVP_MD_size,CRYPTO_free, 1_2_00007FFDFAE92095
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAECA030 CRYPTO_free,CRYPTO_memdup, 1_2_00007FFDFAECA030
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9E010 CRYPTO_malloc, 1_2_00007FFDFAE9E010
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91F28 CRYPTO_free,CRYPTO_malloc,memcpy, 1_2_00007FFDFAE91F28
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9218F EVP_MD_CTX_new,EVP_PKEY_size,CRYPTO_malloc,EVP_DigestSignInit,RSA_pkey_ctx_ctrl,RSA_pkey_ctx_ctrl,EVP_DigestUpdate,EVP_MD_CTX_ctrl,EVP_DigestSignFinal,EVP_DigestSign,BUF_reverse,CRYPTO_free,EVP_MD_CTX_free,CRYPTO_free,EVP_MD_CTX_free, 1_2_00007FFDFAE9218F
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEA5F70 CRYPTO_free,CRYPTO_strdup, 1_2_00007FFDFAEA5F70
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEA9D50 CRYPTO_free,CRYPTO_strndup, 1_2_00007FFDFAEA9D50
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9DD30 CRYPTO_free, 1_2_00007FFDFAE9DD30
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE920F4 CRYPTO_THREAD_read_lock,CRYPTO_THREAD_unlock, 1_2_00007FFDFAE920F4
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE918BB CRYPTO_free,CRYPTO_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,memset, 1_2_00007FFDFAE918BB
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9DCD0 CRYPTO_free, 1_2_00007FFDFAE9DCD0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEADCB0 COMP_zlib,CRYPTO_mem_ctrl,OPENSSL_sk_new,COMP_get_type,CRYPTO_malloc,COMP_get_name,OPENSSL_sk_push,OPENSSL_sk_sort,CRYPTO_mem_ctrl, 1_2_00007FFDFAEADCB0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE97C70 CRYPTO_free, 1_2_00007FFDFAE97C70
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEEBC60 CRYPTO_memcmp, 1_2_00007FFDFAEEBC60
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91E6A CRYPTO_zalloc,ERR_put_error,BUF_MEM_grow,CRYPTO_free, 1_2_00007FFDFAE91E6A
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEF7E00 CRYPTO_free,CRYPTO_malloc,ERR_put_error, 1_2_00007FFDFAEF7E00
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEFBDF0 memset,BN_dup,BN_dup,BN_dup,BN_dup,BN_dup,BN_dup,BN_dup,BN_dup,CRYPTO_strdup,CRYPTO_strdup,ERR_put_error,CRYPTO_free,CRYPTO_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,memset, 1_2_00007FFDFAEFBDF0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9DDE0 CRYPTO_malloc,CRYPTO_free,CRYPTO_malloc, 1_2_00007FFDFAE9DDE0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAECFDC0 CRYPTO_memdup,CRYPTO_memdup,CRYPTO_memdup,CRYPTO_free,CRYPTO_free,CRYPTO_free, 1_2_00007FFDFAECFDC0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEC9D90 CRYPTO_memcmp, 1_2_00007FFDFAEC9D90
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEABD80 CRYPTO_zalloc,ERR_put_error,CRYPTO_THREAD_lock_new,ERR_put_error,CRYPTO_free, 1_2_00007FFDFAEABD80
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEEFD80 EVP_PKEY_get0_RSA,RSA_size,RSA_size,CRYPTO_malloc,RAND_priv_bytes,CRYPTO_free, 1_2_00007FFDFAEEFD80
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE97D70 CRYPTO_zalloc,ERR_put_error, 1_2_00007FFDFAE97D70
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEBD350 CRYPTO_malloc,CRYPTO_clear_free, 1_2_00007FFDFAEBD350
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAECF350 CRYPTO_realloc, 1_2_00007FFDFAECF350
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEE1310 EVP_CIPHER_CTX_free,EVP_MD_CTX_free,CRYPTO_free,CRYPTO_free,CRYPTO_free, 1_2_00007FFDFAEE1310
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91005 CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,memset, 1_2_00007FFDFAE91005
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEC3290 CRYPTO_free_ex_data,OPENSSL_cleanse,OPENSSL_cleanse,X509_free,OPENSSL_sk_pop_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_THREAD_lock_free,CRYPTO_clear_free, 1_2_00007FFDFAEC3290
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEF7270 CRYPTO_malloc,ERR_put_error,CRYPTO_free,CRYPTO_free, 1_2_00007FFDFAEF7270
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9172B CRYPTO_free,CRYPTO_strndup, 1_2_00007FFDFAE9172B
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEA7450 EVP_PKEY_free,EVP_PKEY_free,CRYPTO_free,OPENSSL_sk_pop_free,CRYPTO_free,CRYPTO_clear_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_clear_free, 1_2_00007FFDFAEA7450
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91FB9 BN_bin2bn,BN_is_zero,CRYPTO_free,CRYPTO_strdup,CRYPTO_clear_free, 1_2_00007FFDFAE91FB9
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91B04 CRYPTO_malloc,CRYPTO_mem_ctrl,OPENSSL_sk_find,CRYPTO_free,CRYPTO_mem_ctrl,ERR_put_error,OPENSSL_sk_push,CRYPTO_mem_ctrl,CRYPTO_free,CRYPTO_mem_ctrl,ERR_put_error, 1_2_00007FFDFAE91B04
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEC7410 CRYPTO_free,CRYPTO_free, 1_2_00007FFDFAEC7410
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEE13B0 CRYPTO_malloc,ERR_put_error,CRYPTO_malloc,ERR_put_error,CRYPTO_free,CRYPTO_zalloc,ERR_put_error,CRYPTO_free, 1_2_00007FFDFAEE13B0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91C49 X509_free,EVP_PKEY_free,OPENSSL_sk_pop_free,CRYPTO_free, 1_2_00007FFDFAE91C49
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEC7370 CRYPTO_free, 1_2_00007FFDFAEC7370
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEB3110 ERR_put_error,CRYPTO_THREAD_run_once,CRYPTO_THREAD_run_once,CRYPTO_THREAD_run_once, 1_2_00007FFDFAEB3110
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEDB110 memset,CRYPTO_strdup,CRYPTO_free,CRYPTO_free,OPENSSL_cleanse,OPENSSL_cleanse,CRYPTO_clear_free,CRYPTO_clear_free, 1_2_00007FFDFAEDB110
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE92446 CRYPTO_memdup,ERR_put_error,CRYPTO_free,CRYPTO_free, 1_2_00007FFDFAE92446
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91A0A EVP_MD_size,EVP_CIPHER_iv_length,EVP_CIPHER_key_length,CRYPTO_clear_free,CRYPTO_malloc, 1_2_00007FFDFAE91A0A
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE923EC CRYPTO_free,CRYPTO_malloc,memcmp,CRYPTO_memdup, 1_2_00007FFDFAE923EC
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91B63 EVP_PKEY_get1_tls_encodedpoint,CRYPTO_free,EVP_PKEY_free,CRYPTO_free, 1_2_00007FFDFAE91B63
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEA9210 ASN1_item_d2i,ERR_put_error,ASN1_item_free,memcpy,_time64,X509_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,ASN1_item_free, 1_2_00007FFDFAEA9210
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEC71F0 CRYPTO_free, 1_2_00007FFDFAEC71F0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEC91F0 EVP_MD_size,EVP_MD_CTX_new,EVP_DigestInit_ex,EVP_DigestFinal_ex,EVP_DigestInit_ex,BIO_ctrl,EVP_DigestUpdate,EVP_DigestUpdate,EVP_DigestFinal_ex,EVP_PKEY_new_raw_private_key,EVP_DigestSignInit,EVP_DigestUpdate,EVP_DigestSignFinal,CRYPTO_memcmp,OPENSSL_cleanse,OPENSSL_cleanse,EVP_PKEY_free,EVP_MD_CTX_free, 1_2_00007FFDFAEC91F0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEC51C0 CRYPTO_malloc,CRYPTO_THREAD_lock_new,CRYPTO_new_ex_data,X509_up_ref,X509_chain_up_ref,CRYPTO_strdup,CRYPTO_strdup,CRYPTO_dup_ex_data,CRYPTO_strdup,CRYPTO_memdup,ERR_put_error,CRYPTO_memdup,CRYPTO_strdup,CRYPTO_memdup, 1_2_00007FFDFAEC51C0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91F05 EVP_MD_CTX_new,X509_get0_pubkey,EVP_PKEY_id,EVP_PKEY_id,EVP_PKEY_id,EVP_PKEY_size,EVP_DigestVerifyInit,EVP_PKEY_id,CRYPTO_malloc,RSA_pkey_ctx_ctrl,RSA_pkey_ctx_ctrl,EVP_DigestUpdate,EVP_MD_CTX_ctrl,EVP_DigestVerify,BIO_free,EVP_MD_CTX_free,CRYPTO_free, 1_2_00007FFDFAE91F05
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEB9170 memcpy,CRYPTO_THREAD_read_lock,OPENSSL_LH_retrieve,CRYPTO_THREAD_unlock, 1_2_00007FFDFAEB9170
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE923DD CRYPTO_free,CRYPTO_memdup, 1_2_00007FFDFAE923DD
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE92400 CRYPTO_malloc,ERR_put_error,CRYPTO_free, 1_2_00007FFDFAE92400
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91DAC CONF_parse_list,ERR_put_error,CRYPTO_malloc,ERR_put_error,CRYPTO_free,CRYPTO_free, 1_2_00007FFDFAE91DAC
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEBF6D0 CRYPTO_free,EVP_PKEY_free,CRYPTO_free, 1_2_00007FFDFAEBF6D0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9125D BIO_pop,BIO_free,BIO_free_all,BIO_free_all,BUF_MEM_free,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,SCT_LIST_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,EVP_MD_CTX_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,ASYNC_WAIT_CTX_free,CRYPTO_free,OPENSSL_sk_free,CRYPTO_THREAD_lock_free,CRYPTO_free, 1_2_00007FFDFAE9125D
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEAD660 CRYPTO_THREAD_run_once, 1_2_00007FFDFAEAD660
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE924AF CRYPTO_free,CRYPTO_malloc,memcpy, 1_2_00007FFDFAE924AF
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91844 CRYPTO_free, 1_2_00007FFDFAE91844
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEAF830 CRYPTO_zalloc,ERR_put_error,CRYPTO_free, 1_2_00007FFDFAEAF830
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEDB820 BN_num_bits,BN_bn2bin,CRYPTO_free,CRYPTO_strdup, 1_2_00007FFDFAEDB820
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAED77B0 CRYPTO_free,CRYPTO_strndup, 1_2_00007FFDFAED77B0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEC3790 CRYPTO_zalloc,ERR_put_error,_time64,CRYPTO_THREAD_lock_new,ERR_put_error,CRYPTO_new_ex_data,CRYPTO_THREAD_lock_free,CRYPTO_free, 1_2_00007FFDFAEC3790
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE917A3 CRYPTO_free, 1_2_00007FFDFAE917A3
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE922DE ERR_put_error,CRYPTO_malloc,ERR_put_error,CRYPTO_free,CRYPTO_free, 1_2_00007FFDFAE922DE
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAED7520 CRYPTO_free,CRYPTO_memdup, 1_2_00007FFDFAED7520
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE918C5 ERR_put_error,CRYPTO_free,CRYPTO_strdup, 1_2_00007FFDFAE918C5
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEDB4A0 X509_get0_pubkey,CRYPTO_malloc,RAND_bytes,EVP_PKEY_CTX_new,EVP_PKEY_encrypt_init,EVP_PKEY_encrypt,EVP_PKEY_encrypt,EVP_PKEY_CTX_free,CRYPTO_clear_free,EVP_PKEY_CTX_free, 1_2_00007FFDFAEDB4A0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE99490 CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,memset,CRYPTO_free, 1_2_00007FFDFAE99490
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEB9470 ERR_put_error,ERR_put_error,CRYPTO_zalloc,CRYPTO_THREAD_lock_new,CRYPTO_free,ERR_put_error,OPENSSL_sk_dup,X509_VERIFY_PARAM_new,X509_VERIFY_PARAM_inherit,CRYPTO_memdup,CRYPTO_memdup,CRYPTO_malloc,memcpy,CRYPTO_new_ex_data, 1_2_00007FFDFAEB9470
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE910A5 CRYPTO_zalloc,ERR_put_error,ERR_put_error,CRYPTO_free,EVP_PKEY_up_ref,X509_up_ref,EVP_PKEY_up_ref,X509_chain_up_ref,CRYPTO_malloc,memcpy,CRYPTO_malloc,memcpy,ERR_put_error,EVP_PKEY_free,X509_free,EVP_PKEY_free,OPENSSL_sk_pop_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,X509_STORE_free,X509_STORE_free,CRYPTO_free,CRYPTO_THREAD_lock_free,CRYPTO_free,CRYPTO_malloc,memcpy,CRYPTO_memdup,X509_STORE_up_ref,X509_STORE_up_ref,CRYPTO_strdup, 1_2_00007FFDFAE910A5
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91695 CRYPTO_THREAD_write_lock,CRYPTO_THREAD_unlock, 1_2_00007FFDFAE91695
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEB5624 CRYPTO_THREAD_unlock,CRYPTO_set_ex_data,CRYPTO_set_ex_data,COMP_CTX_get_method, 1_2_00007FFDFAEB5624
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEC75D0 CRYPTO_free, 1_2_00007FFDFAEC75D0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEDD5C0 CRYPTO_free,CRYPTO_free, 1_2_00007FFDFAEDD5C0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAECF590 CRYPTO_malloc,CRYPTO_malloc,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free, 1_2_00007FFDFAECF590
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9231A CRYPTO_free,CRYPTO_memdup, 1_2_00007FFDFAE9231A
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEC7560 CRYPTO_free, 1_2_00007FFDFAEC7560
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9254A CRYPTO_malloc,ERR_put_error,BIO_snprintf, 1_2_00007FFDFAE9254A
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE92310 CRYPTO_free, 1_2_00007FFDFAE92310
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE96B30 CRYPTO_zalloc,CRYPTO_free, 1_2_00007FFDFAE96B30
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEBCB20 ERR_put_error,ERR_put_error,ERR_put_error,EVP_MD_size,ERR_put_error,ERR_put_error,ERR_put_error,CRYPTO_malloc,ERR_put_error,OPENSSL_sk_num,OPENSSL_sk_value,OPENSSL_sk_insert,ERR_put_error,EVP_PKEY_free,X509_get0_pubkey,X509_free,OPENSSL_sk_push,ERR_put_error,X509_free,ERR_put_error, 1_2_00007FFDFAEBCB20
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9EB00 EVP_MD_CTX_md,EVP_MD_size,CRYPTO_memcmp,EVP_MD_CTX_md,EVP_MD_CTX_md,EVP_MD_size,EVP_CIPHER_CTX_cipher,EVP_CIPHER_flags,EVP_CIPHER_CTX_cipher,EVP_CIPHER_flags,CRYPTO_memcmp, 1_2_00007FFDFAE9EB00
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEDAB00 EVP_PKEY_get1_tls_encodedpoint,CRYPTO_free,EVP_PKEY_free, 1_2_00007FFDFAEDAB00
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEEAA8C CRYPTO_free,CRYPTO_memdup, 1_2_00007FFDFAEEAA8C
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE98A70 CRYPTO_free, 1_2_00007FFDFAE98A70
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEDCA70 EVP_CIPHER_CTX_free,CRYPTO_free,CRYPTO_free, 1_2_00007FFDFAEDCA70
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91BFE ERR_put_error,ERR_put_error,ERR_put_error,CRYPTO_zalloc,CRYPTO_THREAD_lock_new,ERR_put_error,CRYPTO_free,OPENSSL_LH_new,OPENSSL_sk_num,EVP_get_digestbyname,EVP_get_digestbyname,OPENSSL_sk_new_null,OPENSSL_sk_new_null,CRYPTO_new_ex_data,RAND_bytes,RAND_priv_bytes,RAND_priv_bytes,RAND_priv_bytes, 1_2_00007FFDFAE91BFE
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91230 memcpy,OPENSSL_LH_retrieve,CRYPTO_THREAD_unlock,memcmp,_time64, 1_2_00007FFDFAE91230
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE917B7 CRYPTO_THREAD_write_lock,CRYPTO_THREAD_unlock, 1_2_00007FFDFAE917B7
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91EAB CRYPTO_memcmp,memchr,CRYPTO_free,CRYPTO_free,CRYPTO_strndup, 1_2_00007FFDFAE91EAB
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91F78 CRYPTO_strdup, 1_2_00007FFDFAE91F78
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91B18 memset,OPENSSL_cleanse,CRYPTO_free,CRYPTO_memdup,OPENSSL_cleanse,CRYPTO_memcmp, 1_2_00007FFDFAE91B18
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91F0A CRYPTO_malloc,memcpy,memcpy,memcmp,memcmp,memcmp,ERR_put_error,CRYPTO_clear_free, 1_2_00007FFDFAE91F0A
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEBC870 CRYPTO_free,CRYPTO_free, 1_2_00007FFDFAEBC870
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91D52 BN_num_bits,CRYPTO_malloc,BN_bn2bin,BN_clear_free,BN_clear_free, 1_2_00007FFDFAE91D52
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEBAA24 ERR_put_error,CRYPTO_set_ex_data,CRYPTO_set_ex_data,COMP_CTX_get_method, 1_2_00007FFDFAEBAA24
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE92252 BIO_s_file,BIO_new,BIO_ctrl,strncmp,strncmp,CRYPTO_realloc,memcpy,CRYPTO_free,CRYPTO_free,CRYPTO_free,PEM_read_bio,ERR_put_error,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,BIO_free, 1_2_00007FFDFAE92252
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEE8A00 CRYPTO_free,CRYPTO_strndup, 1_2_00007FFDFAEE8A00
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEAC9F0 i2d_X509_NAME,i2d_X509_NAME,memcmp,CRYPTO_free,CRYPTO_free, 1_2_00007FFDFAEAC9F0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAED09F0 CRYPTO_free,CRYPTO_strndup, 1_2_00007FFDFAED09F0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9109B CRYPTO_free,CRYPTO_memdup,CRYPTO_memdup, 1_2_00007FFDFAE9109B
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEAC990 CRYPTO_get_ex_new_index, 1_2_00007FFDFAEAC990
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAED896F CRYPTO_malloc, 1_2_00007FFDFAED896F
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEBC960 ERR_put_error,CRYPTO_realloc,CRYPTO_realloc,ERR_put_error, 1_2_00007FFDFAEBC960
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91CE4 CRYPTO_free,CRYPTO_free,CRYPTO_memdup, 1_2_00007FFDFAE91CE4
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEF8F30 HMAC_CTX_new,EVP_CIPHER_CTX_new,EVP_sha256,HMAC_Init_ex,EVP_aes_256_cbc,HMAC_size,EVP_CIPHER_CTX_iv_length,HMAC_Update,HMAC_Final,CRYPTO_memcmp,EVP_CIPHER_CTX_iv_length,EVP_CIPHER_CTX_iv_length,CRYPTO_malloc,CRYPTO_free,CRYPTO_free,memcpy,ERR_clear_error,CRYPTO_free,EVP_CIPHER_CTX_free,HMAC_CTX_free, 1_2_00007FFDFAEF8F30
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9191F ERR_put_error,memcpy,OPENSSL_sk_num,OPENSSL_sk_num,OPENSSL_sk_new_reserve,OPENSSL_sk_value,CRYPTO_dup_ex_data,X509_VERIFY_PARAM_inherit,OPENSSL_sk_dup,OPENSSL_sk_dup, 1_2_00007FFDFAE9191F
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEC6E60 CRYPTO_free,CRYPTO_strdup,CRYPTO_free, 1_2_00007FFDFAEC6E60
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91C2B EVP_CIPHER_key_length,EVP_CIPHER_iv_length,CRYPTO_malloc, 1_2_00007FFDFAE91C2B
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9228E CRYPTO_free, 1_2_00007FFDFAE9228E
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91B4F CRYPTO_THREAD_write_lock,OPENSSL_LH_set_down_load,CRYPTO_THREAD_unlock, 1_2_00007FFDFAE91B4F
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE92261 CRYPTO_zalloc,ERR_put_error, 1_2_00007FFDFAE92261
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE918CF CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_memdup, 1_2_00007FFDFAE918CF
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91357 memcmp,memcmp,EVP_CIPHER_CTX_free,CRYPTO_free,CRYPTO_free,memcmp,memcmp,memcpy,CRYPTO_free,CRYPTO_free, 1_2_00007FFDFAE91357
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEC2D10 CRYPTO_THREAD_write_lock,OPENSSL_LH_insert,OPENSSL_LH_retrieve,OPENSSL_LH_retrieve,OPENSSL_LH_delete,CRYPTO_THREAD_unlock, 1_2_00007FFDFAEC2D10
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91208 CRYPTO_zalloc,memcpy,memcpy,memcpy,CRYPTO_free,memcpy,CRYPTO_free,CRYPTO_free, 1_2_00007FFDFAE91208
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEE2CE0 EVP_CIPHER_CTX_free,EVP_MD_CTX_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,memset,memcpy,memcpy, 1_2_00007FFDFAEE2CE0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAED8CDA CRYPTO_free,CRYPTO_free, 1_2_00007FFDFAED8CDA
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEDACD0 EVP_DigestUpdate,EVP_MD_CTX_free,EVP_PKEY_CTX_free,EVP_PKEY_CTX_free,CRYPTO_clear_free,EVP_MD_CTX_free, 1_2_00007FFDFAEDACD0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEAECC0 CRYPTO_THREAD_run_once,OPENSSL_sk_find,OPENSSL_sk_value,EVP_CIPHER_flags,EVP_get_cipherbyname,EVP_get_cipherbyname,EVP_get_cipherbyname,EVP_get_cipherbyname,EVP_get_cipherbyname, 1_2_00007FFDFAEAECC0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEE8CC0 CRYPTO_malloc,CRYPTO_free,EVP_CIPHER_CTX_free,HMAC_CTX_free,CRYPTO_free,EVP_CIPHER_CTX_free,HMAC_CTX_free,RAND_bytes,EVP_sha256,EVP_EncryptUpdate,EVP_EncryptFinal,HMAC_Update,HMAC_Final, 1_2_00007FFDFAEE8CC0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEA6CA5 CRYPTO_free,CRYPTO_strdup,ERR_put_error,ERR_put_error, 1_2_00007FFDFAEA6CA5
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE915CD EVP_MD_CTX_new,EVP_PKEY_new,EVP_PKEY_assign,DH_free,EVP_PKEY_security_bits,EVP_PKEY_get0_DH,EVP_PKEY_free,DH_get0_key,EVP_PKEY_get1_tls_encodedpoint,EVP_PKEY_free,CRYPTO_free,EVP_MD_CTX_free,BN_num_bits,BN_num_bits,memset,BN_num_bits,BN_bn2bin,CRYPTO_free,EVP_PKEY_size,EVP_DigestSignInit,RSA_pkey_ctx_ctrl,RSA_pkey_ctx_ctrl,EVP_DigestSign,CRYPTO_free,EVP_MD_CTX_free, 1_2_00007FFDFAE915CD
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEC6DF0 CRYPTO_free, 1_2_00007FFDFAEC6DF0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE919BA CRYPTO_malloc, 1_2_00007FFDFAE919BA
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEA6DAB ERR_put_error,CRYPTO_free,CRYPTO_strdup, 1_2_00007FFDFAEA6DAB
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE98D80 CRYPTO_malloc,ERR_put_error, 1_2_00007FFDFAE98D80
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91ABE CONF_parse_list,CRYPTO_malloc,ERR_put_error,memcpy,CRYPTO_free,CRYPTO_free, 1_2_00007FFDFAE91ABE
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAED0340 CRYPTO_memcmp, 1_2_00007FFDFAED0340
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE919EC CRYPTO_malloc,ERR_put_error,CRYPTO_free, 1_2_00007FFDFAE919EC
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE92149 ERR_put_error,CRYPTO_realloc,CRYPTO_realloc,ERR_put_error, 1_2_00007FFDFAE92149
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEF02A0 BN_bin2bn,BN_ucmp,BN_is_zero,CRYPTO_free,CRYPTO_strdup, 1_2_00007FFDFAEF02A0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91D8E BN_copy,BN_free,BN_dup,BN_copy,BN_free,BN_dup,BN_copy,BN_free,BN_dup,BN_copy,BN_free,BN_dup,CRYPTO_free,CRYPTO_strdup, 1_2_00007FFDFAE91D8E
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91EB5 CRYPTO_strdup,CRYPTO_free, 1_2_00007FFDFAE91EB5
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE94443 CRYPTO_zalloc,ERR_put_error,BIO_set_init,BIO_set_data,BIO_clear_flags, 1_2_00007FFDFAE94443
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEE8420 CRYPTO_memcmp, 1_2_00007FFDFAEE8420
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE912E4 EVP_MD_size,RAND_bytes,_time64,CRYPTO_free,CRYPTO_memdup, 1_2_00007FFDFAE912E4
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAED8397 CRYPTO_clear_free, 1_2_00007FFDFAED8397
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEC4370 OPENSSL_LH_retrieve,OPENSSL_LH_delete,CRYPTO_THREAD_unlock, 1_2_00007FFDFAEC4370
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91514 CRYPTO_free, 1_2_00007FFDFAE91514
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEB2150 CRYPTO_free,CRYPTO_free,OPENSSL_sk_pop_free,CRYPTO_free, 1_2_00007FFDFAEB2150
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9225C CRYPTO_zalloc,CRYPTO_zalloc,OBJ_nid2sn,EVP_get_digestbyname,CRYPTO_free,CRYPTO_free,ERR_put_error, 1_2_00007FFDFAE9225C
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91BAE CRYPTO_free,CRYPTO_malloc, 1_2_00007FFDFAE91BAE
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE92116 CRYPTO_malloc, 1_2_00007FFDFAE92116
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEA60AA CRYPTO_free, 1_2_00007FFDFAEA60AA
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9215D CRYPTO_free,CRYPTO_malloc,RAND_bytes, 1_2_00007FFDFAE9215D
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAED0090 CRYPTO_free,CRYPTO_free, 1_2_00007FFDFAED0090
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE94064 BIO_get_data,BIO_get_init,BIO_clear_flags,BIO_set_init,CRYPTO_free,CRYPTO_zalloc,ERR_put_error,BIO_set_init,BIO_clear_flags,BIO_get_data,BIO_set_shutdown,BIO_push,BIO_set_next,BIO_up_ref,BIO_set_init, 1_2_00007FFDFAE94064
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAECA250 EVP_PKEY_get1_tls_encodedpoint,CRYPTO_free,EVP_PKEY_free,CRYPTO_free, 1_2_00007FFDFAECA250
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEE0200 CRYPTO_free,CRYPTO_free,CRYPTO_strndup, 1_2_00007FFDFAEE0200
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEC41B0 memcpy,CRYPTO_THREAD_read_lock,OPENSSL_LH_retrieve,CRYPTO_THREAD_unlock, 1_2_00007FFDFAEC41B0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEA41B0 CRYPTO_clear_free, 1_2_00007FFDFAEA41B0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEA8180 EVP_PKEY_CTX_new,EVP_PKEY_derive_init,EVP_PKEY_derive_set_peer,EVP_PKEY_derive,CRYPTO_malloc,EVP_PKEY_derive,CRYPTO_clear_free,EVP_PKEY_CTX_free, 1_2_00007FFDFAEA8180
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91663 CRYPTO_malloc,ERR_put_error,CRYPTO_free,CRYPTO_free,CRYPTO_free, 1_2_00007FFDFAE91663
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEFC750 SRP_Calc_u,BN_num_bits,CRYPTO_malloc,BN_bn2bin,BN_clear_free,BN_clear_free,CRYPTO_clear_free,BN_clear_free, 1_2_00007FFDFAEFC750
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91B9A CRYPTO_free,CRYPTO_malloc, 1_2_00007FFDFAE91B9A
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAED0740 CRYPTO_free,CRYPTO_memdup, 1_2_00007FFDFAED0740
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEAA710 CRYPTO_THREAD_run_once, 1_2_00007FFDFAEAA710
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEBC6D0 CRYPTO_zalloc,CRYPTO_zalloc,OBJ_nid2sn,EVP_get_digestbyname,CRYPTO_free,CRYPTO_free,ERR_put_error, 1_2_00007FFDFAEBC6D0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE916B8 OPENSSL_sk_new_null,d2i_X509,CRYPTO_free,OPENSSL_sk_push,CRYPTO_free,ERR_clear_error,OPENSSL_sk_value,X509_get0_pubkey,EVP_PKEY_missing_parameters,X509_free,X509_up_ref,X509_free,OPENSSL_sk_pop_free, 1_2_00007FFDFAE916B8
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE94660 BIO_get_data,BIO_get_shutdown,BIO_get_init,BIO_clear_flags,BIO_set_init,CRYPTO_free, 1_2_00007FFDFAE94660
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91E60 CRYPTO_clear_free, 1_2_00007FFDFAE91E60
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEE87E0 CRYPTO_free,CRYPTO_memdup, 1_2_00007FFDFAEE87E0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91249 CRYPTO_zalloc,ERR_put_error,_time64,CRYPTO_THREAD_lock_new,ERR_put_error,CRYPTO_free,CRYPTO_THREAD_lock_free,CRYPTO_THREAD_read_lock,CRYPTO_THREAD_read_lock,CRYPTO_THREAD_unlock,CRYPTO_THREAD_unlock,memset,memcpy, 1_2_00007FFDFAE91249
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91AB9 CRYPTO_free, 1_2_00007FFDFAE91AB9
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91519 CRYPTO_malloc,ERR_put_error,memcpy,CRYPTO_free,ERR_put_error,ERR_put_error,ERR_put_error,memcpy, 1_2_00007FFDFAE91519
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEC4530 CRYPTO_THREAD_read_lock,CRYPTO_THREAD_read_lock,CRYPTO_THREAD_unlock,CRYPTO_THREAD_unlock,memset, 1_2_00007FFDFAEC4530
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEE2530 EVP_CIPHER_CTX_free,EVP_MD_CTX_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,memcpy, 1_2_00007FFDFAEE2530
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE984E0 CRYPTO_zalloc,ERR_put_error, 1_2_00007FFDFAE984E0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE917D5 CRYPTO_malloc,memcpy, 1_2_00007FFDFAE917D5
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE92513 CRYPTO_free, 1_2_00007FFDFAE92513
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91500 CRYPTO_memdup,ERR_put_error,CRYPTO_free,CRYPTO_free, 1_2_00007FFDFAE91500
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE924D7 OPENSSL_sk_new_null,d2i_X509,CRYPTO_free,OPENSSL_sk_push,OPENSSL_sk_num,CRYPTO_memcmp,CRYPTO_free,X509_free,OPENSSL_sk_pop_free,OPENSSL_sk_value,X509_get0_pubkey,X509_free,OPENSSL_sk_shift,OPENSSL_sk_pop_free, 1_2_00007FFDFAE924D7
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEC85F0 CRYPTO_zalloc,CRYPTO_free, 1_2_00007FFDFAEC85F0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEB45E0 X509_VERIFY_PARAM_free,CRYPTO_free,CRYPTO_free,CRYPTO_free_ex_data,OPENSSL_LH_free,X509_STORE_free,CTLOG_STORE_free,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,OPENSSL_sk_free,ENGINE_finish,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_secure_free,CRYPTO_THREAD_lock_free,CRYPTO_free, 1_2_00007FFDFAEB45E0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEA85D0 CRYPTO_malloc,memset,memcpy,memcpy,CRYPTO_clear_free,CRYPTO_clear_free,CRYPTO_clear_free,CRYPTO_clear_free,OPENSSL_cleanse, 1_2_00007FFDFAEA85D0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91F9B CRYPTO_free,BIO_clear_flags,BIO_set_flags,BIO_snprintf,ERR_add_error_data,memcpy, 1_2_00007FFDFAE91F9B
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE98590 CRYPTO_zalloc,ERR_put_error,BUF_MEM_grow, 1_2_00007FFDFAE98590
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA05FA70 CRYPTO_free,CRYPTO_strndup,CRYPTO_free,CRYPTO_memdup,OPENSSL_cleanse, 2_2_00007FFDFA05FA70
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA01FAA0 strncmp,strncmp,strncmp,strncmp,ERR_put_error,CRYPTO_malloc,CRYPTO_malloc,CRYPTO_free,ERR_put_error,strncmp,CRYPTO_free,OPENSSL_sk_new_null,CRYPTO_free,OPENSSL_sk_num,OPENSSL_sk_value,OPENSSL_sk_push,OPENSSL_sk_num,OPENSSL_sk_push,CRYPTO_free,OPENSSL_sk_free,CRYPTO_free,OPENSSL_sk_free, 2_2_00007FFDFA01FAA0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001104 EVP_PKEY_free,X509_free,EVP_PKEY_free,OPENSSL_sk_pop_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,X509_STORE_free,X509_STORE_free,CRYPTO_free,CRYPTO_THREAD_lock_free,CRYPTO_free, 2_2_00007FFDFA001104
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001253 CRYPTO_free, 2_2_00007FFDFA001253
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA051AD0 CRYPTO_free, 2_2_00007FFDFA051AD0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0022CA ERR_put_error,CRYPTO_free,CRYPTO_strdup, 2_2_00007FFDFA0022CA
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0016E5 CRYPTO_zalloc, 2_2_00007FFDFA0016E5
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001CD5 CRYPTO_malloc,COMP_expand_block, 2_2_00007FFDFA001CD5
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA007B20 CRYPTO_free, 2_2_00007FFDFA007B20
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA015B40 CRYPTO_free,OPENSSL_sk_pop_free,CRYPTO_free,CRYPTO_clear_free,CRYPTO_free,CRYPTO_free,EVP_PKEY_free,EVP_PKEY_free,CRYPTO_free,CRYPTO_free,memset,CRYPTO_free, 2_2_00007FFDFA015B40
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001686 CRYPTO_free,CRYPTO_memdup, 2_2_00007FFDFA001686
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA01DBC0 CRYPTO_mem_ctrl,OPENSSL_sk_new,COMP_get_type,CRYPTO_malloc,OPENSSL_sk_push,OPENSSL_sk_sort,CRYPTO_mem_ctrl, 2_2_00007FFDFA01DBC0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00DC20 CRYPTO_free, 2_2_00007FFDFA00DC20
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA037870 CRYPTO_free, 2_2_00007FFDFA037870
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0218D0 CRYPTO_free,CRYPTO_strdup, 2_2_00007FFDFA0218D0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00141F EVP_PKEY_get1_tls_encodedpoint,EVP_PKEY_free,CRYPTO_free,EVP_PKEY_free,CRYPTO_free, 2_2_00007FFDFA00141F
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001F6E CRYPTO_free,CRYPTO_memdup, 2_2_00007FFDFA001F6E
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00193D CRYPTO_free,CRYPTO_memdup, 2_2_00007FFDFA00193D
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001028 EVP_PKEY_free,CRYPTO_free,CRYPTO_free,EVP_MD_CTX_new,RSA_pkey_ctx_ctrl,CRYPTO_free,EVP_MD_CTX_free,EVP_MD_CTX_free, 2_2_00007FFDFA001028
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA053980 CRYPTO_malloc,memcpy, 2_2_00007FFDFA053980
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0024DC CRYPTO_malloc,ERR_put_error,memcpy,CRYPTO_free,CRYPTO_free, 2_2_00007FFDFA0024DC
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA05D9C0 OPENSSL_sk_free,OPENSSL_sk_free,CRYPTO_free,CRYPTO_free,memcmp,OPENSSL_sk_num,OPENSSL_sk_value,OPENSSL_sk_num,memcpy,OPENSSL_sk_num,OPENSSL_sk_value,OPENSSL_sk_num,CRYPTO_memcmp,OPENSSL_sk_free,OPENSSL_sk_dup,OPENSSL_sk_free,OPENSSL_sk_dup,OPENSSL_sk_num,OPENSSL_sk_value,OPENSSL_sk_num,OPENSSL_sk_num,OPENSSL_sk_value,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_free,CRYPTO_free,CRYPTO_free, 2_2_00007FFDFA05D9C0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA002144 EVP_MD_CTX_new,EVP_MD_CTX_copy_ex,EVP_MD_CTX_free,CRYPTO_memcmp,memcpy,memcpy, 2_2_00007FFDFA002144
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001C12 CRYPTO_free,CRYPTO_strdup, 2_2_00007FFDFA001C12
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA023A20 CRYPTO_free,CRYPTO_memdup, 2_2_00007FFDFA023A20
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00207C CRYPTO_free,CRYPTO_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,memset, 2_2_00007FFDFA00207C
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001870 CRYPTO_free,CRYPTO_malloc,CRYPTO_free,CRYPTO_free,CRYPTO_memdup, 2_2_00007FFDFA001870
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00FEA0 EVP_CIPHER_CTX_cipher,EVP_CIPHER_flags,EVP_MD_CTX_md,EVP_MD_size,CRYPTO_memcmp,EVP_MD_CTX_md,EVP_MD_CTX_md,EVP_MD_size,EVP_CIPHER_CTX_cipher,EVP_CIPHER_flags,EVP_CIPHER_CTX_cipher,EVP_CIPHER_flags,CRYPTO_memcmp,strncmp,strncmp,strncmp,strncmp,strncmp, 2_2_00007FFDFA00FEA0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00150A CRYPTO_free,CRYPTO_malloc,ERR_put_error,memcpy, 2_2_00007FFDFA00150A
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA007ED0 CRYPTO_zalloc,ERR_put_error, 2_2_00007FFDFA007ED0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA01DEF0 CRYPTO_THREAD_run_once, 2_2_00007FFDFA01DEF0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA017EE0 CRYPTO_free,CRYPTO_memdup, 2_2_00007FFDFA017EE0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001861 CRYPTO_free,CRYPTO_strndup,CRYPTO_free,OPENSSL_cleanse,_time64,memcpy,OPENSSL_cleanse,OPENSSL_cleanse,EVP_MD_size, 2_2_00007FFDFA001861
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA025F20 ERR_put_error,CRYPTO_free,ERR_put_error,BUF_MEM_free,EVP_MD_CTX_free,X509_free,X509_VERIFY_PARAM_move_peername,CRYPTO_free, 2_2_00007FFDFA025F20
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA009F50 CRYPTO_malloc,memset,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free, 2_2_00007FFDFA009F50
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA015F70 CRYPTO_free,CRYPTO_strdup, 2_2_00007FFDFA015F70
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00218F EVP_MD_CTX_new,EVP_PKEY_size,CRYPTO_malloc,EVP_DigestSignInit,RSA_pkey_ctx_ctrl,RSA_pkey_ctx_ctrl,EVP_DigestUpdate,EVP_MD_CTX_ctrl,EVP_DigestSignFinal,EVP_DigestSign,BUF_reverse,CRYPTO_free,EVP_MD_CTX_free,CRYPTO_free,EVP_MD_CTX_free, 2_2_00007FFDFA00218F
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00E010 CRYPTO_malloc, 2_2_00007FFDFA00E010
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001F28 CRYPTO_free,CRYPTO_malloc,memcpy, 2_2_00007FFDFA001F28
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA03A030 CRYPTO_free,CRYPTO_memdup, 2_2_00007FFDFA03A030
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00101E EVP_PKEY_free,BN_num_bits,BN_bn2bin,EVP_PKEY_free,CRYPTO_free,EVP_PKEY_free,CRYPTO_free,CRYPTO_clear_free,CRYPTO_clear_free, 2_2_00007FFDFA00101E
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA002095 CRYPTO_free,_time64,CRYPTO_free,CRYPTO_malloc,EVP_sha256,EVP_Digest,EVP_MD_size,CRYPTO_free, 2_2_00007FFDFA002095
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA05BC60 CRYPTO_memcmp, 2_2_00007FFDFA05BC60
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA007C70 CRYPTO_free, 2_2_00007FFDFA007C70
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA01DCB0 COMP_zlib,CRYPTO_mem_ctrl,OPENSSL_sk_new,COMP_get_type,CRYPTO_malloc,COMP_get_name,OPENSSL_sk_push,OPENSSL_sk_sort,CRYPTO_mem_ctrl, 2_2_00007FFDFA01DCB0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00DCD0 CRYPTO_free, 2_2_00007FFDFA00DCD0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0018BB CRYPTO_free,CRYPTO_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,memset, 2_2_00007FFDFA0018BB
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00DD30 CRYPTO_free, 2_2_00007FFDFA00DD30
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0020F4 CRYPTO_THREAD_read_lock,CRYPTO_THREAD_unlock, 2_2_00007FFDFA0020F4
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA019D50 CRYPTO_free,CRYPTO_strndup, 2_2_00007FFDFA019D50
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA007D70 CRYPTO_zalloc,ERR_put_error, 2_2_00007FFDFA007D70
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA039D90 CRYPTO_memcmp, 2_2_00007FFDFA039D90
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA01BD80 CRYPTO_zalloc,ERR_put_error,CRYPTO_THREAD_lock_new,ERR_put_error,CRYPTO_free, 2_2_00007FFDFA01BD80
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA05FD80 EVP_PKEY_get0_RSA,RSA_size,RSA_size,CRYPTO_malloc,RAND_priv_bytes,CRYPTO_free, 2_2_00007FFDFA05FD80
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA03FDC0 CRYPTO_memdup,CRYPTO_memdup,CRYPTO_memdup,CRYPTO_free,CRYPTO_free,CRYPTO_free, 2_2_00007FFDFA03FDC0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00DDE0 CRYPTO_malloc,CRYPTO_free,CRYPTO_malloc, 2_2_00007FFDFA00DDE0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA067E00 CRYPTO_free,CRYPTO_malloc,ERR_put_error, 2_2_00007FFDFA067E00
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001E6A CRYPTO_zalloc,ERR_put_error,BUF_MEM_grow,CRYPTO_free, 2_2_00007FFDFA001E6A
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00172B CRYPTO_free,CRYPTO_strndup, 2_2_00007FFDFA00172B
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA033290 CRYPTO_free_ex_data,OPENSSL_cleanse,OPENSSL_cleanse,X509_free,OPENSSL_sk_pop_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_THREAD_lock_free,CRYPTO_clear_free, 2_2_00007FFDFA033290
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001005 CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,memset, 2_2_00007FFDFA001005
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA051310 EVP_CIPHER_CTX_free,EVP_MD_CTX_free,CRYPTO_free,CRYPTO_free,CRYPTO_free, 2_2_00007FFDFA051310
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA03F350 CRYPTO_realloc, 2_2_00007FFDFA03F350
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA02D350 CRYPTO_malloc,CRYPTO_clear_free, 2_2_00007FFDFA02D350
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA037370 CRYPTO_free, 2_2_00007FFDFA037370
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0513B0 CRYPTO_malloc,ERR_put_error,CRYPTO_malloc,ERR_put_error,CRYPTO_free,CRYPTO_zalloc,ERR_put_error,CRYPTO_free, 2_2_00007FFDFA0513B0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001C49 X509_free,EVP_PKEY_free,OPENSSL_sk_pop_free,CRYPTO_free, 2_2_00007FFDFA001C49
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA037410 CRYPTO_free,CRYPTO_free, 2_2_00007FFDFA037410
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001B04 CRYPTO_malloc,CRYPTO_mem_ctrl,OPENSSL_sk_find,CRYPTO_free,CRYPTO_mem_ctrl,ERR_put_error,OPENSSL_sk_push,CRYPTO_mem_ctrl,CRYPTO_free,CRYPTO_mem_ctrl,ERR_put_error, 2_2_00007FFDFA001B04
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA017450 EVP_PKEY_free,EVP_PKEY_free,CRYPTO_free,OPENSSL_sk_pop_free,CRYPTO_free,CRYPTO_clear_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_clear_free, 2_2_00007FFDFA017450
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001FB9 BN_bin2bn,BN_is_zero,CRYPTO_free,CRYPTO_strdup,CRYPTO_clear_free, 2_2_00007FFDFA001FB9
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA002446 CRYPTO_memdup,ERR_put_error,CRYPTO_free,CRYPTO_free, 2_2_00007FFDFA002446
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001A0A EVP_MD_size,EVP_CIPHER_iv_length,EVP_CIPHER_key_length,CRYPTO_clear_free,CRYPTO_malloc, 2_2_00007FFDFA001A0A
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA023110 ERR_put_error,CRYPTO_THREAD_run_once,CRYPTO_THREAD_run_once,CRYPTO_THREAD_run_once, 2_2_00007FFDFA023110
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA04B110 memset,CRYPTO_strdup,CRYPTO_free,CRYPTO_free,OPENSSL_cleanse,OPENSSL_cleanse,CRYPTO_clear_free,CRYPTO_clear_free, 2_2_00007FFDFA04B110
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA029170 memcpy,CRYPTO_THREAD_read_lock,OPENSSL_LH_retrieve,CRYPTO_THREAD_unlock, 2_2_00007FFDFA029170
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001F05 EVP_MD_CTX_new,X509_get0_pubkey,EVP_PKEY_id,EVP_PKEY_id,EVP_PKEY_id,EVP_PKEY_size,EVP_DigestVerifyInit,EVP_PKEY_id,CRYPTO_malloc,RSA_pkey_ctx_ctrl,RSA_pkey_ctx_ctrl,EVP_DigestUpdate,EVP_MD_CTX_ctrl,EVP_DigestVerify,BIO_free,EVP_MD_CTX_free,CRYPTO_free, 2_2_00007FFDFA001F05
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0351C0 CRYPTO_malloc,CRYPTO_THREAD_lock_new,CRYPTO_new_ex_data,X509_up_ref,X509_chain_up_ref,CRYPTO_strdup,CRYPTO_strdup,CRYPTO_dup_ex_data,CRYPTO_strdup,CRYPTO_memdup,ERR_put_error,CRYPTO_memdup,CRYPTO_strdup,CRYPTO_memdup, 2_2_00007FFDFA0351C0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0391F0 EVP_MD_size,EVP_MD_CTX_new,EVP_DigestInit_ex,EVP_DigestFinal_ex,EVP_DigestInit_ex,BIO_ctrl,EVP_DigestUpdate,EVP_DigestUpdate,EVP_DigestFinal_ex,EVP_PKEY_new_raw_private_key,EVP_DigestSignInit,EVP_DigestUpdate,EVP_DigestSignFinal,CRYPTO_memcmp,OPENSSL_cleanse,OPENSSL_cleanse,EVP_PKEY_free,EVP_MD_CTX_free, 2_2_00007FFDFA0391F0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0371F0 CRYPTO_free, 2_2_00007FFDFA0371F0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA019210 ASN1_item_d2i,ERR_put_error,ASN1_item_free,memcpy,_time64,X509_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,ASN1_item_free, 2_2_00007FFDFA019210
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0023EC CRYPTO_free,CRYPTO_malloc,memcmp,CRYPTO_memdup, 2_2_00007FFDFA0023EC
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001B63 EVP_PKEY_get1_tls_encodedpoint,CRYPTO_free,EVP_PKEY_free,CRYPTO_free, 2_2_00007FFDFA001B63
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA01D660 CRYPTO_THREAD_run_once, 2_2_00007FFDFA01D660
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00125D BIO_pop,BIO_free,BIO_free_all,BIO_free_all,BUF_MEM_free,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,SCT_LIST_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,EVP_MD_CTX_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,ASYNC_WAIT_CTX_free,CRYPTO_free,OPENSSL_sk_free,CRYPTO_THREAD_lock_free,CRYPTO_free, 2_2_00007FFDFA00125D
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA02F6D0 CRYPTO_free,EVP_PKEY_free,CRYPTO_free, 2_2_00007FFDFA02F6D0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001DAC CONF_parse_list,ERR_put_error,CRYPTO_malloc,ERR_put_error,CRYPTO_free,CRYPTO_free, 2_2_00007FFDFA001DAC
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA002400 CRYPTO_malloc,ERR_put_error,CRYPTO_free, 2_2_00007FFDFA002400
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0023DD CRYPTO_free,CRYPTO_memdup, 2_2_00007FFDFA0023DD
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0017A3 CRYPTO_free, 2_2_00007FFDFA0017A3
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA033790 CRYPTO_zalloc,ERR_put_error,_time64,CRYPTO_THREAD_lock_new,ERR_put_error,CRYPTO_new_ex_data,CRYPTO_THREAD_lock_free,CRYPTO_free, 2_2_00007FFDFA033790
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0477B0 CRYPTO_free,CRYPTO_strndup, 2_2_00007FFDFA0477B0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA01F830 CRYPTO_zalloc,ERR_put_error,CRYPTO_free, 2_2_00007FFDFA01F830
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA04B820 BN_num_bits,BN_bn2bin,CRYPTO_free,CRYPTO_strdup, 2_2_00007FFDFA04B820
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0024AF CRYPTO_free,CRYPTO_malloc,memcpy, 2_2_00007FFDFA0024AF
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001844 CRYPTO_free, 2_2_00007FFDFA001844
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA029470 ERR_put_error,ERR_put_error,CRYPTO_zalloc,CRYPTO_THREAD_lock_new,CRYPTO_free,ERR_put_error,OPENSSL_sk_dup,X509_VERIFY_PARAM_new,X509_VERIFY_PARAM_inherit,CRYPTO_memdup,CRYPTO_memdup,CRYPTO_malloc,memcpy,CRYPTO_new_ex_data, 2_2_00007FFDFA029470
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0010A5 CRYPTO_zalloc,ERR_put_error,ERR_put_error,CRYPTO_free,EVP_PKEY_up_ref,X509_up_ref,EVP_PKEY_up_ref,X509_chain_up_ref,CRYPTO_malloc,memcpy,CRYPTO_malloc,memcpy,ERR_put_error,EVP_PKEY_free,X509_free,EVP_PKEY_free,OPENSSL_sk_pop_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,X509_STORE_free,X509_STORE_free,CRYPTO_free,CRYPTO_THREAD_lock_free,CRYPTO_free,CRYPTO_malloc,memcpy,CRYPTO_memdup,X509_STORE_up_ref,X509_STORE_up_ref,CRYPTO_strdup, 2_2_00007FFDFA0010A5
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA009490 CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,memset,CRYPTO_free, 2_2_00007FFDFA009490
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0018C5 ERR_put_error,CRYPTO_free,CRYPTO_strdup, 2_2_00007FFDFA0018C5
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA04B4A0 X509_get0_pubkey,CRYPTO_malloc,RAND_bytes,EVP_PKEY_CTX_new,EVP_PKEY_encrypt_init,EVP_PKEY_encrypt,EVP_PKEY_encrypt,EVP_PKEY_CTX_free,CRYPTO_clear_free,EVP_PKEY_CTX_free, 2_2_00007FFDFA04B4A0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA047520 CRYPTO_free,CRYPTO_memdup, 2_2_00007FFDFA047520
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0022DE ERR_put_error,CRYPTO_malloc,ERR_put_error,CRYPTO_free,CRYPTO_free, 2_2_00007FFDFA0022DE
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA037560 CRYPTO_free, 2_2_00007FFDFA037560
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA03F590 CRYPTO_malloc,CRYPTO_malloc,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free, 2_2_00007FFDFA03F590
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00231A CRYPTO_free,CRYPTO_memdup, 2_2_00007FFDFA00231A
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0375D0 CRYPTO_free, 2_2_00007FFDFA0375D0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA04D5C0 CRYPTO_free,CRYPTO_free, 2_2_00007FFDFA04D5C0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA025624 CRYPTO_THREAD_unlock,CRYPTO_set_ex_data,CRYPTO_set_ex_data,COMP_CTX_get_method, 2_2_00007FFDFA025624
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001695 CRYPTO_THREAD_write_lock,CRYPTO_THREAD_unlock, 2_2_00007FFDFA001695
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA008A70 CRYPTO_free, 2_2_00007FFDFA008A70
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA04CA70 EVP_CIPHER_CTX_free,CRYPTO_free,CRYPTO_free, 2_2_00007FFDFA04CA70
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001BFE ERR_put_error,ERR_put_error,ERR_put_error,CRYPTO_zalloc,CRYPTO_THREAD_lock_new,ERR_put_error,CRYPTO_free,OPENSSL_LH_new,OPENSSL_sk_num,EVP_get_digestbyname,EVP_get_digestbyname,OPENSSL_sk_new_null,OPENSSL_sk_new_null,CRYPTO_new_ex_data,RAND_bytes,RAND_priv_bytes,RAND_priv_bytes,RAND_priv_bytes, 2_2_00007FFDFA001BFE
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA05AA8C CRYPTO_free,CRYPTO_memdup, 2_2_00007FFDFA05AA8C
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00EB00 EVP_MD_CTX_md,EVP_MD_size,CRYPTO_memcmp,EVP_MD_CTX_md,EVP_MD_CTX_md,EVP_MD_size,EVP_CIPHER_CTX_cipher,EVP_CIPHER_flags,EVP_CIPHER_CTX_cipher,EVP_CIPHER_flags,CRYPTO_memcmp, 2_2_00007FFDFA00EB00
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA04AB00 EVP_PKEY_get1_tls_encodedpoint,CRYPTO_free,EVP_PKEY_free, 2_2_00007FFDFA04AB00
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA02CB20 ERR_put_error,ERR_put_error,ERR_put_error,EVP_MD_size,ERR_put_error,ERR_put_error,ERR_put_error,CRYPTO_malloc,ERR_put_error,OPENSSL_sk_num,OPENSSL_sk_value,OPENSSL_sk_insert,ERR_put_error,EVP_PKEY_free,X509_get0_pubkey,X509_free,OPENSSL_sk_push,ERR_put_error,X509_free,ERR_put_error, 2_2_00007FFDFA02CB20
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA006B30 CRYPTO_zalloc,CRYPTO_free, 2_2_00007FFDFA006B30
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00254A CRYPTO_malloc,ERR_put_error,BIO_snprintf, 2_2_00007FFDFA00254A
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA002310 CRYPTO_free, 2_2_00007FFDFA002310
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001EAB CRYPTO_memcmp,memchr,CRYPTO_free,CRYPTO_free,CRYPTO_strndup, 2_2_00007FFDFA001EAB
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0017B7 CRYPTO_THREAD_write_lock,CRYPTO_THREAD_unlock, 2_2_00007FFDFA0017B7
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001230 memcpy,OPENSSL_LH_retrieve,CRYPTO_THREAD_unlock,memcmp,_time64, 2_2_00007FFDFA001230
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA02C870 CRYPTO_free,CRYPTO_free, 2_2_00007FFDFA02C870
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001F0A CRYPTO_malloc,memcpy,memcpy,memcmp,memcmp,memcmp,ERR_put_error,CRYPTO_clear_free, 2_2_00007FFDFA001F0A
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001B18 memset,OPENSSL_cleanse,CRYPTO_free,CRYPTO_memdup,OPENSSL_cleanse,CRYPTO_memcmp, 2_2_00007FFDFA001B18
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001F78 CRYPTO_strdup, 2_2_00007FFDFA001F78
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA04896F CRYPTO_malloc, 2_2_00007FFDFA04896F
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001CE4 CRYPTO_free,CRYPTO_free,CRYPTO_memdup, 2_2_00007FFDFA001CE4
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA02C960 ERR_put_error,CRYPTO_realloc,CRYPTO_realloc,ERR_put_error, 2_2_00007FFDFA02C960
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA01C990 CRYPTO_get_ex_new_index, 2_2_00007FFDFA01C990
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00109B CRYPTO_free,CRYPTO_memdup,CRYPTO_memdup, 2_2_00007FFDFA00109B
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0409F0 CRYPTO_free,CRYPTO_strndup, 2_2_00007FFDFA0409F0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA01C9F0 i2d_X509_NAME,i2d_X509_NAME,memcmp,CRYPTO_free,CRYPTO_free, 2_2_00007FFDFA01C9F0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA002252 BIO_s_file,BIO_new,BIO_ctrl,strncmp,strncmp,CRYPTO_realloc,memcpy,CRYPTO_free,CRYPTO_free,CRYPTO_free,PEM_read_bio,ERR_put_error,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,BIO_free, 2_2_00007FFDFA002252
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA058A00 CRYPTO_free,CRYPTO_strndup, 2_2_00007FFDFA058A00
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001D52 BN_num_bits,CRYPTO_malloc,BN_bn2bin,BN_clear_free,BN_clear_free, 2_2_00007FFDFA001D52
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA02AA24 ERR_put_error,CRYPTO_set_ex_data,CRYPTO_set_ex_data,COMP_CTX_get_method, 2_2_00007FFDFA02AA24
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA036E60 CRYPTO_free,CRYPTO_strdup,CRYPTO_free, 2_2_00007FFDFA036E60
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00191F ERR_put_error,memcpy,OPENSSL_sk_num,OPENSSL_sk_num,OPENSSL_sk_new_reserve,OPENSSL_sk_value,CRYPTO_dup_ex_data,X509_VERIFY_PARAM_inherit,OPENSSL_sk_dup,OPENSSL_sk_dup, 2_2_00007FFDFA00191F
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0018CF CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_memdup, 2_2_00007FFDFA0018CF
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001357 memcmp,memcmp,EVP_CIPHER_CTX_free,CRYPTO_free,CRYPTO_free,memcmp,memcmp,memcpy,CRYPTO_free,CRYPTO_free, 2_2_00007FFDFA001357
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001B4F CRYPTO_THREAD_write_lock,OPENSSL_LH_set_down_load,CRYPTO_THREAD_unlock, 2_2_00007FFDFA001B4F
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA002261 CRYPTO_zalloc,ERR_put_error, 2_2_00007FFDFA002261
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00228E CRYPTO_free, 2_2_00007FFDFA00228E
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001C2B EVP_CIPHER_key_length,EVP_CIPHER_iv_length,CRYPTO_malloc, 2_2_00007FFDFA001C2B
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA016CA5 CRYPTO_free,CRYPTO_strdup,ERR_put_error,ERR_put_error, 2_2_00007FFDFA016CA5
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA04ACD0 EVP_DigestUpdate,EVP_MD_CTX_free,EVP_PKEY_CTX_free,EVP_PKEY_CTX_free,CRYPTO_clear_free,EVP_MD_CTX_free, 2_2_00007FFDFA04ACD0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA048CDA CRYPTO_free,CRYPTO_free, 2_2_00007FFDFA048CDA
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA01ECC0 CRYPTO_THREAD_run_once,OPENSSL_sk_find,OPENSSL_sk_value,EVP_CIPHER_flags,EVP_get_cipherbyname,EVP_get_cipherbyname,EVP_get_cipherbyname,EVP_get_cipherbyname,EVP_get_cipherbyname, 2_2_00007FFDFA01ECC0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA058CC0 CRYPTO_malloc,CRYPTO_free,EVP_CIPHER_CTX_free,HMAC_CTX_free,CRYPTO_free,EVP_CIPHER_CTX_free,HMAC_CTX_free,RAND_bytes,EVP_sha256,EVP_EncryptUpdate,EVP_EncryptFinal,HMAC_Update,HMAC_Final, 2_2_00007FFDFA058CC0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001208 CRYPTO_zalloc,memcpy,memcpy,memcpy,CRYPTO_free,memcpy,CRYPTO_free,CRYPTO_free, 2_2_00007FFDFA001208
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA052CE0 EVP_CIPHER_CTX_free,EVP_MD_CTX_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,memset,memcpy,memcpy, 2_2_00007FFDFA052CE0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA032D10 CRYPTO_THREAD_write_lock,OPENSSL_LH_insert,OPENSSL_LH_retrieve,OPENSSL_LH_retrieve,OPENSSL_LH_delete,CRYPTO_THREAD_unlock, 2_2_00007FFDFA032D10
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA008D80 CRYPTO_malloc,ERR_put_error, 2_2_00007FFDFA008D80
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0019BA CRYPTO_malloc, 2_2_00007FFDFA0019BA
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA016DAB ERR_put_error,CRYPTO_free,CRYPTO_strdup, 2_2_00007FFDFA016DAB
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA036DF0 CRYPTO_free, 2_2_00007FFDFA036DF0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0015CD EVP_MD_CTX_new,EVP_PKEY_new,EVP_PKEY_assign,DH_free,EVP_PKEY_security_bits,EVP_PKEY_get0_DH,EVP_PKEY_free,DH_get0_key,EVP_PKEY_get1_tls_encodedpoint,EVP_PKEY_free,CRYPTO_free,EVP_MD_CTX_free,BN_num_bits,BN_num_bits,memset,BN_num_bits,BN_bn2bin,CRYPTO_free,EVP_PKEY_size,EVP_DigestSignInit,RSA_pkey_ctx_ctrl,RSA_pkey_ctx_ctrl,EVP_DigestSign,CRYPTO_free,EVP_MD_CTX_free, 2_2_00007FFDFA0015CD
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001D8E BN_copy,BN_free,BN_dup,BN_copy,BN_free,BN_dup,BN_copy,BN_free,BN_dup,BN_copy,BN_free,BN_dup,CRYPTO_free,CRYPTO_strdup, 2_2_00007FFDFA001D8E
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001EB5 CRYPTO_strdup,CRYPTO_free, 2_2_00007FFDFA001EB5
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0602A0 BN_bin2bn,BN_ucmp,BN_is_zero,CRYPTO_free,CRYPTO_strdup, 2_2_00007FFDFA0602A0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA002149 ERR_put_error,CRYPTO_realloc,CRYPTO_realloc,ERR_put_error, 2_2_00007FFDFA002149
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0019EC CRYPTO_malloc,ERR_put_error,CRYPTO_free, 2_2_00007FFDFA0019EC
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA040340 CRYPTO_memcmp, 2_2_00007FFDFA040340
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001ABE CONF_parse_list,CRYPTO_malloc,ERR_put_error,memcpy,CRYPTO_free,CRYPTO_free, 2_2_00007FFDFA001ABE
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA034370 OPENSSL_LH_retrieve,OPENSSL_LH_delete,CRYPTO_THREAD_unlock, 2_2_00007FFDFA034370
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001514 CRYPTO_free, 2_2_00007FFDFA001514
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA048397 CRYPTO_clear_free, 2_2_00007FFDFA048397
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0012E4 EVP_MD_size,RAND_bytes,_time64,CRYPTO_free,CRYPTO_memdup, 2_2_00007FFDFA0012E4
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA058420 CRYPTO_memcmp, 2_2_00007FFDFA058420
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA004443 CRYPTO_zalloc,ERR_put_error,BIO_set_init,BIO_set_data,BIO_clear_flags, 2_2_00007FFDFA004443
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA004064 BIO_get_data,BIO_get_init,BIO_clear_flags,BIO_set_init,CRYPTO_free,CRYPTO_zalloc,ERR_put_error,BIO_set_init,BIO_clear_flags,BIO_get_data,BIO_set_shutdown,BIO_push,BIO_set_next,BIO_up_ref,BIO_set_init, 2_2_00007FFDFA004064
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA040090 CRYPTO_free,CRYPTO_free, 2_2_00007FFDFA040090
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00215D CRYPTO_free,CRYPTO_malloc,RAND_bytes, 2_2_00007FFDFA00215D
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0160AA CRYPTO_free, 2_2_00007FFDFA0160AA
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA002116 CRYPTO_malloc, 2_2_00007FFDFA002116
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001BAE CRYPTO_free,CRYPTO_malloc, 2_2_00007FFDFA001BAE
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA022150 CRYPTO_free,CRYPTO_free,OPENSSL_sk_pop_free,CRYPTO_free, 2_2_00007FFDFA022150
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00225C CRYPTO_zalloc,CRYPTO_zalloc,OBJ_nid2sn,EVP_get_digestbyname,CRYPTO_free,CRYPTO_free,ERR_put_error, 2_2_00007FFDFA00225C
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001663 CRYPTO_malloc,ERR_put_error,CRYPTO_free,CRYPTO_free,CRYPTO_free, 2_2_00007FFDFA001663
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA018180 EVP_PKEY_CTX_new,EVP_PKEY_derive_init,EVP_PKEY_derive_set_peer,EVP_PKEY_derive,CRYPTO_malloc,EVP_PKEY_derive,CRYPTO_clear_free,EVP_PKEY_CTX_free, 2_2_00007FFDFA018180
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0341B0 memcpy,CRYPTO_THREAD_read_lock,OPENSSL_LH_retrieve,CRYPTO_THREAD_unlock, 2_2_00007FFDFA0341B0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0141B0 CRYPTO_clear_free, 2_2_00007FFDFA0141B0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA050200 CRYPTO_free,CRYPTO_free,CRYPTO_strndup, 2_2_00007FFDFA050200
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA03A250 EVP_PKEY_get1_tls_encodedpoint,CRYPTO_free,EVP_PKEY_free,CRYPTO_free, 2_2_00007FFDFA03A250
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA004660 BIO_get_data,BIO_get_shutdown,BIO_get_init,BIO_clear_flags,BIO_set_init,CRYPTO_free, 2_2_00007FFDFA004660
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA02C6D0 CRYPTO_zalloc,CRYPTO_zalloc,OBJ_nid2sn,EVP_get_digestbyname,CRYPTO_free,CRYPTO_free,ERR_put_error, 2_2_00007FFDFA02C6D0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0016B8 OPENSSL_sk_new_null,d2i_X509,CRYPTO_free,OPENSSL_sk_push,CRYPTO_free,ERR_clear_error,OPENSSL_sk_value,X509_get0_pubkey,EVP_PKEY_missing_parameters,X509_free,X509_up_ref,X509_free,OPENSSL_sk_pop_free, 2_2_00007FFDFA0016B8
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA01A710 CRYPTO_THREAD_run_once, 2_2_00007FFDFA01A710
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001B9A CRYPTO_free,CRYPTO_malloc, 2_2_00007FFDFA001B9A
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA040740 CRYPTO_free,CRYPTO_memdup, 2_2_00007FFDFA040740
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001519 CRYPTO_malloc,ERR_put_error,memcpy,CRYPTO_free,ERR_put_error,ERR_put_error,ERR_put_error,memcpy, 2_2_00007FFDFA001519
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001AB9 CRYPTO_free, 2_2_00007FFDFA001AB9
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001249 CRYPTO_zalloc,ERR_put_error,_time64,CRYPTO_THREAD_lock_new,ERR_put_error,CRYPTO_free,CRYPTO_THREAD_lock_free,CRYPTO_THREAD_read_lock,CRYPTO_THREAD_read_lock,CRYPTO_THREAD_unlock,CRYPTO_THREAD_unlock,memset,memcpy, 2_2_00007FFDFA001249
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0587E0 CRYPTO_free,CRYPTO_memdup, 2_2_00007FFDFA0587E0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001E60 CRYPTO_clear_free, 2_2_00007FFDFA001E60
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001500 CRYPTO_memdup,ERR_put_error,CRYPTO_free,CRYPTO_free, 2_2_00007FFDFA001500
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0024D7 OPENSSL_sk_new_null,d2i_X509,CRYPTO_free,OPENSSL_sk_push,OPENSSL_sk_num,CRYPTO_memcmp,CRYPTO_free,X509_free,OPENSSL_sk_pop_free,OPENSSL_sk_value,X509_get0_pubkey,X509_free,OPENSSL_sk_shift,OPENSSL_sk_pop_free, 2_2_00007FFDFA0024D7
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA002513 CRYPTO_free, 2_2_00007FFDFA002513
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0017D5 CRYPTO_malloc,memcpy, 2_2_00007FFDFA0017D5
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0084E0 CRYPTO_zalloc,ERR_put_error, 2_2_00007FFDFA0084E0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA034530 CRYPTO_THREAD_read_lock,CRYPTO_THREAD_read_lock,CRYPTO_THREAD_unlock,CRYPTO_THREAD_unlock,memset, 2_2_00007FFDFA034530
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA052530 EVP_CIPHER_CTX_free,EVP_MD_CTX_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,memcpy, 2_2_00007FFDFA052530
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA008590 CRYPTO_zalloc,ERR_put_error,BUF_MEM_grow, 2_2_00007FFDFA008590
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0185D0 CRYPTO_malloc,memset,memcpy,memcpy,CRYPTO_clear_free,CRYPTO_clear_free,CRYPTO_clear_free,CRYPTO_clear_free,OPENSSL_cleanse, 2_2_00007FFDFA0185D0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001F9B CRYPTO_free,BIO_clear_flags,BIO_set_flags,BIO_snprintf,ERR_add_error_data,memcpy, 2_2_00007FFDFA001F9B
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0385F0 CRYPTO_zalloc,CRYPTO_free, 2_2_00007FFDFA0385F0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0245E0 X509_VERIFY_PARAM_free,CRYPTO_free,CRYPTO_free,CRYPTO_free_ex_data,OPENSSL_LH_free,X509_STORE_free,CTLOG_STORE_free,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,OPENSSL_sk_free,ENGINE_finish,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_secure_free,CRYPTO_THREAD_lock_free,CRYPTO_free, 2_2_00007FFDFA0245E0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0E0C30 ??0QUrl@@QEAA@AEBV0@@Z,??0QString@@QEAA@XZ,?setPassword@QUrl@@QEAAXAEBVQString@@W4ParsingMode@1@@Z,??1QString@@QEAA@XZ,??0QString@@QEAA@XZ,?setFragment@QUrl@@QEAAXAEBVQString@@W4ParsingMode@1@@Z,??1QString@@QEAA@XZ,??0QCryptographicHash@@QEAA@W4Algorithm@0@@Z,?toEncoded@QUrl@@QEBA?AVQByteArray@@V?$QUrlTwoFlags@W4UrlFormattingOption@QUrl@@W4ComponentFormattingOption@2@@@@Z,?addData@QCryptographicHash@@QEAAXAEBVQByteArray@@@Z,??1QByteArray@@QEAA@XZ,?result@QCryptographicHash@@QEBA?AVQByteArray@@XZ,?data@QString@@QEBAPEBVQChar@@XZ,?number@QByteArray@@SA?AV1@_JH@Z,?left@QByteArray@@QEBA?AV1@H@Z,??1QByteArray@@QEAA@XZ,??1QByteArray@@QEAA@XZ,?size@QString@@QEBAHXZ,?at@QByteArray@@QEBADH@Z,?size@QString@@QEBAHXZ,?data@QString@@QEBAPEBVQChar@@XZ,?data@QString@@QEBAPEBVQChar@@XZ,?number@QString@@SA?AV1@IH@Z,?size@QString@@QEBAHXZ,??0QString@@QEAA@HW4Initialization@Qt@@@Z,?data@QString@@QEBAPEBVQChar@@XZ,?size@QString@@QEBAHXZ,?data@QString@@QEBAPEBVQChar@@XZ,memmove,??0QChar@@QEAA@UQLatin1Char@@@Z,?appendLatin1To@QAbstractConcatenable@@KAXPEBDHPEAVQChar@@@Z,?appendLatin1To@QAbstractConcatenable@@KAXPEBDHPEAVQChar@@@Z,??1QString@@QEAA@XZ,??1QByteArray@@QEAA@XZ,??1QCryptographicHash@@QEAA@XZ,??1QUrl@@QEAA@XZ, 2_2_00007FFDFA0E0C30
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA12A940 ??0QCryptographicHash@@QEAA@W4Algorithm@0@@Z,??0QString@@QEAA@XZ,??0QByteArray@@QEAA@HD@Z,??0QByteArray@@QEAA@HD@Z,?reset@QCryptographicHash@@QEAAXXZ,?size@QString@@QEBAHXZ,?addData@QCryptographicHash@@QEAAXAEBVQByteArray@@@Z,?result@QCryptographicHash@@QEBA?AVQByteArray@@XZ,??4QDateTime@@QEAAAEAV0@$$QEAV0@@Z,??1QByteArray@@QEAA@XZ,?leftJustified@QByteArray@@QEBA?AV1@HD_N@Z,??4QDateTime@@QEAAAEAV0@$$QEAV0@@Z,??1QByteArray@@QEAA@XZ,?size@QString@@QEBAHXZ,??AQByteArray@@QEAA?AVQByteRef@@H@Z,??BQByteRef@@QEBADXZ,??AQByteArray@@QEAA?AVQByteRef@@H@Z,??BQByteRef@@QEBADXZ,??AQByteArray@@QEAA?AVQByteRef@@H@Z,??4QByteRef@@QEAAAEAV0@D@Z,?size@QString@@QEBAHXZ,?size@QString@@QEBAHXZ,??AQByteArray@@QEAA?AVQByteRef@@H@Z,??BQByteRef@@QEBADXZ,??AQByteArray@@QEAA?AVQByteRef@@H@Z,??BQByteRef@@QEBADXZ,??AQByteArray@@QEAA?AVQByteRef@@H@Z,??4QByteRef@@QEAAAEAV0@D@Z,?size@QString@@QEBAHXZ,?append@QByteArray@@QEAAAEAV1@AEBV1@@Z,?reset@QCryptographicHash@@QEAAXXZ,?addData@QCryptographicHash@@QEAAXAEBVQByteArray@@@Z,?result@QCryptographicHash@@QEBA?AVQByteArray@@XZ,??4QDateTime@@QEAAAEAV0@$$QEAV0@@Z,??1QByteArray@@QEAA@XZ,??0QString@@QEAA@XZ,?append@QByteArray@@QEAAAEAV1@AEBV1@@Z,?reset@QCryptographicHash@@QEAAXXZ,?addData@QCryptographicHash@@QEAAXAEBVQByteArray@@@Z,?result@QCryptographicHash@@QEBA?AVQByteArray@@XZ,??4QDateTime@@QEAAAEAV0@$$QEAV0@@Z,??1QByteArray@@QEAA@XZ,??1QByteArray@@QEAA@XZ,??1QByteArray@@QEAA@XZ,??1QByteArray@@QEAA@XZ,??1QCryptographicHash@@QEAA@XZ, 2_2_00007FFDFA12A940
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA1293C0 ??0QCryptographicHash@@QEAA@W4Algorithm@0@@Z,?addData@QCryptographicHash@@QEAAXAEBVQByteArray@@@Z,?addData@QCryptographicHash@@QEAAXPEBDH@Z,?addData@QCryptographicHash@@QEAAXAEBVQByteArray@@@Z,?addData@QCryptographicHash@@QEAAXPEBDH@Z,?addData@QCryptographicHash@@QEAAXAEBVQByteArray@@@Z,?result@QCryptographicHash@@QEBA?AVQByteArray@@XZ,?compare@QByteArray@@QEBAHPEBDW4CaseSensitivity@Qt@@@Z,?reset@QCryptographicHash@@QEAAXXZ,?toHex@QByteArray@@QEBA?AV1@XZ,?addData@QCryptographicHash@@QEAAXAEBVQByteArray@@@Z,??1QByteArray@@QEAA@XZ,?addData@QCryptographicHash@@QEAAXPEBDH@Z,?addData@QCryptographicHash@@QEAAXAEBVQByteArray@@@Z,?addData@QCryptographicHash@@QEAAXPEBDH@Z,?addData@QCryptographicHash@@QEAAXAEBVQByteArray@@@Z,?result@QCryptographicHash@@QEBA?AVQByteArray@@XZ,??4QDateTime@@QEAAAEAV0@$$QEAV0@@Z,??1QByteArray@@QEAA@XZ,?toHex@QByteArray@@QEBA?AV1@XZ,??4QDateTime@@QEAAAEAV0@$$QEAV0@@Z,??1QByteArray@@QEAA@XZ,?reset@QCryptographicHash@@QEAAXXZ,?addData@QCryptographicHash@@QEAAXAEBVQByteArray@@@Z,?addData@QCryptographicHash@@QEAAXPEBDH@Z,?addData@QCryptographicHash@@QEAAXAEBVQByteArray@@@Z,?compare@QByteArray@@QEBAHPEBDW4CaseSensitivity@Qt@@@Z,?addData@QCryptographicHash@@QEAAXPEBDH@Z,?addData@QCryptographicHash@@QEAAXAEBVQByteArray@@@Z,?result@QCryptographicHash@@QEBA?AVQByteArray@@XZ,?toHex@QByteArray@@QEBA?AV1@XZ,??1QByteArray@@QEAA@XZ,?reset@QCryptographicHash@@QEAAXXZ,?addData@QCryptographicHash@@QEAAXAEBVQByteArray@@@Z,?addData@QCryptographicHash@@QEAAXPEBDH@Z,?addData@QCryptographicHash@@QEAAXAEBVQByteArray@@@Z,?addData@QCryptographicHash@@QEAAXPEBDH@Z,?isNull@QByteArray@@QEBA_NXZ,?addData@QCryptographicHash@@QEAAXAEBVQByteArray@@@Z,?addData@QCryptographicHash@@QEAAXPEBDH@Z,?addData@QCryptographicHash@@QEAAXAEBVQByteArray@@@Z,?addData@QCryptographicHash@@QEAAXPEBDH@Z,?addData@QCryptographicHash@@QEAAXAEBVQByteArray@@@Z,?addData@QCryptographicHash@@QEAAXPEBDH@Z,?addData@QCryptographicHash@@QEAAXAEBVQByteArray@@@Z,?result@QCryptographicHash@@QEBA?AVQByteArray@@XZ,?toHex@QByteArray@@QEBA?AV1@XZ,??1QByteArray@@QEAA@XZ,??1QByteArray@@QEAA@XZ,??1QByteArray@@QEAA@XZ,??1QCryptographicHash@@QEAA@XZ, 2_2_00007FFDFA1293C0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA128150 ??0QString@@QEAA@XZ,??0QString@@QEAA@XZ,??0QString@@QEAA@XZ,?shared_null@QHashData@@2U1@B,??0QString@@QEAA@XZ,??0QString@@QEAA@XZ,??0QString@@QEAA@XZ,??0QString@@QEAA@XZ,??0QString@@QEAA@XZ,?system@QRandomGenerator64@@SAPEAV1@XZ,?_fillRange@QRandomGenerator@@AEAAXPEAX0@Z,?number@QByteArray@@SA?AV1@_KH@Z,?hash@QCryptographicHash@@SA?AVQByteArray@@AEBV2@W4Algorithm@1@@Z,?toHex@QByteArray@@QEBA?AV1@XZ,??4QDateTime@@QEAAAEAV0@$$QEAV0@@Z,??1QByteArray@@QEAA@XZ,??1QByteArray@@QEAA@XZ,??1QByteArray@@QEAA@XZ, 2_2_00007FFDFA128150
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA12A7C0 ?size@QString@@QEBAHXZ,??0QCryptographicHash@@QEAA@W4Algorithm@0@@Z,?size@QString@@QEBAHXZ,?begin@QByteArray@@QEAAPEADXZ,?addData@QCryptographicHash@@QEAAXPEBDH@Z,?result@QCryptographicHash@@QEBA?AVQByteArray@@XZ,?toUpper@QString@@QEGBA?AV1@XZ,??0QByteArray@@QEAA@AEBV0@@Z,??YQByteArray@@QEAAAEAV0@AEBV0@@Z,??1QByteArray@@QEAA@XZ,??1QString@@QEAA@XZ,??1QByteArray@@QEAA@XZ,??4QDateTime@@QEAAAEAV0@$$QEAV0@@Z,??1QByteArray@@QEAA@XZ,??1QByteArray@@QEAA@XZ,??1QByteArray@@QEAA@XZ,??1QByteArray@@QEAA@XZ,??1QCryptographicHash@@QEAA@XZ,??0QByteArray@@QEAA@AEBV0@@Z, 2_2_00007FFDFA12A7C0
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: -----BEGIN PUBLIC KEY----- memstr_f54c6137-d
Source: 4OVYJHCTFA.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\msvcp140.amd64.pdb source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002F63000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1659971608.00007FFDFAF96000.00000002.00000001.01000000.0000000C.sdmp, EASteamProxy.exe, 00000002.00000002.1693873503.00007FFDFA536000.00000002.00000001.01000000.00000013.sdmp
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\msvcp140.amd64.pdbGCTL source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002F63000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1659971608.00007FFDFAF96000.00000002.00000001.01000000.0000000C.sdmp, EASteamProxy.exe, 00000002.00000002.1693873503.00007FFDFA536000.00000002.00000001.01000000.00000013.sdmp
Source: Binary string: @ compiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PICOpenSSL 1.1.1s 1 Nov 2022built on: Fri Feb 3 01:12:04 2023 UTCplatform: VC-WIN64AOPENSSLDIR: "C:\Program Files\Common Files\SSL"ENGINESDIR: "D:\juno\p4\desktop\packages\openSSL\1.1.1s\installed\dist\pc64_dll_release\lib\engines-1_1"not available source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002DFA000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1660437574.00007FFDFB193000.00000002.00000001.01000000.0000000A.sdmp, EASteamProxy.exe, 00000002.00000002.1693576225.00007FFDFA3D3000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\msvcp140_1.amd64.pdb source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002F63000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1662343914.00007FFE130C3000.00000002.00000001.01000000.0000000E.sdmp, EASteamProxy.exe, 00000002.00000002.1694524165.00007FFE126D3000.00000002.00000001.01000000.00000019.sdmp
Source: Binary string: wntdll.pdbUGP source: cmd.exe, 00000003.00000002.1924825717.00000000052B0000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1925067473.0000000005720000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: D:\juno\p4\desktop\packages\openSSL\1.1.1s\installed\source\libcrypto-1_1-x64.pdb source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002E7C000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1660437574.00007FFDFB215000.00000002.00000001.01000000.0000000A.sdmp, EASteamProxy.exe, 00000002.00000002.1693576225.00007FFDFA455000.00000002.00000001.01000000.00000015.sdmp, EASteamProxy.exe, 00000005.00000002.1773030063.00007FFDFB435000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: ntdll.pdbUGP source: EASteamProxy.exe, 00000001.00000002.1658752702.0000023839E30000.00000004.00000800.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1658587407.0000023839A3A000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692224582.0000024614F7C000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692548057.0000024615570000.00000004.00000001.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692366674.0000024615370000.00000004.00000800.00020000.00000000.sdmp, EASteamProxy.exe, 00000005.00000002.1771581420.00000257755F7000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000005.00000002.1771917334.0000025775BF6000.00000004.00000001.00020000.00000000.sdmp
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\msvcp140_1.amd64.pdbGCTL source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002F63000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1662343914.00007FFE130C3000.00000002.00000001.01000000.0000000E.sdmp, EASteamProxy.exe, 00000002.00000002.1694524165.00007FFE126D3000.00000002.00000001.01000000.00000019.sdmp
Source: Binary string: wntdll.pdb source: cmd.exe, 00000003.00000002.1924825717.00000000052B0000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1925067473.0000000005720000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: Q:\build\qt\qtbase\lib\Qt5Core.pdb source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000034C8000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1660898119.00007FFDFB73C000.00000002.00000001.01000000.00000006.sdmp, EASteamProxy.exe, 00000002.00000002.1694121588.00007FFDFAA0C000.00000002.00000001.01000000.00000011.sdmp, EASteamProxy.exe, 00000005.00000002.1773451655.00007FFDFB95C000.00000002.00000001.01000000.00000011.sdmp
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdb source: 4OVYJHCTFA.exe, 00000000.00000003.1647120752.0000000000660000.00000004.00001000.00020000.00000000.sdmp, 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1662897785.00007FFE13311000.00000002.00000001.01000000.00000008.sdmp, EASteamProxy.exe, 00000002.00000002.1694632093.00007FFE126F1000.00000002.00000001.01000000.00000014.sdmp
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdbGCTL source: 4OVYJHCTFA.exe, 00000000.00000003.1647120752.0000000000660000.00000004.00001000.00020000.00000000.sdmp, 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1662897785.00007FFE13311000.00000002.00000001.01000000.00000008.sdmp, EASteamProxy.exe, 00000002.00000002.1694632093.00007FFE126F1000.00000002.00000001.01000000.00000014.sdmp
Source: Binary string: FatalErrorWarningDebugassert.report.fatalassert.report.errorassert.report.warningassert.report.debugassert.report.unknownasserts already initializedeax::foundation::initAssertionssAssertFailureFn == nullptr.pdb source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000000.1649950475.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000001.00000002.1659294593.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000002.00000002.1692951141.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000002.00000000.1657354262.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000005.00000002.1772426207.00007FF642825000.00000002.00000001.01000000.00000010.sdmp
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdb source: 4OVYJHCTFA.exe, 00000000.00000003.1647120752.0000000000660000.00000004.00001000.00020000.00000000.sdmp, 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1663012636.00007FFE148E5000.00000002.00000001.01000000.00000009.sdmp, EASteamProxy.exe, 00000002.00000002.1694701423.00007FFE12E15000.00000002.00000001.01000000.00000016.sdmp, EASteamProxy.exe, 00000005.00000002.1774511818.00007FFE148E5000.00000002.00000001.01000000.00000016.sdmp
Source: Binary string: compiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002DFA000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1660437574.00007FFDFB193000.00000002.00000001.01000000.0000000A.sdmp, EASteamProxy.exe, 00000002.00000002.1693576225.00007FFDFA3D3000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: .pdb.map.___> => > source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000000.1649950475.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000001.00000002.1659294593.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000002.00000002.1692951141.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000002.00000000.1657354262.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000005.00000002.1772426207.00007FF642825000.00000002.00000001.01000000.00000010.sdmp
Source: Binary string: D:\juno\p4\desktop\packages\openSSL\1.1.1s\installed\source\libssl-1_1-x64.pdb source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002F63000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1659739933.00007FFDFAF04000.00000002.00000001.01000000.0000000D.sdmp, EASteamProxy.exe, 00000002.00000002.1693179150.00007FFDFA074000.00000002.00000001.01000000.00000018.sdmp, EASteamProxy.exe, 00000005.00000002.1773874761.00007FFDFF244000.00000002.00000001.01000000.00000018.sdmp
Source: Binary string: ntdll.pdb source: EASteamProxy.exe, 00000001.00000002.1658752702.0000023839E30000.00000004.00000800.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1658587407.0000023839A3A000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692224582.0000024614F7C000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692548057.0000024615570000.00000004.00000001.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692366674.0000024615370000.00000004.00000800.00020000.00000000.sdmp, EASteamProxy.exe, 00000005.00000002.1771581420.00000257755F7000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000005.00000002.1771917334.0000025775BF6000.00000004.00000001.00020000.00000000.sdmp
Source: Binary string: Q:\build\qt\qtbase\lib\Qt5Network.pdb source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1661868306.00007FFDFF298000.00000002.00000001.01000000.0000000B.sdmp, EASteamProxy.exe, 00000002.00000002.1693336663.00007FFDFA198000.00000002.00000001.01000000.00000017.sdmp, EASteamProxy.exe, 00000005.00000002.1772708477.00007FFDFB178000.00000002.00000001.01000000.00000017.sdmp
Source: Binary string: C:\jenkins\workspace\dev\juno-win_live\build\eaSteamProxy\pc64-vc-tool-opt\bin\EASteamProxy.pdb source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000000.1649950475.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000001.00000002.1659294593.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000002.00000002.1692951141.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000002.00000000.1657354262.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000005.00000002.1772426207.00007FF642825000.00000002.00000001.01000000.00000010.sdmp
Source: Binary string: C:\jenkins\workspace\dev\juno-win_live\build\eaSteamProxy\pc64-vc-tool-opt\bin\EASteamProxy.pdbc source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000000.1649950475.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000001.00000002.1659294593.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000002.00000002.1692951141.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000002.00000000.1657354262.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000005.00000002.1772426207.00007FF642825000.00000002.00000001.01000000.00000010.sdmp
Source: Binary string: D:\juno\p4\desktop\packages\openSSL\1.1.1s\installed\source\libssl-1_1-x64.pdb?? source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002F63000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1659739933.00007FFDFAF04000.00000002.00000001.01000000.0000000D.sdmp, EASteamProxy.exe, 00000002.00000002.1693179150.00007FFDFA074000.00000002.00000001.01000000.00000018.sdmp, EASteamProxy.exe, 00000005.00000002.1773874761.00007FFDFF244000.00000002.00000001.01000000.00000018.sdmp
Source: Binary string: c:\buildslave\steam_rel_client_win64\build\src\steam_api\win64\Release\steam_api64.pdb source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1662495748.00007FFE13227000.00000002.00000001.01000000.00000007.sdmp, EASteamProxy.exe, 00000002.00000002.1694444874.00007FFE11EC7000.00000002.00000001.01000000.00000012.sdmp, EASteamProxy.exe, 00000005.00000002.1774299159.00007FFE13227000.00000002.00000001.01000000.00000012.sdmp
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdbGCTL source: 4OVYJHCTFA.exe, 00000000.00000003.1647120752.0000000000660000.00000004.00001000.00020000.00000000.sdmp, 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1663012636.00007FFE148E5000.00000002.00000001.01000000.00000009.sdmp, EASteamProxy.exe, 00000002.00000002.1694701423.00007FFE12E15000.00000002.00000001.01000000.00000016.sdmp, EASteamProxy.exe, 00000005.00000002.1774511818.00007FFE148E5000.00000002.00000001.01000000.00000016.sdmp
Source: Binary string: Q:\build\qt\qtbase\lib\Qt5Core.pdbT source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000034C8000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1660898119.00007FFDFB73C000.00000002.00000001.01000000.00000006.sdmp, EASteamProxy.exe, 00000002.00000002.1694121588.00007FFDFAA0C000.00000002.00000001.01000000.00000011.sdmp, EASteamProxy.exe, 00000005.00000002.1773451655.00007FFDFB95C000.00000002.00000001.01000000.00000011.sdmp
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Code function: 0_2_0040301A GetFileAttributesW,SetLastError,FindFirstFileW,FindClose,CompareFileTime, 0_2_0040301A
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Code function: 0_2_00402B79 FindFirstFileW,SetFileAttributesW,lstrcmpW,lstrcmpW,SetFileAttributesW,DeleteFileW,FindNextFileW,FindClose,SetFileAttributesW,RemoveDirectoryW,??3@YAXPAX@Z,??3@YAXPAX@Z, 0_2_00402B79
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF4A260 FindFirstFileExW,FindClose,wcscpy_s,_invalid_parameter_noinfo_noreturn, 1_2_00007FFDFAF4A260

Networking

barindex
Source: Malware configuration extractor URLs: facilitycoursedw.shop
Source: Malware configuration extractor URLs: doughtdrillyksow.shop
Source: Malware configuration extractor URLs: disappointcredisotw.shop
Source: Malware configuration extractor URLs: bargainnygroandjwk.shop
Source: Malware configuration extractor URLs: injurypiggyoewirog.shop
Source: Malware configuration extractor URLs: leafcalfconflcitw.shop
Source: Malware configuration extractor URLs: computerexcudesp.shop
Source: Malware configuration extractor URLs: publicitycharetew.shop
Source: Malware configuration extractor URLs: periodicroytewrsn.shop
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1661868306.00007FFDFF298000.00000002.00000001.01000000.0000000B.sdmp, EASteamProxy.exe, 00000002.00000002.1693336663.00007FFDFA198000.00000002.00000001.01000000.00000017.sdmp String found in binary or memory: 04:7e:cb:e9:fc:a5:5f:7b:d0:9e:ae:36:e1:0c:ae:1email.google.comf5:c8:6a:f3:61:62:f1:3a:64:f5:4f:6d:c9:58:7c:06www.google.comd7:55:8f:da:f5:f1:10:5b:b2:13:28:2b:70:77:29:a3login.yahoo.com39:2a:43:4f:0e:07:df:1f:8a:a3:05:de:34:e0:c2:293e:75:ce:d4:6b:69:30:21:21:88:30:ae:86:a8:2a:71e9:02:8b:95:78:e4:15:dc:1a:71:0a:2b:88:15:44:47login.skype.com92:39:d5:34:8f:40:d1:69:5a:74:54:70:e1:f2:3f:43addons.mozilla.orgb0:b7:13:3e:d0:96:f9:b5:6f:ae:91:c8:74:bd:3a:c0login.live.comd8:f3:5f:4e:b7:87:2b:2d:ab:06:92:e3:15:38:2f:b0global trustee05:e2:e6:a4:cd:09:ea:54:d6:65:b0:75:fe:22:a2:56*.google.com0c:76:da:9c:91:0c:4e:2c:9e:fe:15:d0:58:93:3c:4cDigiNotar Root CAf1:4a:13:f4:87:2b:56:dc:39:df:84:ca:7a:a1:06:49DigiNotar Services CA36:16:71:55:43:42:1b:9d:e6:cb:a3:64:41:df:24:38DigiNotar Services 1024 CA0a:82:bd:1e:14:4e:88:14:d7:5b:1a:55:27:be:bf:3eDigiNotar Root CA G2a4:b6:ce:e3:2e:d3:35:46:26:3c:b3:55:3a:a8:92:21CertiID Enterprise Certificate Authority5b:d5:60:9c:64:17:68:cf:21:0e:35:fd:fb:05:ad:41DigiNotar Qualified CA46:9c:2c:b007:27:10:0dDigiNotar Cyber CA07:27:0f:f907:27:10:0301:31:69:b0DigiNotar PKIoverheid CA Overheid en Bedrijven01:31:34:bfDigiNotar PKIoverheid CA Organisatie - G2d6:d0:29:77:f1:49:fd:1a:83:f2:b9:ea:94:8c:5c:b4DigiNotar Extended Validation CA1e:7d:7a:53:3d:45:30:41:96:40:0f:71:48:1f:45:04DigiNotar Public CA 202546:9c:2c:af46:9c:3c:c907:27:14:a9Digisign Server ID (Enrich)4c:0e:63:6aDigisign Server ID - (Enrich)72:03:21:05:c5:0c:08:57:3d:8e:a5:30:4e:fe:e8:b0UTN-USERFirst-Hardware41MD5 Collisions Inc. (http://www.phreedom.org/md5)08:27*.EGO.GOV.TR08:64e-islem.kktcmerkezbankasi.org03:1d:a7AC DG Tr equals www.yahoo.com (Yahoo)
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1661868306.00007FFDFF298000.00000002.00000001.01000000.0000000B.sdmp, EASteamProxy.exe, 00000002.00000002.1693336663.00007FFDFA198000.00000002.00000001.01000000.00000017.sdmp, EASteamProxy.exe, 00000005.00000002.1772708477.00007FFDFB178000.00000002.00000001.01000000.00000017.sdmp String found in binary or memory: http://bugreports.qt.io/
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1661868306.00007FFDFF298000.00000002.00000001.01000000.0000000B.sdmp, EASteamProxy.exe, 00000002.00000002.1693336663.00007FFDFA198000.00000002.00000001.01000000.00000017.sdmp, EASteamProxy.exe, 00000005.00000002.1772708477.00007FFDFB178000.00000002.00000001.01000000.00000017.sdmp String found in binary or memory: http://bugreports.qt.io/_q_receiveReplyensureClientPrefaceSentMicrosoft-IIS/4.Microsoft-IIS/5.Netsca
Source: EASteamProxy.exe, 00000005.00000002.1771379374.00000257752D0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://c0rl.m%L
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDCA-1.crt0
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDCodeSigningCA-1.crt0
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002BE4000.00000004.00000020.00020000.00000000.sdmp, 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002BE4000.00000004.00000020.00020000.00000000.sdmp, 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002BE4000.00000004.00000020.00020000.00000000.sdmp, 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002BE4000.00000004.00000020.00020000.00000000.sdmp, 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
Source: EASteamProxy.exe, 00000001.00000002.1658340322.0000023839710000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692036205.0000024614C50000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000005.00000002.1771379374.00000257752D0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.co(m/D
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDCA-1.crl08
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002BE4000.00000004.00000020.00020000.00000000.sdmp, 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0:
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002BE4000.00000004.00000020.00020000.00000000.sdmp, 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002BE4000.00000004.00000020.00020000.00000000.sdmp, 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/assured-cs-g1.crl00
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDCA-1.crl0w
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002BE4000.00000004.00000020.00020000.00000000.sdmp, 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://crl4.digicert.com/assured-cs-g1.crl0L
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000000.1649950475.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000001.00000002.1659294593.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000002.00000002.1692951141.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000002.00000000.1657354262.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000005.00000002.1772426207.00007FF642825000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://dm.origin.com/
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000000.1649950475.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000001.00000002.1659294593.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000002.00000002.1692951141.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000002.00000000.1657354262.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000005.00000002.1772426207.00007FF642825000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: http://dm.origin.com/app.httpProxydevUsing
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002BE4000.00000004.00000020.00020000.00000000.sdmp, 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.digicert.com0
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002BE4000.00000004.00000020.00020000.00000000.sdmp, 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://ocsp.digicert.com0A
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002BE4000.00000004.00000020.00020000.00000000.sdmp, 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://ocsp.digicert.com0C
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://ocsp.digicert.com0L
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://ocsp.digicert.com0O
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002BE4000.00000004.00000020.00020000.00000000.sdmp, 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.digicert.com0X
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://s1.symcb.com/pca3-g5.crl0
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://s2.symcb.com0
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://sv.symcb.com/sv.crl0a
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://sv.symcb.com/sv.crt0
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://sv.symcd.com0&
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002BE4000.00000004.00000020.00020000.00000000.sdmp, 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.digicert.com/CPS0
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.digicert.com/ssl-cps-repository.htm0
Source: EASteamProxy.exe, 00000001.00000002.1658471064.0000023839919000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614E5E000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.0000000005617000.00000004.00000800.00020000.00000000.sdmp, EASteamProxy.exe, 00000005.00000002.1771488189.00000257754DF000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.info-zip.org/
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1661868306.00007FFDFF298000.00000002.00000001.01000000.0000000B.sdmp, EASteamProxy.exe, 00000002.00000002.1693336663.00007FFDFA198000.00000002.00000001.01000000.00000017.sdmp, EASteamProxy.exe, 00000005.00000002.1772708477.00007FFDFB178000.00000002.00000001.01000000.00000017.sdmp String found in binary or memory: http://www.phreedom.org/md5)
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1661868306.00007FFDFF298000.00000002.00000001.01000000.0000000B.sdmp, EASteamProxy.exe, 00000002.00000002.1693336663.00007FFDFA198000.00000002.00000001.01000000.00000017.sdmp, EASteamProxy.exe, 00000005.00000002.1772708477.00007FFDFB178000.00000002.00000001.01000000.00000017.sdmp String found in binary or memory: http://www.phreedom.org/md5)08:27
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.symauth.com/cps0(
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.symauth.com/rpa00
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.vmware.com/0
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.vmware.com/0/
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://d.symcb.com/cps0%
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://d.symcb.com/rpa0
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000000.1649950475.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000001.00000002.1659294593.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000002.00000002.1692951141.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000002.00000000.1657354262.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000005.00000002.1772426207.00007FF642825000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: https://github.com/netty/netty/issues/6520.
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000000.1649950475.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000001.00000002.1659294593.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000002.00000002.1692951141.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000002.00000000.1657354262.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000005.00000002.1772426207.00007FF642825000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: https://github.com/netty/netty/issues/6520.s
Source: EASteamProxy.exe, 00000005.00000002.1772426207.00007FF642825000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: https://ps3.scedev.net/
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000000.1649950475.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000001.00000002.1659294593.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000002.00000002.1692951141.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000002.00000000.1657354262.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000005.00000002.1772426207.00007FF642825000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: https://statsigapi.net
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000000.1649950475.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000001.00000002.1659294593.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000002.00000002.1692951141.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000002.00000000.1657354262.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000005.00000002.1772426207.00007FF642825000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: https://statsigapi.net/v1/initializeeax::apps::experimentation::loadFeatureGateseax::apps::experimen
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000000.1649950475.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000001.00000002.1659294593.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000002.00000002.1692951141.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000002.00000000.1657354262.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000005.00000002.1772426207.00007FF642825000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: https://store.steampowered.com/app/
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000000.1649950475.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000001.00000002.1659294593.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000002.00000002.1692951141.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000002.00000000.1657354262.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000005.00000002.1772426207.00007FF642825000.00000002.00000001.01000000.00000010.sdmp String found in binary or memory: https://store.steampowered.com/app/User
Source: EASteamProxy.exe, 00000001.00000002.1658471064.000002383996F000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692143846.0000024614EB4000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.digicert.com/CPS0
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002EE5000.00000004.00000020.00020000.00000000.sdmp, 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002F63000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1659817107.00007FFDFAF39000.00000002.00000001.01000000.0000000D.sdmp, EASteamProxy.exe, 00000001.00000002.1660590275.00007FFDFB28A000.00000002.00000001.01000000.0000000A.sdmp, EASteamProxy.exe, 00000002.00000002.1693777277.00007FFDFA4CA000.00000002.00000001.01000000.00000015.sdmp, EASteamProxy.exe, 00000002.00000002.1693226925.00007FFDFA0A9000.00000002.00000001.01000000.00000018.sdmp, EASteamProxy.exe, 00000005.00000002.1773950262.00007FFDFF279000.00000002.00000001.01000000.00000018.sdmp String found in binary or memory: https://www.openssl.org/H
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Code function: 0_2_00404FAA 0_2_00404FAA
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Code function: 0_2_0041206B 0_2_0041206B
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Code function: 0_2_0041022D 0_2_0041022D
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Code function: 0_2_00411F91 0_2_00411F91
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91C08 1_2_00007FFDFAE91C08
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9FEA0 1_2_00007FFDFAE9FEA0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEEFD80 1_2_00007FFDFAEEFD80
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE92491 1_2_00007FFDFAE92491
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91BC2 1_2_00007FFDFAE91BC2
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEC91F0 1_2_00007FFDFAEC91F0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE923F6 1_2_00007FFDFAE923F6
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9F745 1_2_00007FFDFAE9F745
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE9B480 1_2_00007FFDFAE9B480
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEA5640 1_2_00007FFDFAEA5640
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEA2A10 1_2_00007FFDFAEA2A10
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEF8F30 1_2_00007FFDFAEF8F30
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91357 1_2_00007FFDFAE91357
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE912B2 1_2_00007FFDFAE912B2
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91924 1_2_00007FFDFAE91924
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAEC2D10 1_2_00007FFDFAEC2D10
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE96C80 1_2_00007FFDFAE96C80
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE915CD 1_2_00007FFDFAE915CD
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91E83 1_2_00007FFDFAE91E83
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE912E4 1_2_00007FFDFAE912E4
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91E7E 1_2_00007FFDFAE91E7E
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE924D7 1_2_00007FFDFAE924D7
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF7AAFC 1_2_00007FFDFAF7AAFC
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF64B30 1_2_00007FFDFAF64B30
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF4FA30 1_2_00007FFDFAF4FA30
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF56A58 1_2_00007FFDFAF56A58
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF4E8D0 1_2_00007FFDFAF4E8D0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF5AFD0 1_2_00007FFDFAF5AFD0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF55E60 1_2_00007FFDFAF55E60
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF66EFC 1_2_00007FFDFAF66EFC
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF7FF06 1_2_00007FFDFAF7FF06
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF7BF18 1_2_00007FFDFAF7BF18
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF79E18 1_2_00007FFDFAF79E18
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF60E3C 1_2_00007FFDFAF60E3C
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF74CA0 1_2_00007FFDFAF74CA0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF5FCD0 1_2_00007FFDFAF5FCD0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF563C8 1_2_00007FFDFAF563C8
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF7344C 1_2_00007FFDFAF7344C
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF5D2B0 1_2_00007FFDFAF5D2B0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF4B338 1_2_00007FFDFAF4B338
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF6B160 1_2_00007FFDFAF6B160
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF5C140 1_2_00007FFDFAF5C140
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF4D7B0 1_2_00007FFDFAF4D7B0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF657E0 1_2_00007FFDFAF657E0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF7183C 1_2_00007FFDFAF7183C
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF66668 1_2_00007FFDFAF66668
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF4C6B0 1_2_00007FFDFAF4C6B0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF6A6C0 1_2_00007FFDFAF6A6C0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF566FC 1_2_00007FFDFAF566FC
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF6C720 1_2_00007FFDFAF6C720
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF60560 1_2_00007FFDFAF60560
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF7C610 1_2_00007FFDFAF7C610
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF76650 1_2_00007FFDFAF76650
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF75470 1_2_00007FFDFAF75470
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF5E470 1_2_00007FFDFAF5E470
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF6250C 1_2_00007FFDFAF6250C
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF77540 1_2_00007FFDFAF77540
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001C08 2_2_00007FFDFA001C08
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00FEA0 2_2_00007FFDFA00FEA0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA05FD80 2_2_00007FFDFA05FD80
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA002491 2_2_00007FFDFA002491
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001BC2 2_2_00007FFDFA001BC2
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0391F0 2_2_00007FFDFA0391F0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0023F6 2_2_00007FFDFA0023F6
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00F745 2_2_00007FFDFA00F745
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA00B480 2_2_00007FFDFA00B480
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA015640 2_2_00007FFDFA015640
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA012A10 2_2_00007FFDFA012A10
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001357 2_2_00007FFDFA001357
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA006C80 2_2_00007FFDFA006C80
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA032D10 2_2_00007FFDFA032D10
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001924 2_2_00007FFDFA001924
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0012B2 2_2_00007FFDFA0012B2
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0015CD 2_2_00007FFDFA0015CD
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001E83 2_2_00007FFDFA001E83
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0012E4 2_2_00007FFDFA0012E4
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001E7E 2_2_00007FFDFA001E7E
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0024D7 2_2_00007FFDFA0024D7
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0B3560 2_2_00007FFDFA0B3560
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA13CA80 2_2_00007FFDFA13CA80
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0ECAA0 2_2_00007FFDFA0ECAA0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0CFAC0 2_2_00007FFDFA0CFAC0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA111AE0 2_2_00007FFDFA111AE0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0C9B00 2_2_00007FFDFA0C9B00
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0DFB30 2_2_00007FFDFA0DFB30
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA140BD0 2_2_00007FFDFA140BD0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA186C00 2_2_00007FFDFA186C00
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0FB8C0 2_2_00007FFDFA0FB8C0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0D58E0 2_2_00007FFDFA0D58E0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA1838E0 2_2_00007FFDFA1838E0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA123990 2_2_00007FFDFA123990
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0BA960 2_2_00007FFDFA0BA960
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0EF980 2_2_00007FFDFA0EF980
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0E49F0 2_2_00007FFDFA0E49F0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0E3A00 2_2_00007FFDFA0E3A00
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0CBA30 2_2_00007FFDFA0CBA30
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0FCA40 2_2_00007FFDFA0FCA40
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0B6E60 2_2_00007FFDFA0B6E60
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0CAE60 2_2_00007FFDFA0CAE60
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA114E60 2_2_00007FFDFA114E60
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA118F50 2_2_00007FFDFA118F50
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0CDF50 2_2_00007FFDFA0CDF50
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0CFF60 2_2_00007FFDFA0CFF60
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0E1FE0 2_2_00007FFDFA0E1FE0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA123C90 2_2_00007FFDFA123C90
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0F3CA0 2_2_00007FFDFA0F3CA0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA110CF0 2_2_00007FFDFA110CF0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0BFD00 2_2_00007FFDFA0BFD00
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA118D70 2_2_00007FFDFA118D70
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0C9DA0 2_2_00007FFDFA0C9DA0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0BEDC0 2_2_00007FFDFA0BEDC0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0FCDC0 2_2_00007FFDFA0FCDC0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA103E50 2_2_00007FFDFA103E50
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA113E30 2_2_00007FFDFA113E30
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA118260 2_2_00007FFDFA118260
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0D82D0 2_2_00007FFDFA0D82D0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0EE340 2_2_00007FFDFA0EE340
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0D9340 2_2_00007FFDFA0D9340
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0F7380 2_2_00007FFDFA0F7380
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA1423B0 2_2_00007FFDFA1423B0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA1193B0 2_2_00007FFDFA1193B0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0FC3C0 2_2_00007FFDFA0FC3C0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA117400 2_2_00007FFDFA117400
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0F4440 2_2_00007FFDFA0F4440
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0EF0B0 2_2_00007FFDFA0EF0B0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0FC1A0 2_2_00007FFDFA0FC1A0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA13F1A0 2_2_00007FFDFA13F1A0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0CD1D0 2_2_00007FFDFA0CD1D0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA112690 2_2_00007FFDFA112690
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0F06F0 2_2_00007FFDFA0F06F0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0F26E0 2_2_00007FFDFA0F26E0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA1236F0 2_2_00007FFDFA1236F0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA10E740 2_2_00007FFDFA10E740
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0F8800 2_2_00007FFDFA0F8800
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0D6850 2_2_00007FFDFA0D6850
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0F34B0 2_2_00007FFDFA0F34B0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0CC530 2_2_00007FFDFA0CC530
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0F1590 2_2_00007FFDFA0F1590
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0B35E0 2_2_00007FFDFA0B35E0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0FB630 2_2_00007FFDFA0FB630
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA0C9620 2_2_00007FFDFA0C9620
Source: Joe Sandbox View Dropped File: C:\Users\user\AppData\Local\Temp\msvcp140.dll 74892D9B4028C05DEBAF0B9B5D9DC6D22F7956FA7D7EEE00C681318C26792823
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: String function: 00007FFDFA06CD3F appears 196 times
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: String function: 00007FFDFA06CDD5 appears 104 times
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: String function: 00007FFDFA001023 appears 558 times
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Code function: String function: 0040243B appears 37 times
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: String function: 00007FFDFAE91023 appears 577 times
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: String function: 00007FFDFAEFCDD5 appears 105 times
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: String function: 00007FFDFAEFCD3F appears 200 times
Source: 4OVYJHCTFA.exe, 00000000.00000003.1635577840.000000000246D000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename7ZSfxMod_x86.exe< vs 4OVYJHCTFA.exe
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002EE5000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamelibcryptoH vs 4OVYJHCTFA.exe
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002BE4000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameEASteamProxy.exe& vs 4OVYJHCTFA.exe
Source: 4OVYJHCTFA.exe, 00000000.00000000.1634565659.0000000000432000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilename7ZSfxMod_x86.exe< vs 4OVYJHCTFA.exe
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002F63000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamelibsslH vs 4OVYJHCTFA.exe
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002F63000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemsvcp140.dllT vs 4OVYJHCTFA.exe
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002F63000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemsvcp140_1.dllT vs 4OVYJHCTFA.exe
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000034C8000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameQt5Core.dll( vs 4OVYJHCTFA.exe
Source: 4OVYJHCTFA.exe, 00000000.00000003.1647120752.0000000000660000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamevcruntime140.dllT vs 4OVYJHCTFA.exe
Source: 4OVYJHCTFA.exe, 00000000.00000003.1647120752.0000000000660000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamevcruntime140_1.dllT vs 4OVYJHCTFA.exe
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameQt5Network.dll( vs 4OVYJHCTFA.exe
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamesteam_api.dllB vs 4OVYJHCTFA.exe
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamevcruntime140.dllT vs 4OVYJHCTFA.exe
Source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamevcruntime140_1.dllT vs 4OVYJHCTFA.exe
Source: 4OVYJHCTFA.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: Qt5Core.dll.0.dr Static PE information: Section: .qtmimed ZLIB complexity 0.997458770800317
Source: Qt5Core.dll.1.dr Static PE information: Section: .qtmimed ZLIB complexity 0.997458770800317
Source: classification engine Classification label: mal100.troj.evad.winEXE@16/28@0/0
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Code function: 0_2_00407776 wvsprintfW,GetLastError,FormatMessageW,FormatMessageW,FormatMessageW,lstrlenW,lstrlenW,lstrlenW,??2@YAPAXI@Z,lstrcpyW,lstrcpyW,lstrcpyW,??3@YAXPAX@Z,LocalFree, 0_2_00407776
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA186E00 ?shared_null@QListData@@2UData@1@B,CertOpenSystemStoreW,CertFindCertificateInStore,??0QByteArray@@QEAA@PEBDH@Z,?append@QListData@@QEAAPEAPEAXXZ,??1QByteArray@@QEAA@XZ,CertFindCertificateInStore,CertCloseStore, 2_2_00007FFDFA186E00
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Code function: 0_2_0040118A GetDiskFreeSpaceExW,SendMessageW, 0_2_0040118A
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Code function: 0_2_004034C1 _wtol,_wtol,SHGetSpecialFolderPathW,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,_wtol,CoCreateInstance,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z, 0_2_004034C1
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Code function: 0_2_00401BDF GetModuleHandleW,FindResourceExA,FindResourceExA,FindResourceExA,SizeofResource,LoadResource,LockResource,LoadLibraryA,LoadLibraryA,GetProcAddress,GetProcAddress,wsprintfW,LoadLibraryA,GetProcAddress, 0_2_00401BDF
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe File created: C:\Users\user\AppData\Roaming\demoWordpad_dbg Jump to behavior
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6656:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4080:120:WilError_03
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe File created: C:\Users\user\AppData\Local\Temp\blackleg.pptx Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\explorer.exe
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\explorer.exe
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\explorer.exe Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\explorer.exe Jump to behavior
Source: 4OVYJHCTFA.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe File read: C:\Users\user\Desktop\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: 4OVYJHCTFA.exe ReversingLabs: Detection: 70%
Source: 4OVYJHCTFA.exe Virustotal: Detection: 58%
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe File read: C:\Users\user\Desktop\4OVYJHCTFA.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\4OVYJHCTFA.exe "C:\Users\user\Desktop\4OVYJHCTFA.exe"
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Process created: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe "C:\Users\user\AppData\Local\Temp\EASteamProxy.exe"
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Process created: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknown Process created: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\explorer.exe C:\Windows\SysWOW64\explorer.exe
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\explorer.exe C:\Windows\SysWOW64\explorer.exe
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Process created: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe "C:\Users\user\AppData\Local\Temp\EASteamProxy.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Process created: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\explorer.exe C:\Windows\SysWOW64\explorer.exe Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\explorer.exe C:\Windows\SysWOW64\explorer.exe Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Section loaded: slc.dll Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: qt5core.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: steam_api64.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: vcruntime140_1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: libcrypto-1_1-x64.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: qt5network.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: libssl-1_1-x64.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: msvcp140_1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: pla.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: pdh.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: tdh.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: cabinet.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: wevtapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: shdocvw.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: qt5core.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: steam_api64.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: vcruntime140_1.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: libcrypto-1_1-x64.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: qt5network.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: libssl-1_1-x64.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: vcruntime140_1.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: msvcp140_1.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: pla.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: pdh.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: tdh.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: cabinet.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: wevtapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: shdocvw.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: winbrand.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: shdocvw.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: taskschd.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: xmllite.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: qt5core.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: steam_api64.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: vcruntime140_1.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: libcrypto-1_1-x64.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: qt5network.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: libssl-1_1-x64.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: msvcp140_1.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: vcruntime140_1.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: pla.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: pdh.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: tdh.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: cabinet.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: wevtapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: shdocvw.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: winbrand.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: shdocvw.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: taskschd.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: aepic.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: twinapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: shdocvw.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: aepic.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: twinapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Windows\SysWOW64\explorer.exe Section loaded: shdocvw.dll Jump to behavior
Source: 4OVYJHCTFA.exe Static file information: File size 6198600 > 1048576
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\msvcp140.amd64.pdb source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002F63000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1659971608.00007FFDFAF96000.00000002.00000001.01000000.0000000C.sdmp, EASteamProxy.exe, 00000002.00000002.1693873503.00007FFDFA536000.00000002.00000001.01000000.00000013.sdmp
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\msvcp140.amd64.pdbGCTL source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002F63000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1659971608.00007FFDFAF96000.00000002.00000001.01000000.0000000C.sdmp, EASteamProxy.exe, 00000002.00000002.1693873503.00007FFDFA536000.00000002.00000001.01000000.00000013.sdmp
Source: Binary string: @ compiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PICOpenSSL 1.1.1s 1 Nov 2022built on: Fri Feb 3 01:12:04 2023 UTCplatform: VC-WIN64AOPENSSLDIR: "C:\Program Files\Common Files\SSL"ENGINESDIR: "D:\juno\p4\desktop\packages\openSSL\1.1.1s\installed\dist\pc64_dll_release\lib\engines-1_1"not available source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002DFA000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1660437574.00007FFDFB193000.00000002.00000001.01000000.0000000A.sdmp, EASteamProxy.exe, 00000002.00000002.1693576225.00007FFDFA3D3000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\msvcp140_1.amd64.pdb source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002F63000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1662343914.00007FFE130C3000.00000002.00000001.01000000.0000000E.sdmp, EASteamProxy.exe, 00000002.00000002.1694524165.00007FFE126D3000.00000002.00000001.01000000.00000019.sdmp
Source: Binary string: wntdll.pdbUGP source: cmd.exe, 00000003.00000002.1924825717.00000000052B0000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1925067473.0000000005720000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: D:\juno\p4\desktop\packages\openSSL\1.1.1s\installed\source\libcrypto-1_1-x64.pdb source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002E7C000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1660437574.00007FFDFB215000.00000002.00000001.01000000.0000000A.sdmp, EASteamProxy.exe, 00000002.00000002.1693576225.00007FFDFA455000.00000002.00000001.01000000.00000015.sdmp, EASteamProxy.exe, 00000005.00000002.1773030063.00007FFDFB435000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: ntdll.pdbUGP source: EASteamProxy.exe, 00000001.00000002.1658752702.0000023839E30000.00000004.00000800.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1658587407.0000023839A3A000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692224582.0000024614F7C000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692548057.0000024615570000.00000004.00000001.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692366674.0000024615370000.00000004.00000800.00020000.00000000.sdmp, EASteamProxy.exe, 00000005.00000002.1771581420.00000257755F7000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000005.00000002.1771917334.0000025775BF6000.00000004.00000001.00020000.00000000.sdmp
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\msvcp140_1.amd64.pdbGCTL source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002F63000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1662343914.00007FFE130C3000.00000002.00000001.01000000.0000000E.sdmp, EASteamProxy.exe, 00000002.00000002.1694524165.00007FFE126D3000.00000002.00000001.01000000.00000019.sdmp
Source: Binary string: wntdll.pdb source: cmd.exe, 00000003.00000002.1924825717.00000000052B0000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.1925067473.0000000005720000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: Q:\build\qt\qtbase\lib\Qt5Core.pdb source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000034C8000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1660898119.00007FFDFB73C000.00000002.00000001.01000000.00000006.sdmp, EASteamProxy.exe, 00000002.00000002.1694121588.00007FFDFAA0C000.00000002.00000001.01000000.00000011.sdmp, EASteamProxy.exe, 00000005.00000002.1773451655.00007FFDFB95C000.00000002.00000001.01000000.00000011.sdmp
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdb source: 4OVYJHCTFA.exe, 00000000.00000003.1647120752.0000000000660000.00000004.00001000.00020000.00000000.sdmp, 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1662897785.00007FFE13311000.00000002.00000001.01000000.00000008.sdmp, EASteamProxy.exe, 00000002.00000002.1694632093.00007FFE126F1000.00000002.00000001.01000000.00000014.sdmp
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdbGCTL source: 4OVYJHCTFA.exe, 00000000.00000003.1647120752.0000000000660000.00000004.00001000.00020000.00000000.sdmp, 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1662897785.00007FFE13311000.00000002.00000001.01000000.00000008.sdmp, EASteamProxy.exe, 00000002.00000002.1694632093.00007FFE126F1000.00000002.00000001.01000000.00000014.sdmp
Source: Binary string: FatalErrorWarningDebugassert.report.fatalassert.report.errorassert.report.warningassert.report.debugassert.report.unknownasserts already initializedeax::foundation::initAssertionssAssertFailureFn == nullptr.pdb source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000000.1649950475.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000001.00000002.1659294593.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000002.00000002.1692951141.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000002.00000000.1657354262.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000005.00000002.1772426207.00007FF642825000.00000002.00000001.01000000.00000010.sdmp
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdb source: 4OVYJHCTFA.exe, 00000000.00000003.1647120752.0000000000660000.00000004.00001000.00020000.00000000.sdmp, 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1663012636.00007FFE148E5000.00000002.00000001.01000000.00000009.sdmp, EASteamProxy.exe, 00000002.00000002.1694701423.00007FFE12E15000.00000002.00000001.01000000.00000016.sdmp, EASteamProxy.exe, 00000005.00000002.1774511818.00007FFE148E5000.00000002.00000001.01000000.00000016.sdmp
Source: Binary string: compiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002DFA000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1660437574.00007FFDFB193000.00000002.00000001.01000000.0000000A.sdmp, EASteamProxy.exe, 00000002.00000002.1693576225.00007FFDFA3D3000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: .pdb.map.___> => > source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000000.1649950475.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000001.00000002.1659294593.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000002.00000002.1692951141.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000002.00000000.1657354262.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000005.00000002.1772426207.00007FF642825000.00000002.00000001.01000000.00000010.sdmp
Source: Binary string: D:\juno\p4\desktop\packages\openSSL\1.1.1s\installed\source\libssl-1_1-x64.pdb source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002F63000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1659739933.00007FFDFAF04000.00000002.00000001.01000000.0000000D.sdmp, EASteamProxy.exe, 00000002.00000002.1693179150.00007FFDFA074000.00000002.00000001.01000000.00000018.sdmp, EASteamProxy.exe, 00000005.00000002.1773874761.00007FFDFF244000.00000002.00000001.01000000.00000018.sdmp
Source: Binary string: ntdll.pdb source: EASteamProxy.exe, 00000001.00000002.1658752702.0000023839E30000.00000004.00000800.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1658587407.0000023839A3A000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692224582.0000024614F7C000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692548057.0000024615570000.00000004.00000001.00020000.00000000.sdmp, EASteamProxy.exe, 00000002.00000002.1692366674.0000024615370000.00000004.00000800.00020000.00000000.sdmp, EASteamProxy.exe, 00000005.00000002.1771581420.00000257755F7000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000005.00000002.1771917334.0000025775BF6000.00000004.00000001.00020000.00000000.sdmp
Source: Binary string: Q:\build\qt\qtbase\lib\Qt5Network.pdb source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1661868306.00007FFDFF298000.00000002.00000001.01000000.0000000B.sdmp, EASteamProxy.exe, 00000002.00000002.1693336663.00007FFDFA198000.00000002.00000001.01000000.00000017.sdmp, EASteamProxy.exe, 00000005.00000002.1772708477.00007FFDFB178000.00000002.00000001.01000000.00000017.sdmp
Source: Binary string: C:\jenkins\workspace\dev\juno-win_live\build\eaSteamProxy\pc64-vc-tool-opt\bin\EASteamProxy.pdb source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000000.1649950475.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000001.00000002.1659294593.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000002.00000002.1692951141.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000002.00000000.1657354262.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000005.00000002.1772426207.00007FF642825000.00000002.00000001.01000000.00000010.sdmp
Source: Binary string: C:\jenkins\workspace\dev\juno-win_live\build\eaSteamProxy\pc64-vc-tool-opt\bin\EASteamProxy.pdbc source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000000.1649950475.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000001.00000002.1659294593.00007FF66A3F5000.00000002.00000001.01000000.00000005.sdmp, EASteamProxy.exe, 00000002.00000002.1692951141.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000002.00000000.1657354262.00007FF642825000.00000002.00000001.01000000.00000010.sdmp, EASteamProxy.exe, 00000005.00000002.1772426207.00007FF642825000.00000002.00000001.01000000.00000010.sdmp
Source: Binary string: D:\juno\p4\desktop\packages\openSSL\1.1.1s\installed\source\libssl-1_1-x64.pdb?? source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.0000000002F63000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1659739933.00007FFDFAF04000.00000002.00000001.01000000.0000000D.sdmp, EASteamProxy.exe, 00000002.00000002.1693179150.00007FFDFA074000.00000002.00000001.01000000.00000018.sdmp, EASteamProxy.exe, 00000005.00000002.1773874761.00007FFDFF244000.00000002.00000001.01000000.00000018.sdmp
Source: Binary string: c:\buildslave\steam_rel_client_win64\build\src\steam_api\win64\Release\steam_api64.pdb source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1662495748.00007FFE13227000.00000002.00000001.01000000.00000007.sdmp, EASteamProxy.exe, 00000002.00000002.1694444874.00007FFE11EC7000.00000002.00000001.01000000.00000012.sdmp, EASteamProxy.exe, 00000005.00000002.1774299159.00007FFE13227000.00000002.00000001.01000000.00000012.sdmp
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdbGCTL source: 4OVYJHCTFA.exe, 00000000.00000003.1647120752.0000000000660000.00000004.00001000.00020000.00000000.sdmp, 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000026D6000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1663012636.00007FFE148E5000.00000002.00000001.01000000.00000009.sdmp, EASteamProxy.exe, 00000002.00000002.1694701423.00007FFE12E15000.00000002.00000001.01000000.00000016.sdmp, EASteamProxy.exe, 00000005.00000002.1774511818.00007FFE148E5000.00000002.00000001.01000000.00000016.sdmp
Source: Binary string: Q:\build\qt\qtbase\lib\Qt5Core.pdbT source: 4OVYJHCTFA.exe, 00000000.00000003.1646029435.00000000034C8000.00000004.00000020.00020000.00000000.sdmp, EASteamProxy.exe, 00000001.00000002.1660898119.00007FFDFB73C000.00000002.00000001.01000000.00000006.sdmp, EASteamProxy.exe, 00000002.00000002.1694121588.00007FFDFAA0C000.00000002.00000001.01000000.00000011.sdmp, EASteamProxy.exe, 00000005.00000002.1773451655.00007FFDFB95C000.00000002.00000001.01000000.00000011.sdmp
Source: vcruntime140.dll.0.dr Static PE information: 0xC94BF788 [Wed Jan 6 22:49:44 2077 UTC]
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Code function: 0_2_00406D5D LoadLibraryA,GetProcAddress,GetModuleHandleW,GetWindow,GetWindow,LoadIconW,GetWindow, 0_2_00406D5D
Source: 4OVYJHCTFA.exe Static PE information: real checksum: 0x33302 should be: 0x5ead76
Source: libcrypto-1_1-x64.dll.1.dr Static PE information: real checksum: 0x0 should be: 0x2bdc1b
Source: Qt5Network.dll.1.dr Static PE information: real checksum: 0x0 should be: 0x156ab5
Source: libcrypto-1_1-x64.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x2bdc1b
Source: gqnmaqicmbds.3.dr Static PE information: real checksum: 0x0 should be: 0x523b9
Source: libssl-1_1-x64.dll.0.dr Static PE information: real checksum: 0x0 should be: 0xa8dea
Source: libssl-1_1-x64.dll.1.dr Static PE information: real checksum: 0x0 should be: 0xa8dea
Source: Qt5Network.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x156ab5
Source: Qt5Core.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x607c55
Source: tbh.6.dr Static PE information: real checksum: 0x0 should be: 0x523b9
Source: Qt5Core.dll.1.dr Static PE information: real checksum: 0x0 should be: 0x607c55
Source: vcruntime140.dll.0.dr Static PE information: section name: _RDATA
Source: libcrypto-1_1-x64.dll.0.dr Static PE information: section name: .00cfg
Source: libssl-1_1-x64.dll.0.dr Static PE information: section name: .00cfg
Source: Qt5Core.dll.0.dr Static PE information: section name: .qtmimed
Source: steam_api64.dll.0.dr Static PE information: section name: _RDATA
Source: libcrypto-1_1-x64.dll.1.dr Static PE information: section name: .00cfg
Source: libssl-1_1-x64.dll.1.dr Static PE information: section name: .00cfg
Source: Qt5Core.dll.1.dr Static PE information: section name: .qtmimed
Source: steam_api64.dll.1.dr Static PE information: section name: _RDATA
Source: vcruntime140.dll.1.dr Static PE information: section name: _RDATA
Source: gqnmaqicmbds.3.dr Static PE information: section name: qtam
Source: tbh.6.dr Static PE information: section name: qtam
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Code function: 0_2_00411C20 push eax; ret 0_2_00411C4E
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAED6011 push rcx; ret 1_2_00007FFDFAED6012
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF7D5EA push rdx; retf 1_2_00007FFDFAF7D5EB
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA046011 push rcx; ret 2_2_00007FFDFA046012
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe File created: C:\Users\user\AppData\Local\Temp\msvcp140.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe File created: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe File created: C:\Users\user\AppData\Roaming\demoWordpad_dbg\steam_api64.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe File created: C:\Users\user\AppData\Roaming\demoWordpad_dbg\libssl-1_1-x64.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe File created: C:\Users\user\AppData\Roaming\demoWordpad_dbg\Qt5Network.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe File created: C:\Users\user\AppData\Roaming\demoWordpad_dbg\vcruntime140.dll Jump to dropped file
Source: C:\Windows\SysWOW64\cmd.exe File created: C:\Users\user\AppData\Local\Temp\gqnmaqicmbds Jump to dropped file
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe File created: C:\Users\user\AppData\Local\Temp\libcrypto-1_1-x64.dll Jump to dropped file
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe File created: C:\Users\user\AppData\Local\Temp\Qt5Network.dll Jump to dropped file
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe File created: C:\Users\user\AppData\Local\Temp\Qt5Core.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe File created: C:\Users\user\AppData\Roaming\demoWordpad_dbg\msvcp140_1.dll Jump to dropped file
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe File created: C:\Users\user\AppData\Local\Temp\libssl-1_1-x64.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe File created: C:\Users\user\AppData\Roaming\demoWordpad_dbg\msvcp140.dll Jump to dropped file
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe File created: C:\Users\user\AppData\Local\Temp\vcruntime140_1.dll Jump to dropped file
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe File created: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe File created: C:\Users\user\AppData\Roaming\demoWordpad_dbg\libcrypto-1_1-x64.dll Jump to dropped file
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe File created: C:\Users\user\AppData\Local\Temp\msvcp140_1.dll Jump to dropped file
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe File created: C:\Users\user\AppData\Local\Temp\vcruntime140.dll Jump to dropped file
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe File created: C:\Users\user\AppData\Local\Temp\steam_api64.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe File created: C:\Users\user\AppData\Roaming\demoWordpad_dbg\Qt5Core.dll Jump to dropped file
Source: C:\Windows\SysWOW64\cmd.exe File created: C:\Users\user\AppData\Local\Temp\tbh Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe File created: C:\Users\user\AppData\Roaming\demoWordpad_dbg\vcruntime140_1.dll Jump to dropped file
Source: C:\Windows\SysWOW64\cmd.exe File created: C:\Users\user\AppData\Local\Temp\gqnmaqicmbds Jump to dropped file
Source: C:\Windows\SysWOW64\cmd.exe File created: C:\Users\user\AppData\Local\Temp\tbh Jump to dropped file

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Windows\SysWOW64\cmd.exe Module Loaded: C:\USERS\user\APPDATA\LOCAL\TEMP\GQNMAQICMBDS
Source: C:\Windows\SysWOW64\cmd.exe Module Loaded: C:\USERS\user\APPDATA\LOCAL\TEMP\TBH
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Process information set: NOOPENFILEERRORBOX Jump to behavior

Malware Analysis System Evasion

barindex
Source: C:\Windows\SysWOW64\cmd.exe API/Special instruction interceptor: Address: 6CF73B97
Source: C:\Windows\SysWOW64\explorer.exe API/Special instruction interceptor: Address: 73A317
Source: C:\Windows\SysWOW64\cmd.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\gqnmaqicmbds Jump to dropped file
Source: C:\Windows\SysWOW64\cmd.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\tbh Jump to dropped file
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe API coverage: 0.1 %
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Code function: 0_2_0040301A GetFileAttributesW,SetLastError,FindFirstFileW,FindClose,CompareFileTime, 0_2_0040301A
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Code function: 0_2_00402B79 FindFirstFileW,SetFileAttributesW,lstrcmpW,lstrcmpW,SetFileAttributesW,DeleteFileW,FindNextFileW,FindClose,SetFileAttributesW,RemoveDirectoryW,??3@YAXPAX@Z,??3@YAXPAX@Z, 0_2_00402B79
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF4A260 FindFirstFileExW,FindClose,wcscpy_s,_invalid_parameter_noinfo_noreturn, 1_2_00007FFDFAF4A260
Source: cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: noreply@vmware.com0
Source: cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: http://www.vmware.com/0
Source: 4OVYJHCTFA.exe, 00000000.00000002.1663479280.00000000006E6000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: VMware, Inc.1!0
Source: cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: http://www.vmware.com/0/
Source: cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: VMware, Inc.1
Source: cmd.exe, 00000003.00000002.1924966060.000000000565F000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: VMware, Inc.0
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91D75 __scrt_fastfail,IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 1_2_00007FFDFAE91D75
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Code function: 0_2_00406D5D LoadLibraryA,GetProcAddress,GetModuleHandleW,GetWindow,GetWindow,LoadIconW,GetWindow, 0_2_00406D5D
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAE91D75 __scrt_fastfail,IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 1_2_00007FFDFAE91D75
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: 1_2_00007FFDFAF934B4 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 1_2_00007FFDFAF934B4
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA001D75 __scrt_fastfail,IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 2_2_00007FFDFA001D75
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Code function: 2_2_00007FFDFA196CC0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 2_2_00007FFDFA196CC0

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtCreateFile: Direct from: 0xA200000080 Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtAllocateVirtualMemory: Direct from: 0x24612F4ABF0 Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtProtectVirtualMemory: Direct from: 0x250 Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtQuerySystemInformation: Direct from: 0x25700000000 Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtAllocateVirtualMemory: Direct from: 0x110 Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtCreateFile: Direct from: 0x7B00000080 Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtClose: Direct from: 0xA2F3EFE608
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtCreateFile: Direct from: 0x7FFDFAB878EC Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtClose: Direct from: 0x24612F4CDB0
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtAllocateVirtualMemory: Direct from: 0x257733ACC30 Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtQuerySystemInformation: Direct from: 0x7FFD40CB21D3 Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtProtectVirtualMemory: Direct from: 0x25775296400 Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtProtectVirtualMemory: Direct from: 0x25C Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtAllocateVirtualMemory: Direct from: 0x7FFDFAF28054 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe NtProtectVirtualMemory: Direct from: 0x7FFE221C26A1 Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtProtectVirtualMemory: Direct from: 0x24612DAE010 Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtAllocateVirtualMemory: Direct from: 0x7FFDFAB98054 Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtAllocateVirtualMemory: Direct from: 0xA0A76ACB Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtCreateFile: Direct from: 0x7FFDFAF178EC Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtClose: Direct from: 0x25775296E90
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtProtectVirtualMemory: Direct from: 0x3 Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtAllocateVirtualMemory: Direct from: 0x24612DAEB1E Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtQuerySystemInformation: Direct from: 0x24600000000 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe NtQuerySystemInformation: Direct from: 0x551494E170 Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtAllocateVirtualMemory: Direct from: 0x25773478B0E Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe NtClose: Direct from: 0x1F1E
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe NtClose: Direct from: 0x7BF418E198
Source: C:\Windows\SysWOW64\cmd.exe Memory written: PID: 5776 base: 2D50000 value: 00 Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Memory written: PID: 5776 base: 2F202D8 value: 00 Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Memory written: PID: 5776 base: 2F211E8 value: 00 Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Memory written: PID: 5776 base: 7379C0 value: 55 Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Memory written: PID: 5776 base: 490000 value: 00 Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Memory written: PID: 5796 base: 1E0000 value: 00 Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Memory written: PID: 5796 base: 3AA2D8 value: 00 Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Memory written: PID: 5796 base: 3AB1E8 value: 00 Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Memory written: PID: 5796 base: 7379C0 value: 55 Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Memory written: PID: 5796 base: 400000 value: 00 Jump to behavior
Source: cmd.exe, 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: facilitycoursedw.shop
Source: cmd.exe, 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: doughtdrillyksow.shop
Source: cmd.exe, 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: disappointcredisotw.shop
Source: cmd.exe, 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: bargainnygroandjwk.shop
Source: cmd.exe, 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: injurypiggyoewirog.shop
Source: cmd.exe, 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: leafcalfconflcitw.shop
Source: cmd.exe, 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: computerexcudesp.shop
Source: cmd.exe, 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: publicitycharetew.shop
Source: cmd.exe, 00000003.00000002.1925302371.0000000005C50000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: periodicroytewrsn.shop
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: NULL target: C:\Windows\SysWOW64\cmd.exe protection: read write Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: NULL target: C:\Windows\SysWOW64\explorer.exe protection: read write Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Section loaded: NULL target: C:\Windows\SysWOW64\cmd.exe protection: read write Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Memory written: C:\Windows\SysWOW64\explorer.exe base: 7379C0 Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Memory written: C:\Windows\SysWOW64\explorer.exe base: 490000 Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Memory written: C:\Windows\SysWOW64\explorer.exe base: 7379C0 Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Memory written: C:\Windows\SysWOW64\explorer.exe base: 400000 Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Process created: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe "C:\Users\user\AppData\Local\Temp\EASteamProxy.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\explorer.exe C:\Windows\SysWOW64\explorer.exe Jump to behavior
Source: C:\Users\user\AppData\Roaming\demoWordpad_dbg\EASteamProxy.exe Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\explorer.exe C:\Windows\SysWOW64\explorer.exe Jump to behavior
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Code function: 0_2_0040D72E cpuid 0_2_0040D72E
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Code function: GetLastError,GetLastError,wsprintfW,GetEnvironmentVariableW,GetEnvironmentVariableW,GetLastError,??2@YAPAXI@Z,GetEnvironmentVariableW,GetLastError,lstrcmpiW,??3@YAXPAX@Z,??3@YAXPAX@Z,SetLastError,lstrlenA,??2@YAPAXI@Z,GetLocaleInfoW,_wtol,MultiByteToWideChar, 0_2_00401F9D
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: GetLocaleInfoEx,FormatMessageA, 1_2_00007FFDFAF5285C
Source: C:\Users\user\AppData\Local\Temp\EASteamProxy.exe Code function: ___lc_locale_name_func,GetLocaleInfoEx, 1_2_00007FFDFAF6F4F0
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Code function: 0_2_00401626 ??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,GetLocalTime,SystemTimeToFileTime,??2@YAPAXI@Z,GetLastError,??3@YAXPAX@Z,??3@YAXPAX@Z,GetLastError,??3@YAXPAX@Z,GetLastError,??3@YAXPAX@Z,??3@YAXPAX@Z, 0_2_00401626
Source: C:\Users\user\Desktop\4OVYJHCTFA.exe Code function: 0_2_00404FAA GetVersionExW,GetCommandLineW,_wtol,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,GetModuleFileNameW,_wtol,??2@YAPAXI@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,wsprintfW,_wtol,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,CoInitialize,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,GetKeyState,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,GetFileAttributesW,??3@YAXPAX@Z,??3@YAXPAX@Z,_wtol,memset,ShellExecuteExW,WaitForSingleObject,CloseHandle,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,SetCurrentDirectoryW,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,??3@YAXPAX@Z,MessageBoxA, 0_2_00404FAA

Stealing of Sensitive Information

barindex
Source: Yara match File source: decrypted.memstr, type: MEMORYSTR

Remote Access Functionality

barindex
Source: Yara match File source: decrypted.memstr, type: MEMORYSTR
No contacted IP infos