Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0078A2B0 CryptUnprotectData,LocalAlloc,memcpy,LocalFree, |
0_2_0078A2B0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00799030 CryptBinaryToStringA,GetProcessHeap,HeapAlloc,CryptBinaryToStringA, |
0_2_00799030 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0078C920 memset,lstrlenA,CryptStringToBinaryA,PK11_GetInternalKeySlot,PK11_Authenticate,PK11SDR_Decrypt,memcpy,lstrcatA,lstrcatA,PK11_FreeSlot,lstrcatA, |
0_2_0078C920 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0078A210 CryptStringToBinaryA,LocalAlloc,CryptStringToBinaryA,LocalFree, |
0_2_0078A210 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_007872A0 GetProcessHeap,HeapAlloc,CryptUnprotectData,WideCharToMultiByte,LocalFree, |
0_2_007872A0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C70A9A0 PK11SDR_Decrypt,PORT_NewArena_Util,SEC_QuickDERDecodeItem_Util,PORT_FreeArena_Util,SECITEM_ZfreeItem_Util,PK11_GetInternalKeySlot,PK11_Authenticate,PORT_FreeArena_Util,PK11_ListFixedKeysInSlot,SECITEM_ZfreeItem_Util,PK11_FreeSymKey,PK11_FreeSymKey,PORT_FreeArena_Util,PK11_FreeSymKey,SECITEM_ZfreeItem_Util, |
0_2_6C70A9A0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C704440 PK11_PrivDecrypt, |
0_2_6C704440 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C6D4420 SECKEY_DestroyEncryptedPrivateKeyInfo,memset,PORT_FreeArena_Util,SECITEM_ZfreeItem_Util,SECITEM_ZfreeItem_Util,SECITEM_ZfreeItem_Util,free, |
0_2_6C6D4420 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C7044C0 PK11_PubEncrypt, |
0_2_6C7044C0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C7525B0 PK11_Encrypt,memcpy,PR_SetError,PK11_Encrypt, |
0_2_6C7525B0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C6E8670 PK11_ExportEncryptedPrivKeyInfo, |
0_2_6C6E8670 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C70A650 PK11SDR_Encrypt,PORT_NewArena_Util,PK11_GetInternalKeySlot,PK11_Authenticate,SECITEM_ZfreeItem_Util,TlsGetValue,EnterCriticalSection,PR_Unlock,PK11_CreateContextBySymKey,PK11_GetBlockSize,PORT_Alloc_Util,memcpy,SECITEM_ZfreeItem_Util,PORT_FreeArena_Util,SECITEM_ZfreeItem_Util,PK11_FreeSymKey,PORT_ArenaAlloc_Util,PK11_CipherOp,SEC_ASN1EncodeItem_Util,SECITEM_ZfreeItem_Util,PORT_FreeArena_Util,PK11_DestroyContext, |
0_2_6C70A650 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C6EE6E0 PK11_AEADOp,TlsGetValue,EnterCriticalSection,PORT_Alloc_Util,PK11_Encrypt,PORT_Alloc_Util,memcpy,memcpy,PR_SetError,PR_SetError,PR_Unlock,PR_SetError,PR_Unlock,PK11_Decrypt,PR_GetCurrentThread,PK11_Decrypt,PK11_Encrypt,memcpy,memcpy,PR_SetError,free, |
0_2_6C6EE6E0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C72A730 SEC_PKCS12AddCertAndKey,PORT_ArenaMark_Util,PORT_ArenaMark_Util,PK11_FindKeyByAnyCert,SECKEY_DestroyPrivateKey,PORT_ArenaAlloc_Util,PR_SetError,PR_SetError,PK11_GetInternalKeySlot,PK11_FindKeyByAnyCert,SECKEY_DestroyPrivateKey,PORT_ArenaAlloc_Util,SECKEY_DestroyEncryptedPrivateKeyInfo,strlen,PR_SetError,PORT_FreeArena_Util,PORT_FreeArena_Util,PORT_ArenaAlloc_Util,PR_SetError, |
0_2_6C72A730 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C730180 SECMIME_DecryptionAllowed,SECOID_GetAlgorithmTag_Util, |
0_2_6C730180 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C7043B0 PK11_PubEncryptPKCS1,PR_SetError, |
0_2_6C7043B0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C727C00 SEC_PKCS12DecoderImportBags,PR_SetError,NSS_OptionGet,CERT_DestroyCertificate,SECITEM_ZfreeItem_Util,PR_SetError,SECKEY_DestroyPublicKey,SECITEM_ZfreeItem_Util,PR_SetError,SECKEY_DestroyPublicKey,SECITEM_ZfreeItem_Util,PR_SetError,SECOID_FindOID_Util,SECITEM_ZfreeItem_Util,SECKEY_DestroyPublicKey,SECOID_GetAlgorithmTag_Util,SECITEM_CopyItem_Util,PK11_ImportEncryptedPrivateKeyInfoAndReturnKey,SECITEM_ZfreeItem_Util,SECKEY_DestroyPublicKey,PK11_ImportPublicKey,SECOID_FindOID_Util, |
0_2_6C727C00 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C6E7D60 PK11_ImportEncryptedPrivateKeyInfoAndReturnKey,SECOID_FindOID_Util,SECOID_FindOIDByTag_Util,PK11_PBEKeyGen,PK11_GetPadMechanism,PK11_UnwrapPrivKey,PK11_FreeSymKey,SECITEM_ZfreeItem_Util,PK11_PBEKeyGen,SECITEM_ZfreeItem_Util,PK11_FreeSymKey,PK11_ImportPublicKey,SECKEY_DestroyPublicKey, |
0_2_6C6E7D60 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C72BD30 SEC_PKCS12IsEncryptionAllowed,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy, |
0_2_6C72BD30 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C729EC0 SEC_PKCS12CreateUnencryptedSafe,PORT_ArenaMark_Util,PORT_ArenaAlloc_Util,PR_SetError,PR_SetError,SEC_PKCS7DestroyContentInfo, |
0_2_6C729EC0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C703FF0 PK11_PrivDecryptPKCS1, |
0_2_6C703FF0 |
Source: unknown |
HTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.5:49708 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49738 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.5:49748 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49749 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 20.190.159.2:443 -> 192.168.2.5:49813 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 20.190.159.2:443 -> 192.168.2.5:49840 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.5:49977 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.5:49998 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.5:50073 version: TLS 1.2 |
Source: |
Binary string: mozglue.pdbP source: file.exe, 00000000.00000002.2593670616.000000006F8DD000.00000002.00000001.01000000.0000000B.sdmp, mozglue[1].dll.0.dr, mozglue.dll.0.dr |
Source: |
Binary string: freebl3.pdb source: freebl3[1].dll.0.dr, freebl3.dll.0.dr |
Source: |
Binary string: freebl3.pdbp source: freebl3[1].dll.0.dr, freebl3.dll.0.dr |
Source: |
Binary string: nss3.pdb@ source: file.exe, 00000000.00000002.2593243941.000000006C7DF000.00000002.00000001.01000000.0000000A.sdmp, nss3.dll.0.dr, nss3[1].dll.0.dr |
Source: |
Binary string: my_library.pdbU source: file.exe, chrome.dll.0.dr |
Source: |
Binary string: my_library.pdb source: file.exe, chrome.dll.0.dr |
Source: |
Binary string: softokn3.pdb@ source: softokn3[1].dll.0.dr, softokn3.dll.0.dr |
Source: |
Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\vcruntime140.i386.pdb source: vcruntime140.dll.0.dr, vcruntime140[1].dll.0.dr |
Source: |
Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\msvcp140.i386.pdb source: msvcp140[1].dll.0.dr, msvcp140.dll.0.dr |
Source: |
Binary string: nss3.pdb source: file.exe, 00000000.00000002.2593243941.000000006C7DF000.00000002.00000001.01000000.0000000A.sdmp, nss3.dll.0.dr, nss3[1].dll.0.dr |
Source: |
Binary string: mozglue.pdb source: file.exe, 00000000.00000002.2593670616.000000006F8DD000.00000002.00000001.01000000.0000000B.sdmp, mozglue[1].dll.0.dr, mozglue.dll.0.dr |
Source: |
Binary string: softokn3.pdb source: softokn3[1].dll.0.dr, softokn3.dll.0.dr |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_007940F0 wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,lstrcatA,lstrcatA,lstrcatA,lstrcatA,lstrcatA,lstrcatA,FindNextFileA,FindClose, |
0_2_007940F0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0078E530 FindFirstFileA,StrCmpCA,StrCmpCA,FindNextFileA, |
0_2_0078E530 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0078BE40 FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,StrCmpCA,StrCmpCA,StrCmpCA,memset,lstrcatA,lstrcatA,lstrcatA,memset,lstrcatA,lstrcatA,lstrcatA,memset,lstrcatA,lstrcatA,lstrcatA,StrCmpCA,CopyFileA,StrCmpCA,DeleteFileA,StrCmpCA,FindNextFileA,FindClose, |
0_2_0078BE40 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00794B60 wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,wsprintfA,StrCmpCA,wsprintfA,wsprintfA,PathMatchSpecA,lstrcatA,lstrcatA,lstrcatA,lstrcatA,lstrcatA,CopyFileA,DeleteFileA,FindNextFileA,FindClose, |
0_2_00794B60 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00781710 FindFirstFileA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose, |
0_2_00781710 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0078F7B0 FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose, |
0_2_0078F7B0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0078DB80 FindFirstFileA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,StrCmpCA,FindNextFileA,FindClose, |
0_2_0078DB80 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0078EE20 wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,lstrlenA,DeleteFileA,CopyFileA,FindNextFileA,FindClose, |
0_2_0078EE20 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_0078DF10 FindFirstFileA,StrCmpCA,StrCmpCA,CopyFileA,DeleteFileA,FindNextFileA,FindClose, |
0_2_0078DF10 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00793B00 wsprintfA,FindFirstFileA,lstrcatA,StrCmpCA,StrCmpCA,wsprintfA,PathMatchSpecA,CoInitialize,CoUninitialize,lstrcatA,lstrlenA,StrCmpCA,wsprintfA,wsprintfA,PathMatchSpecA,wsprintfA,CopyFileA,__ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z,DeleteFileA,FindNextFileA,FindClose, |
0_2_00793B00 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_007947C0 GetProcessHeap,HeapAlloc,wsprintfA,FindFirstFileA,StrCmpCA,StrCmpCA,wsprintfA,CopyFileA,DeleteFileA,FindNextFileA,FindClose,lstrcatA,lstrcatA,lstrlenA,lstrlenA, |
0_2_007947C0 |
Source: C:\Users\user\Desktop\file.exe |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\bg\ |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\html\ |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\ |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\ |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\ |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\css\ |
Jump to behavior |
Source: Network traffic |
Suricata IDS: 2044243 - Severity 1 - ET MALWARE [SEKOIA.IO] Win32/Stealc C2 Check-in : 192.168.2.5:49704 -> 185.215.113.206:80 |
Source: Network traffic |
Suricata IDS: 2044244 - Severity 1 - ET MALWARE Win32/Stealc Requesting browsers Config from C2 : 192.168.2.5:49704 -> 185.215.113.206:80 |
Source: Network traffic |
Suricata IDS: 2044245 - Severity 1 - ET MALWARE Win32/Stealc Active C2 Responding with browsers Config : 185.215.113.206:80 -> 192.168.2.5:49704 |
Source: Network traffic |
Suricata IDS: 2044246 - Severity 1 - ET MALWARE Win32/Stealc Requesting plugins Config from C2 : 192.168.2.5:49704 -> 185.215.113.206:80 |
Source: Network traffic |
Suricata IDS: 2044247 - Severity 1 - ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config : 185.215.113.206:80 -> 192.168.2.5:49704 |
Source: Network traffic |
Suricata IDS: 2044248 - Severity 1 - ET MALWARE Win32/Stealc Submitting System Information to C2 : 192.168.2.5:49704 -> 185.215.113.206:80 |