Windows Analysis Report
lcc222.exe

Overview

General Information

Sample name: lcc222.exe
Analysis ID: 1562225
MD5: 06c6aa662ce822503bc39a1c80169b51
SHA1: 6d152057b2a41eb434208443554816e5a60db444
SHA256: 36b395baef52c38bb9f327a43371a58a030d9a558038c40924f87a54058bbe1d
Tags: exemalwaretrojanuser-Joker
Infos:

Detection

Score: 30
Range: 0 - 100
Whitelisted: false
Confidence: 20%

Signatures

AI detected suspicious sample
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to detect virtual machines (SGDT)
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query CPU information (cpuid)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Extensive use of GetProcAddress (often used to hide API calls)
Found dropped PE file which has not been started or loaded
Found evasive API chain checking for process token information
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
IP address seen in connection with other malware
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)

Classification

AV Detection

barindex
Source: Submited Sample Integrated Neural Analysis Model: Matched 99.3% probability
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB704C00 CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error, 2_2_00007FFBAB704C00
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB764C40 ERR_new,ERR_set_debug,X509_get0_pubkey,ERR_new,ERR_set_debug,CRYPTO_malloc,ERR_new,ERR_set_debug,RAND_bytes_ex,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,EVP_PKEY_CTX_new_from_pkey,EVP_PKEY_encrypt_init,EVP_PKEY_encrypt,EVP_PKEY_encrypt,EVP_PKEY_CTX_free,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_clear_free,EVP_PKEY_CTX_free, 2_2_00007FFBAB764C40
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB74EC70 CRYPTO_free, 2_2_00007FFBAB74EC70
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB748C80 CRYPTO_free, 2_2_00007FFBAB748C80
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7022D9 CRYPTO_malloc,CONF_parse_list,CRYPTO_memdup,CRYPTO_free,CRYPTO_free, 2_2_00007FFBAB7022D9
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701AB4 CRYPTO_free,CRYPTO_free,CRYPTO_free,ERR_new,ERR_set_debug,CRYPTO_free,ERR_new,ERR_set_debug,ERR_new,CRYPTO_free,CRYPTO_memdup,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_new,ERR_set_debug, 2_2_00007FFBAB701AB4
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB74EC10 CRYPTO_free, 2_2_00007FFBAB74EC10
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701460 CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error,BIO_snprintf, 2_2_00007FFBAB701460
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB716B20 CRYPTO_THREAD_run_once,OPENSSL_sk_find,OPENSSL_sk_value,EVP_CIPHER_fetch,EVP_CIPHER_get_flags, 2_2_00007FFBAB716B20
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB71EB48 CRYPTO_free, 2_2_00007FFBAB71EB48
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701A0F ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,EVP_CIPHER_CTX_get0_cipher,EVP_CIPHER_get_flags,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,EVP_MD_CTX_get0_md,EVP_MD_get_size,CRYPTO_memcmp,ERR_set_mark,ERR_clear_last_mark,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_pop_to_mark,ERR_clear_last_mark,ERR_new,ERR_set_debug,CRYPTO_free,CRYPTO_free,EVP_MD_CTX_get0_md,CRYPTO_memcmp,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_new,strncmp,strncmp,strncmp,strncmp,strncmp,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_set_debug, 2_2_00007FFBAB701A0F
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB704B30 CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error, 2_2_00007FFBAB704B30
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB72EB10 CRYPTO_THREAD_write_lock,OPENSSL_LH_retrieve,OPENSSL_LH_delete,CRYPTO_THREAD_unlock, 2_2_00007FFBAB72EB10
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701A05 ERR_new,ERR_set_debug,ERR_set_error,ASN1_item_free,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,memcpy,memcpy,_time64,X509_free,memcpy,CRYPTO_free,ERR_new,ERR_set_debug,CRYPTO_free,CRYPTO_free,ASN1_item_free, 2_2_00007FFBAB701A05
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701492 ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,CRYPTO_free, 2_2_00007FFBAB701492
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB742A50 SRP_Calc_u_ex,BN_num_bits,CRYPTO_malloc,ERR_new,ERR_set_debug,BN_bn2bin,BN_clear_free,BN_clear_free, 2_2_00007FFBAB742A50
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70114F CRYPTO_free,ERR_new,ERR_set_debug, 2_2_00007FFBAB70114F
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701893 ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_strdup,ERR_new,ERR_set_debug, 2_2_00007FFBAB701893
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7017DF ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_realloc,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_realloc,ERR_new,ERR_set_debug,ERR_set_error, 2_2_00007FFBAB7017DF
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70204F CRYPTO_free,CRYPTO_malloc,ERR_new,RAND_bytes_ex,ERR_new,ERR_new,ERR_new,ERR_new,ERR_set_debug, 2_2_00007FFBAB70204F
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7024EB CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_set_debug, 2_2_00007FFBAB7024EB
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7589F0 CRYPTO_free,CRYPTO_memdup, 2_2_00007FFBAB7589F0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB74E920 CRYPTO_free, 2_2_00007FFBAB74E920
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB714930 CRYPTO_get_ex_new_index, 2_2_00007FFBAB714930
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701EE2 CRYPTO_free,CRYPTO_strndup,CRYPTO_free,OPENSSL_cleanse,_time64,memcpy,EVP_MD_get0_name,EVP_MD_is_a,ERR_new,ERR_set_debug,OPENSSL_cleanse,ERR_new,OPENSSL_cleanse,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_new,ERR_new,EVP_MD_get_size,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_new,ERR_set_debug, 2_2_00007FFBAB701EE2
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB702185 ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,EVP_PKEY_get1_encoded_public_key,CRYPTO_free,ERR_new,ERR_new,ERR_set_debug,EVP_PKEY_free,CRYPTO_free,ERR_new,ERR_set_debug, 2_2_00007FFBAB702185
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB714990 i2d_X509_NAME,i2d_X509_NAME,memcmp,CRYPTO_free,CRYPTO_free, 2_2_00007FFBAB714990
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB74E8C0 CRYPTO_free, 2_2_00007FFBAB74E8C0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7026B2 ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,CRYPTO_strdup, 2_2_00007FFBAB7026B2
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB76C8E0 CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,memcpy,CRYPTO_free,CRYPTO_free,CRYPTO_free, 2_2_00007FFBAB76C8E0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB77A8F0 EVP_PKEY_CTX_new_from_pkey,ERR_new,ERR_set_debug,EVP_PKEY_decrypt_init,ERR_new,ERR_set_debug,X509_get0_pubkey,ERR_clear_error,ASN1_item_d2i,ASN1_TYPE_get,ERR_new,ERR_set_debug,EVP_PKEY_decrypt,ERR_new,EVP_PKEY_CTX_ctrl,ERR_new,ERR_new,ERR_set_debug,EVP_PKEY_CTX_free,ASN1_item_free, 2_2_00007FFBAB77A8F0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70139D memcpy,CRYPTO_THREAD_read_lock,OPENSSL_LH_retrieve,CRYPTO_THREAD_unlock,CRYPTO_THREAD_unlock, 2_2_00007FFBAB70139D
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB702117 ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_free,CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_free,CRYPTO_free,CRYPTO_memdup,ERR_new,ERR_set_debug, 2_2_00007FFBAB702117
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB704FD0 CRYPTO_free, 2_2_00007FFBAB704FD0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB765070 BN_num_bits,BN_bn2bin,CRYPTO_free,CRYPTO_strdup,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug, 2_2_00007FFBAB765070
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB77B070 ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_free,CRYPTO_strndup,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_set_debug,CRYPTO_free,CRYPTO_memdup,OPENSSL_cleanse,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug, 2_2_00007FFBAB77B070
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB72F070 CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error,_time64,CRYPTO_THREAD_lock_new,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,ERR_new,ERR_set_debug,CRYPTO_new_ex_data,CRYPTO_THREAD_lock_free,ERR_new,ERR_set_debug,memcpy, 2_2_00007FFBAB72F070
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB729080 CRYPTO_free,EVP_PKEY_free,CRYPTO_free, 2_2_00007FFBAB729080
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7020E5 CRYPTO_free,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug, 2_2_00007FFBAB7020E5
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB702144 EVP_CIPHER_get_mode,EVP_CIPHER_get_mode,EVP_CIPHER_get_iv_length,EVP_CIPHER_get_key_length,CRYPTO_malloc,ERR_new,ERR_set_debug, 2_2_00007FFBAB702144
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7017E9 ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,memcmp,CRYPTO_free,CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,memcmp,ERR_new,CRYPTO_memdup,ERR_new,ERR_new,ERR_new,ERR_set_debug, 2_2_00007FFBAB7017E9
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70CEA0 CRYPTO_free,OPENSSL_sk_pop_free,CRYPTO_free,CRYPTO_clear_free,CRYPTO_free,CRYPTO_free,EVP_PKEY_free,EVP_PKEY_free,CRYPTO_free,CRYPTO_free,memset,CRYPTO_free, 2_2_00007FFBAB70CEA0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB772EE0 CRYPTO_memcmp, 2_2_00007FFBAB772EE0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70236A CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error,memcpy,CRYPTO_free,CRYPTO_free, 2_2_00007FFBAB70236A
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB748E90 CRYPTO_malloc,CRYPTO_free,CRYPTO_malloc,ERR_new,ERR_set_debug, 2_2_00007FFBAB748E90
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70117C _time64,OPENSSL_LH_retrieve,OPENSSL_LH_delete,CRYPTO_THREAD_unlock, 2_2_00007FFBAB70117C
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB71EDC1 ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,ERR_new,ERR_set_debug,ERR_set_error,BUF_MEM_free,EVP_MD_CTX_free,X509_free,X509_VERIFY_PARAM_move_peername,CRYPTO_free, 2_2_00007FFBAB71EDC1
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701771 CRYPTO_free, 2_2_00007FFBAB701771
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701811 CRYPTO_free,CRYPTO_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free, 2_2_00007FFBAB701811
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701B54 memcmp,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_set_debug,memcmp,EVP_CIPHER_CTX_free,CRYPTO_free,ERR_new,ERR_set_debug,CRYPTO_free,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,memcmp,memcmp,ERR_new,ERR_set_debug,memcpy,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_free,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_new,ERR_set_debug,CRYPTO_free, 2_2_00007FFBAB701B54
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB71EDC1 ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,ERR_new,ERR_set_debug,ERR_set_error,BUF_MEM_free,EVP_MD_CTX_free,X509_free,X509_VERIFY_PARAM_move_peername,CRYPTO_free, 2_2_00007FFBAB71EDC1
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB71CD30 CRYPTO_free,CRYPTO_free,CRYPTO_free_ex_data,OPENSSL_LH_free,X509_STORE_free,CTLOG_STORE_free,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,OPENSSL_sk_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_secure_free,EVP_MD_get0_provider,EVP_MD_free,EVP_MD_get0_provider,EVP_MD_free,EVP_CIPHER_get0_provider,EVP_CIPHER_free,EVP_MD_get0_provider,EVP_MD_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_THREAD_lock_free,CRYPTO_free,CRYPTO_free, 2_2_00007FFBAB71CD30
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70136B ERR_new,ERR_set_debug,CRYPTO_THREAD_read_lock,CRYPTO_THREAD_unlock,ERR_new,ERR_set_debug,CRYPTO_THREAD_unlock,CRYPTO_THREAD_unlock,memset,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug, 2_2_00007FFBAB70136B
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB748D40 OPENSSL_cleanse,CRYPTO_free, 2_2_00007FFBAB748D40
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701CBC EVP_MD_get_size,ERR_new,ERR_set_debug,RAND_bytes_ex,ERR_new,ERR_set_debug,_time64,CRYPTO_free,CRYPTO_memdup,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug, 2_2_00007FFBAB701CBC
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70222F ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_clear_free, 2_2_00007FFBAB70222F
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB758CA0 CRYPTO_free,CRYPTO_strndup, 2_2_00007FFBAB758CA0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70257C ERR_new,ERR_set_debug,CRYPTO_free,BIO_clear_flags,BIO_set_flags,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,memcpy,OPENSSL_cleanse, 2_2_00007FFBAB70257C
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB71E427 CRYPTO_THREAD_write_lock, 2_2_00007FFBAB71E427
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70198D CRYPTO_THREAD_write_lock,CRYPTO_THREAD_unlock, 2_2_00007FFBAB70198D
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701AC3 CRYPTO_THREAD_read_lock,CRYPTO_THREAD_unlock, 2_2_00007FFBAB701AC3
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB734490 CRYPTO_realloc,memcpy,ERR_new,ERR_set_debug,ERR_set_error, 2_2_00007FFBAB734490
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701D93 EVP_CIPHER_CTX_free,EVP_CIPHER_CTX_free,EVP_CIPHER_CTX_free,CRYPTO_zalloc,EVP_MAC_CTX_free,EVP_MAC_free,CRYPTO_free,EVP_CIPHER_CTX_free,EVP_MAC_fetch,EVP_MAC_CTX_new,EVP_MAC_free,EVP_CIPHER_CTX_new,EVP_CIPHER_fetch,OSSL_PARAM_construct_utf8_string,OSSL_PARAM_construct_end,EVP_MAC_init,EVP_DecryptInit_ex,EVP_CIPHER_free,EVP_CIPHER_free,EVP_CIPHER_free,EVP_MAC_CTX_get_mac_size,EVP_CIPHER_CTX_get_iv_length,EVP_MAC_final,CRYPTO_memcmp,CRYPTO_malloc,CRYPTO_free,CRYPTO_free,memcpy,ERR_clear_error,CRYPTO_free,EVP_CIPHER_CTX_free,EVP_MAC_CTX_free,CRYPTO_free, 2_2_00007FFBAB701D93
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7018B6 CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error, 2_2_00007FFBAB7018B6
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7643C0 EVP_MD_CTX_new,EVP_DigestInit,EVP_DigestUpdate,EVP_DigestUpdate,EVP_DigestFinal_ex,EVP_MD_CTX_free,CRYPTO_malloc,EVP_PKEY_CTX_ctrl,EVP_PKEY_encrypt,EVP_PKEY_CTX_free,ERR_new,ERR_set_debug,EVP_PKEY_CTX_free,CRYPTO_clear_free,ERR_new,ERR_set_debug, 2_2_00007FFBAB7643C0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB76A3D0 ERR_new,ERR_set_debug,CRYPTO_free,CRYPTO_free,CRYPTO_strndup,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug, 2_2_00007FFBAB76A3D0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7023DD EVP_MD_get_size,EVP_CIPHER_get_iv_length,EVP_CIPHER_get_key_length,CRYPTO_clear_free,CRYPTO_malloc,ERR_new,ERR_set_debug, 2_2_00007FFBAB7023DD
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB722410 ERR_new,ERR_set_debug,ERR_set_error,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_zalloc,CRYPTO_THREAD_lock_new,CRYPTO_free,ERR_new,ERR_set_debug,ERR_set_error,OPENSSL_sk_dup,X509_VERIFY_PARAM_new,X509_VERIFY_PARAM_inherit,CRYPTO_memdup,CRYPTO_memdup,CRYPTO_malloc,memcpy,CRYPTO_new_ex_data, 2_2_00007FFBAB722410
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB760330 CRYPTO_free,CRYPTO_strndup, 2_2_00007FFBAB760330
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB704300 CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error, 2_2_00007FFBAB704300
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701B31 CRYPTO_free,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug, 2_2_00007FFBAB701B31
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB712360 CRYPTO_THREAD_run_once, 2_2_00007FFBAB712360
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB758390 CRYPTO_free,CRYPTO_free,CRYPTO_free, 2_2_00007FFBAB758390
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB74E200 CRYPTO_free,CRYPTO_strdup,ERR_new,ERR_set_debug,CRYPTO_free,ERR_new,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug, 2_2_00007FFBAB74E200
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701389 CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error, 2_2_00007FFBAB701389
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB704100 CRYPTO_free, 2_2_00007FFBAB704100
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7019DD BN_copy,BN_free,BN_dup,BN_copy,BN_free,BN_dup,BN_copy,BN_free,BN_dup,BN_copy,BN_free,CRYPTO_free,CRYPTO_strdup, 2_2_00007FFBAB7019DD
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7015E6 CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error,memcpy,CRYPTO_free,ERR_new,ERR_set_debug,ERR_set_error,ERR_new,ERR_set_debug,ERR_set_error,ERR_new,ERR_set_debug,ERR_set_error,memcpy,ERR_new,ERR_set_debug,ERR_set_error,ERR_new,ERR_set_debug,ERR_set_error, 2_2_00007FFBAB7015E6
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701F55 CRYPTO_THREAD_write_lock,CRYPTO_THREAD_unlock, 2_2_00007FFBAB701F55
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB74E190 CRYPTO_free, 2_2_00007FFBAB74E190
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7600A0 CRYPTO_free,CRYPTO_memdup, 2_2_00007FFBAB7600A0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7220A0 memcpy,CRYPTO_THREAD_read_lock,OPENSSL_LH_retrieve,CRYPTO_THREAD_unlock, 2_2_00007FFBAB7220A0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70E0AD ERR_set_debug,CRYPTO_free,CRYPTO_strdup,ERR_new, 2_2_00007FFBAB70E0AD
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7580C0 CRYPTO_memdup,CRYPTO_memdup,CRYPTO_memdup,CRYPTO_free,CRYPTO_free,CRYPTO_free, 2_2_00007FFBAB7580C0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701361 CRYPTO_malloc,EVP_PKEY_set_type,EVP_PKEY_CTX_new_from_pkey,EVP_PKEY_CTX_free,ERR_pop_to_mark,CRYPTO_free,EVP_PKEY_free, 2_2_00007FFBAB701361
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB702423 CRYPTO_zalloc,CRYPTO_zalloc,OBJ_nid2sn,EVP_get_digestbyname,OBJ_nid2sn,EVP_get_digestbyname,CRYPTO_free,CRYPTO_free,ERR_new,ERR_set_debug,ERR_set_error, 2_2_00007FFBAB702423
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB764860 ERR_new,ERR_set_debug,memset,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_memdup,CRYPTO_strdup,CRYPTO_free,CRYPTO_free,ERR_new,ERR_new,ERR_set_debug,OPENSSL_cleanse,OPENSSL_cleanse,CRYPTO_clear_free,CRYPTO_clear_free, 2_2_00007FFBAB764860
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB778870 ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,OPENSSL_sk_free,OPENSSL_sk_free,CRYPTO_free,CRYPTO_free,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,memcmp,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,OPENSSL_sk_num,OPENSSL_sk_value,OPENSSL_sk_num,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,memcpy,OPENSSL_sk_num,OPENSSL_sk_value,OPENSSL_sk_num,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_memcmp,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,OPENSSL_sk_free,OPENSSL_sk_dup,OPENSSL_sk_free,OPENSSL_sk_dup,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,OPENSSL_sk_num,OPENSSL_sk_value,OPENSSL_sk_num,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,OPENSSL_sk_num,OPENSSL_sk_value,OPENSSL_sk_free,ERR_new,ERR_set_debug,OPENSSL_sk_free,OPENSSL_sk_free,CRYPTO_free,CRYPTO_free, 2_2_00007FFBAB778870
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701401 CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,CRYPTO_free, 2_2_00007FFBAB701401
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701F28 ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,CRYPTO_strdup, 2_2_00007FFBAB701F28
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701CA3 CRYPTO_strdup,CRYPTO_free, 2_2_00007FFBAB701CA3
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7025F4 CRYPTO_malloc,ERR_new,ERR_set_debug,memcpy,memcpy,memcmp,memcmp,memcmp,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_clear_free, 2_2_00007FFBAB7025F4
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701F3C CRYPTO_malloc,ERR_new,ERR_set_debug, 2_2_00007FFBAB701F3C
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7016A4 CRYPTO_free,CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug, 2_2_00007FFBAB7016A4
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB74E781 CRYPTO_free,CRYPTO_free, 2_2_00007FFBAB74E781
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7426B0 ERR_new,ERR_set_debug,BN_num_bits,CRYPTO_malloc,ERR_new,ERR_set_debug,BN_bn2bin,ERR_new,ERR_set_debug,BN_clear_free,BN_clear_free,CRYPTO_clear_free,ERR_new,ERR_set_debug,BN_clear_free,BN_clear_free,BN_clear_free, 2_2_00007FFBAB7426B0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB71A6D0 CRYPTO_free,CRYPTO_free,OPENSSL_sk_pop_free,CRYPTO_free, 2_2_00007FFBAB71A6D0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70103C CRYPTO_malloc,COMP_expand_block, 2_2_00007FFBAB70103C
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB74E700 CRYPTO_free, 2_2_00007FFBAB74E700
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70120D EVP_PKEY_free,EVP_PKEY_free,CRYPTO_free,OPENSSL_sk_pop_free,CRYPTO_free,CRYPTO_clear_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,memset, 2_2_00007FFBAB70120D
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB758620 CRYPTO_memcmp, 2_2_00007FFBAB758620
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7024CD CRYPTO_free,CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error,memcpy, 2_2_00007FFBAB7024CD
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB766650 EVP_CIPHER_CTX_free,CRYPTO_free,ERR_new,ERR_set_debug,CRYPTO_free, 2_2_00007FFBAB766650
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7013D9 OPENSSL_sk_new_null,ERR_new,ERR_set_debug,X509_new_ex,d2i_X509,CRYPTO_free,OPENSSL_sk_push,CRYPTO_free,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_set_error,ERR_new,ERR_new,ERR_set_debug,X509_free,OPENSSL_sk_pop_free, 2_2_00007FFBAB7013D9
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB744660 CRYPTO_malloc,memset,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,ERR_new,ERR_set_debug, 2_2_00007FFBAB744660
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70162C EVP_MD_CTX_new,ERR_new,ERR_set_debug,ERR_new,EVP_MD_get0_name,EVP_DigestSignInit_ex,ERR_new,ERR_set_debug,EVP_PKEY_CTX_set_rsa_padding,EVP_PKEY_CTX_set_rsa_pss_saltlen,ERR_new,EVP_DigestSignUpdate,EVP_DigestSignFinal,CRYPTO_malloc,EVP_DigestSignFinal,ERR_new,ERR_new,EVP_DigestSign,ERR_new,CRYPTO_malloc,EVP_DigestSign,BUF_reverse,ERR_new,CRYPTO_free,EVP_MD_CTX_free,ERR_new,ERR_new,ERR_new,ERR_set_debug,CRYPTO_free,EVP_MD_CTX_free, 2_2_00007FFBAB70162C
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7085A0 CRYPTO_zalloc,CRYPTO_free, 2_2_00007FFBAB7085A0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7205E0 X509_VERIFY_PARAM_free,CRYPTO_free_ex_data,BIO_pop,BIO_free,BIO_free_all,BIO_free_all,BUF_MEM_free,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,SCT_LIST_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,EVP_MD_CTX_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,ASYNC_WAIT_CTX_free,CRYPTO_free,OPENSSL_sk_free,CRYPTO_THREAD_lock_free,CRYPTO_free, 2_2_00007FFBAB7205E0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701212 CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free, 2_2_00007FFBAB701212
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB714530 OPENSSL_sk_num,X509_STORE_CTX_new_ex,ERR_new,ERR_set_debug,ERR_set_error,OPENSSL_sk_value,X509_STORE_CTX_init,ERR_new,ERR_set_debug,ERR_set_error,X509_STORE_CTX_free,X509_STORE_CTX_set_flags,CRYPTO_THREAD_run_once,X509_STORE_CTX_set_ex_data,OPENSSL_sk_num,X509_STORE_CTX_set0_dane,X509_STORE_CTX_set_default,X509_VERIFY_PARAM_set1,X509_STORE_CTX_set_verify_cb,X509_verify_cert,X509_STORE_CTX_get_error,OPENSSL_sk_pop_free,X509_STORE_CTX_get0_chain,X509_STORE_CTX_get1_chain,ERR_new,ERR_set_debug,ERR_set_error,X509_VERIFY_PARAM_move_peername,X509_STORE_CTX_free, 2_2_00007FFBAB714530
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB776550 CRYPTO_memcmp, 2_2_00007FFBAB776550
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7026E4 BIO_s_file,BIO_new,ERR_new,ERR_set_debug,BIO_ctrl,ERR_new,ERR_set_debug,strncmp,ERR_new,ERR_set_debug,strncmp,CRYPTO_realloc,memcpy,CRYPTO_free,CRYPTO_free,CRYPTO_free,PEM_read_bio,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,BIO_free, 2_2_00007FFBAB7026E4
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701488 CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error, 2_2_00007FFBAB701488
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701ACD ERR_new,ERR_set_debug,CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,memcpy,memcpy,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_new,memcpy,ERR_new,memcpy,CRYPTO_free,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_new,ERR_new,ERR_new,ERR_set_debug,CRYPTO_free,CRYPTO_free, 2_2_00007FFBAB701ACD
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7019E7 CRYPTO_free, 2_2_00007FFBAB7019E7
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701483 CRYPTO_free,CRYPTO_strndup,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug, 2_2_00007FFBAB701483
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB761B9F CRYPTO_free,ERR_new,ERR_set_debug,CRYPTO_free, 2_2_00007FFBAB761B9F
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB72DBA0 CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error,_time64,CRYPTO_THREAD_lock_new,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_new_ex_data,CRYPTO_THREAD_lock_free,CRYPTO_free, 2_2_00007FFBAB72DBA0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB715BB0 OPENSSL_sk_new,COMP_get_type,CRYPTO_malloc,OPENSSL_sk_push,CRYPTO_free,OPENSSL_sk_sort, 2_2_00007FFBAB715BB0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70155A ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,EVP_PKEY_get1_encoded_public_key,ERR_new,ERR_set_debug,EVP_PKEY_free,CRYPTO_free,ERR_new,ERR_set_debug,EVP_PKEY_free,CRYPTO_free,ERR_new,ERR_set_debug,CRYPTO_free,ERR_new,ERR_set_debug,CRYPTO_free,ERR_new,ERR_set_debug, 2_2_00007FFBAB70155A
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701582 CRYPTO_free,CRYPTO_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free, 2_2_00007FFBAB701582
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB77BB70 OPENSSL_sk_new_null,ERR_new,ERR_set_debug,X509_new_ex,d2i_X509,CRYPTO_free,CRYPTO_memcmp,ERR_new,ERR_set_debug,OPENSSL_sk_push,OPENSSL_sk_num,ERR_new,ERR_set_debug,CRYPTO_free,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,X509_free,OPENSSL_sk_pop_free,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,OPENSSL_sk_value,X509_get0_pubkey,ERR_new,ERR_set_debug,X509_free,OPENSSL_sk_shift,OPENSSL_sk_pop_free,ERR_new,ERR_set_debug, 2_2_00007FFBAB77BB70
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB725B90 CRYPTO_zalloc,CRYPTO_zalloc,OBJ_nid2sn,EVP_get_digestbyname,OBJ_nid2sn,EVP_get_digestbyname,CRYPTO_free,CRYPTO_free,ERR_new,ERR_set_debug,ERR_set_error, 2_2_00007FFBAB725B90
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB72FAF0 CRYPTO_malloc,CRYPTO_free,ERR_new,ERR_set_debug,ERR_set_error,X509_chain_up_ref,CRYPTO_strdup,CRYPTO_strdup,CRYPTO_dup_ex_data,CRYPTO_strdup,CRYPTO_memdup,CRYPTO_memdup,CRYPTO_strdup,CRYPTO_memdup, 2_2_00007FFBAB72FAF0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB74FB00 CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_free,ERR_new,ERR_set_debug, 2_2_00007FFBAB74FB00
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB76BA20 CRYPTO_free,CRYPTO_free,CRYPTO_free, 2_2_00007FFBAB76BA20
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701A15 CRYPTO_THREAD_write_lock,CRYPTO_THREAD_unlock, 2_2_00007FFBAB701A15
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB763A60 ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,EVP_PKEY_get1_encoded_public_key,ERR_new,ERR_set_debug,EVP_PKEY_free,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_free,EVP_PKEY_free, 2_2_00007FFBAB763A60
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB749A60 ERR_new,ERR_set_debug,EVP_MD_CTX_get0_md,EVP_MD_get_size,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_memcmp,ERR_set_mark,ERR_pop_to_mark,ERR_new,ERR_set_debug,ERR_clear_last_mark,EVP_MD_CTX_get0_md,CRYPTO_memcmp,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_free, 2_2_00007FFBAB749A60
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB717A60 CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,CRYPTO_malloc,CRYPTO_free,ERR_new,ERR_set_debug,ERR_set_error,strncmp,CRYPTO_free,CRYPTO_free,OPENSSL_sk_new_null,CRYPTO_free,OPENSSL_sk_num,OPENSSL_sk_value,OPENSSL_sk_push,OPENSSL_sk_delete,OPENSSL_sk_num,OPENSSL_sk_push,CRYPTO_free,OPENSSL_sk_free,CRYPTO_free,OPENSSL_sk_free, 2_2_00007FFBAB717A60
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7011DB EVP_PKEY_free,X509_free,EVP_PKEY_free,OPENSSL_sk_pop_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,X509_STORE_free,X509_STORE_free,CRYPTO_free,CRYPTO_THREAD_lock_free,CRYPTO_free, 2_2_00007FFBAB7011DB
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701A41 CRYPTO_free,CRYPTO_memdup,ERR_new,ERR_set_debug,memcmp,ERR_new,ERR_set_debug,CRYPTO_memdup,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug, 2_2_00007FFBAB701A41
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB743A00 CRYPTO_free,CRYPTO_free,OPENSSL_cleanse,CRYPTO_free,CRYPTO_free,OPENSSL_cleanse,CRYPTO_free,CRYPTO_free, 2_2_00007FFBAB743A00
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701E6A ERR_new,ERR_set_debug,CRYPTO_clear_free, 2_2_00007FFBAB701E6A
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB751970 ERR_new,ERR_set_debug,EVP_PKEY_get1_encoded_public_key,CRYPTO_free,ERR_new,ERR_set_debug,EVP_PKEY_free,CRYPTO_free, 2_2_00007FFBAB751970
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70105F ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_free,EVP_PKEY_free,CRYPTO_free,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_set_debug,CRYPTO_clear_free,CRYPTO_clear_free, 2_2_00007FFBAB70105F
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB74D980 RAND_bytes_ex,CRYPTO_malloc,memset, 2_2_00007FFBAB74D980
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70589C BIO_get_data,BIO_get_init,BIO_clear_flags,BIO_set_init,CRYPTO_free,CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error,BIO_set_init,BIO_clear_flags,BIO_get_data,BIO_set_shutdown,BIO_push,BIO_set_next,BIO_up_ref,BIO_set_init, 2_2_00007FFBAB70589C
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7338C0 CRYPTO_malloc,CRYPTO_realloc,ERR_new,ERR_set_debug,ERR_set_error,memset,OSSL_PARAM_locate_const,CRYPTO_strdup,ERR_new,ERR_set_debug,OSSL_PARAM_locate_const,CRYPTO_strdup,ERR_new,OSSL_PARAM_locate_const,OSSL_PARAM_locate_const,CRYPTO_strdup,ERR_new,OSSL_PARAM_locate_const,OSSL_PARAM_get_uint,OSSL_PARAM_locate_const,OSSL_PARAM_get_uint,ERR_new,OSSL_PARAM_locate_const,OSSL_PARAM_locate_const,OSSL_PARAM_get_int,OSSL_PARAM_locate_const,OSSL_PARAM_get_int,OSSL_PARAM_locate_const,OSSL_PARAM_get_int,ERR_set_mark,EVP_KEYMGMT_free,ERR_pop_to_mark,ERR_new,ERR_new,ERR_new,ERR_new,ERR_new,ERR_new,ERR_new,ERR_new,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,CRYPTO_free,CRYPTO_free, 2_2_00007FFBAB7338C0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7013DE EVP_MD_CTX_new,ERR_new,ERR_set_debug,EVP_PKEY_free,CRYPTO_free,EVP_MD_CTX_free,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,EVP_PKEY_get_security_bits,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,EVP_PKEY_free,EVP_PKEY_get_bn_param,EVP_PKEY_get_bn_param,ERR_new,ERR_set_debug,EVP_PKEY_free,CRYPTO_free,EVP_MD_CTX_free,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,EVP_PKEY_get1_encoded_public_key,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,EVP_PKEY_free,CRYPTO_free,EVP_MD_CTX_free,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,BN_num_bits,BN_num_bits,memset,BN_num_bits,BN_bn2bin,CRYPTO_free,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,EVP_MD_get0_name,EVP_DigestSignInit_ex,ERR_new,ERR_set_debug,EVP_PKEY_CTX_set_rsa_padding,EVP_PKEY_CTX_set_rsa_pss_saltlen,ERR_new,ERR_set_debug,EVP_DigestSign,CRYPTO_free,EVP_PKEY_free,CRYPTO_free,EVP_MD_CTX_free,BN_free,BN_free,BN_free,BN_free,CRYPTO_free,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug, 2_2_00007FFBAB7013DE
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701654 EVP_MD_CTX_new,ERR_new,ERR_set_debug,X509_get0_pubkey,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,EVP_PKEY_get_id,EVP_PKEY_get_id,EVP_PKEY_get_id,ERR_new,EVP_MD_get0_name,EVP_DigestVerifyInit_ex,ERR_new,ERR_set_debug,CRYPTO_malloc,ERR_new,ERR_set_debug,BUF_reverse,EVP_PKEY_CTX_set_rsa_padding,EVP_PKEY_CTX_set_rsa_pss_saltlen,ERR_new,EVP_MD_CTX_ctrl,ERR_new,ERR_set_debug,ERR_new,EVP_DigestVerify,ERR_new,ERR_new,ERR_new,ERR_set_debug,BIO_free,EVP_MD_CTX_free,CRYPTO_free, 2_2_00007FFBAB701654
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB77B900 BN_bin2bn,ERR_new,ERR_set_debug,CRYPTO_free,CRYPTO_strdup,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug, 2_2_00007FFBAB77B900
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70F910 ERR_new,ERR_set_debug,EVP_PKEY_CTX_new_from_pkey,CRYPTO_malloc,CRYPTO_malloc,EVP_PKEY_encapsulate,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_clear_free,CRYPTO_free,EVP_PKEY_CTX_free, 2_2_00007FFBAB70F910
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB726030 ERR_new,ERR_set_debug,ERR_set_error,ERR_new,ERR_set_debug,ERR_set_error,ERR_new,ERR_set_debug,ERR_set_error,EVP_MD_get_size,ERR_new,ERR_set_debug,ERR_set_error,ERR_new,ERR_set_debug,ERR_set_error,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_malloc,CRYPTO_free,EVP_PKEY_free,CRYPTO_free,ERR_new,ERR_set_debug,ERR_set_error,memcpy,OPENSSL_sk_num,OPENSSL_sk_value,OPENSSL_sk_insert,CRYPTO_free,EVP_PKEY_free,CRYPTO_free,ERR_new,ERR_set_debug,ERR_set_error,EVP_PKEY_free,EVP_PKEY_free,CRYPTO_free,EVP_PKEY_free,CRYPTO_free,ERR_new,ERR_set_debug,ERR_set_error,d2i_X509,X509_get0_pubkey,X509_free,CRYPTO_free,EVP_PKEY_free,CRYPTO_free,ERR_new,ERR_set_debug,ERR_set_error,X509_free,OPENSSL_sk_new_null,OPENSSL_sk_push,ERR_new,ERR_set_debug,ERR_set_error,X509_free,CRYPTO_free,EVP_PKEY_free,CRYPTO_free,X509_free,CRYPTO_free,EVP_PKEY_free,CRYPTO_free,ERR_new,ERR_set_debug,ERR_set_error,ERR_new,ERR_set_debug,ERR_set_error, 2_2_00007FFBAB726030
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7023EC CRYPTO_free,CRYPTO_memdup, 2_2_00007FFBAB7023EC
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB71C080 CRYPTO_free,CRYPTO_memdup, 2_2_00007FFBAB71C080
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB702527 CRYPTO_free,CRYPTO_memdup,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug, 2_2_00007FFBAB702527
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70DFB5 CRYPTO_free,CRYPTO_strdup,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug, 2_2_00007FFBAB70DFB5
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701019 ERR_new,ERR_set_debug,CRYPTO_free,CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug, 2_2_00007FFBAB701019
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70202C CRYPTO_free, 2_2_00007FFBAB70202C
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB715F20 CRYPTO_THREAD_run_once, 2_2_00007FFBAB715F20
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701C53 CRYPTO_free,CRYPTO_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free, 2_2_00007FFBAB701C53
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB763F30 ERR_new,ERR_set_debug,X509_get0_pubkey,EVP_PKEY_CTX_new_from_pkey,ERR_new,ERR_set_debug,CRYPTO_malloc,EVP_PKEY_encrypt_init,RAND_bytes_ex,EVP_MD_CTX_new,EVP_DigestInit,EVP_DigestUpdate,EVP_DigestUpdate,EVP_DigestFinal_ex,EVP_MD_CTX_free,EVP_PKEY_CTX_ctrl,EVP_PKEY_encrypt,EVP_PKEY_CTX_free,ERR_new,ERR_set_debug,EVP_PKEY_CTX_free,CRYPTO_clear_free,EVP_MD_CTX_free, 2_2_00007FFBAB763F30
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB71BF30 CRYPTO_memcmp, 2_2_00007FFBAB71BF30
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB76DF40 CRYPTO_malloc,ERR_new,ERR_set_debug,memcpy, 2_2_00007FFBAB76DF40
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB705EE0 BIO_get_data,BIO_get_shutdown,BIO_get_init,BIO_clear_flags,BIO_set_init,CRYPTO_free, 2_2_00007FFBAB705EE0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701B18 ERR_new,ERR_set_debug,memset,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,OPENSSL_cleanse,CRYPTO_free,CRYPTO_memdup,ERR_new,ERR_new,ERR_set_debug,OPENSSL_cleanse,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,CRYPTO_memcmp,ERR_new,ERR_new, 2_2_00007FFBAB701B18
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB703EB0 CRYPTO_free, 2_2_00007FFBAB703EB0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70107D CRYPTO_free, 2_2_00007FFBAB70107D
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB702680 CRYPTO_THREAD_write_lock,CRYPTO_THREAD_unlock, 2_2_00007FFBAB702680
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB76BE20 CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free, 2_2_00007FFBAB76BE20
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7025DB CRYPTO_malloc,ERR_new,ERR_set_debug,memcpy,ERR_new,ERR_set_debug, 2_2_00007FFBAB7025DB
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70150F OPENSSL_sk_num,OPENSSL_sk_num,OPENSSL_sk_new_reserve,ERR_new,ERR_set_debug,ERR_set_error,OPENSSL_sk_value,X509_VERIFY_PARAM_get_depth,CRYPTO_dup_ex_data,X509_VERIFY_PARAM_inherit,OPENSSL_sk_dup,OPENSSL_sk_dup, 2_2_00007FFBAB70150F
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB702720 CRYPTO_free,CRYPTO_strdup, 2_2_00007FFBAB702720
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB702310 ERR_new,ERR_set_debug,_time64,CRYPTO_free,CRYPTO_malloc,ERR_new,ERR_new,EVP_MD_fetch,ERR_new,ERR_new,ERR_set_debug,EVP_MD_free,EVP_MD_get_size,ERR_new,ERR_set_debug,CRYPTO_free,ERR_new,ERR_set_debug,EVP_MD_free,CRYPTO_free, 2_2_00007FFBAB702310
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70108C ERR_new,ERR_set_debug,CRYPTO_free, 2_2_00007FFBAB70108C
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB725E10 ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_realloc,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_realloc,ERR_new,ERR_set_debug,ERR_set_error, 2_2_00007FFBAB725E10
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB763D20 ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,EVP_PKEY_get1_encoded_public_key,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_free,EVP_PKEY_free, 2_2_00007FFBAB763D20
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB725D20 CRYPTO_free,CRYPTO_free, 2_2_00007FFBAB725D20
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701CEE CRYPTO_malloc,memset,memcpy,memcpy,CRYPTO_clear_free,CRYPTO_clear_free,CRYPTO_clear_free,CRYPTO_clear_free,OPENSSL_cleanse, 2_2_00007FFBAB701CEE
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701D89 CRYPTO_free,CRYPTO_memdup, 2_2_00007FFBAB701D89
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB705C9B CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error,BIO_set_init,BIO_set_data,BIO_clear_flags, 2_2_00007FFBAB705C9B
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB715CB0 COMP_zlib,OPENSSL_sk_new,COMP_get_type,CRYPTO_malloc,COMP_get_name,OPENSSL_sk_push,CRYPTO_free,OPENSSL_sk_sort, 2_2_00007FFBAB715CB0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB713CC0 CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_THREAD_lock_new,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free, 2_2_00007FFBAB713CC0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7023F1 CRYPTO_memdup,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,CRYPTO_free, 2_2_00007FFBAB7023F1
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB702595 CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free, 2_2_00007FFBAB702595
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB77B430 ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_malloc,ERR_new,ERR_set_debug,EVP_PKEY_CTX_new_from_pkey,ERR_new,ERR_set_debug,EVP_PKEY_decrypt_init,EVP_PKEY_CTX_set_rsa_padding,OSSL_PARAM_construct_uint,OSSL_PARAM_construct_end,EVP_PKEY_CTX_set_params,EVP_PKEY_decrypt,OPENSSL_cleanse,ERR_new,ERR_new,ERR_new,ERR_set_debug,CRYPTO_free,EVP_PKEY_CTX_free, 2_2_00007FFBAB77B430
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB702126 memcpy,CRYPTO_THREAD_read_lock,OPENSSL_LH_retrieve,CRYPTO_THREAD_unlock,CRYPTO_THREAD_unlock,memcmp,ERR_new,ERR_set_debug,_time64,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug, 2_2_00007FFBAB702126
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB773480 CRYPTO_free,CRYPTO_strndup, 2_2_00007FFBAB773480
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701393 OSSL_PROVIDER_do_all,CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error,memcpy, 2_2_00007FFBAB701393
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70D3CA CRYPTO_free, 2_2_00007FFBAB70D3CA
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701444 EVP_MD_CTX_new,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,EVP_MD_CTX_free,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_memcmp,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,memcpy,memcpy, 2_2_00007FFBAB701444
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701997 ERR_new,ERR_set_debug,EVP_PKEY_CTX_new_from_pkey,CRYPTO_malloc,ERR_new,ERR_set_debug,EVP_PKEY_decapsulate,ERR_new,ERR_new,ERR_set_debug,CRYPTO_clear_free,EVP_PKEY_CTX_free, 2_2_00007FFBAB701997
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70195B CRYPTO_zalloc,EVP_MAC_free,EVP_MAC_CTX_free,CRYPTO_free, 2_2_00007FFBAB70195B
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701A32 CRYPTO_free,CRYPTO_memdup,ERR_new,ERR_set_debug, 2_2_00007FFBAB701A32
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7392E0 CRYPTO_free,CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error, 2_2_00007FFBAB7392E0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7017F8 EVP_MD_CTX_new,EVP_PKEY_new_raw_private_key_ex,EVP_DigestSignInit_ex,EVP_DigestSign,EVP_MD_CTX_free,EVP_PKEY_free,CRYPTO_memcmp,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,_time64,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,EVP_MD_CTX_free,EVP_PKEY_free,ERR_new,ERR_set_debug,EVP_MD_CTX_free,EVP_PKEY_free,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug, 2_2_00007FFBAB7017F8
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70111D CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_THREAD_lock_new,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,EVP_PKEY_up_ref,X509_up_ref,EVP_PKEY_up_ref,X509_chain_up_ref,CRYPTO_malloc,memcpy,CRYPTO_malloc,memcpy,ERR_new,ERR_set_debug,ERR_set_error,EVP_PKEY_free,X509_free,EVP_PKEY_free,OPENSSL_sk_pop_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,X509_STORE_free,X509_STORE_free,CRYPTO_free,CRYPTO_THREAD_lock_free,CRYPTO_free,ERR_new,CRYPTO_malloc,memcpy,CRYPTO_memdup,X509_STORE_up_ref,X509_STORE_up_ref,CRYPTO_strdup, 2_2_00007FFBAB70111D
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70B300 CRYPTO_clear_free, 2_2_00007FFBAB70B300
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701677 CRYPTO_THREAD_write_lock,OPENSSL_LH_retrieve,OPENSSL_LH_delete,CRYPTO_THREAD_unlock, 2_2_00007FFBAB701677
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70D227 CRYPTO_free,CRYPTO_strdup,ERR_new,ERR_set_debug,ERR_set_error,ERR_new,ERR_set_debug,ERR_set_error,ERR_new,ERR_set_debug,ERR_set_error, 2_2_00007FFBAB70D227
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB767230 CRYPTO_free,ERR_new,ERR_set_debug,CRYPTO_free, 2_2_00007FFBAB767230
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701B90 CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free, 2_2_00007FFBAB701B90
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701262 X509_free,EVP_PKEY_free,OPENSSL_sk_pop_free,CRYPTO_free, 2_2_00007FFBAB701262
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701F8C CRYPTO_free,CRYPTO_malloc,ERR_new,ERR_set_debug, 2_2_00007FFBAB701F8C
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB773260 CRYPTO_free,CRYPTO_memdup, 2_2_00007FFBAB773260
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701A23 BN_dup,BN_dup,BN_dup,BN_dup,BN_dup,BN_dup,BN_dup,BN_dup,CRYPTO_strdup,CRYPTO_strdup,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,CRYPTO_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free, 2_2_00007FFBAB701A23
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB749120 CRYPTO_malloc,ERR_new,ERR_set_debug, 2_2_00007FFBAB749120
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7011A9 EVP_MAC_CTX_free,CRYPTO_free, 2_2_00007FFBAB7011A9
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70F160 CRYPTO_free,CRYPTO_memdup, 2_2_00007FFBAB70F160
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB761170 ERR_new,ERR_set_debug,CRYPTO_clear_free, 2_2_00007FFBAB761170
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB72D170 CRYPTO_THREAD_write_lock,OPENSSL_sk_new_null,OPENSSL_LH_delete,OPENSSL_sk_push,OPENSSL_LH_set_down_load,CRYPTO_THREAD_unlock,OPENSSL_sk_pop_free, 2_2_00007FFBAB72D170
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7014CE CRYPTO_free,CRYPTO_free,CRYPTO_memdup,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_set_debug, 2_2_00007FFBAB7014CE
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7430A0 CRYPTO_free,CRYPTO_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free, 2_2_00007FFBAB7430A0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7021DF CRYPTO_memcmp, 2_2_00007FFBAB7021DF
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB702374 CRYPTO_free,CRYPTO_memdup,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug, 2_2_00007FFBAB702374
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7350D8 EVP_MAC_CTX_free,CRYPTO_free, 2_2_00007FFBAB7350D8
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB717840 CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free, 2_2_00007FFBAB717840
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB719870 CRYPTO_free,CRYPTO_strdup, 2_2_00007FFBAB719870
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7577A0 CRYPTO_malloc,CRYPTO_malloc,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free, 2_2_00007FFBAB7577A0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7617A1 CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_set_debug, 2_2_00007FFBAB7617A1
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701087 ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_THREAD_run_once,CRYPTO_THREAD_run_once, 2_2_00007FFBAB701087
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7757FE CRYPTO_free,CRYPTO_memdup,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug, 2_2_00007FFBAB7757FE
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701023 ERR_new,ERR_set_debug,CRYPTO_free,CRYPTO_free, 2_2_00007FFBAB701023
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB751750 CRYPTO_free,CRYPTO_memdup, 2_2_00007FFBAB751750
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7011BD CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error,memcpy,CRYPTO_free,CRYPTO_free, 2_2_00007FFBAB7011BD
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7012CB CRYPTO_THREAD_run_once, 2_2_00007FFBAB7012CB
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7456D0 CRYPTO_free, 2_2_00007FFBAB7456D0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB711620 CRYPTO_free,CRYPTO_strndup, 2_2_00007FFBAB711620
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB773650 CRYPTO_malloc,ERR_new,ERR_set_debug,EVP_CIPHER_CTX_new,ERR_new,ERR_new,ERR_new,ERR_set_debug,EVP_CIPHER_fetch,EVP_CIPHER_get_iv_length,RAND_bytes_ex,EVP_CIPHER_free,EVP_EncryptUpdate,EVP_EncryptFinal,ERR_new,ERR_new,CRYPTO_free,EVP_CIPHER_CTX_free,ERR_new,ERR_new,ERR_set_debug,EVP_CIPHER_CTX_get_iv_length,ERR_new,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_set_debug,CRYPTO_free,EVP_CIPHER_CTX_free, 2_2_00007FFBAB773650
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70F650 EVP_PKEY_CTX_new_from_pkey,EVP_PKEY_derive_set_peer,EVP_PKEY_is_a,CRYPTO_malloc,ERR_new,ERR_set_debug,EVP_PKEY_derive,ERR_new,ERR_new,ERR_set_debug,CRYPTO_clear_free,EVP_PKEY_CTX_free,ERR_new,ERR_set_debug, 2_2_00007FFBAB70F650
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB76B660 CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free, 2_2_00007FFBAB76B660
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB702469 CRYPTO_memcmp,ERR_new,ERR_set_debug,memchr,ERR_new,CRYPTO_free,CRYPTO_free,CRYPTO_strndup,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug, 2_2_00007FFBAB702469
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7021E9 ERR_new,ERR_set_debug,CRYPTO_free,CRYPTO_malloc,ERR_new,ERR_set_debug,memcpy,ERR_new,ERR_set_debug, 2_2_00007FFBAB7021E9
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701181 CRYPTO_free,CRYPTO_free,CRYPTO_free, 2_2_00007FFBAB701181
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB702379 CRYPTO_free, 2_2_00007FFBAB702379
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70110E EVP_PKEY_free,ERR_new,ERR_set_debug,CRYPTO_free,CRYPTO_free,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,EVP_MD_CTX_new,ERR_new,ERR_set_debug,EVP_DigestVerifyInit_ex,ERR_new,ERR_set_debug,ERR_new,CRYPTO_free,ERR_new,ERR_set_debug,EVP_MD_CTX_free,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,EVP_MD_CTX_free, 2_2_00007FFBAB70110E
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70193D CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error, 2_2_00007FFBAB70193D
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB757570 CRYPTO_realloc, 2_2_00007FFBAB757570
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7020F4 CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,CRYPTO_free,CRYPTO_free, 2_2_00007FFBAB7020F4
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701EDD CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error,OPENSSL_sk_find,CRYPTO_free,ERR_new,ERR_set_debug,OPENSSL_sk_push,CRYPTO_free,ERR_new,ERR_new,ERR_set_debug,ERR_set_error, 2_2_00007FFBAB701EDD
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7514E0 CRYPTO_memcmp, 2_2_00007FFBAB7514E0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701992 ERR_new,ERR_set_debug,ERR_set_error,ERR_new,ERR_set_debug,ERR_set_error,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_zalloc,CRYPTO_THREAD_lock_new,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,CRYPTO_strdup,OPENSSL_LH_new,X509_STORE_new,CTLOG_STORE_new_ex,OPENSSL_sk_num,X509_VERIFY_PARAM_new,OPENSSL_sk_new_null,OPENSSL_sk_new_null,CRYPTO_new_ex_data,CRYPTO_secure_zalloc,RAND_bytes_ex,RAND_priv_bytes_ex,RAND_priv_bytes_ex,RAND_priv_bytes_ex,ERR_new,ERR_set_debug, 2_2_00007FFBAB701992
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB72D510 CRYPTO_free_ex_data,OPENSSL_cleanse,OPENSSL_cleanse,X509_free,OPENSSL_sk_pop_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_THREAD_lock_free,CRYPTO_clear_free, 2_2_00007FFBAB72D510
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBB1885218 ASN1_STRING_type,ASN1_STRING_length,ASN1_STRING_get0_data,_Py_BuildValue_SizeT,ASN1_STRING_to_UTF8,_Py_Dealloc,_Py_BuildValue_SizeT,CRYPTO_free, 2_2_00007FFBB1885218
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBB1884F60 i2d_X509,PyBytes_FromStringAndSize,CRYPTO_free, 2_2_00007FFBB1884F60
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBB62918C0 _Py_NoneStruct,_PyArg_UnpackKeywords,PyObject_GetBuffer,PyBuffer_IsContiguous,PyObject_GetBuffer,PyBuffer_IsContiguous,PyLong_AsUnsignedLong,PyLong_AsUnsignedLong,PyLong_AsUnsignedLong,EVP_PBE_scrypt,PyBytes_FromStringAndSize,PyEval_SaveThread,EVP_PBE_scrypt,PyEval_RestoreThread,PyExc_ValueError,PyErr_SetString,PyBuffer_Release,PyBuffer_Release,PyLong_AsLong,PyErr_Occurred,PyLong_AsLong,PyErr_Occurred,PyExc_ValueError,PyExc_ValueError,PyErr_Format,_PyArg_BadArgument,_PyArg_BadArgument,_PyArg_BadArgument,PyExc_TypeError,PyErr_Occurred,PyExc_TypeError,PyErr_Occurred,PyExc_TypeError,PyErr_Occurred,PyExc_TypeError,_PyArg_BadArgument,_PyArg_BadArgument,PyExc_OverflowError,PyExc_OverflowError,_Py_Dealloc,PyExc_ValueError, 2_2_00007FFBB62918C0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBB6296344 CRYPTO_memcmp, 2_2_00007FFBB6296344
Source: lcc222.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Source: Binary string: D:\a\1\b\bin\amd64\select.pdb source: lcc222.exe, 00000000.00000003.1387312374.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2643298480.00007FFBC3133000.00000002.00000001.01000000.00000007.sdmp, select.pyd.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\python312.pdb source: lcc222.exe, 00000002.00000002.2641573933.00007FFBAA782000.00000002.00000001.01000000.00000004.sdmp, python312.dll.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\unicodedata.pdb source: lcc222.exe, 00000000.00000003.1387486648.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2642175555.00007FFBAB66F000.00000002.00000001.01000000.00000011.sdmp, unicodedata.pyd.0.dr
Source: Binary string: D:\a\1\b\libcrypto-3.pdb| source: lcc222.exe, 00000002.00000002.2641163696.00007FFBA9F2A000.00000002.00000001.01000000.00000009.sdmp, libcrypto-3.dll.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\_hashlib.pdb source: lcc222.exe, 00000000.00000003.1379843975.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2642923064.00007FFBB6297000.00000002.00000001.01000000.0000000B.sdmp, _hashlib.pyd.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\_decimal.pdb$$ source: _decimal.pyd.0.dr
Source: Binary string: D:\a\1\b\libssl-3.pdbDD source: lcc222.exe, 00000002.00000002.2642684009.00007FFBAB785000.00000002.00000001.01000000.0000000A.sdmp, libssl-3.dll.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\_lzma.pdbNN source: lcc222.exe, 00000000.00000003.1380012134.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2642466250.00007FFBAB6CC000.00000002.00000001.01000000.0000000E.sdmp, _lzma.pyd.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\_decimal.pdb source: _decimal.pyd.0.dr
Source: Binary string: @ compiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -D"OPENSSL_BUILDING_OPENSSL" -D"OPENSSL_SYS_WIN32" -D"WIN32_LEAN_AND_MEAN" -D"UNICODE" -D"_UNICODE" -D"_CRT_SECURE_NO_DEPRECATE" -D"_WINSOCK_DEPRECATED_NO_WARNINGS" -D"NDEBUG"OpenSSL 3.0.15 3 Sep 20243.0.15built on: Wed Sep 4 15:52:04 2024 UTCplatform: VC-WIN64A-masmOPENSSLDIR: "C:\Program Files\Common Files\SSL"ENGINESDIR: "C:\Program Files\OpenSSL\lib\engines-3"MODULESDIR: "C:\Program Files\OpenSSL\lib\ossl-modules"CPUINFO: N/Anot availableget_and_lock..\s\crypto\ex_data.cossl_crypto_get_ex_new_index_exossl_crypto_new_ex_data_exCRYPTO_dup_ex_dataCRYPTO_set_ex_dataOPENSSL_WIN32_UTF8..\s\crypto\getenv.ccompiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -D"OPENSSL_BUILDING_OPENSSL" -D"OPENSSL_SYS_WIN32" -D"WIN32_LEAN_AND_MEAN" -D"UNICODE" -D"_UNICODE" -D"_CRT_SECURE_NO_DEPRECATE" -D"_WINSOCK_DEPRECATED_NO_WARNINGS" -D"NDEBUG";CPUINFO: OPENSSL_ia32cap=0x%llx:0x%llxOPENSSL_ia32cap env:%sos-specificC:\Program Files\Common Files\SSLC:\Program Files\OpenSSL\lib\ossl-modules.dllCPUINFO: ..\s\crypto\init.cOPENSSL_init_cryptoOPENSSL_atexit..\s\crypto\initthread.c..\s\crypto\mem_sec.cassertion failed: (bit & 1) == 0assertion failed: list >= 0 && list < sh.freelist_sizeassertion failed: ((ptr - sh.arena) & ((sh.arena_size >> list) - 1)) == 0assertion failed: bit > 0 && bit < sh.bittable_sizeassertion failed: TESTBIT(table, bit)assertion failed: !TESTBIT(table, bit)assertion failed: WITHIN_FREELIST(list)assertion failed: WITHIN_ARENA(ptr)assertion failed: temp->next == NULL || WITHIN_ARENA(temp->next)assertion failed: (char **)temp->next->p_next == listassertion failed: WITHIN_FREELIST(temp2->p_next) || WITHIN_ARENA(temp2->p_next)assertion failed: size > 0assertion failed: (size & (size - 1)) == 0assertion failed: (minsize & (minsize - 1)) == 0assertion failed: sh.freelist != NULLassertion failed: sh.bittable != NULLassertion failed: sh.bitmalloc != NULLassertion failed: !sh_testbit(temp, slist, sh.bitmalloc)assertion failed: temp != sh.freelist[slist]assertion failed: sh.freelist[slist] == tempassertion failed: temp-(sh.arena_size >> slist) == sh_find_my_buddy(temp, slist)assertion failed: sh_testbit(chunk, list, sh.bittable)assertion failed: WITHIN_ARENA(chunk)assertion failed: sh_testbit(ptr, list, sh.bittable)assertion failed: ptr == sh_find_my_buddy(buddy, list)assertion failed: ptr != NULLassertion failed: !sh_testbit(ptr, list, sh.bitmalloc)assertion failed: sh.freelist[list] == ptr/*0123456789ABCDEFCRYPTO_memdup..\s\crypto\o_str.chexstr2buf_sepossl_hexstr2buf_sepbuf2hexstr_sepossl_buf2hexstr_sep..\s\crypto\packet.cwpacket_intern_init_lenWPACKET_start_sub_packet_len__..\s\crypto\param_build.cparam_pushparam_push_numOSSL_PARAM_BLD_push_BN_padNegative big numbers are unsupported for OSSL_PARAMOSSL_PARAM_BLD_push_utf8_stringOSSL_PARAM_BLD_push_utf8_ptrOSSL_PARAM_BLD_push_octet_stringOSSL_PARAM_BLD_p
Source: Binary string: D:\a\1\b\bin\amd64\_queue.pdb source: lcc222.exe, 00000000.00000003.1380193680.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2643218174.00007FFBBC343000.00000002.00000001.01000000.0000000C.sdmp, _queue.pyd.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\_lzma.pdb source: lcc222.exe, 00000000.00000003.1380012134.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2642466250.00007FFBAB6CC000.00000002.00000001.01000000.0000000E.sdmp, _lzma.pyd.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\_bz2.pdb source: lcc222.exe, 00000000.00000003.1379492399.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2642560971.00007FFBAB6EE000.00000002.00000001.01000000.0000000D.sdmp, _bz2.pyd.0.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdb source: lcc222.exe, 00000000.00000003.1379327235.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2643079206.00007FFBBBDA3000.00000002.00000001.01000000.00000005.sdmp, VCRUNTIME140.dll.0.dr
Source: Binary string: compiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -D"OPENSSL_BUILDING_OPENSSL" -D"OPENSSL_SYS_WIN32" -D"WIN32_LEAN_AND_MEAN" -D"UNICODE" -D"_UNICODE" -D"_CRT_SECURE_NO_DEPRECATE" -D"_WINSOCK_DEPRECATED_NO_WARNINGS" -D"NDEBUG" source: lcc222.exe, 00000002.00000002.2641163696.00007FFBA9E92000.00000002.00000001.01000000.00000009.sdmp, libcrypto-3.dll.0.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdbGCTL source: lcc222.exe, 00000000.00000003.1379327235.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2643079206.00007FFBBBDA3000.00000002.00000001.01000000.00000005.sdmp, VCRUNTIME140.dll.0.dr
Source: Binary string: D:\a\1\b\libcrypto-3.pdb source: lcc222.exe, 00000002.00000002.2641163696.00007FFBA9F2A000.00000002.00000001.01000000.00000009.sdmp, libcrypto-3.dll.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\_socket.pdb source: lcc222.exe, 00000000.00000003.1380341133.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2642999969.00007FFBBB6D9000.00000002.00000001.01000000.00000006.sdmp, _socket.pyd.0.dr
Source: Binary string: D:\a\1\b\libssl-3.pdb source: lcc222.exe, 00000002.00000002.2642684009.00007FFBAB785000.00000002.00000001.01000000.0000000A.sdmp, libssl-3.dll.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\_ssl.pdb source: lcc222.exe, 00000002.00000002.2642805804.00007FFBB188D000.00000002.00000001.01000000.00000008.sdmp, _ssl.pyd.0.dr
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA239280 FindFirstFileExW,FindClose, 0_2_00007FF6CA239280
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA2383C0 FindFirstFileW,RemoveDirectoryW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW, 0_2_00007FF6CA2383C0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA251874 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose, 0_2_00007FF6CA251874
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA239280 FindFirstFileExW,FindClose, 2_2_00007FF6CA239280
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA2383C0 FindFirstFileW,RemoveDirectoryW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW, 2_2_00007FF6CA2383C0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA251874 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose, 2_2_00007FF6CA251874
Source: Joe Sandbox View IP Address: 172.66.0.235 172.66.0.235
Source: Joe Sandbox View IP Address: 172.66.0.235 172.66.0.235
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBBB6D65E8 memset,recvfrom, 2_2_00007FFBBB6D65E8
Source: global traffic DNS traffic detected: DNS query: pub-df330fbbea624b19b9a4fa4f71271742.r2.dev
Source: lcc222.exe, 00000002.00000002.2640227518.000001D634820000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://.../back.jpeg
Source: lcc222.exe, 00000000.00000003.1387312374.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380193680.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379843975.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1384321042.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379492399.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380341133.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379643311.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380519987.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1382757973.000001F8625FF000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1382757973.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1387486648.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1385556216.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380012134.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _decimal.pyd.0.dr, _socket.pyd.0.dr, _ssl.pyd.0.dr, _hashlib.pyd.0.dr, libcrypto-3.dll.0.dr, _bz2.pyd.0.dr, _queue.pyd.0.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
Source: lcc222.exe, 00000000.00000003.1387312374.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380193680.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379843975.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1384321042.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379492399.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380341133.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379643311.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380519987.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1382757973.000001F8625FF000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1382757973.000001F8625F9000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1387486648.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1385556216.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380012134.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _decimal.pyd.0.dr, _socket.pyd.0.dr, _ssl.pyd.0.dr, _hashlib.pyd.0.dr, libcrypto-3.dll.0.dr, _bz2.pyd.0.dr, _queue.pyd.0.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
Source: lcc222.exe, 00000000.00000003.1387312374.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380193680.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379843975.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1384321042.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379492399.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380341133.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379643311.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380519987.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1382757973.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1387486648.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1385556216.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380012134.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _decimal.pyd.0.dr, _socket.pyd.0.dr, _ssl.pyd.0.dr, _hashlib.pyd.0.dr, libcrypto-3.dll.0.dr, _bz2.pyd.0.dr, _queue.pyd.0.dr, libssl-3.dll.0.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
Source: lcc222.exe, 00000000.00000003.1387312374.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380193680.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379843975.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1384321042.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379492399.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380341133.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379643311.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380519987.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1382757973.000001F8625F9000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1382757973.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1387486648.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1385556216.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380012134.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _decimal.pyd.0.dr, _socket.pyd.0.dr, _ssl.pyd.0.dr, _hashlib.pyd.0.dr, libcrypto-3.dll.0.dr, _bz2.pyd.0.dr, _queue.pyd.0.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
Source: lcc222.exe, 00000002.00000003.1406902541.000001D633DFF000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639181153.000001D633E02000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://code.activestate.com/recipes/577452-a-memoize-decorator-for-instance-methods/
Source: lcc222.exe, 00000002.00000002.2639687361.000001D6344C3000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639687361.000001D634520000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.certigna.fr/certignarootca.crl01
Source: lcc222.exe, 00000002.00000002.2639687361.000001D6343AF000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2638719821.000001D631F21000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
Source: lcc222.exe, 00000002.00000002.2639687361.000001D63444A000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639687361.000001D6342C1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/COMODOCertificationAuthority.crl
Source: lcc222.exe, 00000002.00000002.2639687361.000001D6342C1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/COMODOCertificationAuthority.crl4
Source: lcc222.exe, 00000002.00000002.2639687361.000001D6344C3000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639687361.000001D634520000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.dhimyotis.com/certignarootca.crl
Source: lcc222.exe, 00000002.00000002.2639687361.000001D6344C3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.dhimyotis.com/certignarootca.crl0
Source: lcc222.exe, 00000002.00000002.2639687361.000001D634520000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.dhimyotis.com/certignarootca.crlL
Source: lcc222.exe, 00000002.00000002.2639687361.000001D6344C3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.dhimyotis.com/certignarootca.crlg
Source: lcc222.exe, 00000002.00000002.2639687361.000001D63444A000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.securetrust.com/SGCA.crl
Source: lcc222.exe, 00000002.00000002.2639687361.000001D6342C1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.securetrust.com/SGCA.crl0
Source: lcc222.exe, 00000002.00000002.2639687361.000001D63444A000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.securetrust.com/STCA.crl
Source: lcc222.exe, 00000002.00000002.2639687361.000001D6342C1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.securetrust.com/STCA.crl0
Source: lcc222.exe, 00000002.00000002.2639687361.000001D63444A000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.securetrust.com/STCA.crlP
Source: lcc222.exe, 00000002.00000002.2639687361.000001D63444A000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.xrampsecurity.com/XGCA.crl
Source: lcc222.exe, 00000002.00000002.2639687361.000001D6343AF000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.xrampsecurity.com/XGCA.crl0
Source: lcc222.exe, 00000000.00000003.1387312374.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380193680.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379843975.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1384321042.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379492399.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380341133.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379643311.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380519987.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1382757973.000001F8625FF000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1382757973.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1387486648.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1385556216.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380012134.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _decimal.pyd.0.dr, _socket.pyd.0.dr, _ssl.pyd.0.dr, _hashlib.pyd.0.dr, libcrypto-3.dll.0.dr, _bz2.pyd.0.dr, _queue.pyd.0.dr String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
Source: lcc222.exe, 00000000.00000003.1387312374.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380193680.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379843975.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1384321042.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379492399.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380341133.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379643311.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380519987.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1382757973.000001F8625FF000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1382757973.000001F8625F9000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1387486648.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1385556216.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380012134.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _decimal.pyd.0.dr, _socket.pyd.0.dr, _ssl.pyd.0.dr, _hashlib.pyd.0.dr, libcrypto-3.dll.0.dr, _bz2.pyd.0.dr, _queue.pyd.0.dr String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Source: lcc222.exe, 00000000.00000003.1387312374.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380193680.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379843975.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1384321042.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379492399.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380341133.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379643311.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380519987.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1382757973.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1387486648.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1385556216.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380012134.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _decimal.pyd.0.dr, _socket.pyd.0.dr, _ssl.pyd.0.dr, _hashlib.pyd.0.dr, libcrypto-3.dll.0.dr, _bz2.pyd.0.dr, _queue.pyd.0.dr, libssl-3.dll.0.dr String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
Source: unicodedata.pyd.0.dr String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
Source: lcc222.exe, 00000000.00000003.1380193680.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeS
Source: lcc222.exe, 00000000.00000003.1387312374.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380193680.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379843975.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1384321042.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379492399.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380341133.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379643311.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380519987.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1382757973.000001F8625FF000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1382757973.000001F8625F9000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1387486648.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1385556216.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380012134.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _decimal.pyd.0.dr, _socket.pyd.0.dr, _ssl.pyd.0.dr, _hashlib.pyd.0.dr, libcrypto-3.dll.0.dr, _bz2.pyd.0.dr, _queue.pyd.0.dr String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0
Source: lcc222.exe, 00000002.00000002.2640227518.000001D634820000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://curl.haxx.se/rfc/cookie_spec.html
Source: lcc222.exe, 00000002.00000003.1406902541.000001D633E9A000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639181153.000001D633E97000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://google.com/
Source: lcc222.exe, 00000002.00000003.1407332245.000001D6342D1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639687361.000001D6342C1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://google.com/mail/
Source: lcc222.exe, 00000002.00000002.2639181153.000001D633F0F000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000003.1406902541.000001D633F0F000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639687361.000001D63426E000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000003.1407332245.000001D63427E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://hg.python.org/cpython/file/603b4d593758/Lib/socket.py#l535
Source: lcc222.exe, 00000002.00000002.2638719821.000001D631F21000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.accv.es
Source: lcc222.exe, 00000002.00000002.2639687361.000001D6344C3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.accv.es0
Source: lcc222.exe, 00000000.00000003.1387312374.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380193680.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379843975.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1384321042.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379492399.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380341133.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379643311.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380519987.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1382757973.000001F8625FF000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1382757973.000001F8625F9000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1387486648.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1385556216.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380012134.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _decimal.pyd.0.dr, _socket.pyd.0.dr, _ssl.pyd.0.dr, _hashlib.pyd.0.dr, libcrypto-3.dll.0.dr, _bz2.pyd.0.dr, _queue.pyd.0.dr String found in binary or memory: http://ocsp.digicert.com0
Source: lcc222.exe, 00000000.00000003.1387312374.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380193680.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379843975.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1384321042.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379492399.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380341133.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379643311.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380519987.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1382757973.000001F8625F9000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1382757973.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1387486648.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1385556216.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380012134.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _decimal.pyd.0.dr, _socket.pyd.0.dr, _ssl.pyd.0.dr, _hashlib.pyd.0.dr, libcrypto-3.dll.0.dr, _bz2.pyd.0.dr, _queue.pyd.0.dr String found in binary or memory: http://ocsp.digicert.com0A
Source: lcc222.exe, 00000000.00000003.1387312374.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380193680.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379843975.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1384321042.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379492399.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380341133.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379643311.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380519987.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1382757973.000001F8625FF000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1382757973.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1387486648.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1385556216.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380012134.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _decimal.pyd.0.dr, _socket.pyd.0.dr, _ssl.pyd.0.dr, _hashlib.pyd.0.dr, libcrypto-3.dll.0.dr, _bz2.pyd.0.dr, _queue.pyd.0.dr String found in binary or memory: http://ocsp.digicert.com0C
Source: lcc222.exe, 00000000.00000003.1387312374.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380193680.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379843975.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1384321042.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379492399.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380341133.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379643311.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380519987.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1382757973.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1387486648.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1385556216.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380012134.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _decimal.pyd.0.dr, _socket.pyd.0.dr, _ssl.pyd.0.dr, _hashlib.pyd.0.dr, libcrypto-3.dll.0.dr, _bz2.pyd.0.dr, _queue.pyd.0.dr, libssl-3.dll.0.dr String found in binary or memory: http://ocsp.digicert.com0X
Source: lcc222.exe, 00000002.00000002.2639687361.000001D63444A000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639687361.000001D634220000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639687361.000001D6342C1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://repository.swisssign.com/
Source: lcc222.exe, 00000002.00000002.2640227518.000001D634820000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://tools.ietf.org/html/rfc6125#section-6.4.3
Source: lcc222.exe, 00000002.00000002.2639687361.000001D6344C3000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2638719821.000001D631F21000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1.crt0
Source: lcc222.exe, 00000002.00000002.2639687361.000001D6344C3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1_der.crl
Source: lcc222.exe, 00000002.00000002.2639687361.000001D6344C3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1_der.crl0
Source: lcc222.exe, 00000002.00000002.2639687361.000001D6344C3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.accv.es/legislacion_c.htm
Source: lcc222.exe, 00000002.00000002.2639687361.000001D6344C3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.accv.es/legislacion_c.htm0U
Source: lcc222.exe, 00000002.00000002.2639687361.000001D6344C3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.accv.es00
Source: lcc222.exe, 00000002.00000002.2639687361.000001D6344C3000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639687361.000001D634346000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.cert.fnmt.es/dpcs/
Source: lcc222.exe, 00000000.00000003.1387312374.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380193680.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379843975.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1384321042.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379492399.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380341133.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1379643311.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380519987.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1382757973.000001F8625FF000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1382757973.000001F8625F9000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1387486648.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1385556216.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000000.00000003.1380012134.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _decimal.pyd.0.dr, _socket.pyd.0.dr, _ssl.pyd.0.dr, _hashlib.pyd.0.dr, libcrypto-3.dll.0.dr, _bz2.pyd.0.dr, _queue.pyd.0.dr String found in binary or memory: http://www.digicert.com/CPS0
Source: lcc222.exe, 00000002.00000002.2639687361.000001D6343AF000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639687361.000001D6342C1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.firmaprofesional.com/cps0
Source: lcc222.exe, 00000002.00000003.1407332245.000001D634229000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639687361.000001D634220000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.iana.org/assignments/tls-parameters/tls-parameters.xml#tls-parameters-6
Source: lcc222.exe, 00000002.00000002.2639687361.000001D63444A000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.quovadisglobal.com/cps
Source: lcc222.exe, 00000002.00000002.2639687361.000001D63444A000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.quovadisglobal.com/cps0
Source: lcc222.exe, 00000002.00000002.2639687361.000001D63444A000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.quovadisglobal.com/cpsd
Source: lcc222.exe, 00000002.00000002.2639687361.000001D634220000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://wwwsearch.sf.net/):
Source: lcc222.exe, 00000002.00000003.1406902541.000001D633E9A000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639181153.000001D633E97000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://docs.python.org/3.11/library/binascii.html#binascii.a2b_base64
Source: lcc222.exe, 00000002.00000003.1392626307.000001D633B6B000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000003.1392321976.000001D633B39000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000003.1392321976.000001D633B45000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2638869887.000001D63388C000.00000004.00001000.00020000.00000000.sdmp, lcc222.exe, 00000002.00000003.1390993911.000001D633B45000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000003.1391611778.000001D633B6B000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000003.1390906056.000001D633BC8000.00000004.00000020.00020000.00000000.sdmp, base_library.zip.0.dr String found in binary or memory: https://docs.python.org/3/howto/mro.html.
Source: lcc222.exe, 00000002.00000002.2638869887.000001D633810000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.ExecutionLoader.get_filename
Source: lcc222.exe, 00000002.00000002.2638869887.000001D63388C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.InspectLoader.get_code
Source: lcc222.exe, 00000002.00000002.2638869887.000001D63388C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.InspectLoader.get_source
Source: lcc222.exe, 00000002.00000002.2638869887.000001D63388C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.InspectLoader.is_package
Source: lcc222.exe, 00000002.00000002.2638869887.000001D633810000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.Loader.create_module
Source: lcc222.exe, 00000002.00000002.2639107806.000001D633C20000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.Loader.exec_module
Source: lcc222.exe, 00000002.00000002.2639107806.000001D633C20000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.MetaPathFinder.invalidate_caches
Source: lcc222.exe, 00000002.00000002.2638869887.000001D63388C000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.PathEntryFinder.find_spec
Source: lcc222.exe, 00000002.00000002.2638719821.000001D631F21000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.ResourceLoader.get_data
Source: lcc222.exe, 00000002.00000002.2640227518.000001D634820000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://docs.python.org/3/library/socket.html#socket.socket.connect_ex
Source: lcc222.exe, 00000002.00000002.2639548169.000001D634020000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://foss.heptapod.net/pypy/pypy/-/issues/3539
Source: lcc222.exe, 00000002.00000002.2639687361.000001D634220000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://github.com/Ousret/charset_normalizer
Source: lcc222.exe, 00000002.00000002.2638719821.000001D631F21000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://github.com/Unidata/MetPy/blob/a3424de66a44bf3a92b0dcacf4dff82ad7b86712/src/metpy/plots/wx_sy
Source: lcc222.exe, 00000002.00000002.2640227518.000001D6348E0000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/psf/requests/pull/6710
Source: lcc222.exe, 00000002.00000002.2638869887.000001D633810000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/python/cpython/blob/3.9/Lib/importlib/_bootstrap_external.py#L679-L688
Source: lcc222.exe, 00000002.00000002.2638719821.000001D631F21000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://github.com/python/cpython/blob/839d7893943782ee803536a47f1d4de160314f85/Lib/importlib/abc.py
Source: lcc222.exe, 00000002.00000002.2638719821.000001D631F21000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://github.com/python/cpython/blob/839d7893943782ee803536a47f1d4de160314f85/Lib/importlib/reader
Source: lcc222.exe, 00000002.00000003.1398565783.000001D633DAC000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639181153.000001D633D51000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000003.1398448076.000001D633E33000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000003.1406902541.000001D633D7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://github.com/python/cpython/issues/86361.
Source: lcc222.exe, 00000002.00000002.2640153988.000001D634720000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/python/importlib_metadata/wiki/Development-Methodology
Source: lcc222.exe, 00000002.00000002.2638719821.000001D631F21000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://github.com/tensorflow/datasets/blob/master/tensorflow_datasets/core/utils/resource_utils.py#
Source: lcc222.exe, 00000002.00000002.2639548169.000001D634020000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/urllib3/urllib3/issues/2192#issuecomment-821832963
Source: lcc222.exe, 00000002.00000003.1406902541.000001D633E9A000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639181153.000001D633E97000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://github.com/urllib3/urllib3/issues/2513#issuecomment-1152559900.
Source: lcc222.exe, 00000002.00000002.2640227518.000001D634820000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/urllib3/urllib3/issues/2920
Source: lcc222.exe, 00000002.00000002.2640153988.000001D634720000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/urllib3/urllib3/issues/3290
Source: lcc222.exe, 00000002.00000002.2640153988.000001D634720000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://github.com/urllib3/urllib3/issues/32902
Source: lcc222.exe, 00000002.00000002.2639181153.000001D633EDC000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639687361.000001D634220000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639018435.000001D633B20000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639018435.000001D633B71000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://google.com/
Source: lcc222.exe, 00000002.00000002.2639181153.000001D633EDC000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639687361.000001D634220000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639018435.000001D633B20000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://google.com/mail
Source: lcc222.exe, 00000002.00000002.2639018435.000001D633B71000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://google.com/mail/
Source: lcc222.exe, 00000002.00000003.1406902541.000001D633E9A000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639181153.000001D633E97000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://html.spec.whatwg.org/multipage/
Source: lcc222.exe, 00000002.00000002.2639018435.000001D633B71000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://httpbin.org/
Source: lcc222.exe, 00000002.00000002.2640340509.000001D634920000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://httpbin.org/get
Source: lcc222.exe, 00000002.00000003.1398565783.000001D633DAC000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000003.1397269600.000001D633DE6000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000003.1394281836.000001D633DD1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639181153.000001D633D51000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000003.1395921085.000001D633DEA000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000003.1406902541.000001D633D7F000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000003.1402872571.000001D633DDC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://httpbin.org/post
Source: lcc222.exe, 00000002.00000002.2640153988.000001D634720000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://importlib-resources.readthedocs.io/en/latest/using.html#migrating-from-legacy
Source: lcc222.exe, 00000002.00000002.2639687361.000001D6342C1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://json.org
Source: lcc222.exe, 00000002.00000002.2639687361.000001D6343AF000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://mahler:8092/site-updates.py
Source: lcc222.exe, 00000002.00000002.2639617164.000001D634120000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://packaging.python.org/specifications/entry-points/
Source: lcc222.exe, 00000002.00000002.2639107806.000001D633C20000.00000004.00001000.00020000.00000000.sdmp, base_library.zip.0.dr String found in binary or memory: https://peps.python.org/pep-0205/
Source: lcc222.exe, 00000002.00000002.2641573933.00007FFBAA782000.00000002.00000001.01000000.00000004.sdmp, python312.dll.0.dr String found in binary or memory: https://peps.python.org/pep-0263/
Source: lcc222.exe, 00000002.00000002.2640340509.000001D634990000.00000004.00001000.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2638869887.000001D633810000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://pub-df330fbbea624b19b9a4fa4f71271742.r2.dev/windows.zip
Source: lcc222.exe, 00000002.00000002.2640340509.000001D634990000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://pub-df330fbbea624b19b9a4fa4f71271742.r2.dev/windows.zip0
Source: lcc222.exe, 00000002.00000002.2638869887.000001D633810000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://pub-df330fbbea624b19b9a4fa4f71271742.r2.dev/windows.zipdd
Source: lcc222.exe, 00000002.00000002.2640340509.000001D634920000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://requests.readthedocs.io
Source: lcc222.exe, 00000002.00000002.2639181153.000001D633D51000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000003.1406902541.000001D633D7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://tools.ietf.org/html/rfc2388#section-4.4
Source: lcc222.exe, 00000002.00000003.1406902541.000001D633E23000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639181153.000001D633E23000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://tools.ietf.org/html/rfc7231#section-4.3.6)
Source: lcc222.exe, 00000002.00000002.2639181153.000001D633EDC000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639018435.000001D633B71000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://twitter.com/
Source: lcc222.exe, 00000002.00000003.1406902541.000001D633DFF000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639181153.000001D633E02000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://urllib3.readthedocs.io/en/latest/advanced-usage.html
Source: lcc222.exe, 00000002.00000002.2640153988.000001D634720000.00000004.00001000.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639687361.000001D6342C1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000003.1406859944.000001D6342F6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://urllib3.readthedocs.io/en/latest/advanced-usage.html#https-proxy-error-http-proxy
Source: lcc222.exe, 00000002.00000002.2640083651.000001D634620000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://urllib3.readthedocs.io/en/latest/advanced-usage.html#tls-warnings
Source: lcc222.exe, 00000000.00000003.1384321042.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2642723951.00007FFBAB7C0000.00000002.00000001.01000000.0000000A.sdmp, lcc222.exe, 00000002.00000002.2641361232.00007FFBA9FD4000.00000002.00000001.01000000.00000009.sdmp, libcrypto-3.dll.0.dr, libssl-3.dll.0.dr String found in binary or memory: https://www.openssl.org/H
Source: lcc222.exe, 00000002.00000003.1398565783.000001D633DAC000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000003.1397269600.000001D633DE6000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000003.1394281836.000001D633DD1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639181153.000001D633D51000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000003.1395921085.000001D633DEA000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000003.1406902541.000001D633D7F000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000003.1402872571.000001D633DDC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.python.org
Source: lcc222.exe, 00000002.00000002.2639687361.000001D6343AF000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.python.org/
Source: lcc222.exe, 00000002.00000002.2641872223.00007FFBAA8F8000.00000008.00000001.01000000.00000004.sdmp, python312.dll.0.dr String found in binary or memory: https://www.python.org/psf/license/
Source: lcc222.exe, 00000002.00000002.2641573933.00007FFBAA782000.00000002.00000001.01000000.00000004.sdmp, python312.dll.0.dr String found in binary or memory: https://www.python.org/psf/license/)
Source: lcc222.exe, 00000002.00000002.2639181153.000001D633D51000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000003.1406902541.000001D633D7F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.rfc-editor.org/rfc/rfc8259#section-8.1
Source: lcc222.exe, 00000002.00000002.2639687361.000001D6344C3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://wwww.certigna.fr/autorites/
Source: lcc222.exe, 00000002.00000002.2639687361.000001D6344C3000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639687361.000001D634520000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://wwww.certigna.fr/autorites/0m
Source: lcc222.exe, 00000002.00000002.2639181153.000001D633EDC000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639687361.000001D634220000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2639018435.000001D633B20000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://yahoo.com/
Source: unknown Network traffic detected: HTTP traffic on port 49707 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49707
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA255C00 0_2_00007FF6CA255C00
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA256964 0_2_00007FF6CA256964
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA2389E0 0_2_00007FF6CA2389E0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA231000 0_2_00007FF6CA231000
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA2508C8 0_2_00007FF6CA2508C8
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA241B50 0_2_00007FF6CA241B50
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA256418 0_2_00007FF6CA256418
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA2508C8 0_2_00007FF6CA2508C8
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA242C10 0_2_00007FF6CA242C10
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA253C10 0_2_00007FF6CA253C10
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA23ACAD 0_2_00007FF6CA23ACAD
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA23A47B 0_2_00007FF6CA23A47B
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA245D30 0_2_00007FF6CA245D30
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA242164 0_2_00007FF6CA242164
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA241944 0_2_00007FF6CA241944
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA2439A4 0_2_00007FF6CA2439A4
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA24DA5C 0_2_00007FF6CA24DA5C
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA23A2DB 0_2_00007FF6CA23A2DB
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA241F60 0_2_00007FF6CA241F60
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA241740 0_2_00007FF6CA241740
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA248794 0_2_00007FF6CA248794
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA239800 0_2_00007FF6CA239800
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA251874 0_2_00007FF6CA251874
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA2540AC 0_2_00007FF6CA2540AC
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA2480E4 0_2_00007FF6CA2480E4
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA24E570 0_2_00007FF6CA24E570
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA241D54 0_2_00007FF6CA241D54
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA2435A0 0_2_00007FF6CA2435A0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA249EA0 0_2_00007FF6CA249EA0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA255E7C 0_2_00007FF6CA255E7C
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA24DEF0 0_2_00007FF6CA24DEF0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA259728 0_2_00007FF6CA259728
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA256964 2_2_00007FF6CA256964
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA231000 2_2_00007FF6CA231000
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA241B50 2_2_00007FF6CA241B50
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA256418 2_2_00007FF6CA256418
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA2508C8 2_2_00007FF6CA2508C8
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA242C10 2_2_00007FF6CA242C10
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA253C10 2_2_00007FF6CA253C10
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA255C00 2_2_00007FF6CA255C00
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA23ACAD 2_2_00007FF6CA23ACAD
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA23A47B 2_2_00007FF6CA23A47B
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA245D30 2_2_00007FF6CA245D30
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA242164 2_2_00007FF6CA242164
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA241944 2_2_00007FF6CA241944
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA2439A4 2_2_00007FF6CA2439A4
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA2389E0 2_2_00007FF6CA2389E0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA24DA5C 2_2_00007FF6CA24DA5C
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA23A2DB 2_2_00007FF6CA23A2DB
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA241F60 2_2_00007FF6CA241F60
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA241740 2_2_00007FF6CA241740
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA248794 2_2_00007FF6CA248794
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA239800 2_2_00007FF6CA239800
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA251874 2_2_00007FF6CA251874
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA2540AC 2_2_00007FF6CA2540AC
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA2480E4 2_2_00007FF6CA2480E4
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA2508C8 2_2_00007FF6CA2508C8
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA24E570 2_2_00007FF6CA24E570
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA241D54 2_2_00007FF6CA241D54
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA2435A0 2_2_00007FF6CA2435A0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA249EA0 2_2_00007FF6CA249EA0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA255E7C 2_2_00007FF6CA255E7C
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA24DEF0 2_2_00007FF6CA24DEF0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA259728 2_2_00007FF6CA259728
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB5612F0 2_2_00007FFBAB5612F0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB561880 2_2_00007FFBAB561880
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB68C480 2_2_00007FFBAB68C480
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB690980 2_2_00007FFBAB690980
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB6B73F8 2_2_00007FFBAB6B73F8
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB6B23B0 2_2_00007FFBAB6B23B0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB6B5F00 2_2_00007FFBAB6B5F00
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB6B12B0 2_2_00007FFBAB6B12B0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB6B2F80 2_2_00007FFBAB6B2F80
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB6B8F40 2_2_00007FFBAB6B8F40
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB6B1A00 2_2_00007FFBAB6B1A00
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB6B55D0 2_2_00007FFBAB6B55D0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB6BFA88 2_2_00007FFBAB6BFA88
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB6B4650 2_2_00007FFBAB6B4650
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB6B1920 2_2_00007FFBAB6B1920
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB6E1000 2_2_00007FFBAB6E1000
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB6E77F8 2_2_00007FFBAB6E77F8
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB6E3DC0 2_2_00007FFBAB6E3DC0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB6E2DC0 2_2_00007FFBAB6E2DC0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB6E6080 2_2_00007FFBAB6E6080
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB6E3B20 2_2_00007FFBAB6E3B20
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB77AC80 2_2_00007FFBAB77AC80
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB702617 2_2_00007FFBAB702617
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701A0F 2_2_00007FFBAB701A0F
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701618 2_2_00007FFBAB701618
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB738920 2_2_00007FFBAB738920
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701EE2 2_2_00007FFBAB701EE2
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB702702 2_2_00007FFBAB702702
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70117C 2_2_00007FFBAB70117C
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701B54 2_2_00007FFBAB701B54
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701CBC 2_2_00007FFBAB701CBC
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70149C 2_2_00007FFBAB70149C
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701D93 2_2_00007FFBAB701D93
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB778870 2_2_00007FFBAB778870
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB708720 2_2_00007FFBAB708720
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70116D 2_2_00007FFBAB70116D
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7016FE 2_2_00007FFBAB7016FE
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70155A 2_2_00007FFBAB70155A
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB745C00 2_2_00007FFBAB745C00
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB72BAE0 2_2_00007FFBAB72BAE0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB749A60 2_2_00007FFBAB749A60
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701596 2_2_00007FFBAB701596
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB74D980 2_2_00007FFBAB74D980
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7013DE 2_2_00007FFBAB7013DE
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701654 2_2_00007FFBAB701654
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB726030 2_2_00007FFBAB726030
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701AD7 2_2_00007FFBAB701AD7
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701546 2_2_00007FFBAB701546
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB74DE50 2_2_00007FFBAB74DE50
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7021E4 2_2_00007FFBAB7021E4
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701FDC 2_2_00007FFBAB701FDC
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB76D2D0 2_2_00007FFBAB76D2D0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7017F8 2_2_00007FFBAB7017F8
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7024DC 2_2_00007FFBAB7024DC
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7021C6 2_2_00007FFBAB7021C6
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB773650 2_2_00007FFBAB773650
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB701C12 2_2_00007FFBAB701C12
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBB1888D64 2_2_00007FFBB1888D64
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBB1889E74 2_2_00007FFBB1889E74
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBB1888660 2_2_00007FFBB1888660
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBB1889A7C 2_2_00007FFBB1889A7C
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBB188BBA0 2_2_00007FFBB188BBA0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBB1885324 2_2_00007FFBB1885324
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBB1885AF8 2_2_00007FFBB1885AF8
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBB62918C0 2_2_00007FFBB62918C0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBB62911A0 2_2_00007FFBB62911A0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBB6291580 2_2_00007FFBB6291580
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBBB6D10C0 2_2_00007FFBBB6D10C0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBBB6D3B20 2_2_00007FFBBB6D3B20
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBBBD97CA0 2_2_00007FFBBBD97CA0
Source: C:\Users\user\Desktop\lcc222.exe Code function: String function: 00007FF6CA232910 appears 34 times
Source: C:\Users\user\Desktop\lcc222.exe Code function: String function: 00007FFBAB701325 appears 471 times
Source: C:\Users\user\Desktop\lcc222.exe Code function: String function: 00007FFBAB77D32F appears 327 times
Source: C:\Users\user\Desktop\lcc222.exe Code function: String function: 00007FFBAB77DB03 appears 45 times
Source: C:\Users\user\Desktop\lcc222.exe Code function: String function: 00007FFBAB77D341 appears 1197 times
Source: C:\Users\user\Desktop\lcc222.exe Code function: String function: 00007FFBAB683880 appears 114 times
Source: C:\Users\user\Desktop\lcc222.exe Code function: String function: 00007FFBAB77D33B appears 43 times
Source: C:\Users\user\Desktop\lcc222.exe Code function: String function: 00007FF6CA232710 appears 104 times
Source: C:\Users\user\Desktop\lcc222.exe Code function: String function: 00007FFBAB77D425 appears 48 times
Source: C:\Users\user\Desktop\lcc222.exe Code function: String function: 00007FFBAB683800 appears 51 times
Source: unicodedata.pyd.0.dr Static PE information: Resource name: RT_VERSION type: COM executable for DOS
Source: lcc222.exe, 00000000.00000003.1379327235.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamevcruntime140.dllT vs lcc222.exe
Source: lcc222.exe, 00000000.00000003.1387312374.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameselect.pyd. vs lcc222.exe
Source: lcc222.exe, 00000000.00000003.1380193680.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_queue.pyd. vs lcc222.exe
Source: lcc222.exe, 00000000.00000003.1379843975.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_hashlib.pyd. vs lcc222.exe
Source: lcc222.exe, 00000000.00000003.1384321042.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamelibsslH vs lcc222.exe
Source: lcc222.exe, 00000000.00000003.1379492399.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_bz2.pyd. vs lcc222.exe
Source: lcc222.exe, 00000000.00000003.1380341133.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_socket.pyd. vs lcc222.exe
Source: lcc222.exe, 00000000.00000003.1379643311.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_decimal.pyd. vs lcc222.exe
Source: lcc222.exe, 00000000.00000003.1380519987.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_ssl.pyd. vs lcc222.exe
Source: lcc222.exe, 00000000.00000003.1387486648.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameunicodedata.pyd. vs lcc222.exe
Source: lcc222.exe, 00000000.00000003.1380012134.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename_lzma.pyd. vs lcc222.exe
Source: lcc222.exe Binary or memory string: OriginalFilename vs lcc222.exe
Source: lcc222.exe, 00000002.00000002.2642723951.00007FFBAB7C0000.00000002.00000001.01000000.0000000A.sdmp Binary or memory string: OriginalFilenamelibsslH vs lcc222.exe
Source: lcc222.exe, 00000002.00000002.2642514410.00007FFBAB6D5000.00000002.00000001.01000000.0000000E.sdmp Binary or memory string: OriginalFilename_lzma.pyd. vs lcc222.exe
Source: lcc222.exe, 00000002.00000002.2641361232.00007FFBA9FD4000.00000002.00000001.01000000.00000009.sdmp Binary or memory string: OriginalFilenamelibcryptoH vs lcc222.exe
Source: lcc222.exe, 00000002.00000002.2643031110.00007FFBBB6E3000.00000002.00000001.01000000.00000006.sdmp Binary or memory string: OriginalFilename_socket.pyd. vs lcc222.exe
Source: lcc222.exe, 00000002.00000002.2643110999.00007FFBBBDA9000.00000002.00000001.01000000.00000005.sdmp Binary or memory string: OriginalFilenamevcruntime140.dllT vs lcc222.exe
Source: lcc222.exe, 00000002.00000002.2643248571.00007FFBBC346000.00000002.00000001.01000000.0000000C.sdmp Binary or memory string: OriginalFilename_queue.pyd. vs lcc222.exe
Source: lcc222.exe, 00000002.00000002.2643331694.00007FFBC3136000.00000002.00000001.01000000.00000007.sdmp Binary or memory string: OriginalFilenameselect.pyd. vs lcc222.exe
Source: lcc222.exe, 00000002.00000002.2642874888.00007FFBB18A9000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: OriginalFilename_ssl.pyd. vs lcc222.exe
Source: lcc222.exe, 00000002.00000002.2642953090.00007FFBB629E000.00000002.00000001.01000000.0000000B.sdmp Binary or memory string: OriginalFilename_hashlib.pyd. vs lcc222.exe
Source: lcc222.exe, 00000002.00000002.2642122758.00007FFBAAA21000.00000002.00000001.01000000.00000004.sdmp Binary or memory string: OriginalFilenamepython312.dll. vs lcc222.exe
Source: lcc222.exe, 00000002.00000002.2642592277.00007FFBAB6F3000.00000002.00000001.01000000.0000000D.sdmp Binary or memory string: OriginalFilename_bz2.pyd. vs lcc222.exe
Source: lcc222.exe, 00000002.00000002.2642339969.00007FFBAB674000.00000002.00000001.01000000.00000011.sdmp Binary or memory string: OriginalFilenameunicodedata.pyd. vs lcc222.exe
Source: classification engine Classification label: sus30.winEXE@3/17@1/1
Source: C:\Users\user\Desktop\lcc222.exe File created: C:\Users\user\AppData\Local\Temp\_MEI72642 Jump to behavior
Source: lcc222.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\lcc222.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe File read: C:\Users\user\Desktop\lcc222.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\lcc222.exe "C:\Users\user\Desktop\lcc222.exe"
Source: C:\Users\user\Desktop\lcc222.exe Process created: C:\Users\user\Desktop\lcc222.exe "C:\Users\user\Desktop\lcc222.exe"
Source: C:\Users\user\Desktop\lcc222.exe Process created: C:\Users\user\Desktop\lcc222.exe "C:\Users\user\Desktop\lcc222.exe" Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Section loaded: python3.dll Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Section loaded: libcrypto-3.dll Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Section loaded: libssl-3.dll Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Section loaded: wintypes.dll Jump to behavior
Source: lcc222.exe Static PE information: Image base 0x140000000 > 0x60000000
Source: lcc222.exe Static file information: File size 8547622 > 1048576
Source: lcc222.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: lcc222.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: lcc222.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: lcc222.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: lcc222.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: lcc222.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: lcc222.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Source: lcc222.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: D:\a\1\b\bin\amd64\select.pdb source: lcc222.exe, 00000000.00000003.1387312374.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2643298480.00007FFBC3133000.00000002.00000001.01000000.00000007.sdmp, select.pyd.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\python312.pdb source: lcc222.exe, 00000002.00000002.2641573933.00007FFBAA782000.00000002.00000001.01000000.00000004.sdmp, python312.dll.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\unicodedata.pdb source: lcc222.exe, 00000000.00000003.1387486648.000001F8625F2000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2642175555.00007FFBAB66F000.00000002.00000001.01000000.00000011.sdmp, unicodedata.pyd.0.dr
Source: Binary string: D:\a\1\b\libcrypto-3.pdb| source: lcc222.exe, 00000002.00000002.2641163696.00007FFBA9F2A000.00000002.00000001.01000000.00000009.sdmp, libcrypto-3.dll.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\_hashlib.pdb source: lcc222.exe, 00000000.00000003.1379843975.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2642923064.00007FFBB6297000.00000002.00000001.01000000.0000000B.sdmp, _hashlib.pyd.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\_decimal.pdb$$ source: _decimal.pyd.0.dr
Source: Binary string: D:\a\1\b\libssl-3.pdbDD source: lcc222.exe, 00000002.00000002.2642684009.00007FFBAB785000.00000002.00000001.01000000.0000000A.sdmp, libssl-3.dll.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\_lzma.pdbNN source: lcc222.exe, 00000000.00000003.1380012134.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2642466250.00007FFBAB6CC000.00000002.00000001.01000000.0000000E.sdmp, _lzma.pyd.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\_decimal.pdb source: _decimal.pyd.0.dr
Source: Binary string: @ compiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -D"OPENSSL_BUILDING_OPENSSL" -D"OPENSSL_SYS_WIN32" -D"WIN32_LEAN_AND_MEAN" -D"UNICODE" -D"_UNICODE" -D"_CRT_SECURE_NO_DEPRECATE" -D"_WINSOCK_DEPRECATED_NO_WARNINGS" -D"NDEBUG"OpenSSL 3.0.15 3 Sep 20243.0.15built on: Wed Sep 4 15:52:04 2024 UTCplatform: VC-WIN64A-masmOPENSSLDIR: "C:\Program Files\Common Files\SSL"ENGINESDIR: "C:\Program Files\OpenSSL\lib\engines-3"MODULESDIR: "C:\Program Files\OpenSSL\lib\ossl-modules"CPUINFO: N/Anot availableget_and_lock..\s\crypto\ex_data.cossl_crypto_get_ex_new_index_exossl_crypto_new_ex_data_exCRYPTO_dup_ex_dataCRYPTO_set_ex_dataOPENSSL_WIN32_UTF8..\s\crypto\getenv.ccompiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -D"OPENSSL_BUILDING_OPENSSL" -D"OPENSSL_SYS_WIN32" -D"WIN32_LEAN_AND_MEAN" -D"UNICODE" -D"_UNICODE" -D"_CRT_SECURE_NO_DEPRECATE" -D"_WINSOCK_DEPRECATED_NO_WARNINGS" -D"NDEBUG";CPUINFO: OPENSSL_ia32cap=0x%llx:0x%llxOPENSSL_ia32cap env:%sos-specificC:\Program Files\Common Files\SSLC:\Program Files\OpenSSL\lib\ossl-modules.dllCPUINFO: ..\s\crypto\init.cOPENSSL_init_cryptoOPENSSL_atexit..\s\crypto\initthread.c..\s\crypto\mem_sec.cassertion failed: (bit & 1) == 0assertion failed: list >= 0 && list < sh.freelist_sizeassertion failed: ((ptr - sh.arena) & ((sh.arena_size >> list) - 1)) == 0assertion failed: bit > 0 && bit < sh.bittable_sizeassertion failed: TESTBIT(table, bit)assertion failed: !TESTBIT(table, bit)assertion failed: WITHIN_FREELIST(list)assertion failed: WITHIN_ARENA(ptr)assertion failed: temp->next == NULL || WITHIN_ARENA(temp->next)assertion failed: (char **)temp->next->p_next == listassertion failed: WITHIN_FREELIST(temp2->p_next) || WITHIN_ARENA(temp2->p_next)assertion failed: size > 0assertion failed: (size & (size - 1)) == 0assertion failed: (minsize & (minsize - 1)) == 0assertion failed: sh.freelist != NULLassertion failed: sh.bittable != NULLassertion failed: sh.bitmalloc != NULLassertion failed: !sh_testbit(temp, slist, sh.bitmalloc)assertion failed: temp != sh.freelist[slist]assertion failed: sh.freelist[slist] == tempassertion failed: temp-(sh.arena_size >> slist) == sh_find_my_buddy(temp, slist)assertion failed: sh_testbit(chunk, list, sh.bittable)assertion failed: WITHIN_ARENA(chunk)assertion failed: sh_testbit(ptr, list, sh.bittable)assertion failed: ptr == sh_find_my_buddy(buddy, list)assertion failed: ptr != NULLassertion failed: !sh_testbit(ptr, list, sh.bitmalloc)assertion failed: sh.freelist[list] == ptr/*0123456789ABCDEFCRYPTO_memdup..\s\crypto\o_str.chexstr2buf_sepossl_hexstr2buf_sepbuf2hexstr_sepossl_buf2hexstr_sep..\s\crypto\packet.cwpacket_intern_init_lenWPACKET_start_sub_packet_len__..\s\crypto\param_build.cparam_pushparam_push_numOSSL_PARAM_BLD_push_BN_padNegative big numbers are unsupported for OSSL_PARAMOSSL_PARAM_BLD_push_utf8_stringOSSL_PARAM_BLD_push_utf8_ptrOSSL_PARAM_BLD_push_octet_stringOSSL_PARAM_BLD_p
Source: Binary string: D:\a\1\b\bin\amd64\_queue.pdb source: lcc222.exe, 00000000.00000003.1380193680.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2643218174.00007FFBBC343000.00000002.00000001.01000000.0000000C.sdmp, _queue.pyd.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\_lzma.pdb source: lcc222.exe, 00000000.00000003.1380012134.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2642466250.00007FFBAB6CC000.00000002.00000001.01000000.0000000E.sdmp, _lzma.pyd.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\_bz2.pdb source: lcc222.exe, 00000000.00000003.1379492399.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2642560971.00007FFBAB6EE000.00000002.00000001.01000000.0000000D.sdmp, _bz2.pyd.0.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdb source: lcc222.exe, 00000000.00000003.1379327235.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2643079206.00007FFBBBDA3000.00000002.00000001.01000000.00000005.sdmp, VCRUNTIME140.dll.0.dr
Source: Binary string: compiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -D"OPENSSL_BUILDING_OPENSSL" -D"OPENSSL_SYS_WIN32" -D"WIN32_LEAN_AND_MEAN" -D"UNICODE" -D"_UNICODE" -D"_CRT_SECURE_NO_DEPRECATE" -D"_WINSOCK_DEPRECATED_NO_WARNINGS" -D"NDEBUG" source: lcc222.exe, 00000002.00000002.2641163696.00007FFBA9E92000.00000002.00000001.01000000.00000009.sdmp, libcrypto-3.dll.0.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdbGCTL source: lcc222.exe, 00000000.00000003.1379327235.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2643079206.00007FFBBBDA3000.00000002.00000001.01000000.00000005.sdmp, VCRUNTIME140.dll.0.dr
Source: Binary string: D:\a\1\b\libcrypto-3.pdb source: lcc222.exe, 00000002.00000002.2641163696.00007FFBA9F2A000.00000002.00000001.01000000.00000009.sdmp, libcrypto-3.dll.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\_socket.pdb source: lcc222.exe, 00000000.00000003.1380341133.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000002.2642999969.00007FFBBB6D9000.00000002.00000001.01000000.00000006.sdmp, _socket.pyd.0.dr
Source: Binary string: D:\a\1\b\libssl-3.pdb source: lcc222.exe, 00000002.00000002.2642684009.00007FFBAB785000.00000002.00000001.01000000.0000000A.sdmp, libssl-3.dll.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\_ssl.pdb source: lcc222.exe, 00000002.00000002.2642805804.00007FFBB188D000.00000002.00000001.01000000.00000008.sdmp, _ssl.pyd.0.dr
Source: lcc222.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: lcc222.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: lcc222.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: lcc222.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: lcc222.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: libcrypto-3.dll.0.dr Static PE information: section name: .00cfg
Source: libssl-3.dll.0.dr Static PE information: section name: .00cfg
Source: python312.dll.0.dr Static PE information: section name: PyRuntim
Source: VCRUNTIME140.dll.0.dr Static PE information: section name: fothk
Source: VCRUNTIME140.dll.0.dr Static PE information: section name: _RDATA
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB6E9B0C push 82000085h; retn 0000h 2_2_00007FFBAB6E9B11
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB724331 push rcx; ret 2_2_00007FFBAB724332
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7B80A0 push rbp; retf 2_2_00007FFBAB7B80A3
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7B8020 push rbp; retf 2_2_00007FFBAB7B8023
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7B8038 push rsp; retf 2_2_00007FFBAB7B803B
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7B8030 push rbp; retf 2_2_00007FFBAB7B804B
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7B8048 push rbp; retf 2_2_00007FFBAB7B804B
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7B8098 push rsi; retf 2_2_00007FFBAB7B809B
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7B8008 push rbp; retf 2_2_00007FFBAB7B800B
Source: C:\Users\user\Desktop\lcc222.exe File created: C:\Users\user\AppData\Local\Temp\_MEI72642\VCRUNTIME140.dll Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe File created: C:\Users\user\AppData\Local\Temp\_MEI72642\_socket.pyd Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe File created: C:\Users\user\AppData\Local\Temp\_MEI72642\unicodedata.pyd Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe File created: C:\Users\user\AppData\Local\Temp\_MEI72642\libssl-3.dll Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe File created: C:\Users\user\AppData\Local\Temp\_MEI72642\_lzma.pyd Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe File created: C:\Users\user\AppData\Local\Temp\_MEI72642\_queue.pyd Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe File created: C:\Users\user\AppData\Local\Temp\_MEI72642\_bz2.pyd Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe File created: C:\Users\user\AppData\Local\Temp\_MEI72642\_hashlib.pyd Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe File created: C:\Users\user\AppData\Local\Temp\_MEI72642\_ssl.pyd Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe File created: C:\Users\user\AppData\Local\Temp\_MEI72642\select.pyd Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe File created: C:\Users\user\AppData\Local\Temp\_MEI72642\python312.dll Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe File created: C:\Users\user\AppData\Local\Temp\_MEI72642\libcrypto-3.dll Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe File created: C:\Users\user\AppData\Local\Temp\_MEI72642\_decimal.pyd Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe File created: C:\Users\user\AppData\Local\Temp\_MEI72642\charset_normalizer\md__mypyc.cp312-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe File created: C:\Users\user\AppData\Local\Temp\_MEI72642\charset_normalizer\md.cp312-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA235830 GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError, 0_2_00007FF6CA235830
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB748816 sgdt fword ptr [rax] 2_2_00007FFBAB748816
Source: C:\Users\user\Desktop\lcc222.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI72642\_socket.pyd Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI72642\unicodedata.pyd Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI72642\_lzma.pyd Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI72642\_queue.pyd Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI72642\_bz2.pyd Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI72642\_hashlib.pyd Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI72642\_ssl.pyd Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI72642\select.pyd Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI72642\python312.dll Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI72642\_decimal.pyd Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI72642\charset_normalizer\md__mypyc.cp312-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI72642\charset_normalizer\md.cp312-win_amd64.pyd Jump to dropped file
Source: C:\Users\user\Desktop\lcc222.exe Check user administrative privileges: GetTokenInformation,DecisionNodes
Source: C:\Users\user\Desktop\lcc222.exe API coverage: 1.4 %
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA239280 FindFirstFileExW,FindClose, 0_2_00007FF6CA239280
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA2383C0 FindFirstFileW,RemoveDirectoryW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW, 0_2_00007FF6CA2383C0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA251874 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose, 0_2_00007FF6CA251874
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA239280 FindFirstFileExW,FindClose, 2_2_00007FF6CA239280
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA2383C0 FindFirstFileW,RemoveDirectoryW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW, 2_2_00007FF6CA2383C0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA251874 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose, 2_2_00007FF6CA251874
Source: lcc222.exe, 00000000.00000003.1381716328.000001F8625F1000.00000004.00000020.00020000.00000000.sdmp, cacert.pem.0.dr Binary or memory string: j2aTPs+9xYa9+bG3tD60B8jzljHz7aRP+KNOjSkVWLjVb3/ubCK1sK9IRQq9qEmU
Source: lcc222.exe, 00000002.00000002.2639181153.000001D633D51000.00000004.00000020.00020000.00000000.sdmp, lcc222.exe, 00000002.00000003.1406902541.000001D633D7F000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: cacert.pem.0.dr Binary or memory string: zJVSk/BwJVmcIGfE7vmLV2H0knZ9P4SNVbfo5azV8fUZVqZa+5Acr5Pr5RzUZ5dd
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA23D12C IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 0_2_00007FF6CA23D12C
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA253480 GetProcessHeap, 0_2_00007FF6CA253480
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA23D30C SetUnhandledExceptionFilter, 0_2_00007FF6CA23D30C
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA23C8A0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 0_2_00007FF6CA23C8A0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA23D12C IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 0_2_00007FF6CA23D12C
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA24A614 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 0_2_00007FF6CA24A614
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA23D30C SetUnhandledExceptionFilter, 2_2_00007FF6CA23D30C
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA23C8A0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 2_2_00007FF6CA23C8A0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA23D12C IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 2_2_00007FF6CA23D12C
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FF6CA24A614 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 2_2_00007FF6CA24A614
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB562A70 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 2_2_00007FFBAB562A70
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB563028 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 2_2_00007FFBAB563028
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB6942E8 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 2_2_00007FFBAB6942E8
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB693D20 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 2_2_00007FFBAB693D20
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB6C3E60 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 2_2_00007FFBAB6C3E60
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB6C38A0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 2_2_00007FFBAB6C38A0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB6EAA7C IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 2_2_00007FFBAB6EAA7C
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB6EA050 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 2_2_00007FFBAB6EA050
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7B8030 RtlLookupFunctionEntry,SetUnhandledExceptionFilter, 2_2_00007FFBAB7B8030
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB7B8048 SetUnhandledExceptionFilter, 2_2_00007FFBAB7B8048
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBAB70212B IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 2_2_00007FFBAB70212B
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBB188314C IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 2_2_00007FFBB188314C
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBB1882720 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 2_2_00007FFBB1882720
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBB6294620 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 2_2_00007FFBB6294620
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBB6294060 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 2_2_00007FFBB6294060
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBBB6D2D70 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 2_2_00007FFBBB6D2D70
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBBB6D3328 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 2_2_00007FFBBB6D3328
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBBBDA0AA8 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 2_2_00007FFBBBDA0AA8
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBBC151430 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 2_2_00007FFBBC151430
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBBC151A00 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 2_2_00007FFBBC151A00
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBBC341710 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 2_2_00007FFBBC341710
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBBC341CD0 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 2_2_00007FFBBC341CD0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBC3131AA0 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 2_2_00007FFBC3131AA0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBC31314E0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 2_2_00007FFBC31314E0
Source: C:\Users\user\Desktop\lcc222.exe Process created: C:\Users\user\Desktop\lcc222.exe "C:\Users\user\Desktop\lcc222.exe" Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA259570 cpuid 0_2_00007FF6CA259570
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\certifi VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\charset_normalizer VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\_socket.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\select.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\_ssl.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\_hashlib.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\_queue.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\_bz2.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\_lzma.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\charset_normalizer VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\charset_normalizer VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\charset_normalizer VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\charset_normalizer VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\charset_normalizer\md__mypyc.cp312-win_amd64.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\unicodedata.pyd VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\certifi VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642\base_library.zip VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\AppData\Local\Temp\_MEI72642 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Queries volume information: C:\Users\user\Desktop\lcc222.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA23D010 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter, 0_2_00007FF6CA23D010
Source: C:\Users\user\Desktop\lcc222.exe Code function: 0_2_00007FF6CA255C00 _get_daylight,_get_daylight,_get_daylight,_get_daylight,_get_daylight,GetTimeZoneInformation, 0_2_00007FF6CA255C00
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBBB6D50C0 PySys_Audit,PyEval_SaveThread,bind,PyEval_RestoreThread,_Py_NoneStruct, 2_2_00007FFBBB6D50C0
Source: C:\Users\user\Desktop\lcc222.exe Code function: 2_2_00007FFBBB6D60CC _PyArg_ParseTuple_SizeT,PyEval_SaveThread,listen,PyEval_RestoreThread,_Py_NoneStruct, 2_2_00007FFBBB6D60CC
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs