IOC Report
Qte2311.exe

loading gif

Files

File Path
Type
Category
Malicious
Qte2311.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Qte2311.exe.log
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\r27485
Unknown
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Qte2311.exe
C:\Users\user\Desktop\Qte2311.exe
malicious
C:\Users\user\Desktop\Qte2311.exe
C:\Users\user\Desktop\Qte2311.exe
malicious
C:\Users\user\Desktop\Qte2311.exe
C:\Users\user\Desktop\Qte2311.exe
malicious
C:\Program Files (x86)\jFJKUzqwKIBdWDkcySLyDBhTBgNTKdOJMfgYJclsrVfAJDMiwJDDVHpOzszTWBY\SoZyKEDyfEWrMWEFcBvwSAkabc.exe
"C:\Program Files (x86)\jFJKUzqwKIBdWDkcySLyDBhTBgNTKdOJMfgYJclsrVfAJDMiwJDDVHpOzszTWBY\SoZyKEDyfEWrMWEFcBvwSAkabc.exe"
malicious
C:\Windows\SysWOW64\runas.exe
C:\Windows\SysWOW64\runas.exe
malicious
C:\Program Files (x86)\jFJKUzqwKIBdWDkcySLyDBhTBgNTKdOJMfgYJclsrVfAJDMiwJDDVHpOzszTWBY\SoZyKEDyfEWrMWEFcBvwSAkabc.exe
"C:\Program Files (x86)\jFJKUzqwKIBdWDkcySLyDBhTBgNTKdOJMfgYJclsrVfAJDMiwJDDVHpOzszTWBY\SoZyKEDyfEWrMWEFcBvwSAkabc.exe"
malicious
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\Firefox.exe
malicious

URLs

Name
IP
Malicious
https://duckduckgo.com/chrome_newtab
unknown
http://www.fontbureau.com/designersG
unknown
http://www.pjgfupyp.click/do6
unknown
https://duckduckgo.com/ac/?q=
unknown
http://www.fontbureau.com/designers/?
unknown
http://www.drtonks.com/
unknown
http://www.founder.com.cn/cn/bThe
unknown
http://www.arteunmapa.com/u0t4/
217.160.0.131
http://www.fontbureau.com/designers?
unknown
https://hg.mozilla.org/releases/mozilla-release/rev/68e4c357d26c5a1f075a1ec0c696d4fe684ed881
unknown
http://www.pjgfupyp.click/2
unknown
http://www.tiro.com
unknown
http://www.beautwin.info/u0t4/?ipNhfX=XNk/b9CReA2PmrT6V9nRJKml7Bwv5n/yLOhYcFkNWR1WhWm4S78oywurhHAd6q+OOWdCw7RAri9AvuhxeeQNKzba3a077jm8zA==&DDMD=2V_pWNT8ifT
66.29.151.121
https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
unknown
http://www.fontbureau.com/designers
unknown
http://www.ghswanhar.com/u0t4/
84.32.84.32
http://www.goodfont.co.kr
unknown
http://www.rva.info/u0t4/
13.248.169.48
http://majinfo.tech/u0t4/?ipNhfX=pk6UlYKypwTcdRigHYvXwaXnbRoM4y7Rx6CIM21Q8kT0nxxz4tr7Q0wSojmMfoxURV3
unknown
http://www.sajatypeworks.com
unknown
http://www.typography.netD
unknown
http://www.founder.com.cn/cn/cThe
unknown
http://www.galapagosdesign.com/staff/dennis.htm
unknown
http://www.drtonks.com/u0t4/?ipNhfX=yeZb8GK9kb308m6tqpQSWKVePpKokD/DhHuephdMkCBCe/gXfDvon4YRbmogRZs51d24yXmjv9s2GuQK2J30uG9jNiVx5pUDTA==&DDMD=2V_pWNT8ifT
3.64.163.50
http://www.pjgfupyp.click/
unknown
http://www.ghswanhar.com/u0t4/?ipNhfX=4EteGVMU5QusLCd8WOgjQMJSMXeXzA2vwQTj1x/Wv0fSPBpLzP4ZjqwCxd5WAfB87rYwoEydCHJiwFyGwE65y6hYDNnXCDKbTA==&DDMD=2V_pWNT8ifT
84.32.84.32
https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
unknown
http://www.galapagosdesign.com/DPlease
unknown
http://www.fonts.com
unknown
http://www.sandoll.co.kr
unknown
http://www.owcojyyde.best/u0t4/?ipNhfX=T+ktEIOjX9T5dGcj9rUsXIa48WZT28SiLvO+yVBZwvWEp9g0wSKFlyHjxBvBWF4XQFrqNUOHqhRxKaY3zbxWdu06McXUafUYdA==&DDMD=2V_pWNT8ifT
172.67.191.39
http://www.urwpp.deDPlease
unknown
http://www.zhongyicts.com.cn
unknown
http://www.beautwin.info/u0t4/
66.29.151.121
http://www.sakkal.com
unknown
http://www.sakkal.comX
unknown
https://www.rva.info/u0t4/?ipNhfX=0FEhcIE8iszkrFK7conPxoTSm5tbS5zDq5Q/wzqttSHPlx8Adeeig0MIJDbK
unknown
http://www.pjgfupyp.click/u0t4/?ipNhfX=1CC
unknown
http://www.apache.org/licenses/LICENSE-2.0
unknown
http://www.fontbureau.com
unknown
http://www.arteunmapa.com/u0t4/?ipNhfX=ZUvXaveAn+Mj+tnST7bSiJ2JwfpFPPY9VKgiVLhz9pIo5hypx732FJmQOFcPVCgcsF350nabn4Y8nAcrKLrIHurvDd/yCXFvmw==&DDMD=2V_pWNT8ifT
217.160.0.131
https://mozilla.org0/
unknown
https://crash-reports.mozilla.com/submit?id=
unknown
https://www.google.com/images/branding/product/ico/googleg_lodp.ico
unknown
https://s3-us-west-2.amazonaws.com/s.cdpn.io/16327/MorphSVGPlugin.min.js
unknown
https://s3-us-west-2.amazonaws.com/s.cdpn.io/16327/SplitText.min.js
unknown
http://www.majinfo.tech/u0t4/?ipNhfX=pk6UlYKypwTcdRigHYvXwaXnbRoM4y7Rx6CIM21Q8kT0nxxz4tr7Q0wSojmMfoxURV3iEB8rSWMGZNGZ3jUdb07QIb/TctJEsw==&DDMD=2V_pWNT8ifT
65.21.25.34
http://www.beautwin.info
unknown
https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
unknown
http://www.rva.info/u0t4/?ipNhfX=0FEhcIE8iszkrFK7conPxoTSm5tbS5zDq5Q/wzqttSHPlx8Adeeig0MIJDbK+dlDXWJ9cmev8ZYmFh9Bk+wzUoT6TgNjxSlOMQ==&DDMD=2V_pWNT8ifT
13.248.169.48
https://cdnjs.cloudflare.com/ajax/libs/gsap/1.20.2/TweenMax.min.js
unknown
https://www.ecosia.org/newtab/
unknown
http://www.carterandcone.coml
unknown
https://ac.ecosia.org/autocomplete?q=
unknown
http://www.fontbureau.com/designers/cabarga.htmlN
unknown
http://www.majinfo.tech/u0t4/
65.21.25.34
http://www.founder.com.cn/cn
unknown
http://www.fontbureau.com/designers/frere-user.html
unknown
http://www.jiyu-kobo.co.jp/
unknown
http://www.fontbureau.com/designers8
unknown
https://cdnjs.cloudflare.com/ajax/libs/meyer-reset/2.0/reset.min.css
unknown
https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
unknown
http://www.owcojyyde.best/u0t4/
172.67.191.39