IOC Report
Reader_Install_Setup.exe

loading gif

Files

File Path
Type
Category
Malicious
Reader_Install_Setup.exe
PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
initial sample
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\160[1]
HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\d[1]
Web Open Font Format, CFF, length 40156, version 0.0
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\d[2]
Web Open Font Format, CFF, length 39564, version 0.0
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\YLNGKWRH\231[1]
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\YLNGKWRH\p[1].gif
GIF image data, version 89a, 1 x 1
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ZJCZETOO\d[1]
Web Open Font Format, CFF, length 37480, version 0.0
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ZJCZETOO\d[2]
Web Open Font Format, CFF, length 39972, version 0.0
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ZVZFKMB9\bxf0ivf[1].js
Unicode text, UTF-8 text, with very long lines (2369)
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ZVZFKMB9\d[1]
Web Open Font Format, CFF, length 40596, version 0.0
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ZVZFKMB9\d[2]
Web Open Font Format, CFF, length 40248, version 0.0
dropped
C:\Users\user\AppData\Local\Temp\Adobe_ADMLogs\Adobe_ADM.log
Unicode text, UTF-16, little-endian text, with very long lines (538), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\Adobe_ADMLogs\Adobe_GDE.log
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
There are 4 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Reader_Install_Setup.exe
C:\Users\user\Desktop\Reader_Install_Setup.exe

URLs

Name
IP
Malicious
https://p.typekit.net/V
unknown
https://use.typekit.net/af/a2527e/000000000000000000017704/27/l?primer=0635fba006f1437d962ae878ad04a
unknown
https://reactjs.org/docs/err
unknown
https://use.typekit.net/af/4b3e87/000000000000000000017706/27/d?primer=0635fba006f1437d962ae878ad04a
unknown
https://use.typekit.net/T
unknown
https://reactjs.org/docs/error-decoder.html?invariant=arguments.length
unknown
https://use.typekit.net/bxf0ivf.jsn.type
unknown
https://use.typekit.net/af/a2527e/000000000000000000017704/27/
unknown
https://use.typekit.net/af/cb695f/000000000000000000017701/27/l?primer=0635fba006f1437d962ae878ad04a
unknown
https://use.typekit.net/af/74ffb1/000000000000000000017702/27/a?primer=0635fba006f1437d962ae878ad04a
unknown
https://use.typekit.net/bxf0ivf.js#
unknown
https://use.typekit.net/af/a2527e/000000000000000000017704/27/d?primer=0635fba006f1437d962ae878ad04a
unknown
https://reactjs.org/link/react-polyfills
unknown
https://use.typekit.net/af/cb695f/000000000000000000017701/27/
unknown
https://use.typekit.net/bxf0ivf.js_Install_Setup.exe/160C959/
unknown
http://typekit.com/eulas/000000000000000000017704
unknown
https://use.typekit.net/af/4b3e87/000000000000000000017706/27/a?primer=0635fba006f1437d962ae878ad04a
unknown
http://typekit.com/eulas/000000000000000000017706
unknown
https://use.typekit.net/af/40207f/0000000000000000000176ff/27/a?primer=0635fba006f1437d962ae878ad04a
unknown
http://typekit.com/eulas/0000000000000000000176ff
unknown
http://typekit.com/eulas/000000000000000000017701
unknown
http://typekit.com/eulas/000000000000000000017702
unknown
http://typekit.com/eulas/000000000000000000017703
unknown
http://typekit.com/eulas/000000000000000000017706(v(
unknown
https://use.typekit.net/af/74ffb1/000000000000000000017702/27/
unknown
https://mths.be/array-from
unknown
https://mths.be/array-of
unknown
https://use.typekit.net/af/eaf09c/000000000000000000017703/27/a?primer=0635fba006f1437d962ae878ad04a
unknown
https://use.typekit.net/bxf0ivf.jsn
unknown
https://use.typekit.net/bxf0ivf.jsEvent1256
unknown
https://use.typekit.net/af/eaf09c/000000000000000000017703/27/d?primer=0635fba006f1437d962ae878ad04a
unknown
https://use.typekit.net/
unknown
https://use.typekit.net/af/74ffb1/000000000000000000017702/27/l?primer=0635fba006f1437d962ae878ad04a
unknown
https://use.typekit.net/bxf0ivf.jsinitErrorMultipleInstanceRunningI
unknown
https://use.typekit.net/af/a2527e/000000000000000000017704/27/a?primer=0635fba006f1437d962ae878ad04a
unknown
https://github.com/twbs/bootstrap/blob/main/LICENSE)
unknown
https://use.typekit.net/af/cb695f/000000000000000000017701/27/d?primer=0635fba006f1437d962ae878ad04a
unknown
https://use.typekit.net/af/eaf09c/000000000000000000017703/27/
unknown
https://reactjs.org/docs/error-decoder.html?invariant=
unknown
https://p.typekit.net/
unknown
https://use.typekit.net/af/40207f/0000000000000000000176ff/27/d?primer=0635fba006f1437d962ae878ad04a
unknown
https://getbootstrap.com/)
unknown
https://github.com/Fin
unknown
https://use.typekit.net/af/40207f/0000000000000000000176ff/27/l?primer=0635fba006f1437d962ae878ad04a
unknown
https://use.typekit.net/af/4b3e87/000000000000000000017706/27/
unknown
https://use.typekit.net/af/eaf09c/000000000000000000017703/27/l?primer=0635fba006f1437d962ae878ad04a
unknown
https://use.typekit.net/af/74ffb1/000000000000000000017702/27/d?primer=0635fba006f1437d962ae878ad04a
unknown
http://typekit.com/eulas/000000000000000000017704R
unknown
https://use.typekit.net/bxf0ivf.jsL
unknown
https://p.typekit.net/p.gif?s=1&k=bxf0ivf&ht=tk&h=C%3A%5CUsers%5Cuser%5CDesktop%5CReader_Install_Se
unknown
https://github.com/Financial-Times/polyfill-service/issues/317
unknown
https://p.typekit.net/p.gif
unknown
https://use.typekit.net/bxf0ivf.js
unknown
https://use.typekit.net/af/40207f/0000000000000000000176ff/27/
unknown
https://use.typekit.net/af/cb695f/000000000000000000017701/27/a?primer=0635fba006f1437d962ae878ad04a
unknown
https://reactjs.org/link/react-polyfillsn.unstable_shouldYieldn.unstable_forceFrameRate
unknown
https://reactjs.org/link/react-polyfillsThis
unknown
https://use.typekit.net/af/4b3e87/000000000000000000017706/27/l?primer=0635fba006f1437d962ae878ad04a
unknown
There are 48 hidden URLs, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
96D0000
trusted library allocation
page read and write
8051000
trusted library allocation
page read and write
8012000
trusted library allocation
page read and write
97DD000
trusted library allocation
page read and write
805E000
trusted library allocation
page read and write
8093000
trusted library allocation
page read and write
9653000
trusted library allocation
page read and write
9D68000
trusted library allocation
page read and write
33C4000
heap
page read and write
967F000
trusted library allocation
page read and write
9BFD000
trusted library allocation
page read and write
70D000
unkown
page execute and write copy
9D84000
trusted library allocation
page read and write
7DC8000
heap
page read and write
987A000
trusted library allocation
page read and write
9638000
trusted library allocation
page read and write