Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
Reader_Install_Setup.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
|
initial sample
|
||
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\160[1]
|
HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\d[1]
|
Web Open Font Format, CFF, length 40156, version 0.0
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\d[2]
|
Web Open Font Format, CFF, length 39564, version 0.0
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\YLNGKWRH\231[1]
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\YLNGKWRH\p[1].gif
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ZJCZETOO\d[1]
|
Web Open Font Format, CFF, length 37480, version 0.0
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ZJCZETOO\d[2]
|
Web Open Font Format, CFF, length 39972, version 0.0
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ZVZFKMB9\bxf0ivf[1].js
|
Unicode text, UTF-8 text, with very long lines (2369)
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ZVZFKMB9\d[1]
|
Web Open Font Format, CFF, length 40596, version 0.0
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ZVZFKMB9\d[2]
|
Web Open Font Format, CFF, length 40248, version 0.0
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\Adobe_ADMLogs\Adobe_ADM.log
|
Unicode text, UTF-16, little-endian text, with very long lines (538), with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\Adobe_ADMLogs\Adobe_GDE.log
|
Unicode text, UTF-16, little-endian text, with CRLF line terminators
|
dropped
|
There are 4 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\Reader_Install_Setup.exe
|
C:\Users\user\Desktop\Reader_Install_Setup.exe
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://p.typekit.net/V
|
unknown
|
||
https://use.typekit.net/af/a2527e/000000000000000000017704/27/l?primer=0635fba006f1437d962ae878ad04a
|
unknown
|
||
https://reactjs.org/docs/err
|
unknown
|
||
https://use.typekit.net/af/4b3e87/000000000000000000017706/27/d?primer=0635fba006f1437d962ae878ad04a
|
unknown
|
||
https://use.typekit.net/T
|
unknown
|
||
https://reactjs.org/docs/error-decoder.html?invariant=arguments.length
|
unknown
|
||
https://use.typekit.net/bxf0ivf.jsn.type
|
unknown
|
||
https://use.typekit.net/af/a2527e/000000000000000000017704/27/
|
unknown
|
||
https://use.typekit.net/af/cb695f/000000000000000000017701/27/l?primer=0635fba006f1437d962ae878ad04a
|
unknown
|
||
https://use.typekit.net/af/74ffb1/000000000000000000017702/27/a?primer=0635fba006f1437d962ae878ad04a
|
unknown
|
||
https://use.typekit.net/bxf0ivf.js#
|
unknown
|
||
https://use.typekit.net/af/a2527e/000000000000000000017704/27/d?primer=0635fba006f1437d962ae878ad04a
|
unknown
|
||
https://reactjs.org/link/react-polyfills
|
unknown
|
||
https://use.typekit.net/af/cb695f/000000000000000000017701/27/
|
unknown
|
||
https://use.typekit.net/bxf0ivf.js_Install_Setup.exe/160C959/
|
unknown
|
||
http://typekit.com/eulas/000000000000000000017704
|
unknown
|
||
https://use.typekit.net/af/4b3e87/000000000000000000017706/27/a?primer=0635fba006f1437d962ae878ad04a
|
unknown
|
||
http://typekit.com/eulas/000000000000000000017706
|
unknown
|
||
https://use.typekit.net/af/40207f/0000000000000000000176ff/27/a?primer=0635fba006f1437d962ae878ad04a
|
unknown
|
||
http://typekit.com/eulas/0000000000000000000176ff
|
unknown
|
||
http://typekit.com/eulas/000000000000000000017701
|
unknown
|
||
http://typekit.com/eulas/000000000000000000017702
|
unknown
|
||
http://typekit.com/eulas/000000000000000000017703
|
unknown
|
||
http://typekit.com/eulas/000000000000000000017706(v(
|
unknown
|
||
https://use.typekit.net/af/74ffb1/000000000000000000017702/27/
|
unknown
|
||
https://mths.be/array-from
|
unknown
|
||
https://mths.be/array-of
|
unknown
|
||
https://use.typekit.net/af/eaf09c/000000000000000000017703/27/a?primer=0635fba006f1437d962ae878ad04a
|
unknown
|
||
https://use.typekit.net/bxf0ivf.jsn
|
unknown
|
||
https://use.typekit.net/bxf0ivf.jsEvent1256
|
unknown
|
||
https://use.typekit.net/af/eaf09c/000000000000000000017703/27/d?primer=0635fba006f1437d962ae878ad04a
|
unknown
|
||
https://use.typekit.net/
|
unknown
|
||
https://use.typekit.net/af/74ffb1/000000000000000000017702/27/l?primer=0635fba006f1437d962ae878ad04a
|
unknown
|
||
https://use.typekit.net/bxf0ivf.jsinitErrorMultipleInstanceRunningI
|
unknown
|
||
https://use.typekit.net/af/a2527e/000000000000000000017704/27/a?primer=0635fba006f1437d962ae878ad04a
|
unknown
|
||
https://github.com/twbs/bootstrap/blob/main/LICENSE)
|
unknown
|
||
https://use.typekit.net/af/cb695f/000000000000000000017701/27/d?primer=0635fba006f1437d962ae878ad04a
|
unknown
|
||
https://use.typekit.net/af/eaf09c/000000000000000000017703/27/
|
unknown
|
||
https://reactjs.org/docs/error-decoder.html?invariant=
|
unknown
|
||
https://p.typekit.net/
|
unknown
|
||
https://use.typekit.net/af/40207f/0000000000000000000176ff/27/d?primer=0635fba006f1437d962ae878ad04a
|
unknown
|
||
https://getbootstrap.com/)
|
unknown
|
||
https://github.com/Fin
|
unknown
|
||
https://use.typekit.net/af/40207f/0000000000000000000176ff/27/l?primer=0635fba006f1437d962ae878ad04a
|
unknown
|
||
https://use.typekit.net/af/4b3e87/000000000000000000017706/27/
|
unknown
|
||
https://use.typekit.net/af/eaf09c/000000000000000000017703/27/l?primer=0635fba006f1437d962ae878ad04a
|
unknown
|
||
https://use.typekit.net/af/74ffb1/000000000000000000017702/27/d?primer=0635fba006f1437d962ae878ad04a
|
unknown
|
||
http://typekit.com/eulas/000000000000000000017704R
|
unknown
|
||
https://use.typekit.net/bxf0ivf.jsL
|
unknown
|
||
https://p.typekit.net/p.gif?s=1&k=bxf0ivf&ht=tk&h=C%3A%5CUsers%5Cuser%5CDesktop%5CReader_Install_Se
|
unknown
|
||
https://github.com/Financial-Times/polyfill-service/issues/317
|
unknown
|
||
https://p.typekit.net/p.gif
|
unknown
|
||
https://use.typekit.net/bxf0ivf.js
|
unknown
|
||
https://use.typekit.net/af/40207f/0000000000000000000176ff/27/
|
unknown
|
||
https://use.typekit.net/af/cb695f/000000000000000000017701/27/a?primer=0635fba006f1437d962ae878ad04a
|
unknown
|
||
https://reactjs.org/link/react-polyfillsn.unstable_shouldYieldn.unstable_forceFrameRate
|
unknown
|
||
https://reactjs.org/link/react-polyfillsThis
|
unknown
|
||
https://use.typekit.net/af/4b3e87/000000000000000000017706/27/l?primer=0635fba006f1437d962ae878ad04a
|
unknown
|
There are 48 hidden URLs, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
96D0000
|
trusted library allocation
|
page read and write
|
||
8051000
|
trusted library allocation
|
page read and write
|
||
8012000
|
trusted library allocation
|
page read and write
|
||
97DD000
|
trusted library allocation
|
page read and write
|
||
805E000
|
trusted library allocation
|
page read and write
|
||
8093000
|
trusted library allocation
|
page read and write
|
||
9653000
|
trusted library allocation
|
page read and write
|
||
9D68000
|
trusted library allocation
|
page read and write
|
||
33C4000
|
heap
|
page read and write
|
||
967F000
|
trusted library allocation
|
page read and write
|
||
9BFD000
|
trusted library allocation
|
page read and write
|
||
70D000
|
unkown
|
page execute and write copy
|
||
9D84000
|
trusted library allocation
|
page read and write
|
||
7DC8000
|
heap
|
page read and write
|
||
987A000
|
trusted library allocation
|
page read and write
|
||
9638000
|
trusted library allocation
|
page read and write
|