IOC Report
XnUEBMnOEd.exe

loading gif

Files

File Path
Type
Category
Malicious
XnUEBMnOEd.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\winsvc.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\XnUEBMnOEd.exe
"C:\Users\user\Desktop\XnUEBMnOEd.exe"
malicious
C:\Users\user\winsvc.exe
C:\Users\user\winsvc.exe
malicious
C:\Users\user\winsvc.exe
"C:\Users\user\winsvc.exe"
malicious
C:\Users\user\winsvc.exe
"C:\Users\user\winsvc.exe"
malicious

URLs

Name
IP
Malicious
http://twizt.net
unknown
http://twizt.net/Installedp
unknown
http://twizt.net/lslut.exewinsvc.exeb
unknown
http://twizt.net3(
unknown
http://twizt.netS(
unknown
http://twizt.net/lslut.exewinsvc.exe
unknown
http://fuckput.in/N
unknown
http://twizt.net/
unknown
http://twizt.net/lslut.exeWA
unknown
http://twizt.net/lslut.e(
unknown
http://twizt.net/InstalledopenMozilla/5.0
unknown
http://twizt.net/lslut.exe_Al
unknown
http://twizt.net/lslut.exegB$
unknown
http://twizt.net/lslut.exe8-
unknown
http://twizt.net/lslut.e
unknown
http://twizt.net/lslut.exewinsvc.exen
unknown
http://twizt.net/lsl
unknown
http://twizt.net/lslut.exe_E
unknown
http://twizt.net/Installed
185.215.113.66
http://twizt.net/lslut.exe
185.215.113.66
http://twizt.net/lslut.exe%s:Zone.Identifier%userprofile%%s
unknown
http://fuckput.in/
unknown
There are 12 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
twizt.net
185.215.113.66

IPs

IP
Domain
Country
Malicious
185.215.113.66
twizt.net
Portugal

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Windows Service

Memdumps

Base Address
Regiontype
Protect
Malicious
37DF000
stack
page read and write
172E000
stack
page read and write
580000
heap
page read and write
BE0000
heap
page read and write
841000
unkown
page execute read
841000
unkown
page execute read
30BE000
stack
page read and write
303E000
stack
page read and write
570000
heap
page read and write
339F000
stack
page read and write
845000
unkown
page readonly
843000
unkown
page readonly
17AD000
stack
page read and write
359F000
stack
page read and write
841000
unkown
page execute read
11E8000
heap
page read and write
F7E000
stack
page read and write
176E000
stack
page read and write
BBB000
heap
page read and write
155F000
stack
page read and write
F6A000
stack
page read and write
AC5000
heap
page read and write
11AC000
heap
page read and write
A90000
heap
page read and write
113E000
stack
page read and write
2DFD000
stack
page read and write
FEE000
stack
page read and write
E60000
unkown
page readonly
94E000
stack
page read and write
843000
unkown
page readonly
39C000
stack
page read and write
50C000
stack
page read and write
FAD000
stack
page read and write
12F6000
stack
page read and write
2F3D000
stack
page read and write
9A8000
heap
page read and write
840000
unkown
page readonly
2EFD000
stack
page read and write
159E000
stack
page read and write
2CBE000
stack
page read and write
843000
unkown
page readonly
11A6000
heap
page read and write
845000
unkown
page readonly
2C7E000
stack
page read and write
1450000
heap
page read and write
1440000
heap
page read and write
830000
heap
page read and write
BEA000
heap
page read and write
843000
unkown
page readonly
156E000
stack
page read and write
2DBF000
stack
page read and write
6FB000
stack
page read and write
AC0000
heap
page read and write
1025000
heap
page read and write
381D000
stack
page read and write
94A000
stack
page read and write
9A0000
heap
page read and write
700000
heap
page read and write
391E000
stack
page read and write
E65000
unkown
page readonly
FE0000
heap
page read and write
C40000
heap
page read and write
FD0000
heap
page read and write
841000
unkown
page execute read
11C2000
heap
page read and write
1600000
heap
page read and write
840000
unkown
page readonly
98E000
stack
page read and write
E60000
unkown
page readonly
12FB000
stack
page read and write
B8A000
heap
page read and write
369C000
stack
page read and write
820000
heap
page read and write
F6C000
stack
page read and write
17B0000
heap
page read and write
845000
unkown
page readonly
BD0000
heap
page read and write
6F6000
stack
page read and write
349F000
stack
page read and write
843000
unkown
page readonly
B6C000
stack
page read and write
E65000
unkown
page readonly
81D000
stack
page read and write
946000
stack
page read and write
840000
unkown
page readonly
E61000
unkown
page execute read
A20000
heap
page read and write
F90000
heap
page read and write
840000
unkown
page readonly
15EE000
stack
page read and write
B8E000
heap
page read and write
E61000
unkown
page execute read
1170000
heap
page read and write
A8E000
stack
page read and write
BCF000
heap
page read and write
E63000
unkown
page readonly
1608000
heap
page read and write
840000
unkown
page readonly
841000
unkown
page execute read
845000
unkown
page readonly
B9F000
stack
page read and write
1620000
heap
page read and write
845000
unkown
page readonly
11DB000
heap
page read and write
840000
unkown
page readonly
136E000
stack
page read and write
117E000
heap
page read and write
117A000
heap
page read and write
BD0000
heap
page read and write
140E000
stack
page read and write
F66000
stack
page read and write
2F9F000
stack
page read and write
B4E000
stack
page read and write
15C0000
heap
page read and write
841000
unkown
page execute read
1000000
heap
page read and write
1020000
heap
page read and write
845000
unkown
page readonly
36DE000
stack
page read and write
15AE000
stack
page read and write
31BE000
stack
page read and write
146E000
stack
page read and write
E63000
unkown
page readonly
B80000
heap
page read and write
843000
unkown
page readonly
E3E000
stack
page read and write
There are 116 hidden memdumps, click here to show them.