Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
XnUEBMnOEd.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Users\user\winsvc.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\XnUEBMnOEd.exe
|
"C:\Users\user\Desktop\XnUEBMnOEd.exe"
|
||
C:\Users\user\winsvc.exe
|
C:\Users\user\winsvc.exe
|
||
C:\Users\user\winsvc.exe
|
"C:\Users\user\winsvc.exe"
|
||
C:\Users\user\winsvc.exe
|
"C:\Users\user\winsvc.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://twizt.net
|
unknown
|
||
http://twizt.net/Installedp
|
unknown
|
||
http://twizt.net/lslut.exewinsvc.exeb
|
unknown
|
||
http://twizt.net3(
|
unknown
|
||
http://twizt.netS(
|
unknown
|
||
http://twizt.net/lslut.exewinsvc.exe
|
unknown
|
||
http://fuckput.in/N
|
unknown
|
||
http://twizt.net/
|
unknown
|
||
http://twizt.net/lslut.exeWA
|
unknown
|
||
http://twizt.net/lslut.e(
|
unknown
|
||
http://twizt.net/InstalledopenMozilla/5.0
|
unknown
|
||
http://twizt.net/lslut.exe_Al
|
unknown
|
||
http://twizt.net/lslut.exegB$
|
unknown
|
||
http://twizt.net/lslut.exe8-
|
unknown
|
||
http://twizt.net/lslut.e
|
unknown
|
||
http://twizt.net/lslut.exewinsvc.exen
|
unknown
|
||
http://twizt.net/lsl
|
unknown
|
||
http://twizt.net/lslut.exe_E
|
unknown
|
||
http://twizt.net/Installed
|
185.215.113.66
|
||
http://twizt.net/lslut.exe
|
185.215.113.66
|
||
http://twizt.net/lslut.exe%s:Zone.Identifier%userprofile%%s
|
unknown
|
||
http://fuckput.in/
|
unknown
|
There are 12 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
twizt.net
|
185.215.113.66
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
185.215.113.66
|
twizt.net
|
Portugal
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
|
Windows Service
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
37DF000
|
stack
|
page read and write
|
||
172E000
|
stack
|
page read and write
|
||
580000
|
heap
|
page read and write
|
||
BE0000
|
heap
|
page read and write
|
||
841000
|
unkown
|
page execute read
|
||
841000
|
unkown
|
page execute read
|
||
30BE000
|
stack
|
page read and write
|
||
303E000
|
stack
|
page read and write
|
||
570000
|
heap
|
page read and write
|
||
339F000
|
stack
|
page read and write
|
||
845000
|
unkown
|
page readonly
|
||
843000
|
unkown
|
page readonly
|
||
17AD000
|
stack
|
page read and write
|
||
359F000
|
stack
|
page read and write
|
||
841000
|
unkown
|
page execute read
|
||
11E8000
|
heap
|
page read and write
|
||
F7E000
|
stack
|
page read and write
|
||
176E000
|
stack
|
page read and write
|
||
BBB000
|
heap
|
page read and write
|
||
155F000
|
stack
|
page read and write
|
||
F6A000
|
stack
|
page read and write
|
||
AC5000
|
heap
|
page read and write
|
||
11AC000
|
heap
|
page read and write
|
||
A90000
|
heap
|
page read and write
|
||
113E000
|
stack
|
page read and write
|
||
2DFD000
|
stack
|
page read and write
|
||
FEE000
|
stack
|
page read and write
|
||
E60000
|
unkown
|
page readonly
|
||
94E000
|
stack
|
page read and write
|
||
843000
|
unkown
|
page readonly
|
||
39C000
|
stack
|
page read and write
|
||
50C000
|
stack
|
page read and write
|
||
FAD000
|
stack
|
page read and write
|
||
12F6000
|
stack
|
page read and write
|
||
2F3D000
|
stack
|
page read and write
|
||
9A8000
|
heap
|
page read and write
|
||
840000
|
unkown
|
page readonly
|
||
2EFD000
|
stack
|
page read and write
|
||
159E000
|
stack
|
page read and write
|
||
2CBE000
|
stack
|
page read and write
|
||
843000
|
unkown
|
page readonly
|
||
11A6000
|
heap
|
page read and write
|
||
845000
|
unkown
|
page readonly
|
||
2C7E000
|
stack
|
page read and write
|
||
1450000
|
heap
|
page read and write
|
||
1440000
|
heap
|
page read and write
|
||
830000
|
heap
|
page read and write
|
||
BEA000
|
heap
|
page read and write
|
||
843000
|
unkown
|
page readonly
|
||
156E000
|
stack
|
page read and write
|
||
2DBF000
|
stack
|
page read and write
|
||
6FB000
|
stack
|
page read and write
|
||
AC0000
|
heap
|
page read and write
|
||
1025000
|
heap
|
page read and write
|
||
381D000
|
stack
|
page read and write
|
||
94A000
|
stack
|
page read and write
|
||
9A0000
|
heap
|
page read and write
|
||
700000
|
heap
|
page read and write
|
||
391E000
|
stack
|
page read and write
|
||
E65000
|
unkown
|
page readonly
|
||
FE0000
|
heap
|
page read and write
|
||
C40000
|
heap
|
page read and write
|
||
FD0000
|
heap
|
page read and write
|
||
841000
|
unkown
|
page execute read
|
||
11C2000
|
heap
|
page read and write
|
||
1600000
|
heap
|
page read and write
|
||
840000
|
unkown
|
page readonly
|
||
98E000
|
stack
|
page read and write
|
||
E60000
|
unkown
|
page readonly
|
||
12FB000
|
stack
|
page read and write
|
||
B8A000
|
heap
|
page read and write
|
||
369C000
|
stack
|
page read and write
|
||
820000
|
heap
|
page read and write
|
||
F6C000
|
stack
|
page read and write
|
||
17B0000
|
heap
|
page read and write
|
||
845000
|
unkown
|
page readonly
|
||
BD0000
|
heap
|
page read and write
|
||
6F6000
|
stack
|
page read and write
|
||
349F000
|
stack
|
page read and write
|
||
843000
|
unkown
|
page readonly
|
||
B6C000
|
stack
|
page read and write
|
||
E65000
|
unkown
|
page readonly
|
||
81D000
|
stack
|
page read and write
|
||
946000
|
stack
|
page read and write
|
||
840000
|
unkown
|
page readonly
|
||
E61000
|
unkown
|
page execute read
|
||
A20000
|
heap
|
page read and write
|
||
F90000
|
heap
|
page read and write
|
||
840000
|
unkown
|
page readonly
|
||
15EE000
|
stack
|
page read and write
|
||
B8E000
|
heap
|
page read and write
|
||
E61000
|
unkown
|
page execute read
|
||
1170000
|
heap
|
page read and write
|
||
A8E000
|
stack
|
page read and write
|
||
BCF000
|
heap
|
page read and write
|
||
E63000
|
unkown
|
page readonly
|
||
1608000
|
heap
|
page read and write
|
||
840000
|
unkown
|
page readonly
|
||
841000
|
unkown
|
page execute read
|
||
845000
|
unkown
|
page readonly
|
||
B9F000
|
stack
|
page read and write
|
||
1620000
|
heap
|
page read and write
|
||
845000
|
unkown
|
page readonly
|
||
11DB000
|
heap
|
page read and write
|
||
840000
|
unkown
|
page readonly
|
||
136E000
|
stack
|
page read and write
|
||
117E000
|
heap
|
page read and write
|
||
117A000
|
heap
|
page read and write
|
||
BD0000
|
heap
|
page read and write
|
||
140E000
|
stack
|
page read and write
|
||
F66000
|
stack
|
page read and write
|
||
2F9F000
|
stack
|
page read and write
|
||
B4E000
|
stack
|
page read and write
|
||
15C0000
|
heap
|
page read and write
|
||
841000
|
unkown
|
page execute read
|
||
1000000
|
heap
|
page read and write
|
||
1020000
|
heap
|
page read and write
|
||
845000
|
unkown
|
page readonly
|
||
36DE000
|
stack
|
page read and write
|
||
15AE000
|
stack
|
page read and write
|
||
31BE000
|
stack
|
page read and write
|
||
146E000
|
stack
|
page read and write
|
||
E63000
|
unkown
|
page readonly
|
||
B80000
|
heap
|
page read and write
|
||
843000
|
unkown
|
page readonly
|
||
E3E000
|
stack
|
page read and write
|
There are 116 hidden memdumps, click here to show them.