IOC Report
unpacked_1648556.bin.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\unpacked_1648556.bin.exe
"C:\Users\user\Desktop\unpacked_1648556.bin.exe"
malicious

URLs

Name
IP
Malicious
https://cowspidzu.pro/
unknown
https://muratinue.com/photo.png?id=01B677C698EC38846700FF0000000000000000
unknown
https://muratinue.com/photo.png?id=01B677C698EC38846700FF0000000000000000%
unknown
https://bladisuka.red/photo.png?id=01B677C698EC38846700FF0000000000000000
unknown
https://certifacto.com/R
unknown
https://cowspidzu.pro/photo.png?id=01B677C698EC38846700FF0000000000000000l
unknown
https://certifacto.com/
unknown
https://cowspidzu.pro/photo.png?id=01B677C698EC38846700FF0000000000000000&
unknown
https://bladisuka.red/R
unknown
https://bladisuka.red/photo.png?id=01B677C698EC38846700FF0000000000000000%
unknown
https://certifacto.com/photo.png?id=01B677C698EC38846700FF0000000000000000XHM
unknown
https://muratinue.com/R
unknown
https://certifacto.com/photo.png?id=01B677C698EC38846700FF0000000000000000
unknown
https://muratinue.com/photo.png?id=01B677C698EC38846700FF000000000000000044U3h
unknown
https://bladisuka.red/photo.png?id=01B677C698EC38846700FF0000000000000000=
unknown
https://muratinue.com/
unknown
https://muratinue.com/photo.png?id=01B677C698EC38846700FF0000000000000000xGM
unknown
https://bladisuka.red/
unknown
https://cowspidzu.pro/photo.png?id=01B677C698EC38846700FF0000000000000000
unknown
There are 9 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
certifacto.com
unknown
muratinue.com
unknown
cowspidzu.pro
unknown
bladisuka.red
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
401000
unkown
page execute read
malicious
401000
unkown
page execute read
malicious
400000
unkown
page readonly
4E3000
heap
page read and write
4F4000
heap
page read and write
28B0000
remote allocation
page read and write
289F000
stack
page read and write
4DE000
heap
page read and write
4DE000
heap
page read and write
4F4000
heap
page read and write
4B8000
heap
page read and write
4B8000
heap
page read and write
4CA000
heap
page read and write
4F7000
heap
page read and write
4B2000
heap
page read and write
402000
unkown
page readonly
480000
heap
page read and write
28FE000
stack
page read and write
4E3000
heap
page read and write
28B0000
remote allocation
page read and write
4CC000
heap
page read and write
4CA000
heap
page read and write
4E3000
heap
page read and write
4DE000
heap
page read and write
4CC000
heap
page read and write
48A000
heap
page read and write
4F4000
heap
page read and write
48E000
heap
page read and write
4DE000
heap
page read and write
4F7000
heap
page read and write
19D000
stack
page read and write
4DE000
heap
page read and write
4CD000
heap
page read and write
279E000
stack
page read and write
4F5000
heap
page read and write
251E000
stack
page read and write
4F7000
heap
page read and write
4BE000
heap
page read and write
4F5000
heap
page read and write
265E000
stack
page read and write
9DD000
stack
page read and write
4BE000
heap
page read and write
29FE000
stack
page read and write
420000
heap
page read and write
8DE000
stack
page read and write
4CA000
heap
page read and write
261E000
stack
page read and write
4E3000
heap
page read and write
9F0000
heap
page read and write
4F4000
heap
page read and write
1F0000
heap
page read and write
404000
unkown
page readonly
28B0000
remote allocation
page read and write
4CA000
heap
page read and write
4DE000
heap
page read and write
403000
unkown
page read and write
4DE000
heap
page read and write
404000
unkown
page readonly
4E3000
heap
page read and write
4E3000
heap
page read and write
4F5000
heap
page read and write
4E3000
heap
page read and write
4B2000
heap
page read and write
4B8000
heap
page read and write
4B2000
heap
page read and write
4F4000
heap
page read and write
275F000
stack
page read and write
402000
unkown
page readonly
403000
unkown
page write copy
410000
heap
page read and write
4CA000
heap
page read and write
9C000
stack
page read and write
400000
unkown
page readonly
There are 63 hidden memdumps, click here to show them.