IOC Report
SecuriteInfo.com.Trojan.GenericKD.72085429.24047.31308.exe

loading gif

Files

File Path
Type
Category
Malicious
SecuriteInfo.com.Trojan.GenericKD.72085429.24047.31308.exe
PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
initial sample
C:\Users\user\AppData\Local\Temp\reibootforios_ts\reibootforios_ts_20240328171810539.log
ASCII text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.72085429.24047.31308.exe
"C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.72085429.24047.31308.exe"

URLs

Name
IP
Malicious
http://download.wondershare.com/cbs_down/drfone_recover_full3366.exe
unknown
https://analytics.afirstsoft.cn/collect
unknown
https://download.tenorshare.com/downloads/extra/reibootforiots0
unknown
http://dl.tenorshare.net/reibootforios_ts.exeP%
unknown
https://download.any-data-recovery.com/downloads/extra/AnyDataRecovery_any_x64.exe
unknown
https://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
https://product-alert.afirstsoft.cn/api/exception/sendpid=%d&type=2&exception_code=Hash_Check_Fail_C
unknown
https://update.tenorshare.cn/download/checkCross?cross_end_id=%s
unknown
http://www.openssl.org/support/faq.html
unknown
https://integrated.tenorshare.com/api/v1/ticket/feedback&subject=&version=&log_id=&content=&useremai
unknown
http://dl.tenorshare.net/reibootforios_ts.exe
unknown
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
http://www.tenorshare.com/downloads/service/softwarelog.txthttp://ip-api.com/csvsuccess/QueryTools?L
unknown
http://update.tenorshare.com/queryDownloader?LanguageId=%d&SoftWareID=%d&SiteID=%d%s&package_type=2h
unknown
https://download.tenorshare.com/downloads/extra/reibootforio
unknown
http://dl.tenorshare.n
unknown
http://update.tenorshare.cn/download/checkCross?cross_end_id=%s
unknown
https://update.tenorshare.cn/queryDownloader?LanguageId=%d&SoftWareID=%d&SiteID=%d%s
unknown
http://dl.tenorshare.net/AnyDataRecovery_any_x64.exe
unknown
http://dl.tenorshare.net/AnyDataRecovery_net_x64.exe
unknown
https://download.tenorshare.com/downloads/extra/reibootforios_ts_64.exeN
unknown
https://www.tenorshare.com/J
unknown
https://integrated.tenorshare.com/api/v1/ticket/feedback
unknown
http://curl.haxx.se/docs/http-cookies.html#
unknown
https://download.tenorshare.com/downloads/extra/reibootforios_ts.exext=
unknown
https://www.tenorshare.com/:
unknown
https://download.tenorshare.com/downloads/extra/reibootforios_ts.exe-U
unknown
http://www.tenorshare.com/downloads/service/softwarelog.txtC
unknown
http://curl.haxx.se/docs/http-cookies.html
unknown
https://download.tenorshare.com/downloads/extra/reibootforios_ts.exe
unknown
https://download.tenorshare.com/downloads/extra/reibootforios_ts.exext
unknown
https://update.tenorshare.com/queryDownloader?LanguageId=1033&SoftWareID=141&SiteID=1&package_type=2
unknown
http://ip-api.com/csvm.
unknown
https://download.tenorshare.net/downloads/extra/AnyDataRecovery_net_x64.exe
unknown
https://update.tenorshare.com/queryDownloader?LanguageId=1033&SoftWareID=%d&SiteID=1%s
unknown
https://update.tenorshare.com/download/checkCross?cross_end_id=%s
unknown
https://update.tenorshare.com/queryDownloader?LanguageId=%d&SoftWareID=%d&SiteID=%d%s
unknown
https://analytics-test.afirstsoft.cn/collector
unknown
https://download.tenorshare.com/downloads/extra/reibootforios_ts.exe1000
unknown
https://product-alert.afirstsoft.cn/api/exception/send
unknown
https://download.tenorshare.com/downloads/extra/reibootforios_ts_64.exe
unknown
https://analytics-test.afirstsoft.cn/collectorurl:mac
unknown
https://download.tenorshare.com/downloads/extra/reibootforios_ts.exea1
unknown
https://www.tenorshare.com/downloads/service/softwarelog.txt=
unknown
https://download.tenorshare.com/downloads/extra/AnyDataRecovery_ts_x64.exe
unknown
http://ip-api.com/csv
208.95.112.1
https://check.mobie.app
unknown
http://dl.tenorshare.net/AnyDataRecovery_ts_x64.exe
unknown
http://update.tenorshare.com/queryDownloader?LanguageId=%d&SoftWareID=%d&SiteID=%d%s
unknown
There are 39 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
ip-api.com
208.95.112.1
www.tenorshare.com
unknown
update.tenorshare.com
unknown

IPs

IP
Domain
Country
Malicious
208.95.112.1
ip-api.com
United States

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Tenorshare\Downloader2.5.0
GA_PC
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GuidGuidold
guid
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\GuidGuidold
user_id

Memdumps

Base Address
Regiontype
Protect
Malicious
8A4000
heap
page read and write
8E8000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
8F3000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
2574000
heap
page read and write
3413000
heap
page read and write
90D000
heap
page read and write
8B5000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
58B6000
heap
page read and write
957000
heap
page read and write
934000
heap
page read and write
6D1000
unkown
page execute and read and write
90A000
heap
page read and write
957000
heap
page read and write
4AD6000
heap
page read and write
8FD000
heap
page read and write
5860000
heap
page read and write
933000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
89F000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
4B66000
heap
page read and write
94E000
heap
page read and write
8EC000
heap
page read and write
957000
heap
page read and write
8A4000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
8D1000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
85E000
heap
page read and write
957000
heap
page read and write
3413000
heap
page read and write
933000
heap
page read and write
8B5000
heap
page read and write
7B1000
unkown
page read and write
890000
heap
page read and write
8DD000
heap
page read and write
249C000
stack
page read and write
93F000
heap
page read and write
2570000
heap
page read and write
957000
heap
page read and write
2A90000
heap
page read and write
8EA000
heap
page read and write
957000
heap
page read and write
35BE000
heap
page read and write
2547000
heap
page read and write
8DE000
heap
page read and write
4EAE000
unkown
page read and write
4EB0000
trusted library allocation
page read and write
58D2000
heap
page read and write
850000
heap
page read and write
910000
heap
page read and write
957000
heap
page read and write
93A000
heap
page read and write
2500000
heap
page read and write
590C000
heap
page read and write
8E0000
heap
page read and write
957000
heap
page read and write
933000
heap
page read and write
901000
heap
page read and write
24F0000
heap
page read and write
8D8000
heap
page read and write
957000
heap
page read and write
8D9000
heap
page read and write
957000
heap
page read and write
8F9000
heap
page read and write
5675000
heap
page read and write
957000
heap
page read and write
2570000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
8E2000
heap
page read and write
957000
heap
page read and write
B6E000
stack
page read and write
915000
heap
page read and write
957000
heap
page read and write
4FAC000
stack
page read and write
3800000
remote allocation
page read and write
8E6000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
8EC000
heap
page read and write
90E000
heap
page read and write
254C000
heap
page read and write
8D9000
heap
page read and write
60FF000
unkown
page read and write
33C3000
heap
page read and write
957000
heap
page read and write
3389000
heap
page read and write
957000
heap
page read and write
8F3000
heap
page read and write
8E9000
heap
page read and write
957000
heap
page read and write
24FE000
heap
page read and write
24FB000
heap
page read and write
8EC000
heap
page read and write
957000
heap
page read and write
2A8E000
stack
page read and write
957000
heap
page read and write
901000
heap
page read and write
891000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
906000
heap
page read and write
957000
heap
page read and write
8DE000
heap
page read and write
8D8000
heap
page read and write
948000
heap
page read and write
8EF000
heap
page read and write
2510000
heap
page read and write
88E000
heap
page read and write
957000
heap
page read and write
85A000
heap
page read and write
90C000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
903000
heap
page read and write
4B63000
heap
page read and write
957000
heap
page read and write
90B000
heap
page read and write
5F01000
heap
page read and write
6BE000
unkown
page execute and read and write
401000
unkown
page execute and read and write
4AE4000
heap
page read and write
8FD000
heap
page read and write
5CFE000
stack
page read and write
3649000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
8A3000
heap
page read and write
8F3000
heap
page read and write
957000
heap
page read and write
5FB000
unkown
page execute and write copy
957000
heap
page read and write
90B000
heap
page read and write
3682000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
8D8000
heap
page read and write
893000
heap
page read and write
8E9000
heap
page read and write
92A000
heap
page read and write
957000
heap
page read and write
251C000
heap
page read and write
950000
heap
page read and write
957000
heap
page read and write
33E3000
heap
page read and write
2640000
heap
page read and write
353D000
heap
page read and write
8B7000
heap
page read and write
CA0000
heap
page read and write
88E000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
5895000
heap
page read and write
901000
heap
page read and write
89C000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
90B000
heap
page read and write
957000
heap
page read and write
2520000
heap
page read and write
C6F000
stack
page read and write
8F3000
heap
page read and write
957000
heap
page read and write
8B9000
heap
page read and write
957000
heap
page read and write
CA5000
heap
page read and write
957000
heap
page read and write
580A000
heap
page read and write
5EFF000
stack
page read and write
957000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
8D1000
heap
page read and write
8A4000
heap
page read and write
33AF000
heap
page read and write
957000
heap
page read and write
2547000
heap
page read and write
8B5000
heap
page read and write
CA9000
heap
page read and write
33E4000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
911000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
340D000
heap
page read and write
8A4000
heap
page read and write
904000
heap
page read and write
24F3000
heap
page read and write
908000
heap
page read and write
8ED000
heap
page read and write
889000
heap
page read and write
94E000
heap
page read and write
3352000
heap
page read and write
8CD000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
8A4000
heap
page read and write
33AF000
heap
page read and write
957000
heap
page read and write
8DD000
heap
page read and write
914000
heap
page read and write
8E3000
heap
page read and write
58AC000
heap
page read and write
957000
heap
page read and write
8E0000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
2574000
heap
page read and write
2508000
heap
page read and write
957000
heap
page read and write
58F6000
heap
page read and write
8EC000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
934000
heap
page read and write
957000
heap
page read and write
90B000
heap
page read and write
2B40000
heap
page read and write
8E6000
heap
page read and write
957000
heap
page read and write
58EA000
heap
page read and write
24B1000
heap
page read and write
3736000
heap
page read and write
957000
heap
page read and write
2510000
heap
page read and write
24B1000
heap
page read and write
509C000
stack
page read and write
957000
heap
page read and write
933000
heap
page read and write
2570000
heap
page read and write
8D8000
heap
page read and write
8D4000
heap
page read and write
3412000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
3384000
heap
page read and write
7D0000
heap
page read and write
8A2000
heap
page read and write
3534000
heap
page read and write
8F3000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
351F000
heap
page read and write
94E000
heap
page read and write
906000
heap
page read and write
24F4000
heap
page read and write
33EB000
heap
page read and write
899000
heap
page read and write
3421000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
58BD000
heap
page read and write
957000
heap
page read and write
7E0000
heap
page read and write
906000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
8F5000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
896000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
24A0000
heap
page read and write
948000
heap
page read and write
933000
heap
page read and write
8E8000
heap
page read and write
957000
heap
page read and write
94E000
heap
page read and write
7AF000
unkown
page execute and write copy
957000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
24FC000
heap
page read and write
8FD000
heap
page read and write
8E6000
heap
page read and write
957000
heap
page read and write
3402000
heap
page read and write
957000
heap
page read and write
5F00000
heap
page read and write
957000
heap
page read and write
939000
heap
page read and write
373F000
heap
page read and write
957000
heap
page read and write
3404000
heap
page read and write
957000
heap
page read and write
24F0000
heap
page read and write
957000
heap
page read and write
8B5000
heap
page read and write
957000
heap
page read and write
90B000
heap
page read and write
3530000
heap
page read and write
8E7000
heap
page read and write
3371000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
4F2E000
stack
page read and write
957000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
8DB000
heap
page read and write
8F9000
heap
page read and write
957000
heap
page read and write
934000
heap
page read and write
957000
heap
page read and write
5864000
heap
page read and write
2545000
heap
page read and write
5560000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
3745000
heap
page read and write
957000
heap
page read and write
3351000
heap
page read and write
94E000
heap
page read and write
8E9000
heap
page read and write
3800000
remote allocation
page read and write
911000
heap
page read and write
957000
heap
page read and write
933000
heap
page read and write
957000
heap
page read and write
88D000
heap
page read and write
8D8000
heap
page read and write
8DF000
heap
page read and write
957000
heap
page read and write
93F000
heap
page read and write
957000
heap
page read and write
934000
heap
page read and write
8E2000
heap
page read and write
50AD000
stack
page read and write
5F01000
heap
page read and write
902000
heap
page read and write
79F000
unkown
page execute and read and write
898000
heap
page read and write
58E6000
heap
page read and write
957000
heap
page read and write
933000
heap
page read and write
B2F000
stack
page read and write
957000
heap
page read and write
82E000
stack
page read and write
898000
heap
page read and write
8F6000
heap
page read and write
93F000
heap
page read and write
24F6000
heap
page read and write
6D3000
unkown
page execute and read and write
8F4000
heap
page read and write
957000
heap
page read and write
8FD000
heap
page read and write
8B9000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
2599000
heap
page read and write
24F0000
heap
page read and write
4ADB000
heap
page read and write
957000
heap
page read and write
8DA000
heap
page read and write
195000
stack
page read and write
937000
heap
page read and write
92A000
heap
page read and write
343A000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
8E1000
heap
page read and write
899000
heap
page read and write
8D1000
heap
page read and write
8F9000
heap
page read and write
941000
heap
page read and write
3414000
heap
page read and write
2520000
heap
page read and write
5926000
heap
page read and write
8E3000
heap
page read and write
957000
heap
page read and write
24F0000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
8E6000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
891000
heap
page read and write
957000
heap
page read and write
24F0000
heap
page read and write
957000
heap
page read and write
89F000
heap
page read and write
957000
heap
page read and write
24D0000
heap
page read and write
957000
heap
page read and write
3738000
heap
page read and write
587A000
heap
page read and write
4B61000
heap
page read and write
957000
heap
page read and write
4ADD000
heap
page read and write
8DE000
heap
page read and write
373A000
heap
page read and write
3800000
remote allocation
page read and write
957000
heap
page read and write
957000
heap
page read and write
2572000
heap
page read and write
957000
heap
page read and write
94E000
heap
page read and write
5DFF000
stack
page read and write
915000
heap
page read and write
90C000
heap
page read and write
8E9000
heap
page read and write
957000
heap
page read and write
94E000
heap
page read and write
96000
stack
page read and write
949000
heap
page read and write
33AF000
heap
page read and write
2514000
heap
page read and write
24F9000
heap
page read and write
2599000
heap
page read and write
957000
heap
page read and write
956000
heap
page read and write
957000
heap
page read and write
88D000
heap
page read and write
957000
heap
page read and write
352B000
heap
page read and write
8E6000
heap
page read and write
957000
heap
page read and write
5704000
heap
page read and write
957000
heap
page read and write
886000
heap
page read and write
94E000
heap
page read and write
957000
heap
page read and write
2B50000
trusted library allocation
page read and write
957000
heap
page read and write
24FB000
heap
page read and write
2502000
heap
page read and write
957000
heap
page read and write
92A000
heap
page read and write
90E000
heap
page read and write
8F6000
heap
page read and write
58D6000
heap
page read and write
3359000
heap
page read and write
24D0000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
3714000
heap
page read and write
942000
heap
page read and write
8D1000
heap
page read and write
911000
heap
page read and write
8D9000
heap
page read and write
580E000
heap
page read and write
400000
unkown
page readonly
3376000
heap
page read and write
24B0000
heap
page read and write
957000
heap
page read and write
3424000
heap
page read and write
957000
heap
page read and write
93F000
heap
page read and write
33C7000
heap
page read and write
901000
heap
page read and write
8DD000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
33E5000
heap
page read and write
3767000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
957000
heap
page read and write
936000
heap
page read and write
2518000
heap
page read and write
92A000
heap
page read and write
957000
heap
page read and write
933000
heap
page read and write
910000
heap
page read and write
957000
heap
page read and write
4ADE000
heap
page read and write
957000
heap
page read and write
5790000
heap
page read and write
957000
heap
page read and write
88E000
heap
page read and write
8F9000
heap
page read and write
957000
heap
page read and write
7B1000
unkown
page write copy
957000
heap
page read and write
957000
heap
page read and write
8B8000
heap
page read and write
92A000
heap
page read and write
400000
unkown
page readonly
8F1000
heap
page read and write
901000
heap
page read and write
There are 502 hidden memdumps, click here to show them.