Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
8lvzqcMqGF.exe
|
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
|
initial sample
|
||
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\8lvzqcMqGF.exe.log
|
CSV text
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\8lvzqcMqGF.exe
|
"C:\Users\user\Desktop\8lvzqcMqGF.exe"
|
||
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
|
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
|
||
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
|
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
edurestunningcrackyow.fun
|
|||
pooreveningfuseor.pw
|
|||
associationokeo.shop
|
|||
colorfulequalugliess.shop
|
|||
turkeyunlikelyofw.shop
|
|||
detectordiscusser.shop
|
|||
wisemassiveharmonious.shop
|
|||
relevantvoicelesskw.shop
|
|||
https://associationokeo.shop/api
|
unknown
|
||
https://turkeyunlikelyofw.shop/api
|
unknown
|
||
https://colorfulequalugliess.shop/
|
unknown
|
||
https://turkeyunlikelyofw.shop/
|
unknown
|
||
https://pooreveningfuseor.pw/l
|
unknown
|
||
https://relevantvoicelesskw.shop/R8
|
unknown
|
||
https://associationokeo.shop/apiX
|
unknown
|
||
https://pooreveningfuseor.pw/api/api~
|
unknown
|
||
https://pooreveningfuseor.pw/api
|
unknown
|
||
https://detectordiscusser.shop/
|
unknown
|
||
https://detectordiscusser.shop/api
|
unknown
|
||
https://detectordiscusser.shop/v
|
unknown
|
||
https://pooreveningfuseor.pw/api/
|
unknown
|
||
https://detectordiscusser.shop/apiapi
|
unknown
|
||
https://associationokeo.shop//
|
unknown
|
||
https://associationokeo.shop/Ut
|
unknown
|
||
https://pooreveningfuseor.pw/
|
unknown
|
||
https://associationokeo.shop/d
|
unknown
|
There are 16 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
edurestunningcrackyow.fun
|
unknown
|
||
turkeyunlikelyofw.shop
|
unknown
|
||
detectordiscusser.shop
|
unknown
|
||
relevantvoicelesskw.shop
|
unknown
|
||
pooreveningfuseor.pw
|
unknown
|
||
wisemassiveharmonious.shop
|
unknown
|
||
associationokeo.shop
|
unknown
|
||
colorfulequalugliess.shop
|
unknown
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
400000
|
remote allocation
|
page execute and read and write
|
||
910000
|
trusted library allocation
|
page read and write
|
||
E78000
|
heap
|
page read and write
|
||
62C000
|
heap
|
page read and write
|
||
E00000
|
heap
|
page read and write
|
||
E5A000
|
heap
|
page read and write
|
||
940000
|
heap
|
page read and write
|
||
65C000
|
heap
|
page read and write
|
||
28DD000
|
stack
|
page read and write
|
||
23B6000
|
trusted library allocation
|
page read and write
|
||
E52000
|
heap
|
page read and write
|
||
448D000
|
stack
|
page read and write
|
||
D7E000
|
stack
|
page read and write
|
||
AFC000
|
stack
|
page read and write
|
||
913000
|
trusted library allocation
|
page execute and read and write
|
||
7F0000
|
heap
|
page read and write
|
||
236E000
|
stack
|
page read and write
|
||
289E000
|
stack
|
page read and write
|
||
2370000
|
heap
|
page execute and read and write
|
||
DA0000
|
heap
|
page read and write
|
||
641000
|
heap
|
page read and write
|
||
920000
|
trusted library allocation
|
page read and write
|
||
D80000
|
heap
|
page read and write
|
||
1CC000
|
stack
|
page read and write
|
||
21F0000
|
trusted library allocation
|
page read and write
|
||
5EE000
|
stack
|
page read and write
|
||
5A5000
|
heap
|
page read and write
|
||
279F000
|
stack
|
page read and write
|
||
226E000
|
stack
|
page read and write
|
||
2220000
|
trusted library allocation
|
page read and write
|
||
4F8000
|
stack
|
page read and write
|
||
A4F000
|
stack
|
page read and write
|
||
600000
|
heap
|
page read and write
|
||
2390000
|
trusted library allocation
|
page read and write
|
||
D3F000
|
stack
|
page read and write
|
||
930000
|
heap
|
page read and write
|
||
E0000
|
unkown
|
page readonly
|
||
33B1000
|
trusted library allocation
|
page read and write
|
||
900000
|
trusted library allocation
|
page read and write
|
||
924000
|
trusted library allocation
|
page read and write
|
||
21FA000
|
trusted library allocation
|
page execute and read and write
|
||
E0A000
|
heap
|
page read and write
|
||
E33000
|
heap
|
page read and write
|
||
E4F000
|
heap
|
page read and write
|
||
29DD000
|
stack
|
page read and write
|
||
E45000
|
heap
|
page read and write
|
||
458E000
|
stack
|
page read and write
|
||
2200000
|
trusted library allocation
|
page read and write
|
||
220B000
|
trusted library allocation
|
page execute and read and write
|
||
8CE000
|
stack
|
page read and write
|
||
C30000
|
heap
|
page read and write
|
||
E3F000
|
heap
|
page read and write
|
||
2380000
|
trusted library allocation
|
page execute and read and write
|
||
540000
|
heap
|
page read and write
|
||
DED000
|
stack
|
page read and write
|
||
914000
|
trusted library allocation
|
page read and write
|
||
446000
|
remote allocation
|
page execute and read and write
|
||
23B5000
|
trusted library allocation
|
page execute and read and write
|
||
23B1000
|
trusted library allocation
|
page read and write
|
||
5A0000
|
heap
|
page read and write
|
||
23A0000
|
heap
|
page read and write
|
||
530000
|
heap
|
page read and write
|
||
C35000
|
heap
|
page read and write
|
||
60E000
|
heap
|
page read and write
|
||
2D8E000
|
stack
|
page read and write
|
||
634000
|
heap
|
page read and write
|
||
C2E000
|
stack
|
page read and write
|
||
E28000
|
heap
|
page read and write
|
||
8D0000
|
heap
|
page read and write
|
||
58E000
|
stack
|
page read and write
|
||
77C000
|
stack
|
page read and write
|
||
608000
|
heap
|
page read and write
|
||
48F0000
|
trusted library allocation
|
page read and write
|
||
E38000
|
heap
|
page read and write
|
||
2207000
|
trusted library allocation
|
page execute and read and write
|
||
7E0000
|
heap
|
page read and write
|
||
33B5000
|
trusted library allocation
|
page read and write
|
||
2E8E000
|
stack
|
page read and write
|
||
E2000
|
unkown
|
page readonly
|
||
E6D000
|
heap
|
page read and write
|
There are 70 hidden memdumps, click here to show them.