IOC Report
8lvzqcMqGF.exe

loading gif

Files

File Path
Type
Category
Malicious
8lvzqcMqGF.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\8lvzqcMqGF.exe.log
CSV text
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\8lvzqcMqGF.exe
"C:\Users\user\Desktop\8lvzqcMqGF.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
edurestunningcrackyow.fun
malicious
pooreveningfuseor.pw
malicious
associationokeo.shop
malicious
colorfulequalugliess.shop
malicious
turkeyunlikelyofw.shop
malicious
detectordiscusser.shop
malicious
wisemassiveharmonious.shop
malicious
relevantvoicelesskw.shop
malicious
https://associationokeo.shop/api
unknown
https://turkeyunlikelyofw.shop/api
unknown
https://colorfulequalugliess.shop/
unknown
https://turkeyunlikelyofw.shop/
unknown
https://pooreveningfuseor.pw/l
unknown
https://relevantvoicelesskw.shop/R8
unknown
https://associationokeo.shop/apiX
unknown
https://pooreveningfuseor.pw/api/api~
unknown
https://pooreveningfuseor.pw/api
unknown
https://detectordiscusser.shop/
unknown
https://detectordiscusser.shop/api
unknown
https://detectordiscusser.shop/v
unknown
https://pooreveningfuseor.pw/api/
unknown
https://detectordiscusser.shop/apiapi
unknown
https://associationokeo.shop//
unknown
https://associationokeo.shop/Ut
unknown
https://pooreveningfuseor.pw/
unknown
https://associationokeo.shop/d
unknown
There are 16 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
edurestunningcrackyow.fun
unknown
malicious
turkeyunlikelyofw.shop
unknown
malicious
detectordiscusser.shop
unknown
malicious
relevantvoicelesskw.shop
unknown
malicious
pooreveningfuseor.pw
unknown
malicious
wisemassiveharmonious.shop
unknown
malicious
associationokeo.shop
unknown
malicious
colorfulequalugliess.shop
unknown
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
400000
remote allocation
page execute and read and write
malicious
910000
trusted library allocation
page read and write
E78000
heap
page read and write
62C000
heap
page read and write
E00000
heap
page read and write
E5A000
heap
page read and write
940000
heap
page read and write
65C000
heap
page read and write
28DD000
stack
page read and write
23B6000
trusted library allocation
page read and write
E52000
heap
page read and write
448D000
stack
page read and write
D7E000
stack
page read and write
AFC000
stack
page read and write
913000
trusted library allocation
page execute and read and write
7F0000
heap
page read and write
236E000
stack
page read and write
289E000
stack
page read and write
2370000
heap
page execute and read and write
DA0000
heap
page read and write
641000
heap
page read and write
920000
trusted library allocation
page read and write
D80000
heap
page read and write
1CC000
stack
page read and write
21F0000
trusted library allocation
page read and write
5EE000
stack
page read and write
5A5000
heap
page read and write
279F000
stack
page read and write
226E000
stack
page read and write
2220000
trusted library allocation
page read and write
4F8000
stack
page read and write
A4F000
stack
page read and write
600000
heap
page read and write
2390000
trusted library allocation
page read and write
D3F000
stack
page read and write
930000
heap
page read and write
E0000
unkown
page readonly
33B1000
trusted library allocation
page read and write
900000
trusted library allocation
page read and write
924000
trusted library allocation
page read and write
21FA000
trusted library allocation
page execute and read and write
E0A000
heap
page read and write
E33000
heap
page read and write
E4F000
heap
page read and write
29DD000
stack
page read and write
E45000
heap
page read and write
458E000
stack
page read and write
2200000
trusted library allocation
page read and write
220B000
trusted library allocation
page execute and read and write
8CE000
stack
page read and write
C30000
heap
page read and write
E3F000
heap
page read and write
2380000
trusted library allocation
page execute and read and write
540000
heap
page read and write
DED000
stack
page read and write
914000
trusted library allocation
page read and write
446000
remote allocation
page execute and read and write
23B5000
trusted library allocation
page execute and read and write
23B1000
trusted library allocation
page read and write
5A0000
heap
page read and write
23A0000
heap
page read and write
530000
heap
page read and write
C35000
heap
page read and write
60E000
heap
page read and write
2D8E000
stack
page read and write
634000
heap
page read and write
C2E000
stack
page read and write
E28000
heap
page read and write
8D0000
heap
page read and write
58E000
stack
page read and write
77C000
stack
page read and write
608000
heap
page read and write
48F0000
trusted library allocation
page read and write
E38000
heap
page read and write
2207000
trusted library allocation
page execute and read and write
7E0000
heap
page read and write
33B5000
trusted library allocation
page read and write
2E8E000
stack
page read and write
E2000
unkown
page readonly
E6D000
heap
page read and write
There are 70 hidden memdumps, click here to show them.