IOC Report
https://www.dropbox.com/l/AADMt_ZaHT_hoHAzUbuMSCB681rYTSgmfiA

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\Desktop\cmdline.out
ASCII text, with CRLF line terminators
modified

Processes

Path
Cmdline
Malicious
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://www.dropbox.com/l/AADMt_ZaHT_hoHAzUbuMSCB681rYTSgmfiA" > cmdline.out 2>&1
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\wget.exe
wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "https://www.dropbox.com/l/AADMt_ZaHT_hoHAzUbuMSCB681rYTSgmfiA"

URLs

Name
IP
Malicious
https://www.dropbox.com/l/AADMt_ZaHT_hoHAzUbuMSCB681rYTSgmfiA
https://www.dropbox.com/l/AADMt_ZaHT_hoHAzUbuMSCB681rYTSgmfiA
162.125.9.18
https://www.dropbox.com/l/AADMt_ZaHT_hoHAzUbuMSCB681rYTSgmfiAPR
unknown

Domains

Name
IP
Malicious
www-env.dropbox-dns.com
162.125.9.18
www.dropbox.com
unknown

IPs

IP
Domain
Country
Malicious
162.125.9.18
www-env.dropbox-dns.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
9C000
stack
page read and write
9CD000
stack
page read and write
FF6000
heap
page read and write
111C000
heap
page read and write
FC0000
heap
page read and write
FFF000
heap
page read and write
A88000
heap
page read and write
111E000
heap
page read and write
1004000
heap
page read and write
FFA000
heap
page read and write
1002000
heap
page read and write
A4E000
stack
page read and write
A60000
heap
page read and write
A50000
heap
page read and write
FFA000
heap
page read and write
BB6000
heap
page read and write
111D000
heap
page read and write
100000
heap
page read and write
1E0000
heap
page read and write
DBF000
stack
page read and write
1005000
heap
page read and write
1110000
heap
page read and write
1002000
heap
page read and write
2DFF000
stack
page read and write
111B000
heap
page read and write
BB0000
heap
page read and write
A80000
heap
page read and write
FCB000
heap
page read and write
1115000
heap
page read and write
FFF000
heap
page read and write
FCD000
heap
page read and write
10FE000
stack
page read and write
A0E000
stack
page read and write
FBF000
stack
page read and write
There are 24 hidden memdumps, click here to show them.