IOC Report
Message from KM_360i

loading gif

Processes

Path
Cmdline
Malicious
C:\Windows\System32\OpenWith.exe
C:\Windows\system32\OpenWith.exe -Embedding
C:\Windows\System32\notepad.exe
"C:\Windows\system32\NOTEPAD.EXE" C:\Users\user\Desktop\Message from KM_360i

Registry

Path
Value
Malicious
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe.FriendlyAppName
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe.ApplicationCompany
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files\Mozilla Firefox\firefox.exe.FriendlyAppName
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files\Mozilla Firefox\firefox.exe.ApplicationCompany
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files\Internet Explorer\iexplore.exe.FriendlyAppName
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files\Internet Explorer\iexplore.exe.ApplicationCompany
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLED.EXE.FriendlyAppName
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLED.EXE.ApplicationCompany
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Windows\system32\mspaint.exe.FriendlyAppName
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Windows\system32\mspaint.exe.ApplicationCompany
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Windows\system32\NOTEPAD.EXE.FriendlyAppName
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Windows\system32\NOTEPAD.EXE.ApplicationCompany
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files (x86)\Microsoft Office\root\Office16\Winword.exe.FriendlyAppName
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files (x86)\Microsoft Office\root\Office16\Winword.exe.ApplicationCompany
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files (x86)\Windows Media Player\wmplayer.exe.FriendlyAppName
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files (x86)\Windows Media Player\wmplayer.exe.ApplicationCompany
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE.FriendlyAppName
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE.ApplicationCompany
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\abgrcnq.rkr
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Notepad
fWindowsOnlyEOL
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Notepad
fPasteOriginalEOL
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Notepad
fReverse
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Notepad
fWrapAround
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Notepad
fMatchCase
There are 15 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
1A05735A000
heap
page read and write
2573F040000
heap
page read and write
1A057372000
heap
page read and write
1A057262000
heap
page read and write
1A05737C000
heap
page read and write
1A057372000
heap
page read and write
1A057342000
heap
page read and write
8EC4F59000
stack
page read and write
1A057385000
heap
page read and write
1A057296000
heap
page read and write
1A059A3C000
heap
page read and write
1A055289000
heap
page read and write
1A0599FC000
heap
page read and write
2573F150000
heap
page read and write
1A057378000
heap
page read and write
1A05736A000
heap
page read and write
1A057361000
heap
page read and write
1A057378000
heap
page read and write
1A05737C000
heap
page read and write
1A0572E2000
heap
page read and write
1A05529C000
heap
page read and write
1A057282000
heap
page read and write
1A0572B4000
heap
page read and write
1A057382000
heap
page read and write
1A0599B0000
heap
page read and write
1A0599CD000
heap
page read and write
1A057354000
heap
page read and write
1A057377000
heap
page read and write
1A057381000
heap
page read and write
1A0573AD000
heap
page read and write
2573F19C000
heap
page read and write
1A057348000
heap
page read and write
257418E0000
heap
page read and write
1A05736F000
heap
page read and write
1A0552C7000
heap
page read and write
1A057373000
heap
page read and write
1A057339000
heap
page read and write
2573D6D8000
heap
page read and write
1A0572E7000
heap
page read and write
1A0552B5000
heap
page read and write
9A751A6000
stack
page read and write
1A057358000
heap
page read and write
1A057361000
heap
page read and write
1A057364000
heap
page read and write
1A057278000
heap
page read and write
1A0553C0000
heap
page read and write
1A0572F1000
heap
page read and write
1A057340000
heap
page read and write
1A0572EA000
heap
page read and write
1A0573AD000
heap
page read and write
1A05728C000
heap
page read and write
1A055224000
heap
page read and write
1A05736E000
heap
page read and write
1A057385000
heap
page read and write
1A057381000
heap
page read and write
1A057366000
heap
page read and write
1A057374000
heap
page read and write
1A059A4D000
heap
page read and write
1A057361000
heap
page read and write
1A057373000
heap
page read and write
1A057373000
heap
page read and write
1A057372000
heap
page read and write
1A057366000
heap
page read and write
1A057361000
heap
page read and write
1A056C50000
heap
page read and write
1A05731E000
heap
page read and write
1A057379000
heap
page read and write
9A754FE000
stack
page read and write
2573D709000
heap
page read and write
1A0599F7000
heap
page read and write
1A057361000
heap
page read and write
1A0572B4000
heap
page read and write
1A0599E3000
heap
page read and write
1A057298000
heap
page read and write
1A057372000
heap
page read and write
1A05734B000
heap
page read and write
1A059A5A000
heap
page read and write
1A0572DD000
heap
page read and write
1A057381000
heap
page read and write
9A7577B000
stack
page read and write
1A0573A7000
heap
page read and write
1A05739A000
heap
page read and write
1A055293000
heap
page read and write
1A0573AD000
heap
page read and write
7DF48DE11000
trusted library allocation
page execute read
1A05738E000
heap
page read and write
1A0572DD000
heap
page read and write
1A05729A000
heap
page read and write
1A057220000
heap
page read and write
2573D709000
heap
page read and write
1A057359000
heap
page read and write
1A057389000
heap
page read and write
2573D6FF000
heap
page read and write
1A05733F000
heap
page read and write
2573D706000
heap
page read and write
1A0599E0000
heap
page read and write
1A056BE0000
heap
page read and write
1A059E50000
heap
page read and write
1A05737C000
heap
page read and write
1A057337000
heap
page read and write
1A055297000
heap
page read and write
1A05734F000
heap
page read and write
1A057358000
heap
page read and write
1A05739F000
heap
page read and write
1A057389000
heap
page read and write
1A0572C9000
heap
page read and write
1A057348000
heap
page read and write
1A057378000
heap
page read and write
1A059A0D000
heap
page read and write
1A0551F0000
heap
page read and write
1A0599EA000
heap
page read and write
1A05726F000
heap
page read and write
1A057342000
heap
page read and write
2573D70A000
heap
page read and write
1A057358000
heap
page read and write
1A057344000
heap
page read and write
1A0552C5000
heap
page read and write
1A057285000
heap
page read and write
1A057278000
heap
page read and write
1A057358000
heap
page read and write
1A055299000
heap
page read and write
1A057361000
heap
page read and write
1A059A44000
heap
page read and write
1A057342000
heap
page read and write
1A0572FE000
heap
page read and write
1A05C2F0000
heap
page readonly
1A05738D000
heap
page read and write
1A05734F000
heap
page read and write
1A057378000
heap
page read and write
1A057369000
heap
page read and write
1A057391000
heap
page read and write
9A7597B000
stack
page read and write
1A0572E7000
heap
page read and write
1A059A33000
heap
page read and write
1A0552C9000
heap
page read and write
1A057372000
heap
page read and write
2573D670000
heap
page read and write
1A057361000
heap
page read and write
1A05728E000
heap
page read and write
1A05736E000
heap
page read and write
1A05738C000
heap
page read and write
1A057331000
heap
page read and write
1A055293000
heap
page read and write
1A0552B8000
heap
page read and write
1A05739B000
heap
page read and write
1A059A56000
heap
page read and write
9A755FF000
stack
page read and write
1A0552C4000
heap
page read and write
1A05736E000
heap
page read and write
1A057381000
heap
page read and write
1A059A0F000
heap
page read and write
1A0573AC000
heap
page read and write
1A05738E000
heap
page read and write
1A0552BD000
heap
page read and write
1A05738D000
heap
page read and write
1A057361000
heap
page read and write
1A057389000
heap
page read and write
1A057395000
heap
page read and write
1A0572FE000
heap
page read and write
1A05738D000
heap
page read and write
2573D728000
heap
page read and write
1A057396000
heap
page read and write
1A057365000
heap
page read and write
1A057364000
heap
page read and write
1A057385000
heap
page read and write
1A05738A000
heap
page read and write
1A0552B8000
heap
page read and write
1A057366000
heap
page read and write
1A057280000
heap
page read and write
1A0552C2000
heap
page read and write
1A057378000
heap
page read and write
1A0572A4000
heap
page read and write
9A7557E000
stack
page read and write
1A0572C6000
heap
page read and write
2573D725000
heap
page read and write
1A059A5B000
heap
page read and write
1A057284000
heap
page read and write
1A05528D000
heap
page read and write
1A0552EE000
heap
page read and write
1A05736E000
heap
page read and write
1A057292000
heap
page read and write
1A0572CC000
heap
page read and write
1A059A51000
heap
page read and write
1A056BE3000
heap
page read and write
1A05738D000
heap
page read and write
1A05738D000
heap
page read and write
1A05729D000
heap
page read and write
1A057361000
heap
page read and write
1A059470000
trusted library allocation
page read and write
1A057391000
heap
page read and write
1A056C55000
heap
page read and write
1A057366000
heap
page read and write
2573F195000
heap
page read and write
1A05726A000
heap
page read and write
1A057391000
heap
page read and write
1A057385000
heap
page read and write
1A0599F4000
heap
page read and write
1A05734F000
heap
page read and write
1A0552A0000
heap
page read and write
1A057385000
heap
page read and write
1A057343000
heap
page read and write
1A055289000
heap
page read and write
1A057366000
heap
page read and write
1A057378000
heap
page read and write
1A0572FE000
heap
page read and write
2573D6D0000
heap
page read and write
1A05735B000
heap
page read and write
1A0573A1000
heap
page read and write
1A059A51000
heap
page read and write
1A057391000
heap
page read and write
1A057361000
heap
page read and write
1A057365000
heap
page read and write
1A05738A000
heap
page read and write
1A057263000
heap
page read and write
1A0572EC000
heap
page read and write
1A057378000
heap
page read and write
1A057366000
heap
page read and write
1A05736E000
heap
page read and write
1A05733D000
heap
page read and write
1A05737C000
heap
page read and write
257410E0000
trusted library allocation
page read and write
1A056C5D000
heap
page read and write
1A05734F000
heap
page read and write
1A057347000
heap
page read and write
1A05739F000
heap
page read and write
1A057361000
heap
page read and write
1A057392000
heap
page read and write
1A05729A000
heap
page read and write
1A057396000
heap
page read and write
1A0572AA000
heap
page read and write
1A057354000
heap
page read and write
1A0552C2000
heap
page read and write
1A0572AE000
heap
page read and write
1A05737E000
heap
page read and write
1A0572EA000
heap
page read and write
1A057378000
heap
page read and write
1A0572BB000
heap
page read and write
1A057380000
heap
page read and write
1A0599EE000
heap
page read and write
1A0572B4000
heap
page read and write
1A059A20000
heap
page read and write
1A0552BA000
heap
page read and write
1A059A46000
heap
page read and write
1A05736A000
heap
page read and write
1A05C3F0000
heap
page read and write
1A057381000
heap
page read and write
1A055295000
heap
page read and write
1A0572D6000
heap
page read and write
1A057365000
heap
page read and write
1A05737D000
heap
page read and write
1A05737C000
heap
page read and write
1A05737D000
heap
page read and write
1A05737C000
heap
page read and write
8EC53FF000
stack
page read and write
1A057315000
heap
page read and write
1A057372000
heap
page read and write
1A05737C000
heap
page read and write
1A05737D000
heap
page read and write
1A057361000
heap
page read and write
1A057294000
heap
page read and write
1A0572D6000
heap
page read and write
1A059A11000
heap
page read and write
1A05734F000
heap
page read and write
1A0599FF000
heap
page read and write
1A057382000
heap
page read and write
2573F130000
heap
page read and write
1A059A39000
heap
page read and write
1A056B90000
heap
page read and write
9A756FE000
stack
page read and write
1A057396000
heap
page read and write
1A057385000
heap
page read and write
1A05BEC0000
heap
page read and write
1A05738A000
heap
page read and write
1A0573A7000
heap
page read and write
1A057362000
heap
page read and write
1A059A36000
heap
page read and write
1A059A2A000
heap
page read and write
9A7547E000
stack
page read and write
1A05728C000
heap
page read and write
1A05736E000
heap
page read and write
1A0599C4000
heap
page read and write
1A057396000
heap
page read and write
1A05736E000
heap
page read and write
1A057372000
heap
page read and write
1A057396000
heap
page read and write
1A055284000
heap
page read and write
1A0572A2000
heap
page read and write
1A055268000
heap
page read and write
1A059A3E000
heap
page read and write
8EC537E000
stack
page read and write
1A057396000
heap
page read and write
1A057346000
heap
page read and write
1A057365000
heap
page read and write
1A057361000
heap
page read and write
1A05738D000
heap
page read and write
1A057361000
heap
page read and write
1A0599F4000
heap
page read and write
1A057358000
heap
page read and write
1A0552A3000
heap
page read and write
1A059A18000
heap
page read and write
1A0552E8000
heap
page read and write
1A057320000
heap
page read and write
1A057385000
heap
page read and write
1A057380000
heap
page read and write
1A0572B9000
heap
page read and write
1A057271000
heap
page read and write
1A0552E4000
heap
page read and write
1A057346000
heap
page read and write
1A057396000
heap
page read and write
1A059A51000
heap
page read and write
1A0572BD000
heap
page read and write
1A057382000
heap
page read and write
1A059A40000
heap
page read and write
1A059A5A000
heap
page read and write
2573F110000
trusted library allocation
page read and write
1A0572C1000
heap
page read and write
2573D750000
heap
page read and write
1A059A4B000
heap
page read and write
1A059A09000
heap
page read and write
1A057389000
heap
page read and write
1A05737C000
heap
page read and write
1A05726D000
heap
page read and write
1A05736A000
heap
page read and write
1A0599F2000
heap
page read and write
1A057365000
heap
page read and write
1A0552E8000
heap
page read and write
1A0573AD000
heap
page read and write
1A057361000
heap
page read and write
1A0572E0000
heap
page read and write
1A057363000
heap
page read and write
1A05734F000
heap
page read and write
1A05C2E0000
trusted library allocation
page read and write
1A055285000
heap
page read and write
1A057275000
heap
page read and write
1A0552B3000
heap
page read and write
1A05734B000
heap
page read and write
1A05738D000
heap
page read and write
1A057354000
heap
page read and write
1A0572AA000
heap
page read and write
1A057354000
heap
page read and write
1A0551D0000
heap
page read and write
1A057359000
heap
page read and write
1A057361000
heap
page read and write
1A0552C8000
heap
page read and write
1A057395000
heap
page read and write
1A057372000
heap
page read and write
1A05739F000
heap
page read and write
1A059A13000
heap
page read and write
1A057380000
heap
page read and write
1A057290000
heap
page read and write
2573D72A000
heap
page read and write
1A057372000
heap
page read and write
1A05737C000
heap
page read and write
1A0552B0000
heap
page read and write
1A057359000
heap
page read and write
1A057377000
heap
page read and write
1A05736A000
heap
page read and write
1A0573A1000
heap
page read and write
1A057396000
heap
page read and write
1A057381000
heap
page read and write
1A059A23000
heap
page read and write
1A056C5E000
heap
page read and write
1A0599F6000
heap
page read and write
1A057372000
heap
page read and write
1A057355000
heap
page read and write
1A057396000
heap
page read and write
1A05736E000
heap
page read and write
1A057335000
heap
page read and write
1A057302000
heap
page read and write
1A059A2A000
heap
page read and write
1A057381000
heap
page read and write
9A7567E000
stack
page read and write
1A05737C000
heap
page read and write
1A05738C000
heap
page read and write
1A059A3E000
heap
page read and write
1A057315000
heap
page read and write
1A057372000
heap
page read and write
1A059A4D000
heap
page read and write
1A05729A000
heap
page read and write
1A0552EC000
heap
page read and write
1A057385000
heap
page read and write
1A057361000
heap
page read and write
1A05733B000
heap
page read and write
1A05736C000
heap
page read and write
1A057372000
heap
page read and write
1A057330000
heap
page read and write
1A0552A7000
heap
page read and write
1A057344000
heap
page read and write
1A0572EA000
heap
page read and write
1A0572B4000
heap
page read and write
1A057280000
heap
page read and write
1A05737C000
heap
page read and write
1A05735D000
heap
page read and write
1A0572F4000
heap
page read and write
1A057396000
heap
page read and write
1A057372000
heap
page read and write
1A059A19000
heap
page read and write
1A059A54000
heap
page read and write
1A059A4B000
heap
page read and write
1A05728E000
heap
page read and write
1A05739B000
heap
page read and write
1A057385000
heap
page read and write
1A05736A000
heap
page read and write
1A05737C000
heap
page read and write
1A057389000
heap
page read and write
2573D72E000
heap
page read and write
1A05736E000
heap
page read and write
1A05736A000
heap
page read and write
1A0572FE000
heap
page read and write
1A057372000
heap
page read and write
1A0552BA000
heap
page read and write
1A05734F000
heap
page read and write
1A057396000
heap
page read and write
1A0552B3000
heap
page read and write
2573F190000
heap
page read and write
1A057354000
heap
page read and write
1A05734B000
heap
page read and write
1A057378000
heap
page read and write
1A05738D000
heap
page read and write
1A0599EA000
heap
page read and write
8EC547F000
stack
page read and write
1A0572A2000
heap
page read and write
1A0572A2000
heap
page read and write
1A057378000
heap
page read and write
1A057378000
heap
page read and write
1A0599E5000
heap
page read and write
1A055293000
heap
page read and write
1A057388000
heap
page read and write
1A0572D0000
heap
page read and write
1A057354000
heap
page read and write
1A057372000
heap
page read and write
1A0572B0000
heap
page read and write
1A0599F2000
heap
page read and write
1A057389000
heap
page read and write
1A059A5C000
heap
page read and write
1A059A39000
heap
page read and write
1A05734A000
heap
page read and write
1A057361000
heap
page read and write
2573D701000
heap
page read and write
1A057381000
heap
page read and write
1A059A2A000
heap
page read and write
2573D74C000
heap
page read and write
1A0552BD000
heap
page read and write
1A057372000
heap
page read and write
1A057349000
heap
page read and write
1A05529D000
heap
page read and write
1A05735B000
heap
page read and write
1A057364000
heap
page read and write
1A05B862000
trusted library allocation
page read and write
1A0552B5000
heap
page read and write
1A057389000
heap
page read and write
1A057372000
heap
page read and write
2573F153000
heap
page read and write
1A05738A000
heap
page read and write
1A05736E000
heap
page read and write
1A0572C7000
heap
page read and write
1A057372000
heap
page read and write
2573D726000
heap
page read and write
1A057389000
heap
page read and write
2573D680000
heap
page read and write
1A057347000
heap
page read and write
There are 451 hidden memdumps, click here to show them.