IOC Report
bUBL.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\bUBL.exe
"C:\Users\user\Desktop\bUBL.exe"
malicious

URLs

Name
IP
Malicious
rusia.duckdns.org
malicious

Domains

Name
IP
Malicious
rusia.duckdns.org
46.246.14.17
malicious

IPs

IP
Domain
Country
Malicious
46.246.14.17
rusia.duckdns.org
Sweden
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER
di
HKEY_CURRENT_USER\SOFTWARE\f2887c56e8ee
[kl]

Memdumps

Base Address
Regiontype
Protect
Malicious
C82000
unkown
page readonly
malicious
142E000
heap
page read and write
1830000
trusted library allocation
page execute and read and write
3364000
trusted library allocation
page read and write
1716000
heap
page read and write
33BA000
trusted library allocation
page read and write
1A00000
heap
page read and write
5BD0000
heap
page read and write
1428000
heap
page read and write
10F9000
stack
page read and write
5BB0000
heap
page read and write
1272000
trusted library allocation
page execute and read and write
57DE000
stack
page read and write
54EC000
stack
page read and write
1820000
trusted library allocation
page read and write
33DA000
trusted library allocation
page read and write
145E000
heap
page read and write
3361000
trusted library allocation
page read and write
33CC000
trusted library allocation
page read and write
181F000
stack
page read and write
129A000
trusted library allocation
page execute and read and write
128A000
trusted library allocation
page execute and read and write
14D5000
heap
page read and write
1840000
heap
page execute and read and write
120E000
stack
page read and write
1628000
trusted library allocation
page read and write
1710000
heap
page read and write
1287000
trusted library allocation
page execute and read and write
5BA0000
heap
page read and write
1270000
trusted library allocation
page read and write
3402000
trusted library allocation
page read and write
16FC000
stack
page read and write
14C5000
heap
page read and write
5A30000
trusted library allocation
page execute and read and write
569E000
stack
page read and write
33D4000
trusted library allocation
page read and write
4361000
trusted library allocation
page read and write
1240000
trusted library allocation
page read and write
3396000
trusted library allocation
page read and write
1250000
heap
page read and write
126A000
trusted library allocation
page execute and read and write
1262000
trusted library allocation
page execute and read and write
12A0000
trusted library allocation
page read and write
55A8000
stack
page read and write
55B3000
heap
page read and write
579E000
stack
page read and write
12AB000
trusted library allocation
page execute and read and write
12F5000
heap
page read and write
10F6000
stack
page read and write
12A7000
trusted library allocation
page execute and read and write
D70000
heap
page read and write
1292000
trusted library allocation
page execute and read and write
545D000
stack
page read and write
13FE000
stack
page read and write
33C9000
trusted library allocation
page read and write
C88000
unkown
page readonly
1420000
heap
page read and write
DCE000
stack
page read and write
58DF000
stack
page read and write
12A2000
trusted library allocation
page read and write
12EE000
stack
page read and write
1210000
heap
page read and write
7F030000
trusted library allocation
page execute and read and write
19F0000
trusted library allocation
page read and write
1280000
trusted library allocation
page read and write
D1A000
stack
page read and write
33E4000
trusted library allocation
page read and write
33D0000
trusted library allocation
page read and write
33C0000
trusted library allocation
page read and write
127A000
trusted library allocation
page execute and read and write
556C000
stack
page read and write
552B000
stack
page read and write
5630000
trusted library allocation
page execute and read and write
161E000
stack
page read and write
55C0000
trusted library allocation
page read and write
12F0000
heap
page read and write
D80000
heap
page read and write
C80000
unkown
page readonly
55B0000
heap
page read and write
5640000
unclassified section
page read and write
There are 70 hidden memdumps, click here to show them.