IOC Report
SecuriteInfo.com.Win32.BankerX-gen.7761.21527.exe

loading gif

Files

File Path
Type
Category
Malicious
SecuriteInfo.com.Win32.BankerX-gen.7761.21527.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
C:\TEMP10.dwg
DWG AutoDesk AutoCAD 2004/2005/2006
dropped
C:\abc.scr
Lisp/Scheme program, ISO-8859 text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.Win32.BankerX-gen.7761.21527.exe
"C:\Users\user\Desktop\SecuriteInfo.com.Win32.BankerX-gen.7761.21527.exe"
malicious

URLs

Name
IP
Malicious
http://pan.baidu.com/s/1YNpTbPkGyZ4ANS-94e695g?pwd=i6v4
unknown
http://pan.baidu.com/s/1e49pLO57eL39PXBOAiVf0w?pwd=43j0
unknown
http://12814821.s21d.faiusrd.com/0/ABUIABBLGAAggq6cmwYopNPM-Qc.exe?f=%E8%BF%9C%E7%A8%8B%E5%B8%AE%E5%
unknown
http://pan.baidu.com/s/1CL7GcL7HpOMLfWCo5slmxA?pwd=g41d
unknown
http://pan.baidu.com/s/1YNpTbPkGyZ4ANS-94e695g?pwd=i6v4http://kr66666.comhttp://pan.baidu.com/s/1CL7
unknown
http://kr66666.com/h-nd-26.html
unknown
http://kr66666.com/h-col-103.html
unknown
http://kr66666.com/h-col-103.htmlhttp://12814821.s21d.faiusrd.com/0/ABUIABBLGAAggq6cmwYopNPM-Qc.exe?
unknown
http://kr66666.com
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
8D0000
heap
page read and write
260E000
stack
page read and write
412000
unkown
page readonly
8B0000
heap
page read and write
2CA0000
heap
page read and write
915000
heap
page read and write
47F000
unkown
page readonly
8DA000
heap
page read and write
C68000
heap
page read and write
1F0000
heap
page read and write
4B7F000
stack
page read and write
932000
heap
page read and write
2420000
heap
page read and write
401000
unkown
page execute read
8EB000
heap
page read and write
2400000
heap
page read and write
40E000
unkown
page read and write
40D000
unkown
page write copy
401000
unkown
page execute read
911000
heap
page read and write
95000
stack
page read and write
2C90000
heap
page read and write
400000
unkown
page readonly
8DE000
heap
page read and write
284F000
stack
page read and write
8F8000
heap
page read and write
412000
unkown
page readonly
400000
unkown
page readonly
40B000
unkown
page readonly
915000
heap
page read and write
270F000
stack
page read and write
4A7E000
stack
page read and write
C6E000
heap
page read and write
274E000
stack
page read and write
3FF0000
heap
page read and write
47F000
unkown
page readonly
2C98000
heap
page read and write
40B000
unkown
page readonly
932000
heap
page read and write
40D000
unkown
page write copy
8B4000
heap
page read and write
6E0000
heap
page read and write
2C9E000
heap
page read and write
4130000
trusted library allocation
page read and write
19B000
stack
page read and write
C60000
heap
page read and write
6D0000
heap
page read and write
There are 37 hidden memdumps, click here to show them.