Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
HSBC Havale Bildirimi.exe
|
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
initial sample
|
||
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\HSBC Havale Bildirimi.exe.log
|
ASCII text, with CRLF line terminators
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\HSBC Havale Bildirimi.exe
|
"C:\Users\user\Desktop\HSBC Havale Bildirimi.exe"
|
||
C:\Users\user\Desktop\HSBC Havale Bildirimi.exe
|
"C:\Users\user\Desktop\HSBC Havale Bildirimi.exe"
|
||
C:\Users\user\Desktop\HSBC Havale Bildirimi.exe
|
"C:\Users\user\Desktop\HSBC Havale Bildirimi.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://www.apache.org/licenses/LICENSE-2.0
|
unknown
|
||
http://www.fontbureau.com
|
unknown
|
||
http://www.fontbureau.com/designersG
|
unknown
|
||
http://www.fontbureau.com/designers/?
|
unknown
|
||
http://www.founder.com.cn/cn/bThe
|
unknown
|
||
https://account.dyn.com/
|
unknown
|
||
http://www.fontbureau.com/designers?
|
unknown
|
||
http://www.tiro.com
|
unknown
|
||
http://www.fontbureau.com/designers
|
unknown
|
||
http://www.goodfont.co.kr
|
unknown
|
||
http://www.carterandcone.coml
|
unknown
|
||
http://www.sajatypeworks.com
|
unknown
|
||
http://www.typography.netD
|
unknown
|
||
http://www.fontbureau.com/designers/cabarga.htmlN
|
unknown
|
||
http://www.founder.com.cn/cn/cThe
|
unknown
|
||
http://www.galapagosdesign.com/staff/dennis.htm
|
unknown
|
||
http://www.founder.com.cn/cn
|
unknown
|
||
http://www.fontbureau.com/designers/frere-user.html
|
unknown
|
||
http://www.jiyu-kobo.co.jp/
|
unknown
|
||
http://www.galapagosdesign.com/DPlease
|
unknown
|
||
http://www.fontbureau.com/designers8
|
unknown
|
||
http://www.fonts.com
|
unknown
|
||
http://www.sandoll.co.kr
|
unknown
|
||
http://eu-west-1.sftpcloud.io
|
unknown
|
||
http://www.urwpp.deDPlease
|
unknown
|
||
http://www.zhongyicts.com.cn
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
|
unknown
|
||
http://www.sakkal.com
|
unknown
|
There are 18 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
eu-west-1.sftpcloud.io
|
159.65.94.38
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
159.65.94.38
|
eu-west-1.sftpcloud.io
|
United States
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing
|
EnableConsoleTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\HSBC Havale Bildirimi_RASAPI32
|
EnableFileTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\HSBC Havale Bildirimi_RASAPI32
|
EnableAutoFileTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\HSBC Havale Bildirimi_RASAPI32
|
EnableConsoleTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\HSBC Havale Bildirimi_RASAPI32
|
FileTracingMask
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\HSBC Havale Bildirimi_RASAPI32
|
ConsoleTracingMask
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\HSBC Havale Bildirimi_RASAPI32
|
MaxFileSize
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\HSBC Havale Bildirimi_RASAPI32
|
FileDirectory
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\HSBC Havale Bildirimi_RASMANCS
|
EnableFileTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\HSBC Havale Bildirimi_RASMANCS
|
EnableAutoFileTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\HSBC Havale Bildirimi_RASMANCS
|
EnableConsoleTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\HSBC Havale Bildirimi_RASMANCS
|
FileTracingMask
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\HSBC Havale Bildirimi_RASMANCS
|
ConsoleTracingMask
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\HSBC Havale Bildirimi_RASMANCS
|
MaxFileSize
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\HSBC Havale Bildirimi_RASMANCS
|
FileDirectory
|
There are 5 hidden registries, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
32D1000
|
trusted library allocation
|
page read and write
|
||
402000
|
remote allocation
|
page execute and read and write
|
||
331A000
|
trusted library allocation
|
page read and write
|
||
4E0E000
|
trusted library allocation
|
page read and write
|
||
7BFF000
|
stack
|
page read and write
|
||
18E4000
|
trusted library allocation
|
page read and write
|
||
195E000
|
stack
|
page read and write
|
||
3431000
|
trusted library allocation
|
page read and write
|
||
57BE000
|
trusted library allocation
|
page read and write
|
||
57D6000
|
trusted library allocation
|
page read and write
|
||
18FD000
|
trusted library allocation
|
page execute and read and write
|
||
16AF000
|
heap
|
page read and write
|
||
10A9000
|
stack
|
page read and write
|
||
930E000
|
stack
|
page read and write
|
||
7AB0000
|
trusted library section
|
page read and write
|
||
15F1000
|
heap
|
page read and write
|
||
5C50000
|
heap
|
page read and write
|
||
940E000
|
stack
|
page read and write
|
||
30B2000
|
trusted library allocation
|
page read and write
|
||
42F9000
|
trusted library allocation
|
page read and write
|
||
5D9E000
|
heap
|
page read and write
|
||
FC2000
|
unkown
|
page readonly
|
||
7EE8000
|
trusted library allocation
|
page read and write
|
||
1420000
|
heap
|
page read and write
|
||
7500000
|
trusted library allocation
|
page read and write
|
||
33C0000
|
trusted library allocation
|
page read and write
|
||
7E50000
|
trusted library allocation
|
page read and write
|
||
3328000
|
trusted library allocation
|
page read and write
|
||
11A8000
|
stack
|
page read and write
|
||
3410000
|
trusted library allocation
|
page read and write
|
||
31C0000
|
heap
|
page read and write
|
||
30C7000
|
trusted library allocation
|
page execute and read and write
|
||
433B000
|
trusted library allocation
|
page read and write
|
||
31AC000
|
stack
|
page read and write
|
||
5990000
|
heap
|
page read and write
|
||
1530000
|
heap
|
page read and write
|
||
5CCC000
|
stack
|
page read and write
|
||
11D0000
|
heap
|
page read and write
|
||
695D000
|
stack
|
page read and write
|
||
57BB000
|
trusted library allocation
|
page read and write
|
||
5FCE000
|
stack
|
page read and write
|
||
16BC000
|
heap
|
page read and write
|
||
596B000
|
stack
|
page read and write
|
||
185F000
|
stack
|
page read and write
|
||
1170000
|
heap
|
page read and write
|
||
1524000
|
trusted library allocation
|
page read and write
|
||
18E3000
|
trusted library allocation
|
page execute and read and write
|
||
5C40000
|
trusted library allocation
|
page read and write
|
||
7E52000
|
trusted library allocation
|
page read and write
|
||
16AA000
|
heap
|
page read and write
|
||
1540000
|
heap
|
page read and write
|
||
33DE000
|
trusted library allocation
|
page read and write
|
||
57F0000
|
trusted library allocation
|
page read and write
|
||
15F3000
|
heap
|
page read and write
|
||
161B000
|
heap
|
page read and write
|
||
3318000
|
trusted library allocation
|
page read and write
|
||
1A80000
|
trusted library allocation
|
page execute and read and write
|
||
42D1000
|
trusted library allocation
|
page read and write
|
||
15ED000
|
heap
|
page read and write
|
||
19DE000
|
stack
|
page read and write
|
||
52D8000
|
trusted library allocation
|
page read and write
|
||
30CB000
|
trusted library allocation
|
page execute and read and write
|
||
1906000
|
heap
|
page read and write
|
||
334E000
|
stack
|
page read and write
|
||
30C2000
|
trusted library allocation
|
page read and write
|
||
153E000
|
heap
|
page read and write
|
||
6D1E000
|
stack
|
page read and write
|
||
6887000
|
trusted library allocation
|
page read and write
|
||
15F5000
|
heap
|
page read and write
|
||
57E2000
|
trusted library allocation
|
page read and write
|
||
15C8000
|
heap
|
page read and write
|
||
F05E000
|
stack
|
page read and write
|
||
34B0000
|
trusted library allocation
|
page read and write
|
||
91B6000
|
heap
|
page read and write
|
||
5970000
|
trusted library section
|
page readonly
|
||
59DE000
|
stack
|
page read and write
|
||
5880000
|
trusted library allocation
|
page read and write
|
||
5890000
|
heap
|
page read and write
|
||
9162000
|
heap
|
page read and write
|
||
FC0000
|
unkown
|
page readonly
|
||
6830000
|
trusted library allocation
|
page execute and read and write
|
||
4439000
|
trusted library allocation
|
page read and write
|
||
1740000
|
trusted library allocation
|
page read and write
|
||
1572000
|
heap
|
page read and write
|
||
174D000
|
trusted library allocation
|
page execute and read and write
|
||
1750000
|
heap
|
page read and write
|
||
3390000
|
trusted library allocation
|
page read and write
|
||
6F90000
|
heap
|
page read and write
|
||
57B6000
|
trusted library allocation
|
page read and write
|
||
7900000
|
heap
|
page read and write
|
||
1565000
|
heap
|
page read and write
|
||
32CE000
|
stack
|
page read and write
|
||
30BA000
|
trusted library allocation
|
page execute and read and write
|
||
197B000
|
trusted library allocation
|
page execute and read and write
|
||
5A80000
|
heap
|
page execute and read and write
|
||
33E6000
|
trusted library allocation
|
page read and write
|
||
58C0000
|
heap
|
page execute and read and write
|
||
5993000
|
heap
|
page read and write
|
||
4431000
|
trusted library allocation
|
page read and write
|
||
3100000
|
trusted library allocation
|
page read and write
|
||
5920000
|
trusted library allocation
|
page read and write
|
||
18F0000
|
trusted library allocation
|
page read and write
|
||
601C000
|
trusted library allocation
|
page read and write
|
||
EB2E000
|
stack
|
page read and write
|
||
EBE0000
|
heap
|
page read and write
|
||
400000
|
remote allocation
|
page execute and read and write
|
||
584C000
|
stack
|
page read and write
|
||
15C0000
|
heap
|
page read and write
|
||
3405000
|
trusted library allocation
|
page read and write
|
||
33ED000
|
trusted library allocation
|
page read and write
|
||
7EE0000
|
trusted library allocation
|
page read and write
|
||
1972000
|
trusted library allocation
|
page read and write
|
||
152D000
|
trusted library allocation
|
page execute and read and write
|
||
6880000
|
trusted library allocation
|
page read and write
|
||
5B60000
|
trusted library allocation
|
page read and write
|
||
110A000
|
stack
|
page read and write
|
||
18ED000
|
trusted library allocation
|
page execute and read and write
|
||
58F0000
|
trusted library allocation
|
page execute and read and write
|
||
338B000
|
stack
|
page read and write
|
||
6D5E000
|
stack
|
page read and write
|
||
546E000
|
stack
|
page read and write
|
||
173D000
|
stack
|
page read and write
|
||
5A5E000
|
stack
|
page read and write
|
||
57D1000
|
trusted library allocation
|
page read and write
|
||
1410000
|
heap
|
page read and write
|
||
EDDE000
|
stack
|
page read and write
|
||
57CA000
|
trusted library allocation
|
page read and write
|
||
1900000
|
heap
|
page read and write
|
||
6B1F000
|
stack
|
page read and write
|
||
393B000
|
trusted library allocation
|
page read and write
|
||
1990000
|
trusted library allocation
|
page read and write
|
||
15E9000
|
heap
|
page read and write
|
||
5B40000
|
trusted library allocation
|
page execute and read and write
|
||
14F6000
|
stack
|
page read and write
|
||
9160000
|
heap
|
page read and write
|
||
6970000
|
trusted library allocation
|
page execute and read and write
|
||
6EA2000
|
heap
|
page read and write
|
||
BA20000
|
trusted library section
|
page read and write
|
||
5B30000
|
heap
|
page read and write
|
||
6030000
|
heap
|
page read and write
|
||
6960000
|
trusted library allocation
|
page read and write
|
||
5C55000
|
heap
|
page read and write
|
||
1072000
|
unkown
|
page readonly
|
||
30B6000
|
trusted library allocation
|
page execute and read and write
|
||
18D0000
|
trusted library allocation
|
page read and write
|
||
7ED0000
|
trusted library allocation
|
page read and write
|
||
15F6000
|
heap
|
page read and write
|
||
33CB000
|
trusted library allocation
|
page read and write
|
||
7E00000
|
trusted library allocation
|
page execute and read and write
|
||
3420000
|
heap
|
page read and write
|
||
5ECF000
|
stack
|
page read and write
|
||
5D60000
|
heap
|
page read and write
|
||
31B4000
|
trusted library allocation
|
page read and write
|
||
33E1000
|
trusted library allocation
|
page read and write
|
||
11CE000
|
stack
|
page read and write
|
||
5C10000
|
trusted library section
|
page read and write
|
||
1550000
|
heap
|
page read and write
|
||
5DCE000
|
stack
|
page read and write
|
||
58E0000
|
trusted library allocation
|
page read and write
|
||
6010000
|
trusted library allocation
|
page read and write
|
||
7AFE000
|
stack
|
page read and write
|
||
7522000
|
trusted library allocation
|
page read and write
|
||
30B0000
|
trusted library allocation
|
page read and write
|
||
58A0000
|
heap
|
page read and write
|
||
7EF0000
|
trusted library allocation
|
page execute and read and write
|
||
5893000
|
heap
|
page read and write
|
||
58D0000
|
heap
|
page read and write
|
||
316E000
|
stack
|
page read and write
|
||
5B50000
|
trusted library allocation
|
page read and write
|
||
196A000
|
trusted library allocation
|
page execute and read and write
|
||
1AA7000
|
heap
|
page read and write
|
||
57C2000
|
trusted library allocation
|
page read and write
|
||
36A9000
|
trusted library allocation
|
page read and write
|
||
5B80000
|
heap
|
page read and write
|
||
691D000
|
stack
|
page read and write
|
||
33A0000
|
trusted library allocation
|
page read and write
|
||
5A1E000
|
stack
|
page read and write
|
||
57DD000
|
trusted library allocation
|
page read and write
|
||
3400000
|
trusted library allocation
|
page read and write
|
||
7A00000
|
trusted library section
|
page read and write
|
||
30E0000
|
trusted library allocation
|
page read and write
|
||
6024000
|
trusted library allocation
|
page read and write
|
||
7F110000
|
trusted library allocation
|
page execute and read and write
|
||
57B0000
|
trusted library allocation
|
page read and write
|
||
1510000
|
trusted library allocation
|
page read and write
|
||
1523000
|
trusted library allocation
|
page execute and read and write
|
||
1570000
|
heap
|
page read and write
|
||
57CE000
|
trusted library allocation
|
page read and write
|
||
6FE0000
|
trusted library allocation
|
page execute and read and write
|
||
552B000
|
stack
|
page read and write
|
||
1557000
|
heap
|
page read and write
|
||
1AA0000
|
heap
|
page read and write
|
||
EADE000
|
stack
|
page read and write
|
||
1656000
|
heap
|
page read and write
|
||
1A90000
|
trusted library allocation
|
page read and write
|
||
6E5E000
|
stack
|
page read and write
|
||
1576000
|
heap
|
page read and write
|
||
EF1E000
|
stack
|
page read and write
|
||
1180000
|
heap
|
page read and write
|
||
1977000
|
trusted library allocation
|
page execute and read and write
|
||
6E60000
|
heap
|
page read and write
|
||
3120000
|
heap
|
page execute and read and write
|
||
33B0000
|
heap
|
page execute and read and write
|
||
1520000
|
trusted library allocation
|
page read and write
|
||
30C5000
|
trusted library allocation
|
page execute and read and write
|
||
4C87000
|
trusted library allocation
|
page read and write
|
||
5880000
|
trusted library allocation
|
page read and write
|
||
5C30000
|
trusted library allocation
|
page execute and read and write
|
||
154F000
|
heap
|
page read and write
|
||
5DB0000
|
heap
|
page read and write
|
||
1962000
|
trusted library allocation
|
page read and write
|
||
7F3D0000
|
trusted library allocation
|
page execute and read and write
|
||
5980000
|
heap
|
page read and write
|
||
30C0000
|
trusted library allocation
|
page read and write
|
||
F15E000
|
stack
|
page read and write
|
||
1538000
|
heap
|
page read and write
|
||
1966000
|
trusted library allocation
|
page execute and read and write
|
||
6FB0000
|
trusted library allocation
|
page read and write
|
||
1960000
|
trusted library allocation
|
page read and write
|
||
7AA0000
|
trusted library section
|
page read and write
|
||
18E0000
|
trusted library allocation
|
page read and write
|
||
1970000
|
trusted library allocation
|
page read and write
|
||
91B0000
|
heap
|
page read and write
|
||
687D000
|
stack
|
page read and write
|
||
EEDF000
|
stack
|
page read and write
|
||
5D5E000
|
stack
|
page read and write
|
||
7E10000
|
trusted library allocation
|
page read and write
|
||
31B0000
|
trusted library allocation
|
page read and write
|
||
7190000
|
heap
|
page read and write
|
||
6020000
|
trusted library allocation
|
page read and write
|
||
3110000
|
trusted library allocation
|
page read and write
|
||
5D70000
|
heap
|
page read and write
|
||
30F0000
|
trusted library allocation
|
page execute and read and write
|
||
42D9000
|
trusted library allocation
|
page read and write
|
||
4CD5000
|
trusted library allocation
|
page read and write
|
||
6C1F000
|
stack
|
page read and write
|
||
6F60000
|
trusted library allocation
|
page read and write
|
||
4D23000
|
trusted library allocation
|
page read and write
|
||
19E8000
|
trusted library allocation
|
page read and write
|
||
6E7C000
|
heap
|
page read and write
|
||
15DE000
|
heap
|
page read and write
|
||
F01E000
|
stack
|
page read and write
|
There are 232 hidden memdumps, click here to show them.