IOC Report
957C4XK6Lt.exe

loading gif

Files

File Path
Type
Category
Malicious
957C4XK6Lt.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\8HXJSKQQ\newtpp[1].exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\135143440.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\1682018248.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\sysvratrel.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Windows\sysvratrel.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6ATIQPJI\1[1]
data
dropped
C:\Users\user\tbtnds.dat
data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\957C4XK6Lt.exe
"C:\Users\user\Desktop\957C4XK6Lt.exe"
malicious
C:\Users\user\AppData\Local\Temp\135143440.exe
C:\Users\user\AppData\Local\Temp\135143440.exe
malicious
C:\Users\user\sysvratrel.exe
"C:\Users\user\sysvratrel.exe"
malicious
C:\Users\user\AppData\Local\Temp\1682018248.exe
C:\Users\user\AppData\Local\Temp\1682018248.exe
malicious
C:\Windows\sysvratrel.exe
"C:\Windows\sysvratrel.exe"
malicious
C:\Users\user\sysvratrel.exe
"C:\Users\user\sysvratrel.exe"
malicious

URLs

Name
IP
Malicious
http://twizt.net/pei
unknown
malicious
http://twizt.net/new
unknown
malicious
http://185.215.113.66/1D
unknown
malicious
http://91.202.233.141/
unknown
http://schemas.xmlsoap.org/soap/envelope/
unknown
http://91.202.233.141/1
unknown
http://193.233.132.177/5h.dllm
unknown
http://91.202.233.141/2
unknown
http://193.233.132.177/5z
unknown
http://91.202.233.141/4l3
unknown
http://193.233.132.177/6b
unknown
http://185.215.113.66/383(
unknown
http://193.233.132.177/3B
unknown
http://91.202.233.141/5
unknown
http://91.202.233.141/6
unknown
http://91.202.233.141/3
unknown
http://91.202.233.141/4
unknown
http://185.215.113.66/http://91.202.233.141/http://193.233.132.177/123456%s%s%s:Zone.Identifier%user
unknown
http://91.202.233.141/2s
unknown
http://twizt.net/peinstall.php5%z
unknown
http://twizt.net/newtpp.z%
unknown
http://193.233.132.177/5R
unknown
http://91.202.233.141/1p3
unknown
http://185.215.113.66/
unknown
http://91.202.233.141/40
unknown
http://twizt.net/peinstall.phpb
unknown
http://91.202.233.141/4%
unknown
http://193.233.132.177/1Z
unknown
http://91.202.233.141/6L2
unknown
http://twizt.net/peinstall.phpshqos.dll.muiS9
unknown
http://91.20
unknown
http://twizt.net/newtpp.exeP0S
unknown
http://91.202.233.141/3rosoft
unknown
http://185.215.113.66/1~
unknown
http://schemas.xmlsoap.org/soap/encoding/
unknown
http://twizt.net/peinstall.phpm%
unknown
http://193.233.132.177/
unknown
http://185.215.113.66/5
185.215.113.66
http://185.215.113.66/4
185.215.113.66
http://185.215.113.66/3
185.215.113.66
http://185.215.113.66/2
185.215.113.66
http://193.233.132.177/6
unknown
http://91.202.233.141/2W3C
unknown
http://193.233.132.177/5
unknown
http://185.215.113.66/6
185.215.113.66
http://193.233.132.177/2
unknown
http://193.233.132.177/1
unknown
http://91.202.233.141/4z
unknown
http://193.233.132.177/4
unknown
http://193.233.132.177/3
unknown
http://185.215.113.66/1
185.215.113.66
http://twizt.net/peinstall.php%temp%%s
unknown
http://91.202.233.141/5O
unknown
http://91.202.233.141/6ZF
unknown
http://193.233.132.177/5h.dll
unknown
http://91.202.233.141/6-3
unknown
http://twizt.net/newtpp.exeP0
unknown
http://twizt.net/peinstall.phpystem32
unknown
http://twizt.net/=
unknown
http://twizt.net/newtpp.exe
185.215.113.66
http://twizt.net/peinstall.php
185.215.113.66
There are 51 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
twizt.net
185.215.113.66

IPs

IP
Domain
Country
Malicious
89.236.226.70
unknown
Uzbekistan
malicious
82.114.186.50
unknown
Yemen
malicious
2.190.224.61
unknown
Iran (ISLAMIC Republic Of)
malicious
134.35.173.140
unknown
Yemen
malicious
181.114.188.143
unknown
Bolivia
malicious
82.194.11.2
unknown
Azerbaijan
malicious
189.158.148.85
unknown
Mexico
malicious
92.46.174.254
unknown
Kazakhstan
malicious
134.35.74.170
unknown
Yemen
malicious
85.113.19.18
unknown
Kyrgyzstan
malicious
46.35.86.48
unknown
Yemen
malicious
5.200.190.214
unknown
Iran (ISLAMIC Republic Of)
malicious
5.233.222.244
unknown
Iran (ISLAMIC Republic Of)
malicious
5.200.152.6
unknown
Iran (ISLAMIC Republic Of)
malicious
128.65.176.18
unknown
Iran (ISLAMIC Republic Of)
malicious
212.112.112.84
unknown
Kyrgyzstan
malicious
31.186.49.163
unknown
Kyrgyzstan
malicious
120.237.99.181
unknown
China
malicious
5.251.56.144
unknown
Kazakhstan
malicious
95.71.69.217
unknown
Russian Federation
malicious
89.218.235.182
unknown
Kazakhstan
malicious
36.20.68.95
unknown
China
malicious
37.20.161.137
unknown
Russian Federation
malicious
89.219.115.32
unknown
Iran (ISLAMIC Republic Of)
malicious
41.102.227.47
unknown
Algeria
malicious
151.233.73.168
unknown
Iran (ISLAMIC Republic Of)
malicious
186.94.185.219
unknown
Venezuela
malicious
2.185.146.181
unknown
Iran (ISLAMIC Republic Of)
malicious
95.58.18.206
unknown
Kazakhstan
malicious
134.35.163.241
unknown
Yemen
malicious
197.148.34.173
unknown
Angola
malicious
217.20.222.188
unknown
Syrian Arab Republic
malicious
91.234.219.185
unknown
Uzbekistan
malicious
39.53.75.107
unknown
Pakistan
malicious
31.186.54.5
unknown
Kyrgyzstan
malicious
92.47.124.54
unknown
Kazakhstan
malicious
134.35.81.188
unknown
Yemen
malicious
2.191.221.216
unknown
Iran (ISLAMIC Republic Of)
malicious
2.180.157.70
unknown
Iran (ISLAMIC Republic Of)
malicious
91.202.233.141
unknown
Russian Federation
95.107.12.43
unknown
Russian Federation
156.212.34.122
unknown
Egypt
195.158.15.3
unknown
Uzbekistan
109.72.204.86
unknown
Iran (ISLAMIC Republic Of)
5.63.93.62
unknown
Kazakhstan
239.255.255.250
unknown
Reserved
5.232.84.160
unknown
Iran (ISLAMIC Republic Of)
95.156.103.50
unknown
Russian Federation
105.109.202.176
unknown
Algeria
185.215.113.66
twizt.net
Portugal
134.35.185.171
unknown
Yemen
213.230.90.222
unknown
Uzbekistan
193.233.132.177
unknown
Russian Federation
189.190.10.16
unknown
Mexico
84.53.244.106
unknown
Russian Federation
195.181.62.5
unknown
Iran (ISLAMIC Republic Of)
109.122.77.179
unknown
Serbia
185.177.0.227
unknown
Tajikistan
94.141.69.176
unknown
Uzbekistan
151.233.21.215
unknown
Iran (ISLAMIC Republic Of)
There are 50 hidden IPs, click here to show them.

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Security Center
FirewallOverride
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Security Center
FirewallDisableNotify
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Security Center
AntiSpywareOverride
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Security Center
AntiVirusOverride
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Security Center
AntiVirusDisableNotify
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Security Center
UpdatesOverride
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Security Center
UpdatesDisableNotify
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL
CheckedValue
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
Windows Settings
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Windows Settings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BITS
Start
There are 1 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
410000
unkown
page readonly
malicious
410000
unkown
page readonly
malicious
410000
unkown
page readonly
malicious
410000
unkown
page readonly
malicious
410000
unkown
page readonly
malicious
410000
unkown
page readonly
malicious
4680000
heap
page read and write
malicious
410000
unkown
page readonly
malicious
6A8000
heap
page read and write
malicious
410000
unkown
page readonly
malicious
410000
unkown
page readonly
malicious
410000
unkown
page readonly
malicious
531000
unkown
page execute read
580000
heap
page read and write
68A000
heap
page read and write
766000
heap
page read and write
933000
heap
page read and write
8DE000
heap
page read and write
2FCE000
stack
page read and write
429F000
stack
page read and write
455E000
stack
page read and write
AC0000
heap
page read and write
282E000
stack
page read and write
23AE000
stack
page read and write
990000
heap
page read and write
9C000
stack
page read and write
29AE000
stack
page read and write
5B0000
heap
page read and write
400000
unkown
page readonly
6DD000
heap
page read and write
2AAE000
stack
page read and write
711000
heap
page read and write
820000
heap
page read and write
401000
unkown
page execute read
500000
heap
page read and write
414000
unkown
page write copy
74F000
heap
page read and write
706000
heap
page read and write
79E000
stack
page read and write
749000
heap
page read and write
761000
heap
page read and write
63A000
heap
page read and write
400000
unkown
page readonly
9A0000
heap
page read and write
520000
heap
page read and write
709000
heap
page read and write
42DE000
stack
page read and write
6E5000
heap
page read and write
25EE000
stack
page read and write
759000
heap
page read and write
414000
unkown
page write copy
75E000
heap
page read and write
68E000
heap
page read and write
38CF000
stack
page read and write
757000
heap
page read and write
531000
unkown
page execute read
19D000
stack
page read and write
3A4E000
stack
page read and write
2AED000
stack
page read and write
24AB000
stack
page read and write
761000
heap
page read and write
33CF000
stack
page read and write
532000
unkown
page readonly
747000
heap
page read and write
53E000
stack
page read and write
2BEC000
stack
page read and write
401000
unkown
page execute read
728000
heap
page read and write
414000
unkown
page write copy
750000
heap
page read and write
414000
unkown
page write copy
350F000
stack
page read and write
5AA000
heap
page read and write
710000
heap
page read and write
400000
unkown
page readonly
58E000
stack
page read and write
88F000
stack
page read and write
3A0F000
stack
page read and write
3C50000
heap
page read and write
67D000
stack
page read and write
401000
unkown
page execute read
2BAF000
stack
page read and write
707000
heap
page read and write
414000
unkown
page write copy
534000
unkown
page readonly
618000
heap
page read and write
340E000
stack
page read and write
19B000
stack
page read and write
5A0000
heap
page read and write
401000
unkown
page execute read
4F0000
heap
page read and write
32CE000
stack
page read and write
3B68000
heap
page read and write
89F000
stack
page read and write
715000
heap
page read and write
759000
heap
page read and write
5D0000
heap
page read and write
761000
heap
page read and write
8B0000
heap
page read and write
441E000
stack
page read and write
400000
unkown
page readonly
8BE000
heap
page read and write
420000
heap
page read and write
2D4E000
stack
page read and write
534000
unkown
page readonly
53E000
stack
page read and write
6BE000
stack
page read and write
B20000
heap
page read and write
1F0000
heap
page read and write
451F000
stack
page read and write
74B000
heap
page read and write
761000
heap
page read and write
5FB000
stack
page read and write
419E000
stack
page read and write
2CEF000
stack
page read and write
21A3000
heap
page read and write
2180000
heap
page read and write
19D000
stack
page read and write
390E000
stack
page read and write
3B4F000
stack
page read and write
58E000
stack
page read and write
590000
heap
page read and write
75E000
heap
page read and write
A80000
heap
page read and write
722000
heap
page read and write
747000
heap
page read and write
400000
unkown
page readonly
401000
unkown
page execute read
766000
heap
page read and write
905000
heap
page read and write
364F000
stack
page read and write
414000
unkown
page write copy
19D000
stack
page read and write
97F000
stack
page read and write
759000
heap
page read and write
728000
heap
page read and write
57E000
stack
page read and write
9C000
stack
page read and write
81F000
stack
page read and write
440000
heap
page read and write
414000
unkown
page write copy
1F0000
heap
page read and write
5B5000
heap
page read and write
75D000
heap
page read and write
54E000
stack
page read and write
6F5000
heap
page read and write
272E000
stack
page read and write
610000
heap
page read and write
8A0000
heap
page read and write
82E000
stack
page read and write
530000
unkown
page readonly
9B000
stack
page read and write
761000
heap
page read and write
9C000
stack
page read and write
753000
heap
page read and write
3D9F000
stack
page read and write
745000
heap
page read and write
420000
heap
page read and write
74F000
heap
page read and write
328F000
stack
page read and write
2E4E000
stack
page read and write
763000
heap
page read and write
74D000
heap
page read and write
1DA000
stack
page read and write
87F000
stack
page read and write
75C000
heap
page read and write
400000
unkown
page readonly
2AAE000
stack
page read and write
3B50000
heap
page read and write
2BEE000
stack
page read and write
286E000
stack
page read and write
766000
heap
page read and write
72B000
heap
page read and write
215C000
stack
page read and write
405E000
stack
page read and write
78A000
heap
page read and write
43DF000
stack
page read and write
70E000
heap
page read and write
1E0000
heap
page read and write
500000
heap
page read and write
4F0000
heap
page read and write
745000
heap
page read and write
415F000
stack
page read and write
92F000
stack
page read and write
19D000
stack
page read and write
530000
unkown
page readonly
368E000
stack
page read and write
763000
heap
page read and write
87E000
stack
page read and write
8BA000
heap
page read and write
75F000
heap
page read and write
3120000
heap
page read and write
598000
heap
page read and write
763000
heap
page read and write
1D6000
stack
page read and write
3DDE000
stack
page read and write
766000
heap
page read and write
465F000
stack
page read and write
401000
unkown
page execute read
590000
heap
page read and write
318E000
stack
page read and write
401000
unkown
page execute read
414000
unkown
page write copy
37CE000
stack
page read and write
75C000
heap
page read and write
3C9E000
stack
page read and write
750000
heap
page read and write
2E8E000
stack
page read and write
30CE000
stack
page read and write
401000
unkown
page execute read
414000
unkown
page write copy
761000
heap
page read and write
532000
unkown
page readonly
746000
heap
page read and write
72B000
heap
page read and write
70E000
heap
page read and write
75D000
heap
page read and write
7A1000
heap
page read and write
400000
unkown
page readonly
710000
heap
page read and write
400000
unkown
page readonly
761000
heap
page read and write
748000
heap
page read and write
1E0000
heap
page read and write
4F0000
heap
page read and write
22AE000
stack
page read and write
401000
unkown
page execute read
401000
unkown
page execute read
400000
unkown
page readonly
378F000
stack
page read and write
414000
unkown
page write copy
57E000
stack
page read and write
92F000
heap
page read and write
92C000
heap
page read and write
1F0000
heap
page read and write
9C000
stack
page read and write
401F000
stack
page read and write
6DF000
stack
page read and write
680000
heap
page read and write
53E000
stack
page read and write
400000
unkown
page readonly
2F8D000
stack
page read and write
58E000
stack
page read and write
753000
heap
page read and write
63E000
heap
page read and write
DC000
stack
page read and write
416000
unkown
page read and write
3F1E000
stack
page read and write
78E000
stack
page read and write
920000
heap
page read and write
54E000
stack
page read and write
354E000
stack
page read and write
704000
heap
page read and write
5AE000
heap
page read and write
78E000
heap
page read and write
900000
heap
page read and write
296E000
stack
page read and write
65E000
stack
page read and write
630000
heap
page read and write
26EF000
stack
page read and write
21A0000
heap
page read and write
780000
heap
page read and write
AAF000
stack
page read and write
753000
heap
page read and write
3EDF000
stack
page read and write
There are 255 hidden memdumps, click here to show them.