IOC Report
3q1lESMAMh.exe

loading gif

Files

File Path
Type
Category
Malicious
3q1lESMAMh.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\Public\Desktop\Google Chrome.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:41 2023, mtime=Thu Oct 5 06:54:36 2023, atime=Wed Sep 27 08:36:54 2023, length=3242272, window=hide
dropped
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\3q1lESMAMh.exe.log
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\Tmp6AD4.tmp
data
dropped
C:\Users\user\AppData\Local\Temp\Tmp6AE4.tmp
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-2246122658-3693405117-2476756634-1003\76b53b3ec448f7ccdda2063b15d2bfc3_9e146be9-c76a-4720-bcdb-53011b87bd06
data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\3q1lESMAMh.exe
"C:\Users\user\Desktop\3q1lESMAMh.exe"
malicious

URLs

Name
IP
Malicious
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Text
unknown
http://schemas.xmlsoap.org/ws/2005/02/sc/sct
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/sc/dk
unknown
http://tempuri.org/Entity/Id14ResponseD
unknown
http://tempuri.org/Entity/Id23ResponseD
unknown
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#HexBinary
unknown
http://tempuri.org/Entity/Id12Response
unknown
http://tempuri.org/
unknown
http://tempuri.org/Entity/Id2Response
unknown
http://tempuri.org/Entity/Id15V
unknown
http://schemas.xmlsoap.org/ws/2005/02/sc/dk/p_sha1
unknown
http://tempuri.org/Entity/Id21Response
unknown
http://schemas.xmlsoap.org/2005/02/trust/spnego#GSS_Wrap
unknown
http://tempuri.org/Entity/Id9
unknown
http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLID
unknown
http://tempuri.org/Entity/Id8
unknown
http://tempuri.org/Entity/Id6ResponseD
unknown
http://tempuri.org/Entity/Id5
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Prepare
unknown
http://tempuri.org/Entity/Id4
unknown
http://tempuri.org/Entity/Id7
unknown
http://tempuri.org/Entity/Id6
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust#BinarySecret
unknown
http://tempuri.org/Entity/Id19Response
unknown
http://docs.oasis-open.org/wss/oasis-wss-rel-token-profile-1.0.pdf#license
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/Issue
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Aborted
unknown
http://schemas.xmlsoap.org/ws/2005/02/rm/TerminateSequence
unknown
http://tempuri.org/Entity/Id13ResponseD
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/fault
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat
unknown
http://docs.oasis-open.org/wss/oasis-wss-soap-message-security-1.1#EncryptedKey
unknown
http://tempuri.org/Entity/Id15Response
unknown
http://tempuri.org/Entity/Id5ResponseD
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/SCT/Renew
unknown
http://schemas.xmlsoap.org/ws/2004/08/addressing/faultp9
unknown
http://schemas.xmlsoap.org/ws/2004/10/wscoor/Register
unknown
http://tempuri.org/Entity/Id6Response
unknown
http://schemas.xmlsoap.org/ws/2004/04/trust/SymmetricKey
unknown
https://api.ip.sb/ip
unknown
http://schemas.xmlsoap.org/ws/2004/04/sc
unknown
http://tempuri.org/Entity/Id1ResponseD
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Volatile2PC
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/SCT/Cancel
unknown
http://tempuri.org/Entity/Id9Response
unknown
http://tempuri.org/Entity/Id20
unknown
http://tempuri.org/Entity/Id21
unknown
http://tempuri.org/Entity/Id22
unknown
http://docs.oasis-open.org/wss/oasis-wss-kerberos-token-profile-1.1#Kerberosv5APREQSHA1
unknown
http://tempuri.org/Entity/Id23
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/CK/PSHA1
unknown
http://tempuri.org/Entity/Id24
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/RSTR/Issue
unknown
http://tempuri.org/Entity/Id24Response
unknown
http://tempuri.org/Entity/Id1Response
unknown
http://schemas.xmlsoap.org/ws/2005/02/rm/AckRequested
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/ReadOnly
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Replay
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/tlsnego
unknown
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Base64Binary
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Durable2PC
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/SymmetricKey
unknown
http://tempuri.org/Entity/Id21ResponseD
unknown
http://schemas.xmlsoap.org/ws/2004/08/addressing
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RST/Issue
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Completion
unknown
http://schemas.xmlsoap.org/ws/2004/04/trust
unknown
http://tempuri.org/Entity/Id10
unknown
http://tempuri.org/Entity/Id11
unknown
http://tempuri.org/Entity/Id10ResponseD
unknown
http://tempuri.org/Entity/Id12
unknown
http://tempuri.org/Entity/Id16Response
unknown
http://schemas.xmlsoap.org/ws/2004/10/wscoor/CreateCoordinationContextResponse
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RST/SCT/Cancel
unknown
http://tempuri.org/Entity/Id13
unknown
http://tempuri.org/Entity/Id14
unknown
http://tempuri.org/Entity/Id15
unknown
http://tempuri.org/Entity/Id16
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/Nonce
unknown
http://tempuri.org/Entity/Id17
unknown
http://tempuri.org/Entity/Id18
unknown
http://tempuri.org/Entity/Id5Response
unknown
http://tempuri.org/Entity/Id19
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/dns
unknown
http://tempuri.org/Entity/Id15ResponseD
unknown
http://tempuri.org/Entity/Id10Response
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/Renew
unknown
http://tempuri.org/Entity/Id11ResponseD
unknown
http://tempuri.org/Entity/Id8Response
unknown
http://schemas.xmlsoap.org/ws/2004/04/trust/PublicKey
unknown
http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLV2.0
unknown
http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.0#SAMLAssertionID
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/RST/SCT
unknown
http://schemas.xmlsoap.org/ws/2006/02/addressingidentity
unknown
http://tempuri.org/Entity/Id17ResponseD
unknown
http://schemas.xmlsoap.org/soap/envelope/
unknown
http://tempuri.org/Entity/Id8ResponseD
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/PublicKey
unknown
http://docs.oasis-open.org/wss/oasis-wss-soap-message-security-1.1#EncryptedKeySHA1
unknown
There are 90 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
103.113.70.99
unknown
India
malicious

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F1A578C4CB5DE79A370893983FD4DA8B67B2B064
Blob
malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFiles0000
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFilesHash

Memdumps

Base Address
Regiontype
Protect
Malicious
2BE8000
trusted library allocation
page read and write
malicious
762000
unkown
page readonly
malicious
4FB2000
trusted library allocation
page read and write
75D4000
heap
page read and write
2CB6000
trusted library allocation
page read and write
559C000
heap
page read and write
2B41000
trusted library allocation
page read and write
77D0000
trusted library allocation
page read and write
2DA5000
trusted library allocation
page read and write
2D9C000
trusted library allocation
page read and write
2CC2000
trusted library allocation
page read and write
5C7E000
stack
page read and write
D15000
heap
page read and write
7616000
heap
page read and write
645C000
heap
page read and write
771B000
heap
page read and write
10D5000
trusted library allocation
page execute and read and write
10A0000
trusted library allocation
page read and write
10A3000
trusted library allocation
page execute and read and write
3EEE000
trusted library allocation
page read and write
5DBE000
stack
page read and write
76AE000
heap
page read and write
6DE0000
trusted library allocation
page read and write
BC0000
heap
page read and write
77FA000
trusted library allocation
page read and write
77EF000
trusted library allocation
page read and write
5340000
heap
page read and write
7810000
trusted library allocation
page read and write
3050000
trusted library allocation
page read and write
6856000
trusted library allocation
page read and write
6B7C000
stack
page read and write
63BE000
heap
page read and write
3EDD000
trusted library allocation
page read and write
668E000
stack
page read and write
CAD000
heap
page read and write
113E000
stack
page read and write
76AC000
heap
page read and write
2CEB000
trusted library allocation
page read and write
BB0000
heap
page read and write
3F08000
trusted library allocation
page read and write
6808000
trusted library allocation
page read and write
68D0000
trusted library allocation
page read and write
775E000
heap
page read and write
61FE000
stack
page read and write
1090000
trusted library allocation
page read and write
2DF3000
trusted library allocation
page read and write
5581000
heap
page read and write
2DE7000
trusted library allocation
page read and write
2A88000
trusted library allocation
page read and write
7763000
heap
page read and write
77D2000
trusted library allocation
page read and write
63A0000
trusted library allocation
page execute and read and write
6B00000
trusted library allocation
page read and write
6840000
trusted library allocation
page read and write
63B0000
heap
page read and write
11DE000
heap
page read and write
6E20000
trusted library allocation
page read and write
3EBD000
trusted library allocation
page read and write
C14000
heap
page read and write
4F9E000
trusted library allocation
page read and write
7661000
heap
page read and write
546E000
stack
page read and write
6990000
trusted library allocation
page execute and read and write
2CF2000
trusted library allocation
page read and write
6810000
trusted library allocation
page read and write
2E0E000
trusted library allocation
page read and write
E30000
heap
page read and write
763F000
heap
page read and write
3F7E000
trusted library allocation
page read and write
2D0A000
trusted library allocation
page read and write
3EF9000
trusted library allocation
page read and write
768D000
heap
page read and write
6AC0000
trusted library allocation
page read and write
10D0000
trusted library allocation
page read and write
6E30000
trusted library allocation
page read and write
6AF0000
trusted library allocation
page read and write
3F35000
trusted library allocation
page read and write
797000
unkown
page readonly
2A7F000
stack
page read and write
6E26000
trusted library allocation
page read and write
75F6000
heap
page read and write
870E000
stack
page read and write
6E54000
trusted library allocation
page read and write
B57000
stack
page read and write
3F96000
trusted library allocation
page read and write
2DD5000
trusted library allocation
page read and write
CE0000
heap
page read and write
5593000
heap
page read and write
3F67000
trusted library allocation
page read and write
6380000
heap
page read and write
62FE000
stack
page read and write
75E4000
heap
page read and write
88D0000
trusted library allocation
page read and write
6E40000
trusted library allocation
page execute and read and write
BEE000
heap
page read and write
2B30000
heap
page read and write
50BE000
stack
page read and write
10D2000
trusted library allocation
page read and write
3F83000
trusted library allocation
page read and write
7621000
heap
page read and write
2DC7000
trusted library allocation
page read and write
F7E000
stack
page read and write
6457000
heap
page read and write
10B0000
trusted library allocation
page read and write
76B6000
heap
page read and write
6E50000
trusted library allocation
page read and write
3F21000
trusted library allocation
page read and write
6800000
trusted library allocation
page read and write
2E03000
trusted library allocation
page read and write
10C0000
trusted library allocation
page read and write
5042000
trusted library allocation
page read and write
6940000
trusted library allocation
page execute and read and write
7704000
heap
page read and write
6890000
trusted library allocation
page read and write
C59000
heap
page read and write
2DDC000
trusted library allocation
page read and write
77E8000
trusted library allocation
page read and write
10D7000
trusted library allocation
page execute and read and write
68C0000
trusted library allocation
page read and write
88B2000
trusted library allocation
page read and write
74D0000
heap
page read and write
787D000
stack
page read and write
4FF0000
trusted library allocation
page read and write
CB4000
heap
page read and write
77F5000
trusted library allocation
page read and write
943E000
stack
page read and write
2DF8000
trusted library allocation
page read and write
317C000
trusted library allocation
page read and write
689E000
trusted library allocation
page read and write
3F14000
trusted library allocation
page read and write
3ED7000
trusted library allocation
page read and write
860E000
stack
page read and write
4FC0000
trusted library allocation
page read and write
77D9000
trusted library allocation
page read and write
680A000
trusted library allocation
page read and write
686E000
trusted library allocation
page read and write
6406000
heap
page read and write
11C0000
trusted library allocation
page read and write
78BE000
stack
page read and write
E37000
heap
page read and write
10BD000
trusted library allocation
page execute and read and write
5030000
heap
page read and write
3F02000
trusted library allocation
page read and write
4FA1000
trusted library allocation
page read and write
3F8C000
trusted library allocation
page read and write
6CBE000
stack
page read and write
7C6F000
stack
page read and write
3B4F000
trusted library allocation
page read and write
88AB000
stack
page read and write
5DFE000
stack
page read and write
7693000
heap
page read and write
63CC000
heap
page read and write
3BC4000
trusted library allocation
page read and write
2E55000
trusted library allocation
page read and write
2DAD000
trusted library allocation
page read and write
50D3000
heap
page read and write
2D1A000
trusted library allocation
page read and write
88B0000
trusted library allocation
page read and write
4FC5000
trusted library allocation
page read and write
799E000
stack
page read and write
6B30000
trusted library allocation
page execute and read and write
3F7A000
trusted library allocation
page read and write
556F000
stack
page read and write
2D25000
trusted library allocation
page read and write
3EF3000
trusted library allocation
page read and write
68B0000
trusted library allocation
page read and write
7604000
heap
page read and write
6871000
trusted library allocation
page read and write
684B000
trusted library allocation
page read and write
10AD000
trusted library allocation
page execute and read and write
2D0E000
trusted library allocation
page read and write
77FF000
trusted library allocation
page read and write
88F0000
heap
page read and write
CBF000
heap
page read and write
3B41000
trusted library allocation
page read and write
3F52000
trusted library allocation
page read and write
67CF000
stack
page read and write
4FAD000
trusted library allocation
page read and write
3F4D000
trusted library allocation
page read and write
3B83000
trusted library allocation
page read and write
E2D000
stack
page read and write
6EDF1000
unkown
page execute read
3EF7000
trusted library allocation
page read and write
2CDE000
trusted library allocation
page read and write
10C6000
trusted library allocation
page execute and read and write
876E000
stack
page read and write
642D000
heap
page read and write
689B000
trusted library allocation
page read and write
6AE0000
trusted library allocation
page read and write
D10000
heap
page read and write
2CC5000
trusted library allocation
page read and write
5350000
trusted library allocation
page read and write
5040000
trusted library allocation
page read and write
77EA000
trusted library allocation
page read and write
792000
unkown
page readonly
795E000
stack
page read and write
75D0000
heap
page read and write
3181000
trusted library allocation
page read and write
7664000
heap
page read and write
2CAE000
trusted library allocation
page read and write
3F74000
trusted library allocation
page read and write
5680000
trusted library allocation
page read and write
11D6000
heap
page read and write
6E3A000
trusted library allocation
page read and write
3177000
trusted library allocation
page read and write
5358000
trusted library allocation
page read and write
658E000
stack
page read and write
3EEA000
trusted library allocation
page read and write
2ECF000
trusted library allocation
page read and write
64AA000
heap
page read and write
4C3C000
stack
page read and write
4F8B000
trusted library allocation
page read and write
6920000
trusted library allocation
page read and write
76C6000
heap
page read and write
7F760000
trusted library allocation
page execute and read and write
6851000
trusted library allocation
page read and write
68A0000
trusted library allocation
page read and write
3F89000
trusted library allocation
page read and write
6DE4000
trusted library allocation
page read and write
4FFE000
trusted library allocation
page read and write
7741000
heap
page read and write
3DC4000
trusted library allocation
page read and write
7CA0000
heap
page read and write
66CE000
stack
page read and write
7C90000
trusted library allocation
page execute and read and write
3B62000
trusted library allocation
page read and write
3F87000
trusted library allocation
page read and write
531E000
stack
page read and write
6930000
trusted library allocation
page execute and read and write
6AD0000
trusted library allocation
page read and write
78D0000
trusted library allocation
page read and write
6880000
trusted library allocation
page read and write
6EE0D000
unkown
page read and write
6E23000
trusted library allocation
page read and write
118B000
stack
page read and write
6DC0000
trusted library allocation
page execute and read and write
4F80000
trusted library allocation
page read and write
7729000
heap
page read and write
7756000
heap
page read and write
75DA000
heap
page read and write
6EE0F000
unkown
page readonly
6472000
heap
page read and write
764D000
heap
page read and write
3F47000
trusted library allocation
page read and write
2DEE000
trusted library allocation
page read and write
3F2E000
trusted library allocation
page read and write
2DBA000
trusted library allocation
page read and write
2CFD000
trusted library allocation
page read and write
50D0000
heap
page read and write
7A6000
unkown
page readonly
6819000
trusted library allocation
page read and write
60BE000
stack
page read and write
11D0000
heap
page read and write
6EDF0000
unkown
page readonly
CA4000
heap
page read and write
3056000
trusted library allocation
page read and write
3EFC000
trusted library allocation
page read and write
2D04000
trusted library allocation
page read and write
7678000
heap
page read and write
6B10000
trusted library allocation
page execute and read and write
7C70000
trusted library allocation
page read and write
3EC2000
trusted library allocation
page read and write
10CA000
trusted library allocation
page execute and read and write
762C000
heap
page read and write
3187000
trusted library allocation
page read and write
5D7F000
stack
page read and write
2CAB000
trusted library allocation
page read and write
3EE4000
trusted library allocation
page read and write
7711000
heap
page read and write
316B000
trusted library allocation
page read and write
771F000
heap
page read and write
BE0000
heap
page read and write
3ECD000
trusted library allocation
page read and write
6815000
trusted library allocation
page read and write
7800000
trusted library allocation
page read and write
2B20000
trusted library allocation
page read and write
A59000
stack
page read and write
8710000
trusted library allocation
page read and write
4F84000
trusted library allocation
page read and write
5320000
heap
page read and write
5050000
trusted library allocation
page execute and read and write
78C0000
trusted library allocation
page read and write
2E78000
trusted library allocation
page read and write
3158000
trusted library allocation
page read and write
10A4000
trusted library allocation
page read and write
3F41000
trusted library allocation
page read and write
645A000
heap
page read and write
76ED000
heap
page read and write
760000
unkown
page readonly
C22000
heap
page read and write
1190000
trusted library allocation
page execute and read and write
11B0000
trusted library allocation
page read and write
5670000
trusted library allocation
page read and write
61BF000
stack
page read and write
6895000
trusted library allocation
page read and write
3058000
trusted library allocation
page read and write
77D5000
trusted library allocation
page read and write
646C000
heap
page read and write
64AE000
heap
page read and write
89FD000
stack
page read and write
953E000
stack
page read and write
63BA000
heap
page read and write
8720000
trusted library allocation
page execute and read and write
6862000
trusted library allocation
page read and write
6817000
trusted library allocation
page read and write
3F5D000
trusted library allocation
page read and write
69A0000
trusted library allocation
page execute and read and write
643C000
heap
page read and write
107E000
stack
page read and write
886E000
stack
page read and write
7628000
heap
page read and write
2CD1000
trusted library allocation
page read and write
6910000
trusted library allocation
page read and write
68E0000
trusted library allocation
page read and write
2C47000
trusted library allocation
page read and write
11A0000
trusted library allocation
page read and write
6C7C000
stack
page read and write
3F92000
trusted library allocation
page read and write
6DBC000
stack
page read and write
3F6D000
trusted library allocation
page read and write
10C2000
trusted library allocation
page read and write
4FA6000
trusted library allocation
page read and write
10F0000
trusted library allocation
page read and write
BFF000
heap
page read and write
5360000
heap
page execute and read and write
1140000
heap
page execute and read and write
791E000
stack
page read and write
F3E000
stack
page read and write
6390000
trusted library allocation
page execute and read and write
76D6000
heap
page read and write
CC4000
heap
page read and write
10DB000
trusted library allocation
page execute and read and write
6EE06000
unkown
page readonly
6488000
heap
page read and write
6805000
trusted library allocation
page read and write
2CB9000
trusted library allocation
page read and write
4FD0000
trusted library allocation
page read and write
3CC4000
trusted library allocation
page read and write
There are 328 hidden memdumps, click here to show them.