IOC Report
gm5v3JlTMk.exe

loading gif

Files

File Path
Type
Category
Malicious
gm5v3JlTMk.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\Public\Desktop\Google Chrome.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:41 2023, mtime=Wed Oct 4 11:02:30 2023, atime=Wed Sep 27 04:28:27 2023, length=3242272, window=hide
dropped
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\gm5v3JlTMk.exe.log
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\Tmp2B59.tmp
data
dropped
C:\Users\user\AppData\Local\Temp\Tmp2B6A.tmp
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-2246122658-3693405117-2476756634-1002\76b53b3ec448f7ccdda2063b15d2bfc3_9e146be9-c76a-4720-bcdb-53011b87bd06
data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\gm5v3JlTMk.exe
"C:\Users\user\Desktop\gm5v3JlTMk.exe"
malicious

URLs

Name
IP
Malicious
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Text
unknown
http://schemas.xmlsoap.org/ws/2005/02/sc/sct
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/sc/dk
unknown
http://tempuri.org/Entity/Id14ResponseD
unknown
http://tempuri.org/Entity/Id23ResponseD
unknown
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#HexBinary
unknown
http://tempuri.org/Entity/Id12Response
unknown
http://tempuri.org/
unknown
http://tempuri.org/Entity/Id2Response
unknown
http://schemas.xmlsoap.org/ws/2005/02/sc/dk/p_sha1
unknown
http://tempuri.org/Entity/Id21Response
unknown
http://schemas.xmlsoap.org/2005/02/trust/spnego#GSS_Wrap
unknown
http://tempuri.org/Entity/Id9
unknown
http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLID
unknown
http://tempuri.org/Entity/Id8
unknown
http://tempuri.org/Entity/Id6ResponseD
unknown
http://tempuri.org/Entity/Id5
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Prepare
unknown
http://tempuri.org/Entity/Id4
unknown
http://tempuri.org/Entity/Id7
unknown
http://tempuri.org/Entity/Id6
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust#BinarySecret
unknown
http://tempuri.org/Entity/Id19Response
unknown
http://docs.oasis-open.org/wss/oasis-wss-rel-token-profile-1.0.pdf#license
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/Issue
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Aborted
unknown
http://schemas.xmlsoap.org/ws/2005/02/rm/TerminateSequence
unknown
http://tempuri.org/Entity/Id13ResponseD
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/fault
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat
unknown
http://docs.oasis-open.org/wss/oasis-wss-soap-message-security-1.1#EncryptedKey
unknown
http://tempuri.org/Entity/Id15Response
unknown
http://tempuri.org/Entity/Id5ResponseD
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/SCT/Renew
unknown
http://schemas.xmlsoap.org/ws/2004/08/addressing/faultp9
unknown
http://schemas.xmlsoap.org/ws/2004/10/wscoor/Register
unknown
http://tempuri.org/Entity/Id6Response
unknown
http://schemas.xmlsoap.org/ws/2004/04/trust/SymmetricKey
unknown
https://api.ip.sb/ip
unknown
http://schemas.xmlsoap.org/ws/2004/04/sc
unknown
http://tempuri.org/Entity/Id1ResponseD
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Volatile2PC
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/SCT/Cancel
unknown
http://tempuri.org/Entity/Id9Response
unknown
http://tempuri.org/Entity/Id20
unknown
http://tempuri.org/Entity/Id21
unknown
http://tempuri.org/Entity/Id22
unknown
http://docs.oasis-open.org/wss/oasis-wss-kerberos-token-profile-1.1#Kerberosv5APREQSHA1
unknown
http://tempuri.org/Entity/Id23
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/CK/PSHA1
unknown
http://tempuri.org/Entity/Id24
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/RSTR/Issue
unknown
http://tempuri.org/Entity/Id24Response
unknown
http://tempuri.org/Entity/Id1Response
unknown
http://schemas.xmlsoap.org/ws/2005/02/rm/AckRequested
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/ReadOnly
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Replay
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/tlsnego
unknown
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Base64Binary
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Durable2PC
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/SymmetricKey
unknown
http://tempuri.org/Entity/Id21ResponseD
unknown
http://schemas.xmlsoap.org/ws/2004/08/addressing
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RST/Issue
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Completion
unknown
http://schemas.xmlsoap.org/ws/2004/04/trust
unknown
http://tempuri.org/Entity/Id10
unknown
http://tempuri.org/Entity/Id11
unknown
http://tempuri.org/Entity/Id10ResponseD
unknown
http://tempuri.org/Entity/Id12
unknown
http://tempuri.org/Entity/Id16Response
unknown
http://schemas.xmlsoap.org/ws/2004/10/wscoor/CreateCoordinationContextResponse
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RST/SCT/Cancel
unknown
http://tempuri.org/Entity/Id13
unknown
http://tempuri.org/Entity/Id14
unknown
http://tempuri.org/Entity/Id15
unknown
http://tempuri.org/Entity/Id16
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/Nonce
unknown
http://tempuri.org/Entity/Id17
unknown
http://tempuri.org/Entity/Id18
unknown
http://tempuri.org/Entity/Id5Response
unknown
http://tempuri.org/Entity/Id19
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/dns
unknown
http://tempuri.org/Entity/Id15ResponseD
unknown
http://tempuri.org/Entity/Id10Response
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/Renew
unknown
http://tempuri.org/Entity/Id11ResponseD
unknown
http://tempuri.org/Entity/Id8Response
unknown
http://schemas.xmlsoap.org/ws/2004/04/trust/PublicKey
unknown
http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLV2.0
unknown
http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.0#SAMLAssertionID
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/RST/SCT
unknown
http://schemas.xmlsoap.org/ws/2006/02/addressingidentity
unknown
http://tempuri.org/Entity/Id17ResponseD
unknown
http://schemas.xmlsoap.org/soap/envelope/
unknown
http://tempuri.org/Entity/Id8ResponseD
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/PublicKey
unknown
http://docs.oasis-open.org/wss/oasis-wss-soap-message-security-1.1#EncryptedKeySHA1
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust
unknown
There are 90 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
103.113.70.99
unknown
India
malicious

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F1A578C4CB5DE79A370893983FD4DA8B67B2B064
Blob
malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFiles0000
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFilesHash

Memdumps

Base Address
Regiontype
Protect
Malicious
3198000
trusted library allocation
page read and write
malicious
BC2000
unkown
page readonly
malicious
7CF0000
trusted library allocation
page read and write
3624000
trusted library allocation
page read and write
7270000
trusted library allocation
page read and write
5770000
heap
page execute and read and write
44CD000
trusted library allocation
page read and write
668E000
stack
page read and write
8390000
trusted library allocation
page execute and read and write
15BB000
trusted library allocation
page execute and read and write
6E00000
trusted library allocation
page execute and read and write
CA9000
stack
page read and write
15B5000
trusted library allocation
page execute and read and write
6B7C000
heap
page read and write
324C000
trusted library allocation
page read and write
7CF5000
trusted library allocation
page read and write
6CFE000
trusted library allocation
page read and write
1414000
heap
page read and write
725E000
stack
page read and write
7279000
trusted library allocation
page read and write
83A0000
trusted library allocation
page read and write
30E0000
heap
page execute and read and write
2EAE000
stack
page read and write
412F000
trusted library allocation
page read and write
856E000
stack
page read and write
33DB000
trusted library allocation
page read and write
1180000
heap
page read and write
2EC0000
trusted library allocation
page read and write
3672000
trusted library allocation
page read and write
1320000
heap
page read and write
7E80000
trusted library allocation
page read and write
363D000
trusted library allocation
page read and write
7B11000
heap
page read and write
6C5B000
heap
page read and write
6C54000
heap
page read and write
7D08000
trusted library allocation
page read and write
6CA0000
trusted library allocation
page read and write
2F26000
trusted library allocation
page read and write
6F30000
trusted library allocation
page read and write
33D1000
trusted library allocation
page read and write
133F000
heap
page read and write
35B0000
trusted library allocation
page read and write
179E000
heap
page read and write
35D8000
trusted library allocation
page read and write
6C6A000
trusted library allocation
page read and write
7B76000
heap
page read and write
1312000
trusted library allocation
page read and write
3050000
heap
page read and write
7B4D000
heap
page read and write
6CC2000
trusted library allocation
page read and write
34F4000
trusted library allocation
page read and write
72B0000
trusted library allocation
page read and write
176C000
stack
page read and write
3670000
trusted library allocation
page read and write
6BA6000
heap
page read and write
7BF0000
heap
page read and write
6C75000
trusted library allocation
page read and write
16E0000
trusted library allocation
page read and write
6C34000
heap
page read and write
3459000
trusted library allocation
page read and write
6CB6000
trusted library allocation
page read and write
852F000
stack
page read and write
5A6F000
stack
page read and write
6D10000
trusted library allocation
page read and write
3062000
trusted library allocation
page read and write
6CE0000
trusted library allocation
page read and write
15B2000
trusted library allocation
page read and write
7D24000
trusted library allocation
page read and write
7D50000
trusted library allocation
page read and write
7CF9000
trusted library allocation
page read and write
6A2D000
stack
page read and write
2FF0000
trusted library allocation
page read and write
7E00000
trusted library allocation
page execute and read and write
1780000
trusted library allocation
page read and write
30DE000
stack
page read and write
60A1000
heap
page read and write
67E0000
heap
page read and write
2EB0000
trusted library allocation
page read and write
2ED0000
trusted library allocation
page read and write
BC0000
unkown
page readonly
628E000
stack
page read and write
678F000
stack
page read and write
4112000
trusted library allocation
page read and write
6C1A000
heap
page read and write
2EF3000
heap
page read and write
431E000
trusted library allocation
page read and write
6CD1000
trusted library allocation
page read and write
3060000
trusted library allocation
page read and write
70DC000
stack
page read and write
6C2D000
heap
page read and write
10F0000
heap
page read and write
3461000
trusted library allocation
page read and write
35DF000
trusted library allocation
page read and write
2F2D000
trusted library allocation
page read and write
6C77000
trusted library allocation
page read and write
132E000
heap
page read and write
3515000
trusted library allocation
page read and write
7E24000
trusted library allocation
page read and write
3572000
trusted library allocation
page read and write
6F20000
trusted library allocation
page read and write
573E000
stack
page read and write
357A000
trusted library allocation
page read and write
1347000
heap
page read and write
130D000
trusted library allocation
page execute and read and write
6D80000
trusted library allocation
page read and write
412C000
trusted library allocation
page read and write
2EE5000
trusted library allocation
page read and write
6D00000
trusted library allocation
page read and write
40FF000
trusted library allocation
page read and write
6D70000
trusted library allocation
page read and write
6C49000
heap
page read and write
79E0000
heap
page read and write
354E000
trusted library allocation
page read and write
6C1E000
heap
page read and write
6DA0000
trusted library allocation
page execute and read and write
7BB9000
heap
page read and write
6C06000
heap
page read and write
C06000
unkown
page readonly
711E000
stack
page read and write
56EE000
stack
page read and write
5AAE000
stack
page read and write
1799000
heap
page read and write
172E000
stack
page read and write
6C45000
heap
page read and write
3619000
trusted library allocation
page read and write
842E000
stack
page read and write
1300000
trusted library allocation
page read and write
7CF2000
trusted library allocation
page read and write
12F4000
trusted library allocation
page read and write
35B4000
trusted library allocation
page read and write
13EE000
heap
page read and write
15C7000
heap
page read and write
6CF0000
trusted library allocation
page read and write
6B60000
heap
page read and write
664E000
stack
page read and write
3551000
trusted library allocation
page read and write
3261000
trusted library allocation
page read and write
2EE0000
trusted library allocation
page read and write
6D90000
trusted library allocation
page execute and read and write
81CE000
stack
page read and write
6DF0000
trusted library allocation
page execute and read and write
7B6D000
heap
page read and write
7AFB000
heap
page read and write
654F000
stack
page read and write
7D1F000
trusted library allocation
page read and write
4120000
trusted library allocation
page read and write
3616000
trusted library allocation
page read and write
2F04000
trusted library allocation
page read and write
6CF5000
trusted library allocation
page read and write
BF7000
unkown
page readonly
15B7000
trusted library allocation
page execute and read and write
3469000
trusted library allocation
page read and write
1150000
heap
page read and write
7D20000
trusted library allocation
page read and write
350D000
trusted library allocation
page read and write
1316000
trusted library allocation
page execute and read and write
33EF000
trusted library allocation
page read and write
6D20000
trusted library allocation
page read and write
3246000
trusted library allocation
page read and write
7AEC000
heap
page read and write
824E000
stack
page read and write
69EE000
stack
page read and write
1328000
heap
page read and write
6D40000
trusted library allocation
page read and write
727F000
trusted library allocation
page read and write
12FD000
trusted library allocation
page execute and read and write
1796000
heap
page read and write
7CE0000
trusted library allocation
page execute and read and write
361C000
trusted library allocation
page read and write
7D40000
trusted library allocation
page read and write
7B5B000
heap
page read and write
4119000
trusted library allocation
page read and write
7E30000
trusted library allocation
page execute and read and write
7B2C000
heap
page read and write
7EAB000
trusted library allocation
page read and write
6800000
trusted library allocation
page execute and read and write
3500000
trusted library allocation
page read and write
1185000
heap
page read and write
7AFE000
heap
page read and write
3559000
trusted library allocation
page read and write
12E0000
trusted library allocation
page read and write
323E000
trusted library allocation
page read and write
12F0000
trusted library allocation
page read and write
4133000
trusted library allocation
page read and write
15C0000
heap
page read and write
40F1000
trusted library allocation
page read and write
3244000
trusted library allocation
page read and write
6F40000
trusted library allocation
page read and write
6D30000
trusted library allocation
page read and write
12CD000
stack
page read and write
727B000
trusted library allocation
page read and write
6C65000
trusted library allocation
page read and write
7EA0000
trusted library allocation
page read and write
3645000
trusted library allocation
page read and write
7AF7000
heap
page read and write
13DB000
heap
page read and write
1010000
heap
page read and write
79DD000
stack
page read and write
6C3B000
heap
page read and write
6C79000
trusted library allocation
page read and write
6C00000
heap
page read and write
7DFE000
stack
page read and write
7F8C0000
trusted library allocation
page execute and read and write
6C60000
trusted library allocation
page read and write
6F50000
trusted library allocation
page read and write
5750000
trusted library allocation
page read and write
35A5000
trusted library allocation
page read and write
83B0000
heap
page read and write
368A000
trusted library allocation
page read and write
7AE0000
heap
page read and write
6C2A000
heap
page read and write
128E000
stack
page read and write
360B000
trusted library allocation
page read and write
3070000
trusted library allocation
page execute and read and write
7D15000
trusted library allocation
page read and write
83E0000
heap
page read and write
2EDE000
trusted library allocation
page read and write
13E0000
heap
page read and write
7E20000
trusted library allocation
page read and write
7D1A000
trusted library allocation
page read and write
3541000
trusted library allocation
page read and write
4171000
trusted library allocation
page read and write
7BA8000
heap
page read and write
6C70000
trusted library allocation
page read and write
113E000
stack
page read and write
367F000
trusted library allocation
page read and write
1398000
heap
page read and write
2F40000
heap
page read and write
346C000
trusted library allocation
page read and write
7D0A000
trusted library allocation
page read and write
6CFB000
trusted library allocation
page read and write
596E000
stack
page read and write
1790000
heap
page read and write
60B8000
heap
page read and write
35B6000
trusted library allocation
page read and write
6CCE000
trusted library allocation
page read and write
6C68000
trusted library allocation
page read and write
838E000
stack
page read and write
131A000
trusted library allocation
page execute and read and write
36A3000
trusted library allocation
page read and write
68EE000
stack
page read and write
2F32000
trusted library allocation
page read and write
5760000
trusted library allocation
page read and write
1310000
trusted library allocation
page read and write
2F21000
trusted library allocation
page read and write
7D38000
trusted library allocation
page read and write
7D30000
trusted library allocation
page read and write
7E10000
trusted library allocation
page read and write
BF2000
unkown
page readonly
820E000
stack
page read and write
2F0B000
trusted library allocation
page read and write
DA7000
stack
page read and write
6B2E000
stack
page read and write
83C0000
trusted library allocation
page read and write
2EF0000
heap
page read and write
721C000
stack
page read and write
16CE000
stack
page read and write
6CAB000
trusted library allocation
page read and write
35BE000
trusted library allocation
page read and write
3242000
trusted library allocation
page read and write
7D0F000
trusted library allocation
page read and write
51EC000
stack
page read and write
301E000
trusted library allocation
page read and write
324A000
trusted library allocation
page read and write
1770000
trusted library allocation
page execute and read and write
3010000
trusted library allocation
page read and write
828B000
stack
page read and write
6FDC000
stack
page read and write
33D7000
trusted library allocation
page read and write
2F1E000
trusted library allocation
page read and write
15B0000
trusted library allocation
page read and write
6F90000
trusted library allocation
page execute and read and write
3630000
trusted library allocation
page read and write
7B18000
heap
page read and write
3695000
trusted library allocation
page read and write
5740000
trusted library allocation
page read and write
367C000
trusted library allocation
page read and write
354B000
trusted library allocation
page read and write
7E7E000
stack
page read and write
3479000
trusted library allocation
page read and write
7B47000
heap
page read and write
30F1000
trusted library allocation
page read and write
56A0000
heap
page read and write
12F3000
trusted library allocation
page execute and read and write
99DE000
stack
page read and write
7DBE000
stack
page read and write
5748000
trusted library allocation
page read and write
35CA000
trusted library allocation
page read and write
1361000
heap
page read and write
567E000
stack
page read and write
7B32000
heap
page read and write
6C52000
heap
page read and write
3565000
trusted library allocation
page read and write
7AF2000
heap
page read and write
67F0000
trusted library allocation
page execute and read and write
6F60000
trusted library allocation
page read and write
4125000
trusted library allocation
page read and write
7B30000
heap
page read and write
2F58000
trusted library allocation
page read and write
3682000
trusted library allocation
page read and write
2F00000
trusted library allocation
page read and write
6F70000
trusted library allocation
page execute and read and write
6CB1000
trusted library allocation
page read and write
There are 293 hidden memdumps, click here to show them.