IOC Report
SCB99440721399.exe

loading gif

Files

File Path
Type
Category
Malicious
SCB99440721399.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\SCB99440721399.exe.log
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\188E93\31437F.lck
very short file (no magic)
dropped
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-2246122658-3693405117-2476756634-1002\bc49718863ee53e026d805ec372039e9_9e146be9-c76a-4720-bcdb-53011b87bd06
data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SCB99440721399.exe
"C:\Users\user\Desktop\SCB99440721399.exe"
malicious
C:\Users\user\Desktop\SCB99440721399.exe
"C:\Users\user\Desktop\SCB99440721399.exe"
malicious

URLs

Name
IP
Malicious
http://kbfvzoboss.bid/alien/fre.php
malicious
http://alphastand.top/alien/fre.php
malicious
http://45.77.223.48/~blog/?ajax=posts.php
45.77.223.48
malicious
http://alphastand.win/alien/fre.php
malicious
http://alphastand.trade/alien/fre.php
malicious
http://www.apache.org/licenses/LICENSE-2.0
unknown
http://www.fontbureau.com
unknown
http://www.fontbureau.com/designersG
unknown
http://www.fontbureau.com/designers/?
unknown
http://www.founder.com.cn/cn/bThe
unknown
http://www.fontbureau.com/designers?
unknown
http://www.ibsensoftware.com/
unknown
http://www.tiro.com
unknown
http://www.fontbureau.com/designers
unknown
http://www.goodfont.co.kr
unknown
https://www.chiark.greenend.org.uk/~sgtatham/putty/0
unknown
http://www.carterandcone.coml
unknown
http://www.sajatypeworks.com
unknown
http://www.typography.netD
unknown
http://www.fontbureau.com/designers/cabarga.htmlN
unknown
http://www.founder.com.cn/cn/cThe
unknown
http://www.galapagosdesign.com/staff/dennis.htm
unknown
http://www.founder.com.cn/cn
unknown
http://www.fontbureau.com/designers/frere-user.html
unknown
http://www.jiyu-kobo.co.jp/
unknown
http://www.galapagosdesign.com/DPlease
unknown
http://www.fontbureau.com/designers8
unknown
http://www.fonts.com
unknown
http://www.sandoll.co.kr
unknown
http://www.urwpp.deDPlease
unknown
http://www.zhongyicts.com.cn
unknown
http://www.sakkal.com
unknown
http://www.sakkal.comX
unknown
There are 23 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
45.77.223.48
unknown
United States
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
2F21000
trusted library allocation
page read and write
malicious
3D69000
trusted library allocation
page read and write
malicious
400000
remote allocation
page execute and read and write
malicious
7430000
trusted library section
page read and write
malicious
49A5000
trusted library allocation
page read and write
malicious
4757000
trusted library allocation
page read and write
malicious
104C000
heap
page read and write
1370000
heap
page read and write
732E000
stack
page read and write
2FFF000
trusted library allocation
page read and write
FD9000
heap
page read and write
3007000
trusted library allocation
page read and write
5669000
heap
page read and write
9E10000
trusted library section
page read and write
3001000
trusted library allocation
page read and write
2FEF000
trusted library allocation
page read and write
466C000
trusted library allocation
page read and write
7470000
trusted library allocation
page read and write
142F000
stack
page read and write
101B000
heap
page read and write
2FEB000
trusted library allocation
page read and write
71F0000
heap
page read and write
FCD000
trusted library allocation
page execute and read and write
12F0000
trusted library allocation
page read and write
3285000
trusted library allocation
page read and write
12E2000
trusted library allocation
page read and write
5650000
heap
page read and write
6DF0000
trusted library allocation
page read and write
B97000
stack
page read and write
5540000
heap
page read and write
BC0000
heap
page read and write
BC5000
heap
page read and write
A9A000
stack
page read and write
2FF3000
trusted library allocation
page read and write
3003000
trusted library allocation
page read and write
F80000
heap
page read and write
5440000
trusted library allocation
page read and write
742E000
stack
page read and write
2CFF000
stack
page read and write
FF0000
heap
page read and write
56A0000
heap
page read and write
5203000
heap
page read and write
FBD000
trusted library allocation
page execute and read and write
75BF000
stack
page read and write
2F44000
trusted library allocation
page read and write
7450000
trusted library allocation
page execute and read and write
564D000
stack
page read and write
105D000
heap
page read and write
FC0000
trusted library allocation
page read and write
1388000
trusted library allocation
page read and write
51E0000
trusted library allocation
page read and write
6E12000
trusted library allocation
page read and write
5660000
heap
page read and write
5500000
heap
page read and write
1005000
heap
page read and write
2D50000
heap
page execute and read and write
45D0000
trusted library allocation
page read and write
77C5000
trusted library allocation
page read and write
3D61000
trusted library allocation
page read and write
2D61000
trusted library allocation
page read and write
4E5C000
stack
page read and write
FD0000
heap
page read and write
12E6000
trusted library allocation
page execute and read and write
11D0000
heap
page read and write
2FE0000
trusted library allocation
page read and write
11CF000
stack
page read and write
2FE7000
trusted library allocation
page read and write
FDE000
heap
page read and write
2FE5000
trusted library allocation
page read and write
12DE000
stack
page read and write
74BE000
stack
page read and write
2CB0000
heap
page read and write
568E000
heap
page read and write
2FED000
trusted library allocation
page read and write
F6E000
stack
page read and write
54A0000
heap
page read and write
1240000
heap
page read and write
FB0000
trusted library allocation
page read and write
FB4000
trusted library allocation
page read and write
E00000
heap
page read and write
980000
unkown
page readonly
2FE9000
trusted library allocation
page read and write
12FB000
trusted library allocation
page execute and read and write
12F2000
trusted library allocation
page read and write
12E0000
trusted library allocation
page read and write
77B0000
trusted library allocation
page read and write
77C8000
trusted library allocation
page read and write
5280000
heap
page execute and read and write
1068000
heap
page read and write
71FE000
heap
page read and write
54EB000
stack
page read and write
982000
unkown
page readonly
5460000
trusted library allocation
page execute and read and write
52A0000
trusted library allocation
page execute and read and write
3005000
trusted library allocation
page read and write
51C6000
trusted library allocation
page read and write
54A5000
heap
page read and write
FD0000
heap
page read and write
51A4000
trusted library allocation
page read and write
1010000
heap
page read and write
1450000
heap
page read and write
2FDE000
trusted library allocation
page read and write
2FF5000
trusted library allocation
page read and write
10DE000
heap
page read and write
E3C000
stack
page read and write
1230000
heap
page read and write
D2AF000
stack
page read and write
51C1000
trusted library allocation
page read and write
51CD000
trusted library allocation
page read and write
51AB000
trusted library allocation
page read and write
51F0000
trusted library allocation
page read and write
5270000
heap
page read and write
2FF1000
trusted library allocation
page read and write
1053000
heap
page read and write
51D0000
trusted library allocation
page read and write
51A0000
trusted library allocation
page read and write
51D2000
trusted library allocation
page read and write
F3B000
stack
page read and write
1015000
heap
page read and write
1440000
trusted library allocation
page read and write
D1AE000
stack
page read and write
461E000
trusted library allocation
page read and write
CEAE000
stack
page read and write
9C4E000
stack
page read and write
2D3B000
stack
page read and write
5210000
trusted library allocation
page read and write
1457000
heap
page read and write
3009000
trusted library allocation
page read and write
CF00000
trusted library allocation
page execute and read and write
F2E000
stack
page read and write
51BE000
trusted library allocation
page read and write
2FC5000
trusted library allocation
page read and write
2FF7000
trusted library allocation
page read and write
7770000
trusted library allocation
page execute and read and write
12EA000
trusted library allocation
page execute and read and write
2D40000
trusted library allocation
page read and write
2FFD000
trusted library allocation
page read and write
9E68000
trusted library section
page read and write
2FF9000
trusted library allocation
page read and write
7760000
trusted library allocation
page read and write
49F000
remote allocation
page execute and read and write
51F5000
trusted library allocation
page read and write
FCE000
stack
page read and write
FF8000
heap
page read and write
FB3000
trusted library allocation
page execute and read and write
1310000
trusted library allocation
page read and write
5510000
trusted library allocation
page read and write
EE0000
heap
page read and write
9D4E000
stack
page read and write
2F42000
trusted library allocation
page read and write
5470000
trusted library allocation
page read and write
CEEE000
stack
page read and write
31FF000
stack
page read and write
5490000
trusted library section
page readonly
12F7000
trusted library allocation
page execute and read and write
FA0000
trusted library allocation
page read and write
1055000
heap
page read and write
1060000
heap
page read and write
CFB0000
heap
page read and write
7460000
trusted library section
page read and write
2FFB000
trusted library allocation
page read and write
77C0000
trusted library allocation
page read and write
5200000
heap
page read and write
54F0000
heap
page read and write
10CC000
heap
page read and write
1011000
heap
page read and write
5290000
trusted library allocation
page read and write
FC3000
trusted library allocation
page read and write
5520000
trusted library allocation
page execute and read and write
2C6E000
stack
page read and write
1420000
heap
page read and write
30FF000
stack
page read and write
1014000
heap
page read and write
1360000
trusted library allocation
page execute and read and write
135E000
stack
page read and write
5230000
trusted library allocation
page read and write
2C1E000
stack
page read and write
There are 167 hidden memdumps, click here to show them.