IOC Report
SecuriteInfo.com.W32.Xpack.E.gen.Eldorado.12002.13899.exe

loading gif

Files

File Path
Type
Category
Malicious
SecuriteInfo.com.W32.Xpack.E.gen.Eldorado.12002.13899.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_SecuriteInfo.com_9d50f1a2eb86aa236a701d83e0f8c17bb555f3_2ef1b157_e76709af-2bca-4fd8-aeaf-5d9a60530078\Report.wer
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WER866C.tmp.dmp
Mini DuMP crash report, 14 streams, Thu Apr 25 03:30:42 2024, 0x1205a4 type
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WER86AB.tmp.WERInternalMetadata.xml
XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WER86EB.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\Windows\appcompat\Programs\Amcache.hve
MS Windows registry file, NT/2000 or above
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.W32.Xpack.E.gen.Eldorado.12002.13899.exe
"C:\Users\user\Desktop\SecuriteInfo.com.W32.Xpack.E.gen.Eldorado.12002.13899.exe"
malicious
C:\Windows\SysWOW64\WerFault.exe
C:\Windows\SysWOW64\WerFault.exe -u -p 1072 -s 232

URLs

Name
IP
Malicious
http://mc.qzone.qq.com/cgi-bin/cgi_sale_product
unknown
http://mc.qzone.qq.com/cgi-bin/cgi_help_pasture
unknown
http://mc.xiaoyou.qq.com/cgi-bin/cgi_raise_cub
unknown
http://ctc.appimg.qq.com/mc/module/mc/main/farmui2_v_19.swf
unknown
http://mc.xiaoyou.qq.com/cgi-bin/cgi_harvest_product
unknown
http://www.23gua.comopenS3
unknown
http://api.23gua.com/fy/farm.htmlU
unknown
http://farm.xiaoyou.qq.com/cgi-bin/cgi_farm_upgrade
unknown
http://farm.xiaoyou.qq.com/cgi-bin/cgi_farm_reclaim?mod=user&act=reclaim
unknown
http://mc.xiaoyou.qq.com/cgi-bin/cgi_get_animals
unknown
http://www.indyproject.org/
unknown
http://mc.xiaoyou.qq.com/animalConfig.xml
unknown
http://mc.qzone.qq.com/cgi-bin/cgi_enter
unknown
http://nc.qzone.qq.com/cgi-bin/cgi_farm_plant?mod=farmlandstatus&act=planting
unknown
http://nc.xiaoyou.qq.com/cgi-bin/cgi_farm_opt?mod=farmlandstatus&act=clearWeed
unknown
http://nc.xiaoyou.qq.com/cgi-bin/cgi_farm_plant?mod=farmlandstatus&act=planting
unknown
http://appimg.qq.com/happyfarm/module/Main2_v_9.swf
unknown
http://base.qzone.qq.com/fcg-bin/cgi_get_portrait.fcg?uins=
unknown
http://mc.xiaoyou.qq.com/cgi-bin/cgi_donate_animal
unknown
http://www.23gua.com
unknown
http://mc.qzone.qq.com/cgi-bin/cgi_donate_animal
unknown
http://mc.qzone.qq.com/cgi-bin/cgi_post_product
unknown
http://nc.xiaoyou.qq.com/cgi-bin/cgi_farm_opt?mod=farmlandstatus&act=spraying
unknown
http://www.23gua.cm
unknown
http://nc.qzone.qq.com/cgi-bin/cgi_farm_opt?mod=farmlandstatus&act=water
unknown
http://www.clamav.net
unknown
http://api.23gua.com/fy/
unknown
http://nc.qzone.qq.com/cgi-bin/cgi_farm_attack_beast
unknown
http://mc.xiaoyou.qq.com/cgi-bin/cgi_sale_product
unknown
http://nc.qzone.qq.com/cgi-bin/cgi_farm_saleall?mod=repertory&act=saleAll
unknown
http://ptlogin2.qq.com/getimage?aid=353&U
unknown
http://nc.qzone.qq.com/cgi-bin/cgi_farm_plant?mod=farmlandstatus&act=scarify
unknown
http://farm.qzone.qq.com/cgi-bin/cgi_farm_upgrade
unknown
http://mc.xiaoyou.qq.com/cgi-bin/cgi_enter
unknown
http://mc.qzone.qq.com/cgi-bin/cgi_up_animalhouse
unknown
http://ctc.appimg.qq.com/mc/module/mc/main/farmui1_v_25.swf
unknown
http://mc.qzone.qq.com/cgi-bin/cgi_buy_animal
unknown
http://ad.23gua.com/pasture.html
unknown
http://mc.xiaoyou.qq.com/cgi-bin/cgi_steal_product
unknown
http://nc.qzone.qq.com/cgi-bin/cgi_farm_getstatus_filter?cmd=3
unknown
http://mc.xiaoyou.qq.com/cgi-bin/cgi_post_product
unknown
http://www.23gua.comopen
unknown
http://mc.xiaoyou.qq.com/cgi-bin/cgi_feed_food
unknown
http://nc.xiaoyou.qq.com/cgi-bin/cgi_farm_plant?mod=farmlandstatus&act=scarify
unknown
http://farm.qzone.qq.com/cgi-bin/cgi_farm_getseedinfo?mod=repertory&act=getSeedInfo
unknown
http://mc.qzone.qq.com/cgi-bin/cgi_fight
unknown
http://api.23gua.com/fy/farm.xml
unknown
http://nc.qzone.qq.com/cgi-bin/cgi_farm_steal_v2?mod=farmlandstatus&act=scrounge
unknown
http://captcha.qq.com/getimage?aid=10000101&vc_type=
unknown
http://farm.qzone.qq.com/cgi-bin/cgi_farm_buyseed?mod=repertory&act=buySeed
unknown
http://mc.qzone.qq.com/cgi-bin/cgi_feed_food
unknown
http://mc.qzone.qq.com/cgi-bin/cgi_get_repertory?target=animal
unknown
http://mc.xiaoyou.qq.com/cgi-bin/cgi_fight
unknown
http://farm.qzone.qq.com/cgi-bin/cgi_farm_reclaim?mod=user&act=reclaim
unknown
http://mc.qzone.qq.com/cgi-bin/cgi_steal_product
unknown
http://nc.qzone.qq.com/cgi-bin/cgi_farm_pickup_crystal
unknown
http://api.23gua.com/fy/farm.html
unknown
http://nc.qzone.qq.com/cgi-bin/cgi_farm_index?mod=user&act=run
unknown
http://ctc.appimg.qq.com/mc/module/mc/main/commonui_v_5.swf?v=1
unknown
http://nc.qzone.qq.com/cgi-bin/cgi_farm_plant?mod=farmlandstatus&act=harvest
unknown
http://farm.xiaoyou.qq.com/cgi-bin/cgi_farm_pickup_crystal
unknown
http://nc.xiaoyou.qq.com/cgi-bin/cgi_farm_getFriendList?mod=friend
unknown
http://nc.xiaoyou.qq.com/cgi-bin/cgi_farm_getusercrop?f=1
unknown
http://ad.23gua.com/farm.html
unknown
http://nc.xiaoyou.qq.com/cgi-bin/cgi_farm_plant?mod=farmlandstatus&act=harvest
unknown
http://nc.qzone.qq.com/cgi-bin/cgi_farm_index?mod=user&act=run&ownerId=
unknown
http://farm.qzone.qq.com/cgi-bin/cgi_farm_getuserseed?mod=repertory&act=getUserSeed
unknown
http://nc.xiaoyou.qq.com/cgi-bin/cgi_farm_steal_v2?mod=farmlandstatus&act=scrounge
unknown
Http://ptlogin2.qq.com/check?uin=
unknown
http://farm.xiaoyou.qq.com/cgi-bin/cgi_farm_getseedinfo?mod=repertory&act=getSeedInfo
unknown
http://mc.qzone.qq.com/cgi-bin/cgi_raise_cub
unknown
http://nc.xiaoyou.qq.com/cgi-bin/cgi_farm_saleall?mod=repertory&act=saleAll
unknown
http://farm.xiaoyou.qq.com/cgi-bin/cgi_farm_attack_beast
unknown
http://nc.xiaoyou.qq.com/cgi-bin/cgi_farm_index?mod=user&act=run&ownerId=
unknown
http://appimg.qq.com/happyfarm/module/Main2_v_6.swf
unknown
http://api.23gua.com/farm/key.xml
unknown
http://nc.qzone.qq.com/cgi-bin/cgi_farm_opt?mod=farmlandstatus&act=clearWeed
unknown
http://farm.qzone.qq.com/cgi-bin/cgi_farm_ini_run_v2?v=12
unknown
http://nc.qzone.qq.com/cgi-bin/cgi_farm_opt?mod=farmlandstatus&act=spraying
unknown
http://nc.xiaoyou.qq.com/cgi-bin/cgi_farm_opt?mod=farmlandstatus&act=water
unknown
http://mc.qzone.qq.com/animalConfig.xml
unknown
http://nc.qzone.qq.com/cgi-bin/cgi_farm_getFriendList?mod=friend
unknown
http://farm.qzone.qq.com/cgi-bin/cgi_farm_reclaimpay?mod=user&act=reclaimPay
unknown
http://upx.sf.net
unknown
http://mc.qzone.qq.com/cgi-bin/cgi_get_package
unknown
http://api.23gua.com/fy/card.xml
unknown
http://ptlogin2.qq.com/login?u=
unknown
http://mc.qzone.qq.com/cgi-bin/cgi_get_animals
unknown
http://ptlogin2.qq.com/getimage?aid=353&
unknown
http://mc.qzone.qq.com/cgi-bin/cgi_harvest_product
unknown
http://nc.xiaoyou.qq.com/cgi-bin/cgi_farm_getstatus_filter?cmd=3
unknown
http://ctc.appimg.qq.com/mc/module/Master2_v_5.swf
unknown
http://api.23gua.com/fy/QQ
unknown
http://nc.xiaoyou.qq.com/cgi-bin/cgi_farm_index?mod=user&act=run
unknown
http://nc.qzone.qq.com/cgi-bin/cgi_farm_getusercrop?f=1
unknown
http://farm.xiaoyou.qq.com/cgi-bin/cgi_farm_getuserseed?mod=repertory&act=getUserSeed
unknown
http://mc.xiaoyou.qq.com/cgi-bin/cgi_buy_animal
unknown
http://mc.xiaoyou.qq.com/cgi-bin/cgi_get_repertory?target=animal
unknown
http://farm.xiaoyou.qq.com/cgi-bin/cgi_farm_reclaimpay?mod=user&act=reclaimPay
unknown
http://appimg.qq.com/happyfarm/module/loading2_v_1.swf
unknown
There are 90 hidden URLs, click here to show them.

Registry

Path
Value
Malicious
\REGISTRY\A\{35e4191a-c9d3-ae03-4f67-9ac3e8ed05fc}\Root\InventoryApplicationFile\securiteinfo.com|3e5ac8bc5f4c89d6
ProgramId
\REGISTRY\A\{35e4191a-c9d3-ae03-4f67-9ac3e8ed05fc}\Root\InventoryApplicationFile\securiteinfo.com|3e5ac8bc5f4c89d6
FileId
\REGISTRY\A\{35e4191a-c9d3-ae03-4f67-9ac3e8ed05fc}\Root\InventoryApplicationFile\securiteinfo.com|3e5ac8bc5f4c89d6
LowerCaseLongPath
\REGISTRY\A\{35e4191a-c9d3-ae03-4f67-9ac3e8ed05fc}\Root\InventoryApplicationFile\securiteinfo.com|3e5ac8bc5f4c89d6
LongPathHash
\REGISTRY\A\{35e4191a-c9d3-ae03-4f67-9ac3e8ed05fc}\Root\InventoryApplicationFile\securiteinfo.com|3e5ac8bc5f4c89d6
Name
\REGISTRY\A\{35e4191a-c9d3-ae03-4f67-9ac3e8ed05fc}\Root\InventoryApplicationFile\securiteinfo.com|3e5ac8bc5f4c89d6
OriginalFileName
\REGISTRY\A\{35e4191a-c9d3-ae03-4f67-9ac3e8ed05fc}\Root\InventoryApplicationFile\securiteinfo.com|3e5ac8bc5f4c89d6
Publisher
\REGISTRY\A\{35e4191a-c9d3-ae03-4f67-9ac3e8ed05fc}\Root\InventoryApplicationFile\securiteinfo.com|3e5ac8bc5f4c89d6
Version
\REGISTRY\A\{35e4191a-c9d3-ae03-4f67-9ac3e8ed05fc}\Root\InventoryApplicationFile\securiteinfo.com|3e5ac8bc5f4c89d6
BinFileVersion
\REGISTRY\A\{35e4191a-c9d3-ae03-4f67-9ac3e8ed05fc}\Root\InventoryApplicationFile\securiteinfo.com|3e5ac8bc5f4c89d6
BinaryType
\REGISTRY\A\{35e4191a-c9d3-ae03-4f67-9ac3e8ed05fc}\Root\InventoryApplicationFile\securiteinfo.com|3e5ac8bc5f4c89d6
ProductName
\REGISTRY\A\{35e4191a-c9d3-ae03-4f67-9ac3e8ed05fc}\Root\InventoryApplicationFile\securiteinfo.com|3e5ac8bc5f4c89d6
ProductVersion
\REGISTRY\A\{35e4191a-c9d3-ae03-4f67-9ac3e8ed05fc}\Root\InventoryApplicationFile\securiteinfo.com|3e5ac8bc5f4c89d6
LinkDate
\REGISTRY\A\{35e4191a-c9d3-ae03-4f67-9ac3e8ed05fc}\Root\InventoryApplicationFile\securiteinfo.com|3e5ac8bc5f4c89d6
BinProductVersion
\REGISTRY\A\{35e4191a-c9d3-ae03-4f67-9ac3e8ed05fc}\Root\InventoryApplicationFile\securiteinfo.com|3e5ac8bc5f4c89d6
AppxPackageFullName
\REGISTRY\A\{35e4191a-c9d3-ae03-4f67-9ac3e8ed05fc}\Root\InventoryApplicationFile\securiteinfo.com|3e5ac8bc5f4c89d6
AppxPackageRelativeId
\REGISTRY\A\{35e4191a-c9d3-ae03-4f67-9ac3e8ed05fc}\Root\InventoryApplicationFile\securiteinfo.com|3e5ac8bc5f4c89d6
Size
\REGISTRY\A\{35e4191a-c9d3-ae03-4f67-9ac3e8ed05fc}\Root\InventoryApplicationFile\securiteinfo.com|3e5ac8bc5f4c89d6
Language
\REGISTRY\A\{35e4191a-c9d3-ae03-4f67-9ac3e8ed05fc}\Root\InventoryApplicationFile\securiteinfo.com|3e5ac8bc5f4c89d6
Usn
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\IdentityCRL\ClockData
ClockTimeSeconds
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\IdentityCRL\ClockData
TickCount
There are 11 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
58D000
unkown
page readonly
7AA000
heap
page read and write
563000
unkown
page write copy
563000
unkown
page read and write
400000
unkown
page readonly
7A0000
heap
page read and write
596000
unkown
page readonly
5B0000
heap
page read and write
58D000
unkown
page readonly
401000
unkown
page execute read
9D000
stack
page read and write
400000
unkown
page readonly
401000
unkown
page execute read
564000
unkown
page write copy
670000
heap
page read and write
19D000
stack
page read and write
596000
unkown
page readonly
1F0000
heap
page read and write
7AE000
heap
page read and write
There are 9 hidden memdumps, click here to show them.