IOC Report
SecuriteInfo.com.Trojan.Win32.Krypt.14164.25813.exe

loading gif

Files

File Path
Type
Category
Malicious
SecuriteInfo.com.Trojan.Win32.Krypt.14164.25813.exe
PE32 executable (console) Intel 80386, for MS Windows
initial sample
malicious
\Device\ConDrv
ASCII text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win32.Krypt.14164.25813.exe
"C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win32.Krypt.14164.25813.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
http://jd.sscltan.com/jd/tp1.txthttp://jd.sscltan.com/jd/tp2.txt
unknown
http://jd.sscltan.com/jd/sscjh.txt
unknown
http://jd.sscltan.com/jd/tp2.txt
unknown
http://jd.sscltan.com/jd/zgg.txt
unknown
http://jd.sscltan.com/jd/tp1.txt
unknown
https://http://=deletedUTF-8GBKAdodb.StreamTypeWritePositionCharsetReadTextCloseWriteTextRead
unknown
http://www.sscltan.comhttp://jd.sscltan.com/jd/zgg.txt
unknown
http://img1.tbcdn.cn/tfscom/T1ouC2FdpbXXXtxVjX.swf
unknown
http://www.sscltan.com
unknown
http://s104.cnzz.com/stat.php?id=1935778&web_id=1935778
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
1000000
unkown
page readonly
1CF000
stack
page read and write
1000000
unkown
page readonly
12D4000
unkown
page readonly
67F000
stack
page read and write
1E0000
heap
page read and write
54A000
heap
page read and write
1001000
unkown
page execute read
12D4000
unkown
page readonly
9C000
stack
page read and write
1001000
unkown
page execute read
130000
heap
page read and write
540000
heap
page read and write
140000
heap
page read and write
6C0000
heap
page read and write
18E000
stack
page read and write
DD000
stack
page read and write
54E000
heap
page read and write
50E000
stack
page read and write
There are 9 hidden memdumps, click here to show them.