Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
ciKdWsb5h4.exe
|
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
initial sample
|
||
C:\Users\Public\Desktop\Google Chrome.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working
directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:41 2023, mtime=Wed Oct 4 11:02:32 2023,
atime=Wed Sep 27 04:28:27 2023, length=3242272, window=hide
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\Tmp434B.tmp
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\Tmp435C.tmp
|
data
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-2246122658-3693405117-2476756634-1002\76b53b3ec448f7ccdda2063b15d2bfc3_9e146be9-c76a-4720-bcdb-53011b87bd06
|
data
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\ciKdWsb5h4.exe
|
"C:\Users\user\Desktop\ciKdWsb5h4.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
103.113.70.99:2630
|
|||
http://tempuri.org/Entity/Id24LR
|
unknown
|
||
http://tempuri.org/Entity/Id22LR
|
unknown
|
||
http://tempuri.org/Entity/Id20LR
|
unknown
|
||
http://tempuri.org/Entity/Id15Responsex
|
unknown
|
||
http://tempuri.org/Entity/Id18Responsex
|
unknown
|
||
http://schemas.xmlsoap.org/soap/envelope/
|
unknown
|
||
http://tempuri.org/
|
unknown
|
||
http://tempuri.org/Entity/Id19LR
|
unknown
|
||
http://tempuri.org/Entity/Id17LR
|
unknown
|
||
http://tempuri.org/Entity/Id22Responsex
|
unknown
|
||
http://tempuri.org/Entity/Id6
|
unknown
|
||
http://tempuri.org/Entity/Id15LR
|
unknown
|
||
http://tempuri.org/Entity/Id9LR
|
unknown
|
||
http://tempuri.org/Entity/Id10Responsex
|
unknown
|
||
http://tempuri.org/Entity/Id19Responsex
|
unknown
|
||
http://tempuri.org/Entity/Id13LR
|
unknown
|
||
http://tempuri.org/Entity/Id7LR
|
unknown
|
||
http://tempuri.org/Entity/Id11LR
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2005/02/rm/CreateSequenceResponse
|
unknown
|
||
http://tempuri.org/Entity/Id1LR
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2005/02/rm/TerminateSequence
|
unknown
|
||
http://tempuri.org/Entity/Id5LR
|
unknown
|
||
http://tempuri.org/Entity/Id3LR
|
unknown
|
||
http://tempuri.org/Entity/Id6Responsex
|
unknown
|
||
http://tempuri.org/Entity/Id7Responsex
|
unknown
|
||
http://tempuri.org/Entity/Id1Responsex
|
unknown
|
||
http://tempuri.org/Entity/Id21Responsex
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2004/08/addressing/faultp9
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2005/05/identity/right/possessproperty
|
unknown
|
||
https://api.ip.sb/ip
|
unknown
|
||
http://tempuri.org/Entity/Id23Responsex
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2005/02/rm/SequenceAcknowledgement
|
unknown
|
||
http://tempuri.org/Entity/Id23LR
|
unknown
|
||
http://tempuri.org/Entity/Id21LR
|
unknown
|
||
http://tempuri.org/Entity/Id5Responsex
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous
|
unknown
|
||
http://tempuri.org/Entity/Id14Responsex
|
unknown
|
||
http://tempuri.org/Entity/Id2Responsex
|
unknown
|
||
http://tempuri.org/Entity/Id11Responsex
|
unknown
|
||
http://tempuri.org/Entity/Id20Responsex
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2005/02/rm/AckRequested
|
unknown
|
||
http://tempuri.org/Entity/Id8Responsex
|
unknown
|
||
http://tempuri.org/Entity/Id18LR
|
unknown
|
||
http://tempuri.org/Entity/Id13Responsex
|
unknown
|
||
http://tempuri.org/Entity/Id16Responsex
|
unknown
|
||
http://tempuri.org/Entity/Id16LR
|
unknown
|
||
http://tempuri.org/Entity/Id8LR
|
unknown
|
||
http://tempuri.org/Entity/Id14LR
|
unknown
|
||
http://tempuri.org/Entity/Id6LR
|
unknown
|
||
http://tempuri.org/Entity/
|
unknown
|
||
http://tempuri.org/Entity/Id12LR
|
unknown
|
||
http://tempuri.org/Entity/Id9Responsex
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2004/08/addressing
|
unknown
|
||
http://tempuri.org/Entity/Id10LR
|
unknown
|
||
http://tempuri.org/Entity/Id3Responsex
|
unknown
|
||
http://tempuri.org/Entity/Id4LR
|
unknown
|
||
http://tempuri.org/Entity/Id24Responsex
|
unknown
|
||
http://tempuri.org/Entity/Id2LR
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2005/02/rm
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2005/02/rm/LastMessage
|
unknown
|
||
http://tempuri.org/Entity/Id12Responsex
|
unknown
|
||
http://tempuri.org/Entity/Id17Responsex
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2005/02/rm/CreateSequence
|
unknown
|
||
http://schemas.xmlsoap.org/soap/actor/next
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/dns
|
unknown
|
||
http://tempuri.org/Entity/Id4Responsex
|
unknown
|
There are 57 hidden URLs, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
103.113.70.99
|
unknown
|
India
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F1A578C4CB5DE79A370893983FD4DA8B67B2B064
|
Blob
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
32000
|
unkown
|
page readonly
|
||
4820000
|
trusted library allocation
|
page read and write
|
||
190000
|
heap
|
page read and write
|
||
76000
|
unkown
|
page readonly
|
||
950000
|
trusted library allocation
|
page read and write
|
||
5E90000
|
heap
|
page read and write
|
||
4834000
|
trusted library allocation
|
page read and write
|
||
2290000
|
heap
|
page read and write
|
||
980000
|
trusted library allocation
|
page read and write
|
||
81E000
|
heap
|
page read and write
|
||
4895000
|
trusted library allocation
|
page read and write
|
||
750000
|
heap
|
page read and write
|
||
553E000
|
stack
|
page read and write
|
||
33E1000
|
trusted library allocation
|
page read and write
|
||
48D3000
|
heap
|
page read and write
|
||
4890000
|
trusted library allocation
|
page read and write
|
||
4B80000
|
heap
|
page execute and read and write
|
||
5FE6000
|
trusted library allocation
|
page read and write
|
||
758000
|
heap
|
page read and write
|
||
81C000
|
heap
|
page read and write
|
||
597E000
|
stack
|
page read and write
|
||
22D0000
|
heap
|
page read and write
|
||
960000
|
trusted library allocation
|
page read and write
|
||
4920000
|
trusted library allocation
|
page read and write
|
||
593E000
|
stack
|
page read and write
|
||
6270000
|
trusted library allocation
|
page read and write
|
||
600A000
|
trusted library allocation
|
page read and write
|
||
5FA7000
|
trusted library allocation
|
page read and write
|
||
483E000
|
trusted library allocation
|
page read and write
|
||
4836000
|
trusted library allocation
|
page read and write
|
||
6060000
|
trusted library allocation
|
page read and write
|
||
A40000
|
heap
|
page read and write
|
||
44DE000
|
stack
|
page read and write
|
||
484E000
|
trusted library allocation
|
page read and write
|
||
5FDB000
|
trusted library allocation
|
page read and write
|
||
6030000
|
trusted library allocation
|
page read and write
|
||
6025000
|
trusted library allocation
|
page read and write
|
||
4E80000
|
trusted library allocation
|
page read and write
|
||
33EF000
|
trusted library allocation
|
page read and write
|
||
5FF2000
|
trusted library allocation
|
page read and write
|
||
5EB5000
|
heap
|
page read and write
|
||
602E000
|
trusted library allocation
|
page read and write
|
||
5EE3000
|
heap
|
page read and write
|
||
30000
|
unkown
|
page readonly
|
||
4E70000
|
trusted library allocation
|
page read and write
|
||
6130000
|
trusted library allocation
|
page execute and read and write
|
||
5EF1000
|
heap
|
page read and write
|
||
485D000
|
trusted library allocation
|
page read and write
|
||
602B000
|
trusted library allocation
|
page read and write
|
||
5A7E000
|
stack
|
page read and write
|
||
6050000
|
trusted library allocation
|
page read and write
|
||
5A80000
|
trusted library allocation
|
page read and write
|
||
4F7000
|
stack
|
page read and write
|
||
97A000
|
trusted library allocation
|
page execute and read and write
|
||
972000
|
trusted library allocation
|
page read and write
|
||
96D000
|
trusted library allocation
|
page execute and read and write
|
||
4E78000
|
trusted library allocation
|
page read and write
|
||
5FD0000
|
trusted library allocation
|
page read and write
|
||
740000
|
trusted library allocation
|
page read and write
|
||
9EE000
|
stack
|
page read and write
|
||
953000
|
trusted library allocation
|
page execute and read and write
|
||
60D0000
|
trusted library allocation
|
page execute and read and write
|
||
60A0000
|
trusted library allocation
|
page read and write
|
||
5F5000
|
heap
|
page read and write
|
||
4910000
|
heap
|
page read and write
|
||
5F9B000
|
trusted library allocation
|
page read and write
|
||
5E5F000
|
stack
|
page read and write
|
||
5FA5000
|
trusted library allocation
|
page read and write
|
||
180000
|
heap
|
page read and write
|
||
5FE1000
|
trusted library allocation
|
page read and write
|
||
22B0000
|
trusted library allocation
|
page execute and read and write
|
||
5D5E000
|
stack
|
page read and write
|
||
954000
|
trusted library allocation
|
page read and write
|
||
3402000
|
trusted library allocation
|
page read and write
|
||
75E000
|
heap
|
page read and write
|
||
6020000
|
trusted library allocation
|
page read and write
|
||
6260000
|
trusted library allocation
|
page read and write
|
||
777000
|
heap
|
page read and write
|
||
5F90000
|
trusted library allocation
|
page read and write
|
||
6001000
|
trusted library allocation
|
page read and write
|
||
4830000
|
trusted library allocation
|
page read and write
|
||
23E1000
|
trusted library allocation
|
page read and write
|
||
6250000
|
trusted library allocation
|
page read and write
|
||
791000
|
heap
|
page read and write
|
||
62000
|
unkown
|
page readonly
|
||
11A000
|
stack
|
page read and write
|
||
583E000
|
stack
|
page read and write
|
||
4888000
|
trusted library allocation
|
page read and write
|
||
5FA0000
|
trusted library allocation
|
page read and write
|
||
98B000
|
trusted library allocation
|
page execute and read and write
|
||
483B000
|
trusted library allocation
|
page read and write
|
||
48A0000
|
trusted library allocation
|
page read and write
|
||
48C0000
|
trusted library allocation
|
page read and write
|
||
5B20000
|
trusted library allocation
|
page execute and read and write
|
||
60C0000
|
trusted library allocation
|
page execute and read and write
|
||
4CE1000
|
heap
|
page read and write
|
||
4842000
|
trusted library allocation
|
page read and write
|
||
5FA9000
|
trusted library allocation
|
page read and write
|
||
5D1E000
|
stack
|
page read and write
|
||
4856000
|
trusted library allocation
|
page read and write
|
||
67000
|
unkown
|
page readonly
|
||
6010000
|
trusted library allocation
|
page read and write
|
||
4E0E000
|
stack
|
page read and write
|
||
4870000
|
trusted library allocation
|
page read and write
|
||
6070000
|
trusted library allocation
|
page read and write
|
||
5EA0000
|
heap
|
page read and write
|
||
4930000
|
trusted library allocation
|
page execute and read and write
|
||
5F0000
|
heap
|
page read and write
|
||
6120000
|
trusted library allocation
|
page execute and read and write
|
||
963000
|
trusted library allocation
|
page read and write
|
||
4862000
|
trusted library allocation
|
page read and write
|
||
5E94000
|
heap
|
page read and write
|
||
840000
|
heap
|
page read and write
|
||
95D000
|
trusted library allocation
|
page execute and read and write
|
||
5FFE000
|
trusted library allocation
|
page read and write
|
||
5C1E000
|
stack
|
page read and write
|
||
4970000
|
heap
|
page read and write
|
||
4851000
|
trusted library allocation
|
page read and write
|
||
22C0000
|
trusted library allocation
|
page read and write
|
||
4922000
|
trusted library allocation
|
page read and write
|
||
970000
|
trusted library allocation
|
page read and write
|
||
A46000
|
heap
|
page read and write
|
||
987000
|
trusted library allocation
|
page execute and read and write
|
||
845000
|
heap
|
page read and write
|
||
9F0000
|
heap
|
page execute and read and write
|
||
1E0000
|
heap
|
page read and write
|
||
23DE000
|
stack
|
page read and write
|
||
4880000
|
trusted library allocation
|
page read and write
|
||
5B10000
|
heap
|
page read and write
|
||
7C4000
|
heap
|
page read and write
|
||
982000
|
trusted library allocation
|
page read and write
|
||
A3D000
|
stack
|
page read and write
|
||
5F95000
|
trusted library allocation
|
page read and write
|
||
5B30000
|
trusted library allocation
|
page execute and read and write
|
||
48CE000
|
trusted library allocation
|
page read and write
|
||
7F870000
|
trusted library allocation
|
page execute and read and write
|
||
48D0000
|
heap
|
page read and write
|
||
6040000
|
trusted library allocation
|
page read and write
|
||
985000
|
trusted library allocation
|
page execute and read and write
|
||
60B0000
|
trusted library allocation
|
page read and write
|
||
976000
|
trusted library allocation
|
page execute and read and write
|
There are 131 hidden memdumps, click here to show them.