IOC Report
ciKdWsb5h4.exe

loading gif

Files

File Path
Type
Category
Malicious
ciKdWsb5h4.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\Public\Desktop\Google Chrome.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:41 2023, mtime=Wed Oct 4 11:02:32 2023, atime=Wed Sep 27 04:28:27 2023, length=3242272, window=hide
dropped
C:\Users\user\AppData\Local\Temp\Tmp434B.tmp
data
dropped
C:\Users\user\AppData\Local\Temp\Tmp435C.tmp
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-2246122658-3693405117-2476756634-1002\76b53b3ec448f7ccdda2063b15d2bfc3_9e146be9-c76a-4720-bcdb-53011b87bd06
data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\ciKdWsb5h4.exe
"C:\Users\user\Desktop\ciKdWsb5h4.exe"
malicious

URLs

Name
IP
Malicious
103.113.70.99:2630
malicious
http://tempuri.org/Entity/Id24LR
unknown
http://tempuri.org/Entity/Id22LR
unknown
http://tempuri.org/Entity/Id20LR
unknown
http://tempuri.org/Entity/Id15Responsex
unknown
http://tempuri.org/Entity/Id18Responsex
unknown
http://schemas.xmlsoap.org/soap/envelope/
unknown
http://tempuri.org/
unknown
http://tempuri.org/Entity/Id19LR
unknown
http://tempuri.org/Entity/Id17LR
unknown
http://tempuri.org/Entity/Id22Responsex
unknown
http://tempuri.org/Entity/Id6
unknown
http://tempuri.org/Entity/Id15LR
unknown
http://tempuri.org/Entity/Id9LR
unknown
http://tempuri.org/Entity/Id10Responsex
unknown
http://tempuri.org/Entity/Id19Responsex
unknown
http://tempuri.org/Entity/Id13LR
unknown
http://tempuri.org/Entity/Id7LR
unknown
http://tempuri.org/Entity/Id11LR
unknown
http://schemas.xmlsoap.org/ws/2005/02/rm/CreateSequenceResponse
unknown
http://tempuri.org/Entity/Id1LR
unknown
http://schemas.xmlsoap.org/ws/2005/02/rm/TerminateSequence
unknown
http://tempuri.org/Entity/Id5LR
unknown
http://tempuri.org/Entity/Id3LR
unknown
http://tempuri.org/Entity/Id6Responsex
unknown
http://tempuri.org/Entity/Id7Responsex
unknown
http://tempuri.org/Entity/Id1Responsex
unknown
http://tempuri.org/Entity/Id21Responsex
unknown
http://schemas.xmlsoap.org/ws/2004/08/addressing/faultp9
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/right/possessproperty
unknown
https://api.ip.sb/ip
unknown
http://tempuri.org/Entity/Id23Responsex
unknown
http://schemas.xmlsoap.org/ws/2005/02/rm/SequenceAcknowledgement
unknown
http://tempuri.org/Entity/Id23LR
unknown
http://tempuri.org/Entity/Id21LR
unknown
http://tempuri.org/Entity/Id5Responsex
unknown
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous
unknown
http://tempuri.org/Entity/Id14Responsex
unknown
http://tempuri.org/Entity/Id2Responsex
unknown
http://tempuri.org/Entity/Id11Responsex
unknown
http://tempuri.org/Entity/Id20Responsex
unknown
http://schemas.xmlsoap.org/ws/2005/02/rm/AckRequested
unknown
http://tempuri.org/Entity/Id8Responsex
unknown
http://tempuri.org/Entity/Id18LR
unknown
http://tempuri.org/Entity/Id13Responsex
unknown
http://tempuri.org/Entity/Id16Responsex
unknown
http://tempuri.org/Entity/Id16LR
unknown
http://tempuri.org/Entity/Id8LR
unknown
http://tempuri.org/Entity/Id14LR
unknown
http://tempuri.org/Entity/Id6LR
unknown
http://tempuri.org/Entity/
unknown
http://tempuri.org/Entity/Id12LR
unknown
http://tempuri.org/Entity/Id9Responsex
unknown
http://schemas.xmlsoap.org/ws/2004/08/addressing
unknown
http://tempuri.org/Entity/Id10LR
unknown
http://tempuri.org/Entity/Id3Responsex
unknown
http://tempuri.org/Entity/Id4LR
unknown
http://tempuri.org/Entity/Id24Responsex
unknown
http://tempuri.org/Entity/Id2LR
unknown
http://schemas.xmlsoap.org/ws/2005/02/rm
unknown
http://schemas.xmlsoap.org/ws/2005/02/rm/LastMessage
unknown
http://tempuri.org/Entity/Id12Responsex
unknown
http://tempuri.org/Entity/Id17Responsex
unknown
http://schemas.xmlsoap.org/ws/2005/02/rm/CreateSequence
unknown
http://schemas.xmlsoap.org/soap/actor/next
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/dns
unknown
http://tempuri.org/Entity/Id4Responsex
unknown
There are 57 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
103.113.70.99
unknown
India
malicious

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F1A578C4CB5DE79A370893983FD4DA8B67B2B064
Blob
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
32000
unkown
page readonly
malicious
4820000
trusted library allocation
page read and write
190000
heap
page read and write
76000
unkown
page readonly
950000
trusted library allocation
page read and write
5E90000
heap
page read and write
4834000
trusted library allocation
page read and write
2290000
heap
page read and write
980000
trusted library allocation
page read and write
81E000
heap
page read and write
4895000
trusted library allocation
page read and write
750000
heap
page read and write
553E000
stack
page read and write
33E1000
trusted library allocation
page read and write
48D3000
heap
page read and write
4890000
trusted library allocation
page read and write
4B80000
heap
page execute and read and write
5FE6000
trusted library allocation
page read and write
758000
heap
page read and write
81C000
heap
page read and write
597E000
stack
page read and write
22D0000
heap
page read and write
960000
trusted library allocation
page read and write
4920000
trusted library allocation
page read and write
593E000
stack
page read and write
6270000
trusted library allocation
page read and write
600A000
trusted library allocation
page read and write
5FA7000
trusted library allocation
page read and write
483E000
trusted library allocation
page read and write
4836000
trusted library allocation
page read and write
6060000
trusted library allocation
page read and write
A40000
heap
page read and write
44DE000
stack
page read and write
484E000
trusted library allocation
page read and write
5FDB000
trusted library allocation
page read and write
6030000
trusted library allocation
page read and write
6025000
trusted library allocation
page read and write
4E80000
trusted library allocation
page read and write
33EF000
trusted library allocation
page read and write
5FF2000
trusted library allocation
page read and write
5EB5000
heap
page read and write
602E000
trusted library allocation
page read and write
5EE3000
heap
page read and write
30000
unkown
page readonly
4E70000
trusted library allocation
page read and write
6130000
trusted library allocation
page execute and read and write
5EF1000
heap
page read and write
485D000
trusted library allocation
page read and write
602B000
trusted library allocation
page read and write
5A7E000
stack
page read and write
6050000
trusted library allocation
page read and write
5A80000
trusted library allocation
page read and write
4F7000
stack
page read and write
97A000
trusted library allocation
page execute and read and write
972000
trusted library allocation
page read and write
96D000
trusted library allocation
page execute and read and write
4E78000
trusted library allocation
page read and write
5FD0000
trusted library allocation
page read and write
740000
trusted library allocation
page read and write
9EE000
stack
page read and write
953000
trusted library allocation
page execute and read and write
60D0000
trusted library allocation
page execute and read and write
60A0000
trusted library allocation
page read and write
5F5000
heap
page read and write
4910000
heap
page read and write
5F9B000
trusted library allocation
page read and write
5E5F000
stack
page read and write
5FA5000
trusted library allocation
page read and write
180000
heap
page read and write
5FE1000
trusted library allocation
page read and write
22B0000
trusted library allocation
page execute and read and write
5D5E000
stack
page read and write
954000
trusted library allocation
page read and write
3402000
trusted library allocation
page read and write
75E000
heap
page read and write
6020000
trusted library allocation
page read and write
6260000
trusted library allocation
page read and write
777000
heap
page read and write
5F90000
trusted library allocation
page read and write
6001000
trusted library allocation
page read and write
4830000
trusted library allocation
page read and write
23E1000
trusted library allocation
page read and write
6250000
trusted library allocation
page read and write
791000
heap
page read and write
62000
unkown
page readonly
11A000
stack
page read and write
583E000
stack
page read and write
4888000
trusted library allocation
page read and write
5FA0000
trusted library allocation
page read and write
98B000
trusted library allocation
page execute and read and write
483B000
trusted library allocation
page read and write
48A0000
trusted library allocation
page read and write
48C0000
trusted library allocation
page read and write
5B20000
trusted library allocation
page execute and read and write
60C0000
trusted library allocation
page execute and read and write
4CE1000
heap
page read and write
4842000
trusted library allocation
page read and write
5FA9000
trusted library allocation
page read and write
5D1E000
stack
page read and write
4856000
trusted library allocation
page read and write
67000
unkown
page readonly
6010000
trusted library allocation
page read and write
4E0E000
stack
page read and write
4870000
trusted library allocation
page read and write
6070000
trusted library allocation
page read and write
5EA0000
heap
page read and write
4930000
trusted library allocation
page execute and read and write
5F0000
heap
page read and write
6120000
trusted library allocation
page execute and read and write
963000
trusted library allocation
page read and write
4862000
trusted library allocation
page read and write
5E94000
heap
page read and write
840000
heap
page read and write
95D000
trusted library allocation
page execute and read and write
5FFE000
trusted library allocation
page read and write
5C1E000
stack
page read and write
4970000
heap
page read and write
4851000
trusted library allocation
page read and write
22C0000
trusted library allocation
page read and write
4922000
trusted library allocation
page read and write
970000
trusted library allocation
page read and write
A46000
heap
page read and write
987000
trusted library allocation
page execute and read and write
845000
heap
page read and write
9F0000
heap
page execute and read and write
1E0000
heap
page read and write
23DE000
stack
page read and write
4880000
trusted library allocation
page read and write
5B10000
heap
page read and write
7C4000
heap
page read and write
982000
trusted library allocation
page read and write
A3D000
stack
page read and write
5F95000
trusted library allocation
page read and write
5B30000
trusted library allocation
page execute and read and write
48CE000
trusted library allocation
page read and write
7F870000
trusted library allocation
page execute and read and write
48D0000
heap
page read and write
6040000
trusted library allocation
page read and write
985000
trusted library allocation
page execute and read and write
60B0000
trusted library allocation
page read and write
976000
trusted library allocation
page execute and read and write
There are 131 hidden memdumps, click here to show them.