IOC Report
SecuriteInfo.com.Variant.Doina.72984.2628.5521.exe

loading gif

Files

File Path
Type
Category
Malicious
SecuriteInfo.com.Variant.Doina.72984.2628.5521.exe
PE32+ executable (console) x86-64, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Temp\uKPwkwKUWlbmzgNfgIh
PE32+ executable (native) x86-64, for MS Windows
dropped
malicious
C:\Windows\SoftwareDistribution\Download\bugado.exe
PE32+ executable (console) x86-64, for MS Windows
dropped
malicious
C:\Windows\SoftwareDistribution\Download\bugado.sys
PE32+ executable (native) x86-64, for MS Windows
dropped
malicious
\Device\ConDrv
ASCII text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.Variant.Doina.72984.2628.5521.exe
"C:\Users\user\Desktop\SecuriteInfo.com.Variant.Doina.72984.2628.5521.exe"
malicious
C:\Windows\SoftwareDistribution\Download\bugado.exe
"C:\Windows\SoftwareDistribution\Download\bugado.exe" C:\Windows\SoftwareDistribution\Download\bugado.sys
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\cmd.exe
C:\Windows\system32\cmd.exe /c cls

URLs

Name
IP
Malicious
http://crl.thawte.com/ThawteTimestampingCA.crl0
unknown
http://ocsp.thawte.com0
unknown
http://ocsp.veH
unknown

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\uKPwkwKUWlbmzgNfgIh
ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\uKPwkwKUWlbmzgNfgIh
Type

Memdumps

Base Address
Regiontype
Protect
Malicious
23F9BA77000
heap
page read and write
23F9BA73000
heap
page read and write
7FF7257F0000
unkown
page readonly
23F9BA64000
heap
page read and write
23F9BA0F000
heap
page read and write
23F9BA68000
heap
page read and write
23F9BA54000
heap
page read and write
23F9BA81000
heap
page read and write
7FF617580000
unkown
page readonly
23F9F030000
heap
page read and write
9F459FF000
stack
page read and write
7FF617580000
unkown
page readonly
23F9D370000
heap
page read and write
23F9BA18000
heap
page read and write
23F9D455000
heap
page read and write
13A43E40000
heap
page read and write
7FF725839000
unkown
page readonly
23F9B940000
heap
page read and write
7FF7258AE000
unkown
page write copy
23F9BA82000
heap
page read and write
23F9BA98000
heap
page read and write
23F9D450000
heap
page read and write
13A43D60000
heap
page read and write
23F9BA7F000
heap
page read and write
23F9B9C9000
heap
page read and write
7FF617591000
unkown
page readonly
23F9BA18000
heap
page read and write
7FF617591000
unkown
page readonly
13A441B0000
heap
page read and write
23F9BA62000
heap
page read and write
23F9BA3A000
heap
page read and write
7FF7258A6000
unkown
page readonly
2C3ACFD000
stack
page read and write
7FF7257F1000
unkown
page execute read
23F9BA11000
heap
page read and write
23F9BA39000
heap
page read and write
7FF6175A2000
unkown
page read and write
2C3AEFF000
stack
page read and write
23F9BA54000
heap
page read and write
23F9B9EC000
heap
page read and write
13A43F3C000
heap
page read and write
2C3ADFF000
stack
page read and write
23F9BA72000
heap
page read and write
23F9BA54000
heap
page read and write
13A43F30000
heap
page read and write
23F9B9DF000
heap
page read and write
7FF7258A6000
unkown
page readonly
7FF617581000
unkown
page execute read
7FF617581000
unkown
page execute read
7FF7258D2000
unkown
page readonly
7FF725839000
unkown
page readonly
13A43E60000
heap
page read and write
23F9BA80000
heap
page read and write
9F458F6000
stack
page read and write
7FF7258AD000
unkown
page write copy
23F9B950000
heap
page read and write
23F9BA54000
heap
page read and write
13A43F36000
heap
page read and write
23F9BA63000
heap
page read and write
23F9BA5F000
heap
page read and write
23F9B9FD000
heap
page read and write
23F9B9FB000
heap
page read and write
23F9B9B7000
heap
page read and write
23F9BA9B000
heap
page read and write
7FF7258AD000
unkown
page read and write
7FF7258D2000
unkown
page readonly
7FF7257F1000
unkown
page execute read
23F9BA18000
heap
page read and write
23F9B9EC000
heap
page read and write
23F9B9FB000
heap
page read and write
7FF6175A3000
unkown
page readonly
23F9B9B0000
heap
page read and write
23F9B9DA000
heap
page read and write
23F9BA66000
heap
page read and write
7FF7258D0000
unkown
page read and write
7FF6175A3000
unkown
page readonly
23F9BA97000
heap
page read and write
7FF7257F0000
unkown
page readonly
23F9B980000
heap
page read and write
23F9BA75000
heap
page read and write
7FF6175A2000
unkown
page write copy
There are 71 hidden memdumps, click here to show them.