Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
SecuriteInfo.com.Variant.Doina.72984.2628.5521.exe
|
PE32+ executable (console) x86-64, for MS Windows
|
initial sample
|
||
C:\Users\user\AppData\Local\Temp\uKPwkwKUWlbmzgNfgIh
|
PE32+ executable (native) x86-64, for MS Windows
|
dropped
|
||
C:\Windows\SoftwareDistribution\Download\bugado.exe
|
PE32+ executable (console) x86-64, for MS Windows
|
dropped
|
||
C:\Windows\SoftwareDistribution\Download\bugado.sys
|
PE32+ executable (native) x86-64, for MS Windows
|
dropped
|
||
\Device\ConDrv
|
ASCII text, with CRLF line terminators
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\SecuriteInfo.com.Variant.Doina.72984.2628.5521.exe
|
"C:\Users\user\Desktop\SecuriteInfo.com.Variant.Doina.72984.2628.5521.exe"
|
||
C:\Windows\SoftwareDistribution\Download\bugado.exe
|
"C:\Windows\SoftwareDistribution\Download\bugado.exe" C:\Windows\SoftwareDistribution\Download\bugado.sys
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
||
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /c cls
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://crl.thawte.com/ThawteTimestampingCA.crl0
|
unknown
|
||
http://ocsp.thawte.com0
|
unknown
|
||
http://ocsp.veH
|
unknown
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\uKPwkwKUWlbmzgNfgIh
|
ImagePath
|
||
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\uKPwkwKUWlbmzgNfgIh
|
Type
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
23F9BA77000
|
heap
|
page read and write
|
||
23F9BA73000
|
heap
|
page read and write
|
||
7FF7257F0000
|
unkown
|
page readonly
|
||
23F9BA64000
|
heap
|
page read and write
|
||
23F9BA0F000
|
heap
|
page read and write
|
||
23F9BA68000
|
heap
|
page read and write
|
||
23F9BA54000
|
heap
|
page read and write
|
||
23F9BA81000
|
heap
|
page read and write
|
||
7FF617580000
|
unkown
|
page readonly
|
||
23F9F030000
|
heap
|
page read and write
|
||
9F459FF000
|
stack
|
page read and write
|
||
7FF617580000
|
unkown
|
page readonly
|
||
23F9D370000
|
heap
|
page read and write
|
||
23F9BA18000
|
heap
|
page read and write
|
||
23F9D455000
|
heap
|
page read and write
|
||
13A43E40000
|
heap
|
page read and write
|
||
7FF725839000
|
unkown
|
page readonly
|
||
23F9B940000
|
heap
|
page read and write
|
||
7FF7258AE000
|
unkown
|
page write copy
|
||
23F9BA82000
|
heap
|
page read and write
|
||
23F9BA98000
|
heap
|
page read and write
|
||
23F9D450000
|
heap
|
page read and write
|
||
13A43D60000
|
heap
|
page read and write
|
||
23F9BA7F000
|
heap
|
page read and write
|
||
23F9B9C9000
|
heap
|
page read and write
|
||
7FF617591000
|
unkown
|
page readonly
|
||
23F9BA18000
|
heap
|
page read and write
|
||
7FF617591000
|
unkown
|
page readonly
|
||
13A441B0000
|
heap
|
page read and write
|
||
23F9BA62000
|
heap
|
page read and write
|
||
23F9BA3A000
|
heap
|
page read and write
|
||
7FF7258A6000
|
unkown
|
page readonly
|
||
2C3ACFD000
|
stack
|
page read and write
|
||
7FF7257F1000
|
unkown
|
page execute read
|
||
23F9BA11000
|
heap
|
page read and write
|
||
23F9BA39000
|
heap
|
page read and write
|
||
7FF6175A2000
|
unkown
|
page read and write
|
||
2C3AEFF000
|
stack
|
page read and write
|
||
23F9BA54000
|
heap
|
page read and write
|
||
23F9B9EC000
|
heap
|
page read and write
|
||
13A43F3C000
|
heap
|
page read and write
|
||
2C3ADFF000
|
stack
|
page read and write
|
||
23F9BA72000
|
heap
|
page read and write
|
||
23F9BA54000
|
heap
|
page read and write
|
||
13A43F30000
|
heap
|
page read and write
|
||
23F9B9DF000
|
heap
|
page read and write
|
||
7FF7258A6000
|
unkown
|
page readonly
|
||
7FF617581000
|
unkown
|
page execute read
|
||
7FF617581000
|
unkown
|
page execute read
|
||
7FF7258D2000
|
unkown
|
page readonly
|
||
7FF725839000
|
unkown
|
page readonly
|
||
13A43E60000
|
heap
|
page read and write
|
||
23F9BA80000
|
heap
|
page read and write
|
||
9F458F6000
|
stack
|
page read and write
|
||
7FF7258AD000
|
unkown
|
page write copy
|
||
23F9B950000
|
heap
|
page read and write
|
||
23F9BA54000
|
heap
|
page read and write
|
||
13A43F36000
|
heap
|
page read and write
|
||
23F9BA63000
|
heap
|
page read and write
|
||
23F9BA5F000
|
heap
|
page read and write
|
||
23F9B9FD000
|
heap
|
page read and write
|
||
23F9B9FB000
|
heap
|
page read and write
|
||
23F9B9B7000
|
heap
|
page read and write
|
||
23F9BA9B000
|
heap
|
page read and write
|
||
7FF7258AD000
|
unkown
|
page read and write
|
||
7FF7258D2000
|
unkown
|
page readonly
|
||
7FF7257F1000
|
unkown
|
page execute read
|
||
23F9BA18000
|
heap
|
page read and write
|
||
23F9B9EC000
|
heap
|
page read and write
|
||
23F9B9FB000
|
heap
|
page read and write
|
||
7FF6175A3000
|
unkown
|
page readonly
|
||
23F9B9B0000
|
heap
|
page read and write
|
||
23F9B9DA000
|
heap
|
page read and write
|
||
23F9BA66000
|
heap
|
page read and write
|
||
7FF7258D0000
|
unkown
|
page read and write
|
||
7FF6175A3000
|
unkown
|
page readonly
|
||
23F9BA97000
|
heap
|
page read and write
|
||
7FF7257F0000
|
unkown
|
page readonly
|
||
23F9B980000
|
heap
|
page read and write
|
||
23F9BA75000
|
heap
|
page read and write
|
||
7FF6175A2000
|
unkown
|
page write copy
|
There are 71 hidden memdumps, click here to show them.