IOC Report
YBuzMywtqU.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\YBuzMywtqU.exe
"C:\Users\user\Desktop\YBuzMywtqU.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
https://login.microsoftonline.com/
unknown
https://login.microsoftonline.com/error?code=70000
unknown
https://login.microsoftonline.com/8/I
unknown
http://crl.micro
unknown
http://crl.microsoft
unknown
https://login.microsoftonline.com/common/oauth2/v2.0/token0
unknown
https://login.microsoftonline.com/osoftonline.com/5)6
unknown
https://login.microsoftonline.com/common/oauth2/v2.0/token03
unknown
https://login.microsoftonline.com/common/oauth2/v2.0/tokenK-
unknown
https://login.microsoftonline.com/common/oauth2/v2.0/tokenlt
unknown
https://login.microsoftonline.com/common/oauth2/v2.0/tokenSY
unknown
https://login.microsoftonline.com/common/oauth2/v2.0/tokenou
unknown
https://login.microsoftonline.com/common/oauth2/v2.0/tokenltificate
unknown
https://login.microsoftonline.com/common/oauth2/v2.0/token3-
unknown
https://login.microsoftonline.com/common/oauth2/v2.0/token
unknown
There are 5 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
login.microsoftonline.com
unknown

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive
GrimiApplication

Memdumps

Base Address
Regiontype
Protect
Malicious
5A4000
heap
page read and write
140000000
unkown
page readonly
2170000
heap
page read and write
5C4000
heap
page read and write
1C0000
heap
page read and write
587000
heap
page read and write
5F2000
heap
page read and write
140149000
unkown
page write copy
5BC000
heap
page read and write
1FF5000
heap
page read and write
140178000
unkown
page readonly
606000
heap
page read and write
2140000
unkown
page execute read
5EE000
heap
page read and write
2CCB000
unkown
page read and write
140166000
unkown
page readonly
534000
heap
page read and write
2CC5000
unkown
page read and write
2BBF000
stack
page read and write
2CBF000
stack
page read and write
14C000
stack
page read and write
2CCA000
unkown
page read and write
140166000
unkown
page readonly
2160000
unkown
page execute read
2140000
unkown
page read and write
1E0000
heap
page read and write
14015A000
unkown
page read and write
581000
heap
page read and write
5C4000
heap
page read and write
587000
heap
page read and write
5F3000
heap
page read and write
140119000
unkown
page readonly
190000
heap
page read and write
2CCB000
unkown
page read and write
140001000
unkown
page execute read
28BF000
stack
page read and write
5EE000
heap
page read and write
510000
heap
page read and write
180000
heap
page read and write
55B000
heap
page read and write
29BD000
stack
page read and write
20F6000
stack
page read and write
140119000
unkown
page readonly
51C000
heap
page read and write
2CC0000
unkown
page read and write
5BC000
heap
page read and write
2140000
remote allocation
page read and write
565000
heap
page read and write
5A4000
heap
page read and write
27BE000
stack
page read and write
140178000
unkown
page readonly
140001000
unkown
page execute read
5F0000
heap
page read and write
559000
heap
page read and write
556000
heap
page read and write
5F2000
heap
page read and write
2140000
remote allocation
page read and write
2ABB000
stack
page read and write
2140000
remote allocation
page read and write
1FF0000
heap
page read and write
140149000
unkown
page read and write
606000
heap
page read and write
26BF000
stack
page read and write
5EE000
heap
page read and write
140000000
unkown
page read and write
5BC000
heap
page read and write
5F0000
heap
page read and write
140152000
unkown
page read and write
5EE000
heap
page read and write
There are 59 hidden memdumps, click here to show them.