IOC Report
ws_ftp le 508.exe

loading gif

Files

File Path
Type
Category
Malicious
ws_ftp le 508.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\Desktop\SFS5D46.tmp
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Desktop\SFS5D75.tmp
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\ws_ftp le 508.exe
"C:\Users\user\Desktop\ws_ftp le 508.exe"
malicious
C:\Users\user\Desktop\SFS5D46.tmp
"C:\Users\user\Desktop\SFS5D46.tmp"
malicious
C:\Users\user\Desktop\SFS5D75.tmp
"C:\Users\user\Desktop\SFS5D75.tmp"

URLs

Name
IP
Malicious
http://www.ipswitch.com
unknown
https://buy.ipswitch.com/cgi-ole/buypro.showform/wsftppro/?000001767Ipswitch
unknown
HTTP://www.ipswitch.com
unknown
http://www.ipswitch.com/downloads/ws_ftp_PRO.html
unknown
http://www.ipswitch.comopenHTTP://www.ipswitch.comWS_FTPhttp://www.ipswitch.com/downloads/ws_ftp_PRO
unknown
http://www.ipswitch.com/products/ws_ftp/
unknown
http://www.ipswitch.com/products/ws_ftp/DLG_NOT_AUTHRemoveDIRWS_FTPINSTOPTSWS_FTPWS_FTP.exe%s
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
770000
heap
page read and write
7DE000
stack
page read and write
415000
unkown
page read and write
410000
unkown
page read and write
55E000
stack
page read and write
401000
unkown
page execute read
415000
unkown
page write copy
402000
unkown
page readonly
410000
heap
page read and write
1F0000
heap
page read and write
8E0000
heap
page read and write
865000
heap
page read and write
45E000
stack
page read and write
40F000
unkown
page readonly
401000
unkown
page execute read
2B70000
trusted library allocation
page read and write
403000
unkown
page read and write
400000
unkown
page readonly
22B0000
heap
page read and write
19B000
stack
page read and write
416000
unkown
page write copy
670000
heap
page read and write
690000
heap
page read and write
79F000
stack
page read and write
9D000
stack
page read and write
402000
unkown
page readonly
5DE000
stack
page read and write
401000
unkown
page execute read
8AE000
stack
page read and write
410000
unkown
page write copy
84A000
heap
page read and write
22B5000
heap
page read and write
660000
heap
page read and write
5C0000
heap
page read and write
510000
heap
page read and write
61E000
stack
page read and write
67E000
heap
page read and write
186000
stack
page read and write
84E000
heap
page read and write
8DF000
stack
page read and write
3370000
trusted library allocation
page read and write
403000
unkown
page write copy
400000
unkown
page readonly
900000
heap
page read and write
400000
unkown
page readonly
401000
unkown
page execute read
417000
unkown
page readonly
A3F000
stack
page read and write
881000
heap
page read and write
186000
stack
page read and write
670000
heap
page read and write
403000
unkown
page read and write
404000
unkown
page readonly
4E0000
heap
page read and write
400000
unkown
page readonly
49E000
heap
page read and write
403000
unkown
page write copy
1F0000
heap
page read and write
24D0000
heap
page read and write
402000
unkown
page readonly
24D4000
heap
page read and write
417000
unkown
page readonly
404000
unkown
page readonly
402000
unkown
page readonly
24F0000
heap
page read and write
881000
heap
page read and write
A70000
heap
page read and write
99000
stack
page read and write
9D000
stack
page read and write
A0F000
stack
page read and write
22B9000
heap
page read and write
590000
heap
page read and write
400000
unkown
page readonly
2390000
heap
page read and write
65F000
stack
page read and write
40F000
unkown
page readonly
401000
unkown
page execute read
49A000
heap
page read and write
404000
unkown
page readonly
67A000
heap
page read and write
426000
unkown
page readonly
840000
heap
page read and write
881000
heap
page read and write
490000
heap
page read and write
426000
unkown
page readonly
400000
unkown
page readonly
79F000
stack
page read and write
867000
heap
page read and write
404000
unkown
page readonly
1F0000
heap
page read and write
401000
unkown
page execute read
There are 81 hidden memdumps, click here to show them.