Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
ws_ftp le 508.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Users\user\Desktop\SFS5D46.tmp
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Users\user\Desktop\SFS5D75.tmp
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\ws_ftp le 508.exe
|
"C:\Users\user\Desktop\ws_ftp le 508.exe"
|
||
C:\Users\user\Desktop\SFS5D46.tmp
|
"C:\Users\user\Desktop\SFS5D46.tmp"
|
||
C:\Users\user\Desktop\SFS5D75.tmp
|
"C:\Users\user\Desktop\SFS5D75.tmp"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://www.ipswitch.com
|
unknown
|
||
https://buy.ipswitch.com/cgi-ole/buypro.showform/wsftppro/?000001767Ipswitch
|
unknown
|
||
HTTP://www.ipswitch.com
|
unknown
|
||
http://www.ipswitch.com/downloads/ws_ftp_PRO.html
|
unknown
|
||
http://www.ipswitch.comopenHTTP://www.ipswitch.comWS_FTPhttp://www.ipswitch.com/downloads/ws_ftp_PRO
|
unknown
|
||
http://www.ipswitch.com/products/ws_ftp/
|
unknown
|
||
http://www.ipswitch.com/products/ws_ftp/DLG_NOT_AUTHRemoveDIRWS_FTPINSTOPTSWS_FTPWS_FTP.exe%s
|
unknown
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
770000
|
heap
|
page read and write
|
||
7DE000
|
stack
|
page read and write
|
||
415000
|
unkown
|
page read and write
|
||
410000
|
unkown
|
page read and write
|
||
55E000
|
stack
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
415000
|
unkown
|
page write copy
|
||
402000
|
unkown
|
page readonly
|
||
410000
|
heap
|
page read and write
|
||
1F0000
|
heap
|
page read and write
|
||
8E0000
|
heap
|
page read and write
|
||
865000
|
heap
|
page read and write
|
||
45E000
|
stack
|
page read and write
|
||
40F000
|
unkown
|
page readonly
|
||
401000
|
unkown
|
page execute read
|
||
2B70000
|
trusted library allocation
|
page read and write
|
||
403000
|
unkown
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
22B0000
|
heap
|
page read and write
|
||
19B000
|
stack
|
page read and write
|
||
416000
|
unkown
|
page write copy
|
||
670000
|
heap
|
page read and write
|
||
690000
|
heap
|
page read and write
|
||
79F000
|
stack
|
page read and write
|
||
9D000
|
stack
|
page read and write
|
||
402000
|
unkown
|
page readonly
|
||
5DE000
|
stack
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
8AE000
|
stack
|
page read and write
|
||
410000
|
unkown
|
page write copy
|
||
84A000
|
heap
|
page read and write
|
||
22B5000
|
heap
|
page read and write
|
||
660000
|
heap
|
page read and write
|
||
5C0000
|
heap
|
page read and write
|
||
510000
|
heap
|
page read and write
|
||
61E000
|
stack
|
page read and write
|
||
67E000
|
heap
|
page read and write
|
||
186000
|
stack
|
page read and write
|
||
84E000
|
heap
|
page read and write
|
||
8DF000
|
stack
|
page read and write
|
||
3370000
|
trusted library allocation
|
page read and write
|
||
403000
|
unkown
|
page write copy
|
||
400000
|
unkown
|
page readonly
|
||
900000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
401000
|
unkown
|
page execute read
|
||
417000
|
unkown
|
page readonly
|
||
A3F000
|
stack
|
page read and write
|
||
881000
|
heap
|
page read and write
|
||
186000
|
stack
|
page read and write
|
||
670000
|
heap
|
page read and write
|
||
403000
|
unkown
|
page read and write
|
||
404000
|
unkown
|
page readonly
|
||
4E0000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
49E000
|
heap
|
page read and write
|
||
403000
|
unkown
|
page write copy
|
||
1F0000
|
heap
|
page read and write
|
||
24D0000
|
heap
|
page read and write
|
||
402000
|
unkown
|
page readonly
|
||
24D4000
|
heap
|
page read and write
|
||
417000
|
unkown
|
page readonly
|
||
404000
|
unkown
|
page readonly
|
||
402000
|
unkown
|
page readonly
|
||
24F0000
|
heap
|
page read and write
|
||
881000
|
heap
|
page read and write
|
||
A70000
|
heap
|
page read and write
|
||
99000
|
stack
|
page read and write
|
||
9D000
|
stack
|
page read and write
|
||
A0F000
|
stack
|
page read and write
|
||
22B9000
|
heap
|
page read and write
|
||
590000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
2390000
|
heap
|
page read and write
|
||
65F000
|
stack
|
page read and write
|
||
40F000
|
unkown
|
page readonly
|
||
401000
|
unkown
|
page execute read
|
||
49A000
|
heap
|
page read and write
|
||
404000
|
unkown
|
page readonly
|
||
67A000
|
heap
|
page read and write
|
||
426000
|
unkown
|
page readonly
|
||
840000
|
heap
|
page read and write
|
||
881000
|
heap
|
page read and write
|
||
490000
|
heap
|
page read and write
|
||
426000
|
unkown
|
page readonly
|
||
400000
|
unkown
|
page readonly
|
||
79F000
|
stack
|
page read and write
|
||
867000
|
heap
|
page read and write
|
||
404000
|
unkown
|
page readonly
|
||
1F0000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
There are 81 hidden memdumps, click here to show them.