IOC Report
yPIOW6yoPi.exe

loading gif

Files

File Path
Type
Category
Malicious
yPIOW6yoPi.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_yPIOW6yoPi.exe_f1164e2edceb3e426fcc8f132ef36e41c5c6259_1752a2a0_ca2fc48c-3ee1-4ae6-930c-46450d7d3581\Report.wer
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
malicious
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_yPIOW6yoPi.exe_fd4b28536be3f5f250312b9457878378f496af_1752a2a0_039bda82-6726-4bed-ba54-b8025f3f7407\Report.wer
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
malicious
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_yPIOW6yoPi.exe_fd4b28536be3f5f250312b9457878378f496af_1752a2a0_7145277a-e9bd-46c5-bc6a-b581742e3b6f\Report.wer
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
malicious
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_yPIOW6yoPi.exe_fd4b28536be3f5f250312b9457878378f496af_1752a2a0_83c67f10-09d1-4f5e-bb02-5897b429db17\Report.wer
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
malicious
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_yPIOW6yoPi.exe_fd4b28536be3f5f250312b9457878378f496af_1752a2a0_9225f348-fc1c-43e9-969c-f488455d47d0\Report.wer
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
malicious
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_yPIOW6yoPi.exe_fd4b28536be3f5f250312b9457878378f496af_1752a2a0_a4670110-4580-4a73-a4d1-32c5eedad24e\Report.wer
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
malicious
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_yPIOW6yoPi.exe_fd4b28536be3f5f250312b9457878378f496af_1752a2a0_ab7867eb-ccc1-47e5-b15e-9c3a94fe2e36\Report.wer
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
malicious
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_yPIOW6yoPi.exe_fd4b28536be3f5f250312b9457878378f496af_1752a2a0_f8f41f5e-6227-4ae3-bf1b-518301d54ad4\Report.wer
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\xenor\yavascript.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Roaming\xenor\yavascript.exe:Zone.Identifier
ASCII text, with CRLF line terminators
modified
malicious
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_yavascript.exe_3ada1d2124dd83478d28603eafb8278c3cd43a8_ea442dc3_026179ac-8916-407f-91dc-a5a14972c7f8\Report.wer
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_yavascript.exe_3ada1d2124dd83478d28603eafb8278c3cd43a8_ea442dc3_6bc045d0-02d5-4a02-89f2-a6a0651423b7\Report.wer
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_yavascript.exe_3ada1d2124dd83478d28603eafb8278c3cd43a8_ea442dc3_781d5b2c-740b-40ff-8110-596b8b9678ba\Report.wer
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_yavascript.exe_3ada1d2124dd83478d28603eafb8278c3cd43a8_ea442dc3_8517f58d-bc75-442d-86f3-9222e589eca9\Report.wer
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_yavascript.exe_3ada1d2124dd83478d28603eafb8278c3cd43a8_ea442dc3_e4ea9386-551c-4f98-b367-86f863fb4c76\Report.wer
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_yavascript.exe_5234ed1d7ecb99e2551a7c6515903d7434b037_ea442dc3_01c2a705-21c2-451f-a615-5ae6805d6bae\Report.wer
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_yavascript.exe_9a5ba2c8fe28881fe54ec8233a3cde1e501b46_ea442dc3_2ee97c34-6f1f-426e-8948-3ed966e17be7\Report.wer
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERA4E7.tmp.dmp
Mini DuMP crash report, 14 streams, Sat Jan 11 05:12:39 2025, 0x1205a4 type
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERA6BD.tmp.WERInternalMetadata.xml
XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERA6FD.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERA97B.tmp.dmp
Mini DuMP crash report, 14 streams, Sat Jan 11 05:12:40 2025, 0x1205a4 type
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERAA96.tmp.WERInternalMetadata.xml
XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERAAC5.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERAE8C.tmp.dmp
Mini DuMP crash report, 14 streams, Sat Jan 11 05:12:41 2025, 0x1205a4 type
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERAF97.tmp.WERInternalMetadata.xml
XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERAFC7.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERB207.tmp.dmp
Mini DuMP crash report, 14 streams, Sat Jan 11 05:12:42 2025, 0x1205a4 type
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERB2B4.tmp.WERInternalMetadata.xml
XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERB2F3.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERB553.tmp.dmp
Mini DuMP crash report, 14 streams, Sat Jan 11 05:12:43 2025, 0x1205a4 type
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERB7B5.tmp.WERInternalMetadata.xml
XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERB833.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERBA73.tmp.dmp
Mini DuMP crash report, 14 streams, Sat Jan 11 05:12:44 2025, 0x1205a4 type
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERBB30.tmp.WERInternalMetadata.xml
XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERBB6F.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERBDCE.tmp.dmp
Mini DuMP crash report, 14 streams, Sat Jan 11 05:12:45 2025, 0x1205a4 type
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERBEF8.tmp.WERInternalMetadata.xml
XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERBF19.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERC427.tmp.dmp
Mini DuMP crash report, 14 streams, Sat Jan 11 05:12:47 2025, 0x1205a4 type
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERC571.tmp.WERInternalMetadata.xml
XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERC591.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERC977.tmp.dmp
Mini DuMP crash report, 14 streams, Sat Jan 11 05:12:48 2025, 0x1205a4 type
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERCA24.tmp.WERInternalMetadata.xml
XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERCA73.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
dropped