IOC Report
ngbtiladkrthgad.exe

loading gif

Files

File Path
Type
Category
Malicious
ngbtiladkrthgad.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\o89zu\dbs0r9
SQLite 3.x database, last written using SQLite version 3042000, page size 32768, file counter 2, database pages 9, cookie 0x6, schema 4, UTF-8, version-valid-for 2
dropped
C:\ProgramData\o89zu\gdtrim
ASCII text, with very long lines (1809), with CRLF line terminators
dropped
C:\ProgramData\o89zu\hdjw4o
SQLite 3.x database, last written using SQLite version 3046000, file counter 6, database pages 41, 1st free page 29, free pages 1, cookie 0x25, schema 4, UTF-8, version-valid-for 6
dropped
C:\ProgramData\o89zu\hvsri5
SQLite 3.x database, user version 12, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 3, database pages 3, cookie 0x1, schema 4, UTF-8, version-valid-for 3
dropped
C:\ProgramData\o89zu\jmym7q
SQLite 3.x database, last written using SQLite version 3046000, page size 2048, file counter 6, database pages 68, cookie 0x4a, schema 4, UTF-8, version-valid-for 6
dropped
C:\ProgramData\o89zu\sjwt0hlfu
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\ProgramData\o89zu\sr90rq
SQLite 3.x database, last written using SQLite version 3035005, file counter 2, database pages 31, cookie 0x18, schema 4, UTF-8, version-valid-for 2
dropped
C:\ProgramData\o89zu\uaiwlfus2
SQLite 3.x database, last written using SQLite version 3046000, page size 2048, file counter 2, database pages 20, cookie 0xc, schema 4, UTF-8, version-valid-for 2
dropped
C:\ProgramData\o89zu\xb1vk6
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ZJCZETOO\json[1].json
JSON data
dropped
Chrome Cache Entry: 66
ASCII text, with very long lines (5162), with no line terminators
downloaded
Chrome Cache Entry: 67
ASCII text
downloaded
Chrome Cache Entry: 68
ASCII text, with very long lines (65531)
downloaded
Chrome Cache Entry: 69
ASCII text, with very long lines (2412)
downloaded
Chrome Cache Entry: 70
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 71
ASCII text, with very long lines (859)
downloaded
There are 7 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\ngbtiladkrthgad.exe
"C:\Users\user\Desktop\ngbtiladkrthgad.exe"
malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9223 --profile-directory="Default"
malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1892,i,7460351053640162327,6554442286005526848,262144 --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2444 /prefetch:3
malicious
C:\Windows\SysWOW64\cmd.exe
"C:\Windows\system32\cmd.exe" /c timeout /t 11 & rd /s /q "C:\ProgramData\o89zu" & exit
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\timeout.exe
timeout /t 11

URLs

Name
IP
Malicious
https://t.me/
unknown
https://t.me/g_etcontentdqu220Mozilla/5.0
unknown
https://duckduckgo.com/ac/?q=
unknown
http://www.broofa.com
unknown
https://contile-images.services.mozilla.com/0TegrVVRalreHILhR2WvtD_CFzj13HCDcLqqpvXSOuY.10862.jpg
unknown
https://web.telegram.org
unknown
https://t.me/g_etcontent
149.154.167.99
https://bridge.lga1.admarketplace.net/ctp?version=16.0.0&key=1696332238301000001.2&ci=1696332238417.
unknown
http://www.microsoft.cd
unknown
https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
unknown
https://ac.ecosia.org?q=
unknown
https://bridge.lga1.ap01.net/ctp?version=16.0.0&key=1696332238301000001.1&ci=1696332238417.12791&cta
unknown
https://www.google.com/async/newtab_promos
216.58.206.36
https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
unknown
http://e5.i.lencr.org/0
unknown
https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br
unknown
https://steamcommunity.com/profiles/76561199832267488dqu220Mozilla/5.0
unknown
https://www.google.com/images/branding/product/ico/googleg_alldp.ico
unknown
https://www.google.com/async/ddljson?async=ntp:2
216.58.206.36
https://play.google.com/log?format=json&hasfast=true
unknown
https://steamcommunity.com/profiles/76561199832267488
https://www.ecosia.org/newtab/v20
unknown
https://contile-images.services.mozilla.com/obgoOYObjIFea_bXuT6L4LbBJ8j425AD87S1HMD3BWg.9991.jpg
unknown
https://imp.mt48.net/static?id=7RHzfOIXjFEYsBdvIpkX4QqmfZfYfQfafZbXfpbWfpbX7ReNxR3UIG8zInwYIFIVs9eYi
unknown
http://x1.c.lencr.org/0
unknown
http://x1.i.lencr.org/0
unknown
https://duckduckgo.com/chrome_newtabv20
unknown
http://e5.c.lencr.org/101.crl0
unknown
https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
unknown
https://www.google.com/async/newtab_ogb?hl=en-US&async=fixed:0
216.58.206.36
https://apis.google.com
unknown
http://e5.o.lencr.org0
unknown
https://support.mozilla.org/products/firefoxgro.all
unknown
https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE
216.58.206.36
https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
unknown
https://gemini.google.com/app?q=
unknown
https://www.amazon.com/?tag=admarketus-20&ref=pd_sl_7548d4575af019e4c148ccf1a78112802e66a0816a72fc94
unknown
There are 27 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
s.p.formaxprime.co.uk
78.47.63.132
malicious
plus.l.google.com
142.250.185.174
t.me
149.154.167.99
www.google.com
216.58.206.36
apis.google.com
unknown

IPs

IP
Domain
Country
Malicious
192.168.2.4
unknown
unknown
malicious
78.47.63.132
s.p.formaxprime.co.uk
Germany
malicious
149.154.167.99
t.me
United Kingdom
216.58.206.36
www.google.com
United States
142.250.185.174
plus.l.google.com
United States
127.0.0.1
unknown
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
2B80000
heap
page read and write
351B000
heap
page read and write
2DB1000
heap
page read and write
3A68000
heap
page read and write
3A88000
heap
page read and write
347C000
heap
page read and write
34E3000
heap
page read and write
31E2000
heap
page read and write
25BF000
stack
page read and write
3194000
heap
page read and write
4E40000
heap
page read and write
3494000
heap
page read and write
2DB0000
heap
page read and write
8EF000
stack
page read and write
2FEE000
stack
page read and write
3060000
heap
page read and write
66C000
heap
page read and write
422000
unkown
page write copy
344F000
heap
page read and write
3130000
heap
page read and write
46E9000
heap
page read and write
3456000
heap
page read and write
5FE000
heap
page read and write
33E2000
heap
page read and write
4055000
heap
page read and write
665000
heap
page read and write
4674000
heap
page read and write
462A000
heap
page read and write
41E000
unkown
page readonly
98E000
stack
page read and write
427000
unkown
page readonly
3183000
heap
page read and write
673000
heap
page read and write
2FF4000
heap
page read and write
2BAC000
stack
page read and write
27BC000
stack
page read and write
5F9000
heap
page read and write
349B000
heap
page read and write
440000
heap
page read and write
36A1000
heap
page read and write
365F000
heap
page read and write
3401000
heap
page read and write
400000
unkown
page readonly
4E0000
heap
page read and write
3796000
heap
page read and write
3152000
heap
page read and write
665000
heap
page read and write
31F0000
trusted library allocation
page read and write
31E8000
heap
page read and write
19F000
stack
page read and write
2C1E000
stack
page read and write
4634000
heap
page read and write
4E7000
heap
page read and write
4060000
heap
page read and write
3AD8000
heap
page read and write
4CE000
stack
page read and write
3364000
heap
page read and write
6B2000
heap
page read and write
3B00000
heap
page read and write
2DB1000
heap
page read and write
4F1F000
stack
page read and write
190000
stack
page read and write
366F000
heap
page read and write
40EA000
heap
page read and write
2C27000
heap
page read and write
2D4F000
stack
page read and write
41E000
unkown
page readonly
4DBC000
stack
page read and write
3F75000
heap
page read and write
2DB1000
heap
page read and write
3A50000
heap
page read and write
640000
heap
page read and write
26BF000
stack
page read and write
306A000
heap
page read and write
2FFB000
heap
page read and write
3467000
heap
page read and write
4610000
heap
page read and write
2C20000
heap
page read and write
672000
heap
page read and write
33E9000
heap
page read and write
401000
unkown
page execute read
33FB000
heap
page read and write
291F000
stack
page read and write
2C10000
remote allocation
page read and write
4E4A000
heap
page read and write
367C000
heap
page read and write
329E000
stack
page read and write
325C000
stack
page read and write
3636000
heap
page read and write
4E7000
heap
page read and write
34A1000
heap
page read and write
460A000
heap
page read and write
3FB5000
heap
page read and write
674000
heap
page read and write
281E000
stack
page read and write
3BA0000
heap
page read and write
2B90000
heap
page read and write
47F4000
heap
page read and write
47AA000
heap
page read and write
66C000
heap
page read and write
6AC000
heap
page read and write
3348000
heap
page read and write
27BF000
stack
page read and write
319D000
heap
page read and write
6B0000
heap
page read and write
3673000
heap
page read and write
3F95000
heap
page read and write
2FF0000
heap
page read and write
4E7000
heap
page read and write
665000
heap
page read and write
673000
heap
page read and write
671000
heap
page read and write
367E000
heap
page read and write
5F0000
heap
page read and write
33EF000
heap
page read and write
9B000
stack
page read and write
427000
unkown
page readonly
470A000
heap
page read and write
665000
heap
page read and write
9D7000
heap
page read and write
3680000
heap
page read and write
4E7000
heap
page read and write
2D50000
heap
page read and write
665000
heap
page read and write
2EB0000
trusted library allocation
page read and write
36E1000
heap
page read and write
31C6000
heap
page read and write
31F0000
trusted library allocation
page read and write
9D0000
heap
page read and write
3072000
heap
page read and write
402A000
heap
page read and write
31E0000
heap
page read and write
34A3000
heap
page read and write
384D000
heap
page read and write
6AD000
heap
page read and write
430000
heap
page read and write
2C4E000
stack
page read and write
3FC0000
heap
page read and write
464A000
heap
page read and write
350C000
heap
page read and write
3736000
heap
page read and write
19C000
stack
page read and write
30F0000
heap
page read and write
33F6000
heap
page read and write
6ED000
heap
page read and write
66C000
heap
page read and write
674000
heap
page read and write
6B2000
heap
page read and write
296E000
stack
page read and write
37F9000
heap
page read and write
374B000
heap
page read and write
31C1000
heap
page read and write
368D000
heap
page read and write
423000
unkown
page read and write
467F000
heap
page read and write
3642000
heap
page read and write
2BDE000
stack
page read and write
66C000
heap
page read and write
3474000
heap
page read and write
3405000
heap
page read and write
31C8000
heap
page read and write
386E000
heap
page read and write
2FF2000
heap
page read and write
2D5F000
stack
page read and write
34EC000
heap
page read and write
37A9000
heap
page read and write
31F0000
trusted library allocation
page read and write
4734000
heap
page read and write
2AAC000
stack
page read and write
8F0000
heap
page read and write
4654000
heap
page read and write
37A1000
heap
page read and write
94E000
stack
page read and write
31A9000
heap
page read and write
3483000
heap
page read and write
3F60000
heap
page read and write
34EA000
heap
page read and write
3F53000
heap
page read and write
66C000
heap
page read and write
18E000
stack
page read and write
33C2000
heap
page read and write
6AF000
heap
page read and write
36EB000
heap
page read and write
363D000
heap
page read and write
3B08000
heap
page read and write
6B8000
heap
page read and write
34EE000
heap
page read and write
2A6D000
stack
page read and write
9CE000
stack
page read and write
3F4B000
heap
page read and write
33A6000
heap
page read and write
3330000
heap
page read and write
400000
unkown
page readonly
3110000
heap
page read and write
422000
unkown
page write copy
3362000
heap
page read and write
3447000
heap
page read and write
37D9000
heap
page read and write
346E000
heap
page read and write
4E10000
heap
page read and write
4E5000
heap
page read and write
37E4000
heap
page read and write
3666000
heap
page read and write
3649000
heap
page read and write
2B7E000
stack
page read and write
5355000
heap
page read and write
66C000
heap
page read and write
27FD000
stack
page read and write
461F000
heap
page read and write
471F000
heap
page read and write
31CE000
heap
page read and write
33A4000
heap
page read and write
6AF000
heap
page read and write
401000
unkown
page execute read
3063000
heap
page read and write
4714000
heap
page read and write
2DB1000
heap
page read and write
472A000
heap
page read and write
34C3000
heap
page read and write
364C000
heap
page read and write
6B2000
heap
page read and write
31D6000
heap
page read and write
3655000
heap
page read and write
3696000
heap
page read and write
2C10000
remote allocation
page read and write
2EEE000
stack
page read and write
4135000
heap
page read and write
2A60000
heap
page read and write
3523000
heap
page read and write
65B000
heap
page read and write
3B10000
heap
page read and write
406A000
heap
page read and write
2C10000
remote allocation
page read and write
37C4000
heap
page read and write
4612000
heap
page read and write
6AD000
heap
page read and write
348D000
heap
page read and write
18C000
stack
page read and write
4075000
heap
page read and write
3173000
heap
page read and write
31C0000
heap
page read and write
384B000
heap
page read and write
6BC000
heap
page read and write
3A37000
heap
page read and write
3699000
heap
page read and write
3741000
heap
page read and write
3513000
heap
page read and write
345F000
heap
page read and write
36D9000
heap
page read and write
3380000
heap
page read and write
3332000
heap
page read and write
3630000
heap
page read and write
33A0000
heap
page read and write
3A31000
heap
page read and write
3685000
heap
page read and write
34BB000
heap
page read and write
31A3000
heap
page read and write
There are 247 hidden memdumps, click here to show them.