IOCReport

loading gif

Files

File Path
Type
Category
Malicious
Bewerbungsschreiben.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\Bewerbungsschreiben.exe.log
ASCII text, with CRLF line terminators
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Bewerbungsschreiben.exe
'C:\Users\user\Desktop\Bewerbungsschreiben.exe'
malicious
C:\Users\user\Desktop\Bewerbungsschreiben.exe
C:\Users\user\Desktop\Bewerbungsschreiben.exe
malicious
C:\Users\user\Desktop\Bewerbungsschreiben.exe
C:\Users\user\Desktop\Bewerbungsschreiben.exe
malicious
C:\Users\user\Desktop\Bewerbungsschreiben.exe
C:\Users\user\Desktop\Bewerbungsschreiben.exe
malicious
C:\Users\user\Desktop\Bewerbungsschreiben.exe
C:\Users\user\Desktop\Bewerbungsschreiben.exe
malicious
C:\Users\user\Desktop\Bewerbungsschreiben.exe
C:\Users\user\Desktop\Bewerbungsschreiben.exe
malicious

URLs

Name
IP
Malicious
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
clean
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
unknown
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
2EC1000
unkown
page read and write
malicious
12ED1000
unkown
page read and write
malicious
3C254FF000
unkown
page read and write
clean
7FFA35920000
unkown
page read and write
clean
1B840000
unkown
page read and write
clean
2DF0000
unkown
page readonly
clean
1BCA0000
unkown
page read and write
clean
14D0000
unkown
page readonly
clean
7FF542525000
unkown
page readonly
clean
C10000
unkown image
page readonly
clean
1B850000
unkown
page read and write
clean
1470000
unkown
page read and write
clean
1B850000
unkown
page read and write
clean
C10000
unkown image
page readonly
clean
11FE000
unkown
page read and write
clean
1B890000
heap private
page read and write
clean
1BE90000
unkown
page read and write
clean
1B840000
unkown
page read and write
clean
1B880000
unkown
page read and write
clean
7FF5420E6000
unkown
page readonly
clean
7FF5420F5000
unkown
page readonly
clean
12D7000
unkown
page read and write
clean
7FF54251A000
unkown
page readonly
clean
1BD70000
unkown
page read and write
clean
C12000
unkown image
page readonly
clean
1520000
unkown
page read and write
clean
1B840000
unkown
page read and write
clean
1BD20000
unkown
page read and write
clean
1BD50000
unkown
page read and write
clean
7FFA3595C000
unkown
page execute and read and write
clean
7FF542537000
unkown
page readonly
clean
1540000
heap private
page read and write
clean
7FFA35913000
unkown
page read and write
clean
1B840000
unkown
page read and write
clean
372000
unkown image
page readonly
clean
1B9B0000
unkown
page read and write
clean
D30000
unkown image
page readonly
clean
7FFA35903000
unkown
page execute and read and write
clean
1B820000
unkown
page read and write
clean
3C24FDE000
unkown
page read and write
clean
1BE40000
unkown
page read and write
clean
7FF542596000
unkown
page readonly
clean
7FF4D79D0000
unkown
page execute and read and write
clean
1B9F0000
unkown
page read and write
clean
7FF54241E000
unkown
page readonly
clean
1B820000
unkown
page read and write
clean
1530000
unkown
page read and write
clean
DB6000
unkown image
page readonly
clean
1B43C000
unkown
page read and write
clean
1B9D0000
unkown
page read and write
clean
1530000
unkown
page read and write
clean
CB0000
unkown
page readonly
clean
1BAA0000
unkown
page read and write
clean
7FFA359B0000
unkown
page read and write
clean
22B2BD40000
unkown
page readonly
clean
420000
unkown image
page readonly
clean
22B2BC70000
unkown
page readonly
clean
1BE0E000
unkown
page read and write
clean
1B880000
unkown
page read and write
clean
7FF54256A000
unkown
page readonly
clean
1430000
heap private
page read and write
clean
3C25375000
unkown
page read and write
clean
1B860000
unkown
page read and write
clean
3C24F5B000
unkown
page read and write
clean
7FF542297000
unkown
page readonly
clean
1B870000
heap private
page read and write
clean
1BDF0000
unkown
page read and write
clean
22B2BE3C000
unkown
page read and write
clean
12EC8000
unkown
page read and write
clean
22B2BE4D000
unkown
page read and write
clean
1B879000
heap private
page read and write
clean
1B9E0000
unkown
page read and write
clean
1B840000
unkown
page read and write
clean
1B9C0000
unkown
page read and write
clean
1B830000
unkown
page read and write
clean
1BF0F000
unkown
page read and write
clean
22B2C602000
unkown
page read and write
clean
1BD40000
unkown
page read and write
clean
7FFA35A20000
unkown
page read and write
clean
10E0000
unkown
page read and write
clean
1B840000
unkown
page read and write
clean
1B840000
unkown
page read and write
clean
422000
unkown image
page readonly
clean
FD6000
unkown image
page readonly
clean
7FFA35A30000
unkown
page execute and read and write
clean
123F000
heap default
page read and write
clean
22B2BE4E000
unkown
page read and write
clean
22B2BF02000
unkown
page read and write
clean
7FF542604000
unkown
page readonly
clean
420000
unkown image
page readonly
clean
22B2BC00000
heap private
page read and write
clean
D32000
unkown image
page readonly
clean
7FF541C30000
unkown
page readonly
clean
1BE50000
unkown
page read and write
clean
7FFA3592D000
unkown
page execute and read and write
clean
1BDC0000
unkown
page read and write
clean
370000
unkown image
page readonly
clean
1BE20000
unkown
page read and write
clean
3C255F7000
unkown
page read and write
clean
1B873000
heap private
page read and write
clean
1200000
heap default
page read and write
clean
7FF542611000
unkown
page readonly
clean
1B9E0000
unkown
page read and write
clean
312000
unkown image
page readonly
clean
1268000
heap default
page read and write
clean
1B840000
unkown
page read and write
clean
F50000
unkown image
page readonly
clean
1B840000
unkown
page read and write
clean
22B2BE6F000
unkown
page read and write
clean
2DEF000
unkown
page read and write
clean
7FF542574000
unkown
page readonly
clean
C96000
unkown image
page readonly
clean
1490000
unkown
page read and write
clean
310000
unkown image
page readonly
clean
370000
unkown image
page readonly
clean
1BAA1000
unkown
page read and write
clean
1BDB0000
unkown
page read and write
clean
14E0000
unkown
page read and write
clean
7FFA35AB0000
unkown
page read and write
clean
7FF54252B000
unkown
page readonly
clean
D30000
unkown image
page readonly
clean
22B2BE8A000
unkown
page read and write
clean
396000
unkown image
page readonly
clean
1B850000
unkown
page read and write
clean
1B893000
heap private
page read and write
clean
1B840000
unkown
page read and write
clean
7FF542612000
unkown
page readonly
clean
7FF54260A000
unkown
page readonly
clean
1B850000
unkown
page read and write
clean
7FFA3590D000
unkown
page execute and read and write
clean
D30000
unkown image
page readonly
clean
12DC000
unkown
page read and write
clean
1BD8D000
unkown
page read and write
clean
420000
unkown image
page readonly
clean
1010000
unkown
page readonly
clean
22B2BE29000
unkown
page read and write
clean
310000
unkown image
page readonly
clean
3C2527D000
unkown
page read and write
clean
14C0000
heap private
page execute and read and write
clean
1BEC0000
unkown
page read and write
clean
22B2BD50000
unkown
page readonly
clean
1B9B0000
unkown
page read and write
clean
120D000
heap default
page read and write
clean
1B850000
unkown
page read and write
clean
1B840000
unkown
page read and write
clean
123C000
heap default
page read and write
clean
1B9B0000
unkown
page read and write
clean
1B9A0000
unkown
page read and write
clean
7FF542484000
unkown
page readonly
clean
7FFA35904000
unkown
page read and write
clean
7FF54250C000
unkown
page readonly
clean
7FF54251E000
unkown
page readonly
clean
7FF54257F000
unkown
page readonly
clean
1B840000
unkown
page read and write
clean
1BA00000
heap private
page read and write
clean
7FFA359B6000
unkown
page read and write
clean
4A6000
unkown image
page readonly
clean
7FF54250A000
unkown
page readonly
clean
372000
unkown image
page readonly
clean
1B9A0000
unkown
page read and write
clean
DD5000
unkown
page read and write
clean
1B860000
unkown
page read and write
clean
1BD80000
unkown
page read and write
clean
1BE10000
unkown
page read and write
clean
1B840000
unkown
page read and write
clean
1BEA0000
unkown
page read and write
clean
3C2547B000
unkown
page read and write
clean
1B840000
unkown
page read and write
clean
22B2BF13000
unkown
page read and write
clean
7FF542564000
unkown
page readonly
clean
7FF54254F000
unkown
page readonly
clean
7FFA35A25000
unkown
page read and write
clean
22B2C000000
unkown
page readonly
clean
1B880000
unkown
page read and write
clean
1BDE0000
unkown
page read and write
clean
1BA10000
unkown
page read and write
clean
1B840000
unkown
page read and write
clean
1B780000
unkown
page readonly
clean
370000
unkown image
page readonly
clean
7FFA35A2B000
unkown
page read and write
clean
F52000
unkown image
page readonly
clean
22B2BF08000
unkown
page read and write
clean
1BDD0000
unkown
page read and write
clean
1400000
unkown
page read and write
clean
312000
unkown image
page readonly
clean
1BD30000
unkown
page read and write
clean
7FF54258E000
unkown
page readonly
clean
22B2C460000
unkown
page readonly
clean
396000
unkown image
page readonly
clean
7FF542401000
unkown
page readonly
clean
1BE60000
unkown
page read and write
clean
22B2BE13000
unkown
page read and write
clean
7FFA35910000
unkown
page read and write
clean
C96000
unkown image
page readonly
clean
7FFA3591D000
unkown
page execute and read and write
clean
1435000
heap private
page read and write
clean
7FFA359BC000
unkown
page execute and read and write
clean
7FFA359E6000
unkown
page execute and read and write
clean
14A4000
unkown
page read and write
clean
1BD90000
unkown
page read and write
clean
1B824000
unkown
page read and write
clean
1B821000
unkown
page read and write
clean
1550000
unkown
page readonly
clean
22B2BE00000
unkown
page read and write
clean
310000
unkown image
page readonly
clean
1BA90000
heap private
page execute and read and write
clean
1C00E000
unkown
page read and write
clean
7FFA359C0000
unkown
page execute and read and write
clean
1B840000
unkown
page read and write
clean
1B860000
unkown
page read and write
clean
22B2BF00000
unkown
page read and write
clean
12ECD000
unkown
page read and write
clean
1BEC5000
unkown
page read and write
clean
1440000
unkown
page read and write
clean
1B830000
unkown
page read and write
clean
F52000
unkown image
page readonly
clean
3F6000
unkown image
page readonly
clean
C10000
unkown image
page readonly
clean
1BEB0000
unkown
page read and write
clean
7FF54254C000
unkown
page readonly
clean
1AEF0000
unkown
page read and write
clean
7FF5420E0000
unkown
page readonly
clean
3C256FE000
unkown
page read and write
clean
12EC1000
unkown
page read and write
clean
1BBA0000
unkown
page read and write
clean
7FF5423C3000
unkown
page readonly
clean
1B880000
unkown
page read and write
clean
1B840000
unkown
page read and write
clean
3F6000
unkown image
page readonly
clean
DB6000
unkown image
page readonly
clean
22B2BE27000
unkown
page read and write
clean
1219000
heap default
page read and write
clean
1B9A0000
unkown
page read and write
clean
7FF542473000
unkown
page readonly
clean
1B820000
unkown
page read and write
clean
7FF542588000
unkown
page readonly
clean
22B2BE4A000
unkown
page read and write
clean
14F0000
unkown
page read and write
clean
1510000
unkown
page readonly
clean
1BE00000
unkown
page read and write
clean
1545000
heap private
page read and write
clean
1B850000
unkown
page read and write
clean
22B2C800000
unkown
page readonly
clean
22B2BE4B000
unkown
page read and write
clean
7FF54241B000
unkown
page readonly
clean
C12000
unkown image
page readonly
clean
7FFA35AC0000
unkown
page read and write
clean
D32000
unkown image
page readonly
clean
1BE30000
unkown
page read and write
clean
1520000
unkown
page read and write
clean
1BDA0000
unkown
page read and write
clean
2EB0000
heap private
page read and write
clean
422000
unkown image
page readonly
clean
7FF54246D000
unkown
page readonly
clean
14A0000
unkown
page read and write
clean
1BA80000
unkown
page read and write
clean
7FF54259D000
unkown
page readonly
clean
13FF000
unkown
page read and write
clean
3C257FF000
unkown
page read and write
clean
1B840000
unkown
page read and write
clean
1BD60000
unkown
page read and write
clean
7FF542557000
unkown
page readonly
clean
1B840000
unkown
page read and write
clean
F50000
unkown image
page readonly
clean
7FF54248C000
unkown
page readonly
clean
22B2BC60000
heap default
page read and write
clean
22B2BE02000
unkown
page read and write
clean
1BC62000
unkown
page read and write
clean
7FF542520000
unkown
page readonly
clean
4A6000
unkown image
page readonly
clean
1BD10000
unkown
page read and write
clean
FD6000
unkown image
page readonly
clean
1B9C0000
unkown
page read and write
clean
7FF542371000
unkown
page readonly
clean
1B860000
unkown
page read and write
clean
1BE70000
unkown
page read and write
clean
1B780000
unkown
page read and write
clean
F50000
unkown image
page readonly
clean
1B440000
unkown
page readonly
clean
1BE80000
unkown
page read and write
clean
7FF542599000
unkown
page readonly
clean
7FF541D81000
unkown
page readonly
clean
1B99D000
unkown
page read and write
clean
1B9D0000
unkown
page read and write
clean
22B2BD60000
unkown
page read and write
clean
There are 275 hidden memdumps, click here to show them.