Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
http://www.mijn-authenticatiebetaalpas.xyz
|
URL
|
initial url
|
||
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{53688A37-77AC-11EB-90EB-ECF4BBEA1588}.dat
|
Microsoft Word Document
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{53688A39-77AC-11EB-90EB-ECF4BBEA1588}.dat
|
Microsoft Word Document
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{53688A3A-77AC-11EB-90EB-ECF4BBEA1588}.dat
|
Microsoft Word Document
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\dnserror[1]
|
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
|
downloaded
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\down[1]
|
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
|
downloaded
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\errorPageStrings[1]
|
UTF-8 Unicode (with BOM) text, with CRLF line terminators
|
downloaded
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\httpErrorPagesScripts[1]
|
UTF-8 Unicode (with BOM) text, with CRLF line terminators
|
downloaded
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\NewErrorPageTemplate[1]
|
UTF-8 Unicode (with BOM) text, with CRLF line terminators
|
downloaded
|
||
C:\Users\user\AppData\Local\Temp\~DF1347B0B958333FB5.TMP
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\~DF654EA8BDB7E65203.TMP
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\~DFBA8EE7F2C08F87E8.TMP
|
data
|
dropped
|
There are 2 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\internet explorer\iexplore.exe
|
'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
|
||
C:\Program Files (x86)\Internet Explorer\iexplore.exe
|
'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:6824 CREDAT:17410 /prefetch:2
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://www.mijn-authenticatiebetaalpas.xyz/Root
|
unknown
|
||
http://www.mijn-authenticatiebetaalpas.xyz/
|
unknown
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
www.mijn-authenticatiebetaalpas.xyz
|
unknown
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
C:\Program Files\internet explorer\iexplore.exe
|
{53688A37-77AC-11EB-90EB-ECF4BBEA1588}
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Count
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Time
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Blocked
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Count
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Time
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Count
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Time
|
||
C:\Program Files\internet explorer\iexplore.exe
|
LoadTimeArray
|
||
C:\Program Files\internet explorer\iexplore.exe
|
LoadTimeArray
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Count
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Time
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Blocked
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Count
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Time
|
||
C:\Program Files\internet explorer\iexplore.exe
|
LoadTimeArray
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Count
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Time
|
||
C:\Program Files\internet explorer\iexplore.exe
|
LoadTimeArray
|
There are 9 hidden registries, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
22000429000
|
unkown
|
page read and write
|
||
2200044C000
|
unkown
|
page read and write
|
||
7FF550B85000
|
unkown
|
page readonly
|
||
22000500000
|
unkown
|
page read and write
|
||
22000447000
|
unkown
|
page read and write
|
||
7FF550B97000
|
unkown
|
page readonly
|
||
22000B40000
|
unkown
|
page read and write
|
||
57FFD7F000
|
unkown
|
page read and write
|
||
22000E00000
|
unkown
|
page readonly
|
||
7FF550BEE000
|
unkown
|
page readonly
|
||
57800F7000
|
unkown
|
page read and write
|
||
7FF550B6C000
|
unkown
|
page readonly
|
||
7FF5503B1000
|
unkown
|
page readonly
|
||
22000426000
|
unkown
|
page read and write
|
||
7FF550B7E000
|
unkown
|
page readonly
|
||
22000413000
|
unkown
|
page read and write
|
||
22000400000
|
unkown
|
page read and write
|
||
7FF550A61000
|
unkown
|
page readonly
|
||
7FF550BF9000
|
unkown
|
page readonly
|
||
7FF550248000
|
unkown
|
page readonly
|
||
7FF550B8B000
|
unkown
|
page readonly
|
||
7FF550AE4000
|
unkown
|
page readonly
|
||
57803FE000
|
unkown
|
page read and write
|
||
7FF5509D1000
|
unkown
|
page readonly
|
||
7FF550A7E000
|
unkown
|
page readonly
|
||
22000451000
|
unkown
|
page read and write
|
||
22000508000
|
unkown
|
page read and write
|
||
7FF550BD4000
|
unkown
|
page readonly
|
||
22000502000
|
unkown
|
page read and write
|
||
22000513000
|
unkown
|
page read and write
|
||
22001140000
|
unkown
|
page readonly
|
||
2200047F000
|
unkown
|
page read and write
|
||
22000B30000
|
unkown
|
page readonly
|
||
22000470000
|
unkown
|
page read and write
|
||
7FF550B6A000
|
unkown
|
page readonly
|
||
7FF550A7B000
|
unkown
|
page readonly
|
||
7FF550BCA000
|
unkown
|
page readonly
|
||
7FF550C72000
|
unkown
|
page readonly
|
||
2200048A000
|
unkown
|
page read and write
|
||
7FF550BF6000
|
unkown
|
page readonly
|
||
2200043C000
|
unkown
|
page read and write
|
||
7FF550ACD000
|
unkown
|
page readonly
|
||
7FF550B80000
|
unkown
|
page readonly
|
||
2200044B000
|
unkown
|
page read and write
|
||
22000402000
|
unkown
|
page read and write
|
||
7FF550BAC000
|
unkown
|
page readonly
|
||
7FF550BB7000
|
unkown
|
page readonly
|
||
7FF550C6A000
|
unkown
|
page readonly
|
||
220006D0000
|
unkown
|
page readonly
|
||
7FF550AEC000
|
unkown
|
page readonly
|
||
7FF550C64000
|
unkown
|
page readonly
|
||
2200044E000
|
unkown
|
page read and write
|
||
7FF550AD3000
|
unkown
|
page readonly
|
||
22000380000
|
heap private
|
page read and write
|
||
2200044A000
|
unkown
|
page read and write
|
||
7FF550BC4000
|
unkown
|
page readonly
|
||
57FFF7B000
|
unkown
|
page read and write
|
||
7FF550BDF000
|
unkown
|
page readonly
|
||
57FFCFF000
|
unkown
|
page read and write
|
||
7FF550BE8000
|
unkown
|
page readonly
|
||
220003F0000
|
unkown
|
page readonly
|
||
220003E0000
|
heap default
|
page read and write
|
||
57801FD000
|
unkown
|
page read and write
|
||
7FF550C71000
|
unkown
|
page readonly
|
||
7FF550740000
|
unkown
|
page readonly
|
||
57FFC7B000
|
unkown
|
page read and write
|
||
7FF550755000
|
unkown
|
page readonly
|
||
57802FE000
|
unkown
|
page read and write
|
||
22000448000
|
unkown
|
page read and write
|
||
7FF550BFD000
|
unkown
|
page readonly
|
||
7FF550B7A000
|
unkown
|
page readonly
|
||
7FF550A23000
|
unkown
|
page readonly
|
||
2200047A000
|
unkown
|
page read and write
|
||
22000600000
|
unkown
|
page readonly
|
||
7FF5508F7000
|
unkown
|
page readonly
|
||
7FF550BAF000
|
unkown
|
page readonly
|
||
22000C02000
|
unkown
|
page read and write
|
||
2200044F000
|
unkown
|
page read and write
|
||
7FF550746000
|
unkown
|
page readonly
|
There are 69 hidden memdumps, click here to show them.