IOCReport

loading gif

Files

File Path
Type
Category
Malicious
http://www.mijn-authenticatiebetaalpas.xyz
URL
initial url
malicious
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{53688A37-77AC-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{53688A39-77AC-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{53688A3A-77AC-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\dnserror[1]
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\down[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\NewErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Temp\~DF1347B0B958333FB5.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF654EA8BDB7E65203.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFBA8EE7F2C08F87E8.TMP
data
dropped
clean
There are 2 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\internet explorer\iexplore.exe
'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:6824 CREDAT:17410 /prefetch:2
clean

URLs

Name
IP
Malicious
http://www.mijn-authenticatiebetaalpas.xyz/Root
unknown
malicious
http://www.mijn-authenticatiebetaalpas.xyz/
unknown
malicious

Domains

Name
IP
Malicious
www.mijn-authenticatiebetaalpas.xyz
unknown
malicious

Registry

Path
Value
Malicious
C:\Program Files\internet explorer\iexplore.exe
{53688A37-77AC-11EB-90EB-ECF4BBEA1588}
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Blocked
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Blocked
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
There are 9 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
22000429000
unkown
page read and write
clean
2200044C000
unkown
page read and write
clean
7FF550B85000
unkown
page readonly
clean
22000500000
unkown
page read and write
clean
22000447000
unkown
page read and write
clean
7FF550B97000
unkown
page readonly
clean
22000B40000
unkown
page read and write
clean
57FFD7F000
unkown
page read and write
clean
22000E00000
unkown
page readonly
clean
7FF550BEE000
unkown
page readonly
clean
57800F7000
unkown
page read and write
clean
7FF550B6C000
unkown
page readonly
clean
7FF5503B1000
unkown
page readonly
clean
22000426000
unkown
page read and write
clean
7FF550B7E000
unkown
page readonly
clean
22000413000
unkown
page read and write
clean
22000400000
unkown
page read and write
clean
7FF550A61000
unkown
page readonly
clean
7FF550BF9000
unkown
page readonly
clean
7FF550248000
unkown
page readonly
clean
7FF550B8B000
unkown
page readonly
clean
7FF550AE4000
unkown
page readonly
clean
57803FE000
unkown
page read and write
clean
7FF5509D1000
unkown
page readonly
clean
7FF550A7E000
unkown
page readonly
clean
22000451000
unkown
page read and write
clean
22000508000
unkown
page read and write
clean
7FF550BD4000
unkown
page readonly
clean
22000502000
unkown
page read and write
clean
22000513000
unkown
page read and write
clean
22001140000
unkown
page readonly
clean
2200047F000
unkown
page read and write
clean
22000B30000
unkown
page readonly
clean
22000470000
unkown
page read and write
clean
7FF550B6A000
unkown
page readonly
clean
7FF550A7B000
unkown
page readonly
clean
7FF550BCA000
unkown
page readonly
clean
7FF550C72000
unkown
page readonly
clean
2200048A000
unkown
page read and write
clean
7FF550BF6000
unkown
page readonly
clean
2200043C000
unkown
page read and write
clean
7FF550ACD000
unkown
page readonly
clean
7FF550B80000
unkown
page readonly
clean
2200044B000
unkown
page read and write
clean
22000402000
unkown
page read and write
clean
7FF550BAC000
unkown
page readonly
clean
7FF550BB7000
unkown
page readonly
clean
7FF550C6A000
unkown
page readonly
clean
220006D0000
unkown
page readonly
clean
7FF550AEC000
unkown
page readonly
clean
7FF550C64000
unkown
page readonly
clean
2200044E000
unkown
page read and write
clean
7FF550AD3000
unkown
page readonly
clean
22000380000
heap private
page read and write
clean
2200044A000
unkown
page read and write
clean
7FF550BC4000
unkown
page readonly
clean
57FFF7B000
unkown
page read and write
clean
7FF550BDF000
unkown
page readonly
clean
57FFCFF000
unkown
page read and write
clean
7FF550BE8000
unkown
page readonly
clean
220003F0000
unkown
page readonly
clean
220003E0000
heap default
page read and write
clean
57801FD000
unkown
page read and write
clean
7FF550C71000
unkown
page readonly
clean
7FF550740000
unkown
page readonly
clean
57FFC7B000
unkown
page read and write
clean
7FF550755000
unkown
page readonly
clean
57802FE000
unkown
page read and write
clean
22000448000
unkown
page read and write
clean
7FF550BFD000
unkown
page readonly
clean
7FF550B7A000
unkown
page readonly
clean
7FF550A23000
unkown
page readonly
clean
2200047A000
unkown
page read and write
clean
22000600000
unkown
page readonly
clean
7FF5508F7000
unkown
page readonly
clean
7FF550BAF000
unkown
page readonly
clean
22000C02000
unkown
page read and write
clean
2200044F000
unkown
page read and write
clean
7FF550746000
unkown
page readonly
clean
There are 69 hidden memdumps, click here to show them.