IOCReport

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\zeD11Fztx8.exe
'C:\Users\user\Desktop\zeD11Fztx8.exe'
malicious
C:\Users\user\Desktop\zeD11Fztx8.exe
C:\Users\user\Desktop\zeD11Fztx8.exe
malicious
C:\Windows\SysWOW64\storageservice.exe
C:\Windows\SysWOW64\storageservice.exe
malicious
C:\Windows\SysWOW64\storageservice.exe
C:\Windows\SysWOW64\storageservice.exe
malicious
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe -k netsvcs -p
clean
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe -k netsvcs -p
clean
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe -k netsvcs -p
clean

URLs

Name
IP
Malicious
http://173.230.145.224:8080/
unknown
malicious
http://173.230.145.224:8080/gP
unknown
malicious
http://173.230.145.224:8080/m
unknown
malicious
http://80.86.91.232:7080/
unknown
clean
http://80.86.91.232:7080/h
unknown
clean
http://80.86.91.232:7080/G
unknown
clean
https://79.172.249.82:443/
79.172.249.82
clean
http://193.169.54.12:8080/
unknown
clean
http://79.172.249.82:443/$
unknown
clean
http://80.86.91.232:7080/24
unknown
clean
http://80.86.91.232:7080/ed
unknown
clean
http://80.86.91.232:7080/7
unknown
clean
http://79.172.249.82:443/
unknown
clean
http://80.86.91.232:7080/9.54.12:8080/;
unknown
clean
http://193.169.54.12:8080//
unknown
clean
There are 5 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
193.169.54.12
unknown
Germany
clean
80.86.91.232
unknown
Germany
clean
173.230.145.224
unknown
United States
clean
79.172.249.82
unknown
Hungary
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
1381000
unkown image
page execute read
malicious
1381000
unkown image
page execute read
malicious
1381000
unkown image
page execute read
malicious
1381000
unkown image
page execute read
malicious
1381000
unkown image
page execute read
malicious
1381000
unkown image
page execute read
malicious
1381000
unkown image
page execute read
malicious
1381000
unkown image
page execute read
malicious
E74000
unkown
page read and write
clean
7FF59441A000
unkown
page readonly
clean
7FF532A90000
unkown
page readonly
clean
1A3F6880000
unkown
page readonly
clean
7FF59A7AE000
unkown
page readonly
clean
7FF5CDC16000
unkown
page readonly
clean
7FF58117F000
unkown
page readonly
clean
7FF4F7A9C000
unkown
page readonly
clean
7FF509E8A000
unkown
page readonly
clean
7FF509A02000
unkown
page readonly
clean
1C1EBF9B000
unkown
page read and write
clean
138D000
unkown image
page readonly
clean
7FF5A5A70000
unkown
page readonly
clean
1CB1000
unkown
page read and write
clean
1A3F4AF9000
unkown
page read and write
clean
1C1EBF9A000
unkown
page read and write
clean
7FF541DB4000
unkown
page readonly
clean
7FF57253B000
unkown
page readonly
clean
291EB310000
unkown
page write copy
clean
7FF5CDC11000
unkown
page readonly
clean
1A3F4AE4000
unkown
page read and write
clean
E74000
unkown
page read and write
clean
1C1EE072000
unkown
page read and write
clean
3B0F000
stack
page read and write
clean
7FF5A5AD8000
unkown
page readonly
clean
7FF4F7D72000
unkown
page readonly
clean
7FF5322F1000
unkown
page readonly
clean
1C1EBED8000
unkown
page read and write
clean
7FF4F7D82000
unkown
page readonly
clean
1C1EE0EC000
unkown
page read and write
clean
1C1EBE8C000
unkown
page read and write
clean
37D0000
unkown
page readonly
clean
1380000
unkown image
page readonly
clean
2A32E000000
heap default
page read and write
clean
7FF532971000
unkown
page readonly
clean
2197F400000
unkown
page read and write
clean