IOCReport

loading gif

Files

File Path
Type
Category
Malicious
SWIFT COPY.pdf.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v2.0_32\UsageLogs\SWIFT COPY.pdf.exe.log
ASCII text, with CRLF line terminators
modified
malicious
C:\Users\user\AppData\Local\Temp\tmp15D1.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\bSlxGzdE.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Roaming\bSlxGzdE.exe:Zone.Identifier
ASCII text, with CRLF line terminators
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SWIFT COPY.pdf.exe
'C:\Users\user\Desktop\SWIFT COPY.pdf.exe'
malicious
C:\Windows\SysWOW64\schtasks.exe
'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\bSlxGzdE' /XML 'C:\Users\user\AppData\Local\Temp\tmp15D1.tmp'
malicious
C:\Users\user\Desktop\SWIFT COPY.pdf.exe
C:\Users\user\Desktop\SWIFT COPY.pdf.exe
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
clean

URLs

Name
IP
Malicious
http://127.0.0.1:HTTP/1.1
unknown
clean
https://api.ipify.org%GETMozilla/5.0
unknown
clean
http://DynDns.comDynDNS
unknown
clean
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
unknown
clean
http://hcVzVgyZjXO8egOI.net
unknown
clean
https://api.ipify.org%
unknown
clean
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
unknown
clean
https://stackpath.bootstrapcdn.com/bootstrap/4.5.0/css/bootstrap.min.css
unknown
clean
http://hsfZEB.com
unknown
clean

Domains

Name
IP
Malicious
mail.esquiresweaters.com
192.185.171.219
malicious

IPs

IP
Domain
Country
Malicious
192.185.171.219
mail.esquiresweaters.com
United States
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
402000
unkown image
page execute and read and write
malicious
28EB000
unkown
page read and write
malicious
402000
unkown
page execute and read and write
malicious
2BC1000
unkown
page read and write
malicious
38C1000
unkown
page read and write
malicious
A70000
unkown
page readonly
clean
8B0000
unkown
page readonly
clean
4A5000
unkown
page read and write
clean
5E5E000
unkown
page read and write
clean
556000
unkown
page read and write
clean
A10000
unkown
page read and write
clean
2440000
unkown
page read and write
clean
562E000
unkown
page read and write
clean
A474000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
968000
unkown
page read and write
clean
725000
heap default
page read and write
clean
A77000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
120000
unkown image
page readonly
clean
5910000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
AD7000
unkown
page read and write
clean
1CA000
unkown image
page readonly
clean
B22000
unkown
page execute and read and write
clean
A40000
unkown
page read and write
clean
241E000
unkown
page read and write
clean
A20000
unkown
page read and write
clean
AB0000
unkown
page read and write
clean
2398000
unkown
page read and write
clean
5600000
unkown
page read and write
clean
A70000
unkown
page read and write
clean
AF0000
unkown
page execute and read and write
clean
C37000
unkown
page read and write
clean
9EA000
unkown
page execute and read and write
clean
A90000
unkown
page read and write
clean
5690000
unkown
page readonly
clean
7430000
unkown
page read and write
clean
5A0F000
unkown
page read and write
clean
5920000
unkown
page execute and read and write
clean
529E000
unkown
page read and write
clean
49EB000
unkown
page readonly
clean
490000
heap private
page read and write
clean
AF0000
unkown
page read and write
clean
4A2000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
2610000
unkown
page readonly
clean
5A70000
unkown
page read and write
clean
5360000
unkown
page readonly
clean
54E0000
unkown
page execute and read and write
clean
AE0000
unkown
page read and write
clean
968000
unkown
page read and write
clean
A490000
unkown
page read and write
clean
644000
unkown
page read and write
clean
A80000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
2690000
heap private
page execute and read and write
clean
4A5000
unkown
page read and write
clean
4D80000
unkown
page read and write
clean
567D000
unkown
page read and write
clean
A19000
unkown
page read and write
clean
A00000
unkown
page read and write
clean
984000
heap default
page read and write
clean
4C0000
unkown
page read and write
clean
5600000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
730000
unkown
page readonly
clean
A00000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
4C20000
heap private
page read and write
clean
552D000
unkown
page read and write
clean
256E000
unkown
page read and write
clean
7430000
unkown
page read and write
clean
B16000
unkown
page execute and read and write
clean
E70000
unkown
page readonly
clean
5BDD000
unkown
page read and write
clean
A02000
unkown
page read and write
clean
5F9E000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
C12000
heap default
page read and write
clean
E60000
heap private
page read and write
clean
96F000
unkown
page read and write
clean
AD5000
unkown
page read and write
clean
3E9000
unkown
page read and write
clean
2440000
unkown
page read and write
clean
596D000
unkown
page read and write
clean
96E000
unkown
page read and write
clean
3A96000
unkown
page read and write
clean
3E0000
unkown
page read and write
clean
3FE000
unkown
page read and write
clean
96F000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
2959000
unkown
page read and write
clean
4ACC000
unkown
page read and write
clean
ADA000
unkown
page read and write
clean
5C0000
unkown
page readonly
clean
7430000
unkown
page read and write
clean
BA0000
unkown
page read and write
clean
7F2000
unkown
page read and write
clean
2870000
heap private
page read and write
clean
AD0000
unkown
page read and write
clean
5640000
unkown
page readonly
clean
CB1000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
5D5E000
unkown
page read and write
clean
2580000
unkown
page readonly
clean
51FE000
unkown
page read and write
clean
9D0000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
23DE000
unkown
page read and write
clean
49C0000
unkown
page readonly
clean
85E000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
5760000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
71E000
unkown
page read and write
clean
49C7000
unkown
page readonly
clean
3BE7000
unkown
page read and write
clean
A9C000
unkown
page read and write
clean
A70000
unkown
page read and write
clean
A40000
unkown
page read and write
clean
648000
unkown
page read and write
clean
3EC000
unkown
page read and write
clean
7C0000
unkown
page read and write
clean
AB0000
unkown
page read and write
clean
2460000
heap private
page read and write
clean
73E0000
unkown
page read and write
clean
4D81000
unkown
page read and write
clean
4A5000
unkown
page read and write
clean
A90000
unkown
page read and write
clean
50BE000
unkown
page read and write
clean
5A20000
unkown
page read and write
clean
95E000
heap default
page read and write
clean
C2A000
unkown
page read and write
clean
B32000
unkown
page read and write
clean
A40000
unkown
page read and write
clean
96F000
unkown
page read and write
clean
A70000
unkown
page read and write
clean
27A8000
unkown
page read and write
clean
96F000
unkown
page read and write
clean
966000
unkown
page read and write
clean
4A10000
unkown
page readonly
clean
4A5000
unkown
page read and write
clean
4CBD000
unkown
page read and write
clean
5070000
unkown
page read and write
clean
AD2000
unkown
page read and write
clean
B3B000
unkown
page execute and read and write
clean
96F000
unkown
page read and write
clean
4A5000
unkown
page read and write
clean
4A80000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
5900000
unkown
page read and write
clean
7C2000
unkown
page execute and read and write
clean
4D31000
unkown
page read and write
clean
3BD2000
unkown
page read and write
clean
2440000
unkown
page readonly
clean
3BC1000
unkown
page read and write
clean
E40000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
4A2000
unkown
page read and write
clean
96E000
unkown
page read and write
clean
5A6D000
unkown
page read and write
clean
A00000
unkown
page read and write
clean
A3E000
unkown
page read and write
clean
A70000
unkown
page read and write
clean
A10000
unkown
page read and write
clean
1CA000
unkown image
page readonly
clean
49BD000
unkown
page read and write
clean
95E000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
7BA000
unkown
page execute and read and write
clean
2390000
unkown
page read and write
clean
3F2000
unkown
page read and write
clean
7440000
unkown
page read and write
clean
4A5000
unkown
page read and write
clean
7FBD0000
unkown
page execute and read and write
clean
B02000
unkown
page execute and read and write
clean
96F000
unkown
page read and write
clean
BEE000
unkown
page read and write
clean
5740000
unkown
page readonly
clean
4A2000
unkown
page read and write
clean
4A5000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
7430000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
B50000
heap private
page read and write
clean
5C1E000
unkown
page read and write
clean
5070000
unkown
page read and write
clean
C5B000
heap default
page read and write
clean
AD0000
unkown
page read and write
clean
4F9B000
unkown
page readonly
clean
4FC0000
unkown
page read and write
clean
590E000
unkown
page read and write
clean
966000
heap default
page read and write
clean
968000
unkown
page read and write
clean
7EA000
unkown
page execute and read and write
clean
4E40000
unkown
page read and write
clean
4F7C000
unkown
page readonly
clean
5A20000
unkown
page read and write
clean
957000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
8D0000
unkown
page read and write
clean
CC5000
unkown
page read and write
clean
9F0000
heap default
page read and write
clean
5B0000
unkown
page read and write
clean
96E000
unkown
page read and write
clean
4A5000
unkown
page read and write
clean
7CC000
unkown
page execute and read and write
clean
4A0000
unkown
page read and write
clean
A10000
unkown
page read and write
clean
A50000
unkown
page read and write
clean
54EF000
unkown
page read and write
clean
92C000
heap default
page read and write
clean
3F5000
unkown
page read and write
clean
A80000
unkown
page read and write
clean
4A5000
unkown
page read and write
clean
B2A000
unkown
page execute and read and write
clean
4A0000
unkown
page read and write
clean
7430000
unkown
page read and write
clean
5AD000
unkown
page read and write
clean
2430000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
B37000
unkown
page execute and read and write
clean
4A70000
heap private
page read and write
clean
2390000
unkown
page read and write
clean
4A5000
unkown
page read and write
clean
5A10000
unkown
page read and write
clean
4F70000
unkown
page readonly
clean
515E000
unkown
page read and write
clean
4F30000
unkown
page read and write
clean
2390000
unkown
page read and write
clean
8E0000
unkown
page execute and read and write
clean
120000
unkown image
page readonly
clean
C38000
unkown
page read and write
clean
AD3000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
750000
unkown
page read and write
clean
54F0000
unkown
page execute and read and write
clean
AD0000
unkown
page read and write
clean
5C0000
unkown
page readonly
clean
49CC000
unkown
page readonly
clean
A470000
unkown
page read and write
clean
AD2000
unkown
page read and write
clean
58DC000
unkown
page read and write
clean
53CE000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
96C000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
5D0000
unkown
page readonly
clean
B9E000
unkown
page read and write
clean
54D0000
unkown
page execute and read and write
clean
96F000
unkown
page read and write
clean
740000
unkown
page readonly
clean
45B000
unkown
page read and write
clean
AF0000
unkown
page read and write
clean
8C0000
unkown
page readonly
clean
C49000
heap default
page read and write
clean
5060000
unkown
page read and write
clean
58CD000
unkown
page read and write
clean
539E000
unkown
page read and write
clean
7430000
unkown
page read and write
clean
DDE000
unkown
page read and write
clean
28C1000
unkown
page read and write
clean
A40000
unkown
page read and write
clean
7FA80000
unkown
page execute and read and write
clean
C29000
unkown
page read and write
clean
56A0000
unkown
page readonly
clean
2CF5000
unkown
page read and write
clean
5A10000
unkown
page execute and read and write
clean
58F0000
unkown
page read and write
clean
AD2000
unkown
page read and write
clean
4D30000
unkown
page read and write
clean
3DC000
unkown
page read and write
clean
AC0000
unkown
page read and write
clean
E30000
unkown
page readonly
clean
96F000
unkown
page read and write
clean
2390000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
7B2000
unkown
page execute and read and write
clean
5060000
unkown
page read and write
clean
2CC1000
unkown
page read and write
clean
4BD0000
unkown
page read and write
clean
4AE000
unkown
page read and write
clean
BD0000
heap private
page read and write
clean
790000
heap private
page read and write
clean
2880000
unkown
page readonly
clean
53ED000
unkown
page read and write
clean
4C10000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
7440000
unkown
page read and write
clean
4D4F000
unkown
page read and write
clean
7F7000
unkown
page execute and read and write
clean
A60000
unkown
page read and write
clean
968000
unkown
page read and write
clean
A30000
unkown
page read and write
clean
A80000
unkown
page read and write
clean
4A0000
unkown
page readonly
clean
5E0000
unkown
page read and write
clean
A50000
unkown
page read and write
clean
7450000
unkown
page read and write
clean
A50000
unkown
page read and write
clean
A60000
unkown
page readonly
clean
400000
unkown image
page readonly
clean
4D4F000
unkown
page read and write
clean
2430000
unkown
page readonly
clean
727000
unkown
page read and write
clean
2640000
unkown
page readonly
clean
A20000
unkown
page read and write
clean
122000
unkown image
page readonly
clean
C9E000
unkown
page read and write
clean
A10000
unkown
page read and write
clean
96F000
unkown
page read and write
clean
57CE000
unkown
page read and write
clean
5610000
unkown
page read and write
clean
B12000
unkown
page read and write
clean
89C000
unkown
page read and write
clean
5A21000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
2390000
unkown
page read and write
clean
9E2000
unkown
page execute and read and write
clean
7A0000
unkown
page read and write
clean
8F9000
unkown
page read and write
clean
2632000
unkown
page read and write
clean
A80000
unkown
page read and write
clean
A480000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
2630000
unkown
page read and write
clean
B10000
unkown
page read and write
clean
A00000
unkown
page read and write
clean
6DE000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
4D33000
unkown
page read and write
clean
CC8000
unkown
page read and write
clean
A70000
unkown
page read and write
clean
96F000
unkown
page read and write
clean
2D41000
unkown
page read and write
clean
5600000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
2390000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
23A0000
unkown
page read and write
clean
B2C000
unkown
page execute and read and write
clean
54CD000
unkown
page read and write
clean
5CAF000
unkown
page read and write
clean
A16000
unkown
page read and write
clean
7447000
unkown
page read and write
clean
BC0000
unkown
page read and write
clean
A30000
unkown
page read and write
clean
E1E000
unkown
page read and write
clean
2CEF000
unkown
page read and write
clean
5600000
unkown
page read and write
clean
96C000
unkown
page read and write
clean
2390000
unkown
page read and write
clean
122000
unkown image
page readonly
clean
BE0000
heap default
page read and write
clean
3FB000
unkown
page read and write
clean
4A0000
unkown
page read and write
clean
7430000
unkown
page read and write
clean
7DA000
unkown
page execute and read and write
clean
A50000
unkown
page read and write
clean
720000
heap default
page read and write
clean
400000
unkown image
page execute and read and write
clean
4A0000
unkown
page read and write
clean
120000
unkown image
page readonly
clean
4AA000
unkown image
page readonly
clean
3C36000
unkown
page read and write
clean
4E80000
unkown
page readonly
clean
968000
unkown
page read and write
clean
279E000
unkown
page read and write
clean
BEA000
heap default
page read and write
clean
5ADE000
unkown
page read and write
clean
8F0000
heap default
page read and write
clean
A70000
unkown
page read and write
clean
400000
unkown
page execute and read and write
clean
5630000
unkown
page readonly
clean
BF0000
unkown
page readonly
clean
A86000
unkown
page read and write
clean
3A68000
unkown
page read and write
clean
5BAE000
unkown
page read and write
clean
3EF000
unkown
page read and write
clean
2390000
unkown
page read and write
clean
A30000
unkown
page read and write
clean
2CBD000
unkown
page read and write
clean
AE0000
unkown
page read and write
clean
AA0000
unkown
page read and write
clean
B20000
unkown
page read and write
clean
50FE000
unkown
page read and write
clean
96E000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
C39000
unkown
page read and write
clean
4C30000
unkown
page read and write
clean
577E000
unkown
page read and write
clean
2431000
unkown
page read and write
clean
810000
heap private
page read and write
clean
AD0000
unkown
page read and write
clean
5600000
unkown
page read and write
clean
5E9E000
unkown
page read and write
clean
E67000
heap private
page read and write
clean
A53000
unkown
page read and write
clean
8F6000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
A50000
unkown
page read and write
clean
A1E000
unkown
page read and write
clean
AD2000
unkown
page read and write
clean
5061000
unkown
page read and write
clean
AA0000
unkown
page read and write
clean
5600000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
7D7000
unkown
page execute and read and write
clean
4A0000
unkown
page read and write
clean
2390000
unkown
page execute and read and write
clean
523E000
unkown
page read and write
clean
A20000
unkown
page read and write
clean
3F8000
unkown
page read and write
clean
533F000
unkown
page read and write
clean
968000
unkown
page read and write
clean
8A0000
unkown
page read and write
clean
1200000
unkown
page readonly
clean
4C0000
unkown
page readonly
clean
AD0000
unkown
page read and write
clean
525E000
unkown
page read and write
clean
4F77000
unkown
page readonly
clean
A70000
unkown
page read and write
clean
5370000
unkown
page execute and read and write
clean
5A71000
unkown
page read and write
clean
CC8000
unkown
page read and write
clean
A60000
unkown
page read and write
clean
7FB000
unkown
page execute and read and write
clean
5F0000
unkown
page read and write
clean
2630000
unkown
page read and write
clean
A460000
unkown
page read and write
clean
57DE000
unkown
page read and write
clean
900000
unkown
page readonly
clean
CC8000
heap default
page read and write
clean
7E2000
unkown
page execute and read and write
clean
402000
unkown image
page readonly
clean
268E000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
4A5000
unkown
page read and write
clean
A00000
unkown
page read and write
clean
E20000
unkown
page readonly
clean
9F5000
heap default
page read and write
clean
4D4E000
unkown
page read and write
clean
5D1D000
unkown
page read and write
clean
4C0000
unkown
page read and write
clean
4CC0000
unkown
page readonly
clean
4BCD000
unkown
page read and write
clean
5050000
unkown
page execute and read and write
clean
2390000
unkown
page read and write
clean
C79000
unkown
page read and write
clean
C99000
unkown
page read and write
clean
5630000
unkown
page readonly
clean
B1A000
unkown
page execute and read and write
clean
2570000
heap private
page execute and read and write
clean
E50000
unkown
page execute and read and write
clean
5600000
unkown
page read and write
clean
96A000
unkown
page read and write
clean
A70000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
AEF000
unkown
page read and write
clean
4A5000
unkown
page read and write
clean
690000
unkown
page read and write
clean
AD0000
unkown
page read and write
clean
53B000
unkown
page read and write
clean
There are 462 hidden memdumps, click here to show them.