IOCReport

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\DOCUMENTOS CORREOS.exe
'C:\Users\user\Desktop\DOCUMENTOS CORREOS.exe'
malicious
C:\Users\user\Desktop\DOCUMENTOS CORREOS.exe
'C:\Users\user\Desktop\DOCUMENTOS CORREOS.exe'
malicious

URLs

Name
IP
Malicious
https://www.mediafire.com
unknown
clean
https://www.mediafire.com/file/md0mc3zocq6uh6b/gbam_encrypted_65A39A0.bin/file
unknown
clean
https://static.cloudflareinsights.com/beacon.min.js
unknown
clean
https://www.mediafire.com/file/md0mc3zocq6uh6b/gbam_encrypted_65A39A0.bin/file
clean
https://www.mediafire.com/file/md0mc3zocq6uh6b/gbam_encrypted_65A39
unknown
clean
https://www.mediafire.com/images/logos/mf_logo250x250.png
unknown
clean

Domains

Name
IP
Malicious
www.mediafire.com
104.16.203.237
clean

IPs

IP
Domain
Country
Malicious
192.168.2.1
unknown
unknown
clean
104.16.203.237
www.mediafire.com
United States
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
620000
unkown
page execute and read and write
malicious
560000
unkown
page execute and read and write
malicious
560000
unkown
page execute and read and write
malicious
187E8700000
unkown
page read and write
clean
7FF546AA7000
unkown
page readonly
clean
16EE23A0000
unkown
page read and write
clean
17FA99F0000
heap default
page read and write
clean
1AA26C5F000
unkown
page read and write
clean
7FF5BAEAC000
unkown
page readonly
clean
46A2000
unkown
page readonly
clean
26E126A2000
unkown
page read and write
clean
187E8655000
unkown
page read and write
clean
17FA9C00000
unkown
page readonly
clean
18D8F710000
unkown
page readonly
clean
D602CFF000
unkown
page read and write
clean
7FF578B04000
unkown
page readonly
clean
1DA07D00000
unkown
page read and write
clean
28AFAD90000
unkown
page readonly
clean
7FF546C92000
unkown
page readonly
clean
7FF5884FE000
unkown
page readonly
clean
7FF54C734000
unkown
page readonly
clean
38E2000
unkown
page readonly
clean
7FF588486000
unkown
page readonly
clean
7FF5BF76A000
unkown
page readonly
clean
262FAF08000
unkown
page read and write
clean
7FF588248000
unkown
page readonly
clean
7FF5BF84C000
unkown
page readonly
clean
16EE2429000
unkown
page read and write
clean
262F8DC0000
heap private
page read and write
clean
252D7E000
unkown
page read and write
clean
7FF579E7C000
unkown
page readonly
clean
7FF56EE36000
unkown
page readonly
clean
7FF54C716000
unkown
page readonly
clean
64A000
heap default
page read and write
clean
7FF50746E000
unkown
page readonly
clean
112A57A0000
unkown
page read and write
clean
262F9013000
unkown
page read and write
clean
26E17B6E000
unkown
page read and write
clean
7FF5C71DC000
unkown
page readonly
clean
7FF546D81000
unkown
page readonly
clean
7FF54C5D7000
unkown
page readonly
clean
B5172FD000
unkown
page read and write
clean
7FF579F09000
unkown
page readonly
clean
26E12695000
unkown
page read and write
clean
7FF56EE6F000
unkown
page readonly
clean
1EFB0000
unkown
page readonly
clean
4300000
unkown
page readonly
clean
7FF56EF29000
unkown
page readonly
clean
18D8FB0F000
heap private
page read and write
clean
1DA07C13000
unkown
page read and write
clean
19167C13000
unkown
page read and write
clean
7FF546906000
unkown
page readonly
clean
7FF5DE46A000
unkown
page readonly
clean
7FF4F94A2000
unkown
page readonly
clean
1C8EAE69000
unkown
page read and write
clean
7FF5BAEFF000
unkown
page readonly
clean
7FF5BAD8F000
unkown
page readonly
clean
3E56000
unkown
page readonly
clean
52000FF000
unkown
page read and write
clean
83F000
unkown
page read and write
clean
7FF5C7290000
unkown
page readonly
clean