IOCReport

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\ZGNX11JMSc.exe
'C:\Users\user\Desktop\ZGNX11JMSc.exe'
malicious
C:\Users\user\Desktop\ZGNX11JMSc.exe
'C:\Users\user\Desktop\ZGNX11JMSc.exe'
malicious

URLs

Name
IP
Malicious
http://ceattire.com/bin_UYDMbHwI28.bin
185.211.56.131
malicious
www.yellow-wink.com/nff/
malicious
http://ceattire.com/
unknown
malicious
http://ceattire.com/bin_UYDMbHwI28.binI
unknown
clean
http://ceattire.com/bin_UYDMbHwI28.binK
unknown
clean
http://ceattire.com/o
unknown
clean

Domains

Name
IP
Malicious
ceattire.com
185.211.56.131
malicious
gentrypartyof8.com
66.235.200.146
malicious
www.gentrypartyof8.com
unknown
malicious
www.automotivevita.com
unknown
malicious
www.bloomandbrewcafe.com
unknown
malicious
www.stonalogov.com
unknown
malicious
www.dating-web.site
64.190.62.111
clean
137gate.com
31.44.185.28
clean

IPs

IP
Domain
Country
Malicious
185.211.56.131
ceattire.com
Iran (ISLAMIC Republic Of)
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
2240000
unkown
page execute and read and write
malicious
9C0000
unkown
page execute and read and write
malicious
60000
unkown
page execute and read and write
malicious
401000
unkown image
page execute read
malicious
401000
unkown image
page execute read
malicious
401000
unkown image
page execute read
malicious
25BDAB37000
unkown
page read and write
clean
BBEB7FA000
unkown
page read and write
clean
25BDAF1C000
unkown
page read and write
clean
2403E48B000
unkown
page read and write
clean
2403F790000
unkown
page read and write
clean
1D6EDF40000
unkown
page readonly
clean
1D4EFC10000
unkown
page read and write
clean
7FF53CBE2000
unkown
page readonly
clean
7FF51A606000
unkown
page readonly
clean
7FF539B9E000
unkown
page readonly
clean
1F532BA0000
unkown
page read and write
clean
1F87BB5B000
unkown
page read and write
clean
1D6ED1D0000
unkown
page read and write
clean
7FF55DD56000
unkown
page readonly
clean
1D4EFB20000
unkown
page readonly
clean
7FF54F9A3000
unkown
page readonly
clean
7FF5163BE000
unkown
page readonly
clean
E5D9E7E000
unkown
page read and write
clean
1F87B21F000
unkown
page read and write
clean
4DDBE7F000
unkown
page read and write
clean
7FF5DFACE000
unkown
page readonly
clean
1C64CBBD000
unkown
page read and write
clean
25BDA320000
unkown
page read and write
clean
7FF51A66C000
unkown
page readonly
clean
25BDAB42000
unkown
page read and write
clean
25BDAB33000
unkown
page read and write
clean
24043D50000
unkown
page read and write
clean
7FF5882F8000
unkown
page readonly
clean
25BDA3D6000
unkown
page read and write
clean
1F87BB83000
unkown
page read and write
clean
7FF560789000
unkown
page readonly
clean
25BDABA3000
unkown
page read and write
clean
232DB502000
unkown
page read and write
clean
7FF59404A000
unkown
page readonly
clean
7FF588041000
unkown
page readonly
clean
7FF539B1C000
unkown
page readonly
clean
25BDAB58000
unkown
page read and write
clean
25BDA2CA000
unkown
page read and write
clean
7FF588495000
unkown
page readonly
clean
25BDA3B2000
unkown
page read and write
clean
7FF5B7081000
unkown
page readonly
clean
7FF5B7008000
unkown
page readonly
clean
1C64CB49000
unkown
page read and write
clean
7FF595AB0000
unkown
page readonly
clean
25BDA3A9000
unkown
page read and write
clean
242D2080000
heap default
page read and write
clean
1E120000
unkown
page execute and read and write
clean
240439D0000
unkown
page read and write
clean
28300800000
unkown
page readonly
clean
7FF5CC6D5000
unkown
page readonly
clean
25BDAB02000
unkown
page read and write
clean
7FF551A31000
unkown
page readonly
clean