IOCReport

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SOCAR Petroleum S.A Romania ordin urgent nr. 21199.exe
'C:\Users\user\Desktop\SOCAR Petroleum S.A Romania ordin urgent nr. 21199.exe'
malicious

URLs

Name
IP
Malicious
https://andreameixueiro.com/karin_entmCGmZw1b;z
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
401000
unkown image
page execute read
malicious
401000
unkown image
page execute read
malicious
7FF56B6A7000
unkown
page readonly
clean
4A1000
heap default
page read and write
clean
7FF56BBFE000
unkown
page readonly
clean
2082E165000
unkown
page read and write
clean
2082D8C1000
unkown
page read and write
clean
AD083AF000
unkown
page read and write
clean
7FF56BD05000
unkown
page readonly
clean
7FF56BD5F000
unkown
page readonly
clean
7FF57A727000
unkown
page readonly
clean
7FF56B91C000
unkown
page readonly
clean
2290000
heap private
page read and write
clean
2082D83C000
unkown
page read and write
clean
2082DF00000
unkown
page readonly
clean
2082E602000
unkown
page read and write
clean
1D9097A0000
unkown
page readonly
clean
7FF4FF6AB000
unkown
page readonly
clean
2082D908000
unkown
page read and write
clean
2082E166000
unkown
page read and write
clean
7FF4FF5B0000
unkown
page readonly
clean
2082D700000
unkown
page readonly
clean
7FF4FF65A000
unkown
page readonly
clean
7FF56BA14000
unkown
page readonly
clean
7FF4FF752000
unkown
page readonly
clean
2354000
heap private
page read and write
clean
98000
unkown
page read and write
clean
7FF56B947000
unkown
page readonly
clean
2082E173000
unkown
page read and write
clean
7FF56B93B000
unkown
page readonly
clean
2082E1AB000
unkown
page read and write
clean
2082E160000
unkown
page read and write
clean
BEF2F7A000
unkown
page read and write
clean
7FF56BBFB000
unkown
page readonly
clean
2082E15D000
unkown
page read and write
clean
7FF4FF103000
unkown
page readonly
clean
9E0000
unkown
page readonly
clean
16420613000
unkown
page read and write
clean
BEF2CFF000
unkown
page read and write
clean
7FF4FF312000
unkown
page readonly
clean
5C666FB000
unkown
page read and write
clean
7FF4FF89A000
unkown
page readonly
clean
164205E0000
unkown
page readonly
clean
5C6619B000
unkown
page read and write
clean
1D90A002000
unkown
page read and write
clean
2082E142000
unkown
page read and write
clean
1D9096C0000
heap default
page read and write
clean
2082E17D000
unkown
page read and write
clean
2320000
unkown
page readonly
clean
2082D8EC000
unkown
page read and write
clean
2082E14B000
unkown
page read and write
clean
5C6647F000
unkown
page read and write
clean
BEF2E7F000
unkown
page read and write
clean
7FF56B9AD000
unkown
page readonly
clean
BEF2D7F000
unkown
page read and write
clean
1D909829000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
7FF57AE14000
unkown
page readonly
clean
1D909902000
unkown
page read and write
clean
2082DF10000
unkown
page read and write
clean
2082E172000
unkown
page read and write
clean
2082D8C6000
unkown
page read and write
clean
16420655000
unkown
page read and write
clean
164205F0000
unkown
page readonly
clean
7FF56BD6E000
unkown
page readonly
clean
7FF56B82E000
unkown
page readonly
clean
2C80000
unkown
page execute and read and write
clean
2082E150000
unkown
page read and write
clean
7FF4FF28E000
unkown
page readonly
clean
2082E183000
unkown
page read and write
clean
7FF4FF8A1000
unkown
page readonly
clean
400000
unkown image
page readonly
clean
2082D6F0000
heap default
page read and write
clean
21A0000
unkown
page execute read
clean
23C1E8FF000
unkown
page read and write
clean
AD9C077000
unkown
page read and write
clean
5C669FF000
unkown
page read and write
clean