IOCReport

loading gif

Files

File Path
Type
Category
Malicious
shipping documents approval.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\shipping documents approval.exe.log
ASCII text, with CRLF line terminators
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\shipping documents approval.exe
'C:\Users\user\Desktop\shipping documents approval.exe'
malicious
C:\Users\user\Desktop\shipping documents approval.exe
{path}
malicious
C:\Users\user\Desktop\shipping documents approval.exe
{path}
malicious

URLs

Name
IP
Malicious
http://127.0.0.1:HTTP/1.1
unknown
clean
http://www.fontbureau.com/designersG
unknown
clean
http://www.fontbureau.com/designers/?
unknown
clean
http://www.founder.com.cn/cn/bThe
unknown
clean
http://www.fontbureau.comalsFj
unknown
clean
http://www.jiyu-kobo.co.jp/jp/G
unknown
clean
http://www.fontbureau.com/designers?
unknown
clean
http://www.fontbureau.comd;
unknown
clean
http://www.tiro.com
unknown
clean
http://www.fontbureau.com/designers
unknown
clean
http://www.goodfont.co.kr
unknown
clean
http://www.carterandcone.com
unknown
clean
http://www.carterandcone.comMi
unknown
clean
http://www.sajatypeworks.com
unknown
clean
http://www.carterandcone.como.q
unknown
clean
http://www.typography.netD
unknown
clean
http://www.founder.com.cn/cn/cThe
unknown
clean
http://www.galapagosdesign.com/staff/dennis.htm
unknown
clean
http://fontfabrik.com
unknown
clean
http://www.jiyu-kobo.co.jp/waX
unknown
clean
http://www.jiyu-kobo.co.jp//
unknown
clean
http://www.galapagosdesign.com/DPlease
unknown
clean
http://www.fontbureau.comrsiv
unknown
clean
http://www.fonts.com
unknown
clean
http://www.sandoll.co.kr
unknown
clean
http://www.urwpp.deDPlease
unknown
clean
http://www.zhongyicts.com.cn
unknown
clean
http://www.founder.com.cn/cnei
unknown
clean
http://www.sakkal.com
unknown
clean
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
unknown
clean
http://EoZDnS.com
unknown
clean
http://www.apache.org/licenses/LICENSE-2.0
unknown
clean
http://www.fontbureau.com
unknown
clean
http://www.galapagosdesign.com/
unknown
clean
http://DynDns.comDynDNS
unknown
clean
http://www.carterandcone.come
unknown
clean
http://www.fontbureau.commetX
unknown
clean
http://www.carterandcone.comd
unknown
clean
http://www.jiyu-kobo.co.jp/Q
unknown
clean
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
unknown
clean
http://www.founder.com.cn/cnhe
unknown
clean
http://www.jiyu-kobo.co.jp/G
unknown
clean
http://www.zhongyicts.com.cnMi
unknown
clean
http://www.fontbureau.comX
unknown
clean
http://www.fontbureau.comlic
unknown
clean
http://www.galapagosdesign.com/staff/dennis.htmo
unknown
clean
http://www.jiyu-kobo.co.jp/jp/
unknown
clean
http://www.fontbureau.coma
unknown
clean
http://www.carterandcone.coml
unknown
clean
http://www.fontbureau.com/designers/cabarga.htmlN
unknown
clean
http://www.founder.com.cn/cn.
unknown
clean
http://www.founder.com.cn/cn
unknown
clean
http://www.fontbureau.com/designers/frere-jones.html
unknown
clean
http://www.fontbureau.comf
unknown
clean
http://www.monotype.
unknown
clean
http://www.fontbureau.comcec
unknown
clean
http://www.jiyu-kobo.co.jp/
unknown
clean
http://www.jiyu-kobo.co.jp/l
unknown
clean
http://www.fontbureau.com/designers8
unknown
clean
http://www.jiyu-kobo.co.jp/j
unknown
clean
http://www.fontbureau.comals/
unknown
clean
http://www.jiyu-kobo.co.jp/c
unknown
clean
There are 52 hidden URLs, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
4331000
unkown
page read and write
malicious
402000
unkown
page execute and read and write
malicious
3398000
unkown
page read and write
malicious
4FFE000
unkown
page read and write
clean
5741000
unkown
page read and write
clean
5E6D000
unkown
page read and write
clean
5741000
unkown
page read and write
clean
5E90000
unkown
page read and write
clean
172A000
unkown
page read and write
clean
5741000
unkown
page read and write
clean
5E62000
unkown
page read and write
clean
5741000
unkown
page read and write
clean
1770000
unkown
page read and write
clean
5742000
unkown
page read and write
clean