IOCReport

loading gif

Files

File Path
Type
Category
Malicious
doc_2021_98666_SIGNED - PRO FACTURA.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\doc_2021_98666_SIGNED - PRO FACTURA.exe.log
ASCII text, with CRLF line terminators
modified
malicious
C:\Users\user\AppData\Local\Temp\tmpDCE9.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\bWuIYd.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Roaming\bWuIYd.exe:Zone.Identifier
ASCII text, with CRLF line terminators
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\doc_2021_98666_SIGNED - PRO FACTURA.exe
'C:\Users\user\Desktop\doc_2021_98666_SIGNED - PRO FACTURA.exe'
malicious
C:\Windows\System32\schtasks.exe
'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\bWuIYd' /XML 'C:\Users\user\AppData\Local\Temp\tmpDCE9.tmp'
malicious
C:\Users\user\Desktop\doc_2021_98666_SIGNED - PRO FACTURA.exe
C:\Users\user\Desktop\doc_2021_98666_SIGNED - PRO FACTURA.exe
malicious
C:\Users\user\Desktop\doc_2021_98666_SIGNED - PRO FACTURA.exe
C:\Users\user\Desktop\doc_2021_98666_SIGNED - PRO FACTURA.exe
malicious
C:\Users\user\Desktop\doc_2021_98666_SIGNED - PRO FACTURA.exe
C:\Users\user\Desktop\doc_2021_98666_SIGNED - PRO FACTURA.exe
malicious
C:\Users\user\Desktop\doc_2021_98666_SIGNED - PRO FACTURA.exe
C:\Users\user\Desktop\doc_2021_98666_SIGNED - PRO FACTURA.exe
malicious
C:\Users\user\Desktop\doc_2021_98666_SIGNED - PRO FACTURA.exe
C:\Users\user\Desktop\doc_2021_98666_SIGNED - PRO FACTURA.exe
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
clean

URLs

Name
IP
Malicious
194.5.98.127
malicious
127.0.0.1
malicious
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
32EA000
unkown
page read and write
malicious
12F61000
unkown
page read and write
malicious
1B840000
unkown
page read and write
clean
BB2000
unkown image
page readonly
clean
109E000
heap default
page read and write
clean
2DA0000
unkown
page read and write
clean
10A2000
heap default
page read and write
clean
7FF50E6D1000
unkown
page readonly
clean
13F0000
unkown
page readonly
clean
1B940000
heap private
page execute and read and write
clean
2DD0000
unkown
page read and write
clean
1B960000
unkown
page read and write
clean
2DB0000
unkown
page read and write
clean
BB0000
unkown image
page readonly
clean
1B930000
unkown
page read and write
clean
1B813000
unkown
page read and write
clean
BF0000
unkown image
page readonly
clean
7C0000
unkown image
page readonly
clean
BF2000
unkown image
page readonly
clean
1B960000
unkown
page read and write
clean
23785702000
unkown
page read and write
clean
7FF50E880000
unkown
page readonly
clean
1B930000
unkown
page read and write
clean
2E40000
heap private
page read and write
clean
1B930000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
1B2C5000
unkown
page read and write
clean
7FF50E8C4000
unkown
page readonly
clean
7FFA35F1C000
unkown
page execute and read and write
clean
2E30000
unkown
page read and write
clean
1B970000
unkown
page read and write
clean
1C8A0000
unkown
page read and write
clean
BB0000
unkown image
page readonly
clean
BA8000
unkown image
page readonly
clean
1B930000
unkown
page read and write
clean
1BD70000
unkown
page read and write
clean
1B960000
unkown
page read and write
clean
1B970000
unkown
page read and write
clean
10D3000
heap default
page read and write
clean
1B970000
unkown
page read and write
clean
90270F7000
unkown
page read and write
clean
2DC0000
unkown
page read and write
clean
7FFA35E73000
unkown
page read and write
clean
1B9CF000
unkown
page read and write
clean
1B960000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
1B87D000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
1B4CB000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
1B970000
unkown
page read and write
clean
BB2000
unkown image
page readonly
clean
1B960000
unkown
page read and write
clean
125E000
unkown
page read and write
clean
2DB0000
unkown
page read and write
clean
1B910000
heap private
page read and write
clean
23785530000
unkown
page readonly
clean
2D70000
heap private
page execute and read and write
clean
1B970000
unkown
page read and write
clean
1B953000
heap private
page read and write
clean
2378564E000
unkown
page read and write
clean
115D000
unkown
page read and write
clean
23785708000
unkown
page read and write
clean
1B960000
unkown
page read and write
clean
23785650000
unkown
page read and write
clean
1B87D000
unkown
page read and write
clean
90271FE000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
FF0000
unkown
page read and write
clean
1069000
heap default
page read and write
clean
7FF50E897000
unkown
page readonly
clean
1B87D000
unkown
page read and write
clean
A80000
unkown image
page readonly
clean
1B930000
unkown
page read and write
clean
7FF50E87A000
unkown
page readonly
clean
12A0000
unkown
page read and write
clean
EF0000
unkown
page read and write
clean
23785460000
unkown
page readonly
clean
BC5000
heap private
page read and write
clean
1B990000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
115B000
unkown
page read and write
clean
7FFA36043000
unkown
page read and write
clean
1060000
heap default
page read and write
clean
D18000
unkown image
page readonly
clean
1B980000
heap private
page read and write
clean
1B930000
unkown
page read and write
clean
9026D7E000
unkown
page read and write
clean
7FF50E8EE000
unkown
page readonly
clean
1B930000
unkown
page read and write
clean
1BFA0000
unkown
page read and write
clean
7FFA35E80000
unkown
page read and write
clean
1B970000
unkown
page read and write
clean
A80000
unkown image
page readonly
clean
2DB0000
unkown
page read and write
clean
7FF50E87E000
unkown
page readonly
clean
1B841000
unkown
page read and write
clean
7FFA35F90000
unkown
page execute and read and write
clean
142A6000
unkown
page read and write
clean
7FF50E7CD000
unkown
page readonly
clean
9026C7B000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
12E5000
heap private
page read and write
clean
CD8000
unkown image
page readonly
clean
2DF0000
unkown
page read and write
clean
23786000000
unkown
page readonly
clean
1BEA0000
unkown
page read and write
clean
7FFA35F85000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
1B810000
unkown
page read and write
clean
2DC0000
unkown
page read and write
clean
7C0000
unkown image
page readonly
clean
D50000
unkown image
page readonly
clean
7FFA35E84000
unkown
page read and write
clean
7FF50E7EC000
unkown
page readonly
clean
7FFA36030000
unkown
page read and write
clean
1B87D000
unkown
page read and write
clean
7FF50E5F7000
unkown
page readonly
clean
1B930000
unkown
page read and write
clean
1C8A0000
unkown
page read and write
clean
7FF50E7D3000
unkown
page readonly
clean
2E20000
unkown
page read and write
clean
1B824000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
2DC0000
unkown
page read and write
clean
BC0000
heap private
page read and write
clean
7FF50E964000
unkown
page readonly
clean
23785700000
unkown
page read and write
clean
10D7000
heap default
page read and write
clean
7C0000
unkown image
page readonly
clean
D50000
unkown image
page readonly
clean
1B82F000
unkown
page read and write
clean
2E10000
unkown
page read and write
clean
2D80000
unkown
page read and write
clean
13961000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
1C900000
unkown
page read and write
clean
7FFA35E7D000
unkown
page execute and read and write
clean
2D60000
unkown
page readonly
clean
2378563C000
unkown
page read and write
clean
1C130000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
1AF80000
unkown
page read and write
clean
1C8B0000
unkown
page read and write
clean
1145000
heap default
page read and write
clean
1B82B000
unkown
page read and write
clean
7FF50E972000
unkown
page readonly
clean
7FF50E8F6000
unkown
page readonly
clean
1C140000
unkown
page read and write
clean
2DA0000
unkown
page read and write
clean
D50000
unkown image
page readonly
clean
7FF50E455000
unkown
page readonly
clean
1C920000
unkown
page read and write
clean
7FF50E86A000
unkown
page readonly
clean
1C8E0000
unkown
page read and write
clean
8E8000
unkown image
page readonly
clean
23785613000
unkown
page read and write
clean
1C0C0000
unkown
page read and write
clean
1C730000
unkown
page readonly
clean
2378564A000
unkown
page read and write
clean
1C130000
unkown
page read and write
clean
7FF50E55A000
unkown
page readonly
clean
1B9C0000
unkown
page read and write
clean
1C130000
unkown
page read and write
clean
7FFA35F46000
unkown
page execute and read and write
clean
2DC0000
unkown
page read and write
clean
90272FD000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
7FFA36040000
unkown
page read and write
clean
7FFA36010000
unkown
page read and write
clean
1B817000
unkown
page read and write
clean
7FFA35E8D000
unkown
page execute and read and write
clean
1B9B0000
unkown
page read and write
clean
D98000
unkown image
page readonly
clean
1B960000
unkown
page read and write
clean
A82000
unkown image
page readonly
clean
1B81F000
unkown
page read and write
clean
7FF50E8B7000
unkown
page readonly
clean
7FF50E8E8000
unkown
page readonly
clean
23785540000
unkown
page readonly
clean
2DB0000
unkown
page read and write
clean
7FF50E8DF000
unkown
page readonly
clean
7FF50E885000
unkown
page readonly
clean
12F5D000
unkown
page read and write
clean
7FF50E77B000
unkown
page readonly
clean
1BB90000
unkown
page read and write
clean
10EA000
heap default
page read and write
clean
C72000
unkown image
page readonly
clean
1B857000
unkown
page read and write
clean
23785652000
unkown
page read and write
clean
1B960000
unkown
page read and write
clean
2DA0000
unkown
page read and write
clean
7FFA35E6D000
unkown
page execute and read and write
clean
1BFB0000
unkown
page read and write
clean
23785629000
unkown
page read and write
clean
1B837000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
23785800000
unkown
page readonly
clean
1C0B0000
unkown
page read and write
clean
7FFA35E70000
unkown
page read and write
clean
7FF50E86C000
unkown
page readonly
clean
2DE0000
unkown
page read and write
clean
23785649000
unkown
page read and write
clean
1B920000
unkown
page read and write
clean
1C910000
unkown
page read and write
clean
12D0000
unkown
page readonly
clean
1C8D0000
unkown
page read and write
clean
237853F0000
heap private
page read and write
clean
7FF50E8FD000
unkown
page readonly
clean
1280000
unkown
page read and write
clean
1C8B0000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
7C2000
unkown image
page readonly
clean
1B970000
unkown
page readonly
clean
7FFA35E63000
unkown
page execute and read and write
clean
1B930000
unkown
page read and write
clean
7FF50E88B000
unkown
page readonly
clean
2378564C000
unkown
page read and write
clean
1B970000
unkown
page read and write
clean
7FF50E761000
unkown
page readonly
clean
13EE000
unkown
page read and write
clean
C70000
unkown image
page readonly
clean
1C0D0000
unkown
page read and write
clean
12B4000
unkown
page read and write
clean
1B960000
unkown
page read and write
clean
7FF50E971000
unkown
page readonly
clean
1B970000
unkown
page read and write
clean
23785C60000
unkown
page readonly
clean
9026F7B000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
1C99E000
unkown
page read and write
clean
D52000
unkown image
page readonly
clean
1B970000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
D52000
unkown image
page readonly
clean
A80000
unkown image
page readonly
clean
23785713000
unkown
page read and write
clean
1C160000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
2DA0000
unkown
page read and write
clean
C70000
unkown image
page readonly
clean
1B930000
unkown
page read and write
clean
BF0000
unkown image
page readonly
clean
1B960000
unkown
page read and write
clean
1B960000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
1C140000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
1B920000
unkown
page read and write
clean
1C88A000
unkown
page read and write
clean
1C8C0000
unkown
page read and write
clean
C70000
unkown image
page readonly
clean
23785450000
heap default
page read and write
clean
1B81D000
unkown
page read and write
clean
7FFA35F16000
unkown
page read and write
clean
1B87D000
unkown
page read and write
clean
F20000
unkown
page readonly
clean
7FFA35F20000
unkown
page execute and read and write
clean
1C150000
unkown
page read and write
clean
7FFA36050000
unkown
page execute and read and write
clean
1C690000
unkown
page readonly
clean
2D50000
unkown
page read and write
clean
7FF50E8AF000
unkown
page readonly
clean
1030000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
7FF50E8D4000
unkown
page readonly
clean
1B930000
unkown
page read and write
clean
2E00000
unkown
page read and write
clean
1B970000
unkown
page read and write
clean
1B829000
unkown
page read and write
clean
1B960000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
1C630000
unkown
page readonly
clean
2DB0000
unkown
page read and write
clean
2F51000
unkown
page read and write
clean
2C8E000
unkown
page read and write
clean
C72000
unkown image
page readonly
clean
1C930000
unkown
page read and write
clean
7FF50E77E000
unkown
page readonly
clean
1B930000
unkown
page read and write
clean
E78000
unkown image
page readonly
clean
7FFA35F10000
unkown
page read and write
clean
1C8F0000
unkown
page read and write
clean
1B960000
unkown
page read and write
clean
7C2000
unkown image
page readonly
clean
2DA0000
unkown
page read and write
clean
1B970000
unkown
page read and write
clean
7FFA36020000
unkown
page read and write
clean
1B87D000
unkown
page read and write
clean
23785600000
unkown
page read and write
clean
1B970000
unkown
page read and write
clean
7FF50E723000
unkown
page readonly
clean
7FFA35E64000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
1050000
unkown
page readonly
clean
90273FF000
unkown
page read and write
clean
1C09D000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
9026FFF000
unkown
page read and write
clean
9026E75000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
1B980000
unkown
page read and write
clean
2DC0000
unkown
page readonly
clean
1C940000
unkown
page read and write
clean
12F51000
unkown
page read and write
clean
2C90000
unkown
page readonly
clean
1C42F000
unkown
page read and write
clean
1C0A0000
unkown
page read and write
clean
9026CFE000
unkown
page read and write
clean
BF2000
unkown image
page readonly
clean
E78000
unkown image
page readonly
clean
BA8000
unkown image
page readonly
clean
1B930000
unkown
page read and write
clean
2DC0000
unkown
page read and write
clean
2DA0000
unkown
page read and write
clean
7FFA35F80000
unkown
page read and write
clean
7FF50E8AC000
unkown
page readonly
clean
1C680000
unkown
page readonly
clean
8E8000
unkown image
page readonly
clean
1B9D0000
unkown
page read and write
clean
23785550000
unkown
page read and write
clean
1B960000
unkown
page read and write
clean
7FF50E8F9000
unkown
page readonly
clean
12B0000
unkown
page read and write
clean
2DA0000
unkown
page read and write
clean
7FFA35E8B000
unkown
page execute and read and write
clean
7FF50E446000
unkown
page readonly
clean
1B930000
unkown
page read and write
clean
1C750000
unkown
page read and write
clean
23785681000
unkown
page read and write
clean
1B960000
unkown
page read and write
clean
1B830000
unkown
page read and write
clean
12E0000
heap private
page read and write
clean
CD8000
unkown image
page readonly
clean
1C0A0000
unkown
page read and write
clean
1C140000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
D98000
unkown image
page readonly
clean
1B830000
unkown
page read and write
clean
A82000
unkown image
page readonly
clean
7FF44A210000
unkown
page execute and read and write
clean
1B960000
unkown
page read and write
clean
23785E02000
unkown
page read and write
clean
12F58000
unkown
page read and write
clean
1B960000
unkown
page read and write
clean
7FF50E440000
unkown
page readonly
clean
7FFA35EBC000
unkown
page execute and read and write
clean
2DB0000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
330B000
unkown
page read and write
clean
1C52E000
unkown
page read and write
clean
1BA90000
unkown
page read and write
clean
1B9A0000
unkown
page read and write
clean
2DA0000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
BB0000
unkown image
page readonly
clean
1B930000
unkown
page read and write
clean
1B960000
unkown
page read and write
clean
7FF50E8CA000
unkown
page readonly
clean
BF0000
unkown image
page readonly
clean
1B950000
heap private
page read and write
clean
2378566D000
unkown
page read and write
clean
1B4D0000
unkown
page readonly
clean
1C22E000
unkown
page read and write
clean
7FF50E7E4000
unkown
page readonly
clean
1B930000
unkown
page read and write
clean
106F000
heap default
page read and write
clean
D18000
unkown image
page readonly
clean
1B817000
unkown
page read and write
clean
2F4E000
unkown
page read and write
clean
7FF50E96A000
unkown
page readonly
clean
1010000
unkown
page read and write
clean
1B960000
unkown
page read and write
clean
1B930000
unkown
page read and write
clean
1C32E000
unkown
page read and write
clean
1C62E000
unkown
page read and write
clean
1BA8E000
unkown
page read and write
clean
There are 369 hidden memdumps, click here to show them.