IOCReport

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\plAI22fb26.exe
'C:\Users\user\Desktop\plAI22fb26.exe'
malicious

URLs

Name
IP
Malicious
https://www.instagram.com/invertexto/
unknown
clean
http://94.228.123.161/dashboard/
unknown
clean
http://www.indyproject.org/
unknown
clean
https://pagead2.goog
unknown
clean
http://abrilprorock2018.webcindario.com/br/config.php
unknown
clean
https://www.invertexto.com/
unknown
clean
https://www.invertexto.com/aja
unknown
clean
http://94.228.126.231/lending/
unknown
clean
https://www.invertexto.com/img/face-note.png
unknown
clean

Domains

Name
IP
Malicious
www.invertexto.com
54.207.65.61
clean

IPs

IP
Domain
Country
Malicious
54.207.65.61
www.invertexto.com
United States
clean

Registry

Path
Value
Malicious
C:\Users\user\Desktop\plAI22fb26.exe
AlphaColor
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
2AF77258000
unkown
page read and write
clean
7FF57A1CA000
unkown image
page readonly
clean
6070000
unkown
page read and write
clean
1150000
unkown image
page write copy
clean
7FF50213F000
unkown image
page readonly
clean
7FF57A16C000
unkown image
page readonly
clean
7DF58D930000
unkown image
page readonly
clean
2A6D9702000
unkown
page read and write
clean
2AF77200000
unkown
page read and write
clean
7FF502194000
unkown image
page readonly
clean
1ED537E0000
unkown
page read and write
clean
7FF57B542000
unkown image
page readonly
clean
1FEF7E90000
unkown image
page read and write
clean
2A6DEC60000
unkown
page read and write
clean
20D3EF60000
unkown image
page read and write
clean
7FF57B62E000
unkown image
page readonly
clean
2A6DEB70000
unkown
page read and write
clean
7FF515DBA000
unkown image
page readonly
clean
7FF5BB725000
unkown image
page readonly
clean
1147000
unkown image
page read and write
clean
1651000
heap default
page read and write
clean
7FF5BB323000
unkown image
page readonly
clean
1910A44A000
unkown
page read and write
clean
7FF57A235000
unkown image
page readonly
clean
7DF5283A0000
unkown image
page readonly
clean
22A665F0000
unkown image
page readonly
clean
11A4000
unkown image
page readonly
clean
2A6DA570000
unkown
page read and write
clean
1C2D47A0000
unkown
page read and write
clean
7FF5FFFD0000
unkown image
page readonly
clean
1C2D427D000
unkown
page read and write
clean
2A6DEBD0000
unkown
page read and write
clean
162B000
heap default
page read and write
clean
20D3EFD0000
heap default
page read and write
clean
7FF545ACE000
unkown image
page readonly
clean
2A6D9F13000
unkown
page read and write
clean
2A6DEC22000
unkown
page read and write
clean
1C2D424D000
unkown
page read and write
clean
2A6DED04000
unkown
page read and write
clean
1055000
unkown image
page write copy
clean
2A6D962A000
unkown
page read and write
clean
2A6D9676000
unkown
page read and write
clean
114E000
unkown image
page write copy
clean
7FF579E62000
unkown image
page readonly
clean
7FF5BB751000
unkown image
page readonly
clean
2AF77780000
unkown image
page readonly
clean
7FF5BB75C000
unkown image
page readonly
clean
7FF57A1DC000
unkown image
page readonly
clean
3C88000
unkown
page read and write
clean
94BB1FB000
unkown
page read and write
clean
180000
unkown
page read and write
clean
7FF5BB667000
unkown image
page readonly
clean
7FF5E8D6B000
unkown image
page readonly
clean
1ED5387F000
unkown
page read and write
clean
1626000
heap default
page read and write
clean
7FF545D12000
unkown image
page readonly
clean
65D2000
unkown
page read and write
clean
7FF545B7E000
unkown image
page readonly
clean
1910A2C0000
heap default
page read and write
clean
1FEF8580000
unkown image
page readonly
clean
59F137F000
unkown
page read and write
clean
7FF5BB76C000
unkown image
page readonly
clean