IOC Report

loading gif

Files

File Path
Type
Category
Malicious
DHL_Shipment_Notification_1231413385_Notification_1231413385_september2021.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Temp\LABERT\Cirkusforestillinger.exe
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\DHL_Shipment_Notification_1231413385_Notification_1231413385_september2021.exe
'C:\Users\user\Desktop\DHL_Shipment_Notification_1231413385_Notification_1231413385_september2021.exe'
malicious
C:\Program Files (x86)\Internet Explorer\ieinstal.exe
'C:\Users\user\Desktop\DHL_Shipment_Notification_1231413385_Notification_1231413385_september2021.exe'
malicious

URLs

Name
IP
Malicious
http://178.32.63.50/moss/Host_AKhLBP62.bin
178.32.63.50
malicious
http://178.32.63.50/moss/Host_AKhLBP62.bin:
unknown
clean
http://178.32.63.50/moss/Host_AKhLBP62.binF
unknown
clean
http://178.32.63.50/boss/Host_AKhLBP62.bin
unknown
clean
http://178.32.63.50/moss/Host_AKhLBP62.binhttp://178.32.63.50/boss/Host_AKhLBP62.binwininet.dllMozil
unknown
clean

Domains

Name
IP
Malicious
septnet.duckdns.org
193.104.197.28
malicious

IPs

IP
Domain
Country
Malicious
193.104.197.28
septnet.duckdns.org
unknown
malicious
178.32.63.50
unknown
France
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Halvngen7
clean
HKEY_CURRENT_USER\SOFTWARE\NetWire
HostId
clean
HKEY_CURRENT_USER\SOFTWARE\NetWire
Install Date
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
2300000
unkown
page execute and read and write
malicious
7F7B0000
unkown image
page readonly
clean
2C20000
heap private
page read and write
clean
1C531000
unkown
page read and write
clean
7F7C0000
unkown image
page readonly
clean
23A0000
heap private
page read and write
clean
1C72F000
unkown
page read and write
clean
2ACE000
unkown image
page readonly
clean
21E0000
unkown
page read and write
clean
2E31000
unkown
page read and write
clean
19B000
unkown
page read and write
clean
8DF000
unkown
page read and write
clean
39B0000
unkown image
page readonly
clean
400000
unkown image
page readonly
clean
7F7B2000
unkown image
page readonly
clean
2B71000
unkown image
page readonly
clean
1A0000
unkown image
page readonly
clean
2320000
unkown image
page readonly
clean
69E000
unkown
page read and write
clean
2B01000
unkown image
page readonly
clean
1EE1F000
unkown
page read and write
clean
2AF6000
unkown image
page readonly
clean
614000
unkown
page read and write
clean
534000
heap default
page read and write
clean
610000
heap default
page read and write
clean
2C30000
unkown
page read and write
clean
2B83000
unkown image
page readonly
clean
30A0000
unkown image
page readonly
clean
2B9B000
unkown image
page readonly
clean
2B35000
unkown image
page readonly
clean
500000
unkown
page read and write
clean
2250000
heap private
page read and write
clean
35C0000
unkown
page read and write
clean
2240000
unkown image
page readonly
clean
31D0000
unkown image
page readonly
clean
2340000
unkown
page read and write
clean
2B31000
unkown image
page readonly
clean
7FFC0000
unkown image
page readonly
clean
1ECDC000
unkown
page read and write
clean
79F000
unkown
page read and write
clean
2ADC000
unkown image
page readonly
clean
2B2E000
unkown
page read and write
clean
2B7D000
unkown image
page readonly
clean
2DC0000
unkown image
page readonly
clean
2DF0000
unkown image
page readonly
clean
3A3000
unkown
page read and write
clean
2AE2000
unkown image
page readonly
clean
1ED9E000
unkown
page read and write
clean
10000
unkown image
page readonly
clean
39C1000
unkown image
page readonly
clean
31E8000
heap default
page read and write
clean
2D30000
unkown image
page readonly
clean
20000
unkown image
page readonly
clean
3314000
unkown
page read and write
clean
31C0000
unkown image
page readonly
clean
2B5F000
unkown image
page readonly
clean
7FFB2000
unkown image
page readonly
clean
2B56000
unkown image
page readonly
clean
297F000
unkown image
page readonly
clean
2220000
unkown image
page readonly
clean
3000000
unkown image
page readonly
clean
7F7D0000
unkown image
page readonly
clean
2F1E000
unkown
page read and write
clean
7FFC2000
unkown image
page readonly
clean
1E7D0000
heap private
page read and write
clean
29CC000
unkown image
page readonly
clean
91E000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
2BA7000
unkown image
page readonly
clean
30000
unkown image
page read and write
clean
7F7C2000
unkown image
page readonly
clean
1EDDE000
unkown
page read and write
clean
3620000
heap private
page read and write
clean
2AC5000
unkown image
page readonly
clean
2B40000
unkown image
page readonly
clean
2DF0000
unkown image
page readonly
clean
2ACC000
unkown image
page readonly
clean
7F7B0000
unkown image
page readonly
clean
2BB4000
unkown image
page readonly
clean
2DE0000
unkown image
page read and write
clean
3263000
heap default
page read and write
clean
22F0000
unkown image
page readonly
clean
7FFC2000
unkown image
page readonly
clean
1ED1F000
unkown
page read and write
clean
7F7D0000
unkown image
page readonly
clean
21C0000
unkown
page execute read
clean
96000
unkown
page read and write
clean
419000
unkown image
page readonly
clean
2B07000
unkown image
page readonly
clean
7F7B0000
unkown image
page readonly
clean
7FFD0000
unkown image
page readonly
clean
C20000
unkown image
page readonly
clean
2B65000
unkown image
page readonly
clean
2BC0000
heap private
page read and write
clean
1F0000
unkown image
page readonly
clean
A1F000
unkown
page read and write
clean
2B95000
unkown image
page readonly
clean
2330000
heap private
page read and write
clean
620000
unkown
page read and write
clean
323A000
heap default
page read and write
clean
2B15000
unkown image
page readonly
clean
7F7C0000
unkown image
page readonly
clean
35D0000
unkown
page readonly
clean
7FFB2000
unkown image
page readonly
clean
7F7B2000
unkown image
page readonly
clean
401000
unkown image
page execute read
clean
1C530000
unkown
page read and write
clean
30CE000
unkown
page execute and read and write
clean
3000000
unkown image
page readonly
clean
3301000
unkown image
page readonly
clean
7FFB0000
unkown image
page readonly
clean
2B38000
unkown image
page readonly
clean
4F1000
unkown image
page readonly
clean
400000
unkown image
page readonly
clean
22E0000
unkown
page read and write
clean
3570000
unkown
page read and write
clean
1E4E0000
unkown
page read and write
clean
614000
unkown
page read and write
clean
2C24000
heap private
page read and write
clean
DA0000
unkown image
page readonly
clean
1C0000
unkown image
page readonly
clean
2BAE000
unkown image
page readonly
clean
1D0000
unkown image
page readonly
clean
51E000
heap default
page read and write
clean
7F7C0000
unkown image
page readonly
clean
7FFD0000
unkown image
page readonly
clean
7F7D0000
unkown image
page readonly
clean
2B2E000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
2B21000
unkown image
page readonly
clean
2B62000
unkown image
page readonly
clean
2AE5000
unkown image
page readonly
clean
419000
unkown image
page readonly
clean
7F7C2000
unkown image
page readonly
clean
1C531000
unkown
page read and write
clean
39F000
unkown
page read and write
clean
31E0000
heap default
page read and write
clean
324E000
heap default
page read and write
clean
7FE50000
unkown image
page readonly
clean
29D0000
unkown image
page readonly
clean
3830000
unkown image
page readonly
clean
32F0000
unkown image
page readonly
clean
3310000
heap default
page read and write
clean
7FFC0000
unkown image
page readonly
clean
4DD0000
unkown
page read and write
clean
1E0000
unkown image
page readonly
clean
2AAB000
unkown image
page readonly
clean
2B19000
unkown image
page readonly
clean
510000
heap default
page read and write
clean
2988000
unkown image
page readonly
clean
7F7B2000
unkown image
page readonly
clean
2AA0000
unkown image
page readonly
clean
32E0000
unkown image
page readonly
clean
3630000
unkown image
page readonly
clean
416000
unkown image
page read and write
clean
23B0000
unkown
page read and write
clean
401000
unkown image
page execute read
clean
51A000
heap default
page read and write
clean
2BAA000
unkown image
page readonly
clean
A20000
unkown image
page readonly
clean
2B0C000
unkown image
page readonly
clean
30A0000
unkown image
page readonly
clean
2260000
unkown
page read and write
clean
3229000
heap default
page read and write
clean
2AD1000
unkown image
page readonly
clean
1EBBF000
unkown
page read and write
clean
7FFB0000
unkown image
page readonly
clean
3000000
unkown image
page readonly
clean
1E5E0000
unkown
page read and write
clean
2ABA000
unkown image
page readonly
clean
35E0000
unkown image
page readonly
clean
2339000
heap private
page read and write
clean
7F7C2000
unkown image
page readonly
clean
2ADA000
unkown image
page readonly
clean
2B91000
unkown image
page readonly
clean
2BB4000
unkown image
page readonly
clean
1ED15000
unkown
page read and write
clean
2DD0000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
7F650000
unkown image
page readonly
clean
2BB4000
unkown image
page readonly
clean
1E4E1000
unkown
page read and write
clean
1ED5B000
unkown
page read and write
clean
7DE000
unkown
page read and write
clean
1EB7E000
unkown
page read and write
clean
There are 175 hidden memdumps, click here to show them.