IOC Report

loading gif

Files

File Path
Type
Category
Malicious
DHL_AWB_DOCUMENT_pdf.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Temp\tmp9820.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\DHL_AWB_DOCUMENT_pdf.exe.log
ASCII text, with CRLF line terminators
modified
clean
C:\Users\user\AppData\Local\Temp\1baba914-78bb-a57e-5fc4-bf0123172b93
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\bhv2B6.tmp
Extensible storage engine DataBase, version 0x620, checksum 0x5cc662f4, page size 32768, DirtyShutdown, Windows version 10.0
dropped
clean
C:\Users\user\AppData\Local\Temp\tmp2B6B.tmp
Little-endian UTF-16 Unicode text, with no line terminators
dropped
clean
C:\Users\user\AppData\Roaming\lgrlEexTAQO.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
clean
C:\Users\user\AppData\Roaming\lgrlEexTAQO.exe:Zone.Identifier
ASCII text, with CRLF line terminators
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\DHL_AWB_DOCUMENT_pdf.exe
'C:\Users\user\Desktop\DHL_AWB_DOCUMENT_pdf.exe'
malicious
C:\Windows\SysWOW64\schtasks.exe
'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\lgrlEexTAQO' /XML 'C:\Users\user\AppData\Local\Temp\tmp9820.tmp'
malicious
C:\Users\user\Desktop\DHL_AWB_DOCUMENT_pdf.exe
C:\Users\user\Desktop\DHL_AWB_DOCUMENT_pdf.exe
malicious
C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
'C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe' /stext 'C:\Users\user\AppData\Local\Temp\tmp2B6B.tmp'
malicious
C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
'C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe' /stext 'C:\Users\user\AppData\Local\Temp\tmp25DA.tmp'
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
clean

URLs

Name
IP
Malicious
http://www.msn.com/de-ch/entertainment/_h/c920645c/webcore/externalscripts/oneTrustV2/scripttemplate
unknown
clean
https://www.google.com/chrome/static/images/folder-applications.svg
unknown
clean
https://www.google.com/chrome/static/css/main.v2.min.css
unknown
clean
https://2542116.fls.doubleclick.net/activityi;src=2542116;type=chrom322;cat=chrom01g;ord=58648497779
unknown
clean
https://cvision.media.net/new/286x175/2/75/95/36/612b163a-ff7b-498a-bad2-3c52bbd2c504.jpg?v=9
unknown
clean
https://www.google.com/chrome/static/images/fallback/google-chrome-logo.jpg
unknown
clean
https://cvision.media.net/new/286x175/2/57/35/144/83ebc513-f6d1-4e0e-a39a-bef975147e85.jpg?v=9
unknown
clean
http://www.msn.com
unknown
clean
http://www.fontbureau.com/designers
unknown
clean
http://www.nirsoft.net
unknown
clean
https://deff.nelreports.net/api/report?cat=msn
unknown
clean
https://contextual.media.net/__media__/js/util/nrrV9140.js
unknown
clean
https://www.google.com/chrome/static/images/chrome-logo.svg
unknown
clean
https://www.google.com/chrome/static/images/homepage/homepage_features.png
unknown
clean
http://www.collada.org/2005/11/COLLADASchema9Done
unknown
clean
https://mem.gfx.ms/me/MeControl/10.19168.0/en-US/meCore.min.js
unknown
clean
https://www.google.com/chrome/static/images/download-browser/big_pixel_phone.png
unknown
clean
http://www.sajatypeworks.com
unknown
clean
https://www.google.com/chrome/
unknown
clean
http://www.founder.com.cn/cn/cThe
unknown
clean
https://a.pomf.cat/
unknown
clean
https://assets.adobedtm.com/5ef092d1efb5/4d1d9f749fd3/434d91f2e635/RCc13122162a9a46c3b4cbf05ffccde0f
unknown
clean
https://2542116.fls.doubleclick.net/activityi;src=2542116;type=clien612;cat=chromx;ord=1;num=3931852
unknown
clean
https://www.google.com/chrome/static/images/homepage/hero-anim-bottom-left.png
unknown
clean
https://www.google.com/chrome/static/images/chrome_safari-behavior.jpg
unknown
clean
http://www.msn.com/?ocid=iehp
unknown
clean
https://assets.adobedtm.com/5ef092d1efb5/4d1d9f749fd3/434d91f2e635/RCee0d4d5fd4424c8390d703b105f82c3
unknown
clean
http://crl.pki.goog/GTS1O1core.crl0
unknown
clean
http://images.outbrainimg.com/transform/v3/eyJpdSI6IjE4MmE0M2M0MDY3OGU1N2E4MjhkM2NjNDdlNGMzZmNkYjU1N
unknown
clean
http://www.galapagosdesign.com/DPlease
unknown
clean
https://www.google.com/chrome/static/images/icon-announcement.svg
unknown
clean
https://contextual.media.net/medianet.php?cid=8CU157172&crid=722878611&size=306x271&https=1https://c
unknown
clean
http://www.urwpp.deDPlease
unknown
clean
http://www.nirsoft.net/
unknown
clean
http://www.zhongyicts.com.cn
unknown
clean
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
clean
https://www.google.com/chrome/static/images/homepage/hero-anim-middle.png
unknown
clean
https://www.google.com/chrome/static/css/main.v3.min.css
unknown
clean
https://www.google.com/chrome/application/x-msdownloadC:
unknown
clean
https://www.google.com/chrome/static/images/fallback/icon-file-download.jpg
unknown
clean
http://www.fontbureau.comic
unknown
clean
https://assets.adobedtm.com/5ef092d1efb5/4d1d9f749fd3/434d91f2e635/RC5bdddb231cf54f958a5b6e76e9d8eee
unknown
clean
https://optanon.blob.core.windows.net/skins/4.1.0/default_flat_top_two_button_black/v2/css/optanon.c
unknown
clean
http://images.outbrainimg.com/transform/v3/eyJpdSI6ImY3MDA1MDJkMTdmZDY0M2VkZTBjNzg5MTE1OWEyYTYxMWRiN
unknown
clean
https://www.google.com/chrome/static/images/download-browser/pixel_phone.png
unknown
clean
http://pki.goog/gsr2/GTS1O1.crt0
unknown
clean
https://contextual.media.net/medianet.php?cid=8CU157172&crid=858412214&size=306x271&https=1
unknown
clean
https://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml
unknown
clean
https://www.google.com/chrome/static/images/app-store-download.png
unknown
clean
https://www.google.com/chrome/static/images/homepage/hero-anim-top-right.png
unknown
clean
https://contextual.media.net/
unknown
clean
https://optanon.blob.core.windows.net/skins/4.1.0/default_flat_top_two_button_black/v2/images/cookie
unknown
clean
https://pki.goog/repository/0
unknown
clean
https://mem.gfx.ms/meversion?partner=RetailStore2&market=en-us&uhf=1
unknown
clean
https://cvision.media.net/new/300x300/3/167/174/27/39ab3103-8560-4a55-bfc4-401f897cf6f2.jpg?v=9
unknown
clean