IOC Report

loading gif

Files

File Path
Type
Category
Malicious
n#U00ba410000512664.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
data
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Microsoft Cabinet archive data, 61414 bytes, 1 file
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
data
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
data
modified
clean
C:\Users\user\AppData\Local\Temp\~DF8D00AB13BF3C3E52.TMP
Composite Document File V2 Document, Cannot read section info
dropped
clean
\Device\ConDrv
ASCII text, with CRLF line terminators
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\n#U00ba410000512664.exe
"C:\Users\user\Desktop\n#U00ba410000512664.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
"C:\Users\user\Desktop\n#U00ba410000512664.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
clean

URLs

Name
IP
Malicious
http://127.0.0.1:HTTP/1.1
unknown
clean
http://x1.i.lencr.org/
unknown
clean
http://DynDns.comDynDNS
unknown
clean
http://XrlCbH.com
unknown
clean
https://doc-00-5k-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/mppp68ugon2ln1s6q81d25lmk78u5skq/1637587350000/06007705055686197661/*/12bEv52T0WqCex9NqBV7JSBLb08xvi7Jq?e=download
142.250.181.225
clean
https://doc-00-5k-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/mppp68ug
unknown
clean
http://cps.letsencrypt.org0
unknown
clean
http://www.topqualityfreeware.com/
unknown
clean
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
unknown
clean
https://doc-00-5k-docs.googleusercontent.com/
unknown
clean
https://drive.google.com/
unknown
clean
http://r3.i.lencr.org/09
unknown
clean
http://x1.c.lencr.org/0
unknown
clean
http://x1.i.lencr.org/0
unknown
clean
http://gZr4dT3tmP.org
unknown
clean
https://doc-00-5k-docs.googleusercontent.com/&
unknown
clean
http://r3.o.lencr.org0
unknown
clean
http://topqualityfreeware.com
unknown
clean
http://mail.neopyme.com
unknown
clean
http://neopyme.com
unknown
clean
https://csp.withgoogle.com/csp/report-to/gse_l9ocaq
unknown
clean
There are 11 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
neopyme.com
54.36.109.179
malicious
mail.neopyme.com
unknown
malicious
drive.google.com
172.217.16.142
clean
googlehosted.l.googleusercontent.com
142.250.181.225
clean
doc-00-5k-docs.googleusercontent.com
unknown
clean
x1.i.lencr.org
unknown
clean

IPs

IP
Domain
Country
Malicious
54.36.109.179
neopyme.com
France
malicious
142.250.181.225
googlehosted.l.googleusercontent.com
United States
clean
172.217.16.142
drive.google.com
United States
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
1DDF1000
unkown
page read and write
malicious
D00000
unkown
page execute and read and write
malicious
7DF594610000
unkown image
page readonly
clean
1DF3C973000
unkown
page read and write
clean
2903F740000
unkown
page read and write
clean
20060000
unkown
page read and write
clean
2740256E000
unkown
page read and write
clean
FF1000
stack
page read and write
clean
1CC61000
unkown
page read and write
clean
1CF79A00000
unkown
page read and write
clean
295AE65B000
unkown
page read and write
clean
258176CE000
unkown
page read and write
clean
28CF8874000
unkown
page read and write
clean
1CC61000
unkown
page read and write
clean
27402576000
unkown
page read and write
clean
7DF443750000
unkown image
page readonly
clean
FF1000
stack
page read and write
clean
1DF3CFF1000
unkown
page read and write
clean
7FF518270000
unkown image
page readonly
clean
1CF791F1000
unkown image
page readonly
clean
1DF3D1E2000
unkown
page read and write
clean
2581769D000
unkown
page read and write
clean
1DF3C295000
unkown
page read and write
clean
2D766DC000
unkown
page read and write
clean
21BC167E000
unkown
page read and write
clean
274021C1000
unkown image
page readonly
clean
1CC61000
unkown
page read and write
clean
1DF3CF19000
unkown
page read and write
clean
1010000
stack
page read and write
clean
1DF3CF51000
unkown
page read and write
clean
6E7000
unkown
page read and write
clean
1DF3C98C000
unkown
page read and write