IOC Report

loading gif

Files

File Path
Type
Category
Malicious
Sales Order List.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Temp\~DF904D784913DB7A54.TMP
Composite Document File V2 Document, Cannot read section info
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Sales Order List.exe
"C:\Users\user\Desktop\Sales Order List.exe"
malicious

URLs

Name
IP
Malicious
http://topqualityfreeware.com
unknown
clean
http://www.topqualityfreeware.com/
unknown
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
20F0000
unkown
page execute and read and write
malicious
7FF5B9230000
unkown image
page readonly
clean
1D82F9A8000
unkown
page read and write
clean
1D82FE02000
unkown
page read and write
clean
7FFC2000
unkown image
page readonly
clean
22591B30000
unkown image
page read and write
clean
7FF5D416A000
unkown image
page readonly
clean
7FF533367000
unkown image
page readonly
clean
7DF5411C0000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
205B59C0000
unkown
page readonly
clean
7FF5D40E7000
unkown image
page readonly
clean
7DF5411B2000
unkown image
page readonly
clean
1D82F984000
unkown
page read and write
clean
F07B679000
stack
page read and write
clean
1D82F968000
unkown
page read and write
clean
7FF5D40EA000
unkown image
page readonly
clean
7DF58F082000
unkown image
page readonly
clean
1D82F970000
unkown
page read and write
clean
511000
heap default
page read and write
clean
1D82F316000
unkown
page read and write
clean
225920D0000
unkown image
page readonly
clean
7FF5B8F95000
unkown image
page readonly
clean
7FF5B9263000
unkown image
page readonly
clean
7FF5334CA000
unkown image
page readonly
clean
205B4B00000
heap default
page read and write
clean
F01DD3A000
unkown
page read and write
clean
426000
unkown image
page readonly
clean
7DF5411D0000
unkown image
page readonly
clean
7FF5B9311000
unkown image
page readonly
clean
1D82F252000
unkown
page read and write
clean
1D725E8A000
unkown
page read and write
clean
1D82F7F0000
unkown
page read and write
clean
1D82F270000
unkown
page read and write
clean
7FF533551000
unkown image
page readonly
clean
1D82F995000
unkown
page read and write
clean
7DF594E72000
unkown image
page readonly
clean
7DF5C6F72000
unkown image
page readonly
clean
1D82F980000
unkown
page read and write
clean
7DF5411B2000
unkown image
page readonly
clean
205B5770000
unkown
page read and write
clean
7FF5E6A19000
unkown image
page readonly
clean
7FF5334AE000
unkown image
page readonly
clean
2E60000
unkown image
page read and write
clean
7FF5D3F21000
unkown image
page readonly
clean
7FF5E6B80000
unkown image
page readonly
clean
7FF58718D000
unkown image
page readonly
clean
205B4A80000
unkown image
page readonly
clean
1D82F9CB000
unkown
page read and write
clean
7FF5813F2000
unkown image
page readonly
clean
7FF5E6741000
unkown image
page readonly
clean
7FF5E6B4E000
unkown image
page readonly
clean
1B158C00000
unkown image
page readonly
clean
7FF5E6C61000
unkown image
page readonly
clean
1B158852000
unkown
page read and write
clean
1D82F2BD000
unkown
page read and write
clean
1B158A00000
unkown image
page readonly
clean
1D82F255000
unkown
page read and write
clean
7FF533466000
unkown image
page readonly
clean
7DF5F48D2000
unkown image
page readonly
clean
7FF5E69C5000
unkown image
page readonly
clean
1D82F967000
unkown
page read and write
clean
7DF594E80000
unkown image
page readonly
clean
205B5700000
unkown
page read and write
clean
7FF5E6747000
unkown image
page readonly
clean
29BE000
stack
page read and write
clean
7FF586E95000
unkown image
page readonly
clean
401000
unkown image
page execute read
clean
205B5A30000
unkown
page read and write
clean
9A000
unkown
page read and write
clean
2A2E000
stack
page read and write
clean