IOC Report

loading gif

Files

File Path
Type
Category
Malicious
REVGKXx6Ns.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Temp\~DF0E195A349794F694.TMP
Composite Document File V2 Document, Cannot read section info
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\REVGKXx6Ns.exe
"C:\Users\user\Desktop\REVGKXx6Ns.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
"C:\Users\user\Desktop\REVGKXx6Ns.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
clean

URLs

Name
IP
Malicious
https://drive.google.com/0Y
unknown
clean
https://drive.google.com/obal
unknown
clean
https://drive.google.com/A-
unknown
clean
https://drive.google.com/a-
unknown
clean
http://www.topqualityfreeware.com/
unknown
clean
https://drive.google.com/
unknown
clean
https://drive.google.com/)-
unknown
clean
https://drive.google.com/3
unknown
clean
https://drive.google.com/crosoft
unknown
clean
https://drive.google.com/1-
unknown
clean
https://drive.google.com/q-
unknown
clean
http://topqualityfreeware.com
unknown
clean
https://drive.google.com/rA-
unknown
clean
https://drive.google.com/Aq
unknown
clean
https://drive.google.com/_1
unknown
clean
https://drive.google.com/y-
unknown
clean
https://drive.google.com/a
unknown
clean
https://csp.withgoogle.com/csp/report-to/gse_l9ocaq
unknown
clean
https://drive.google.com/20000Z
unknown
clean
There are 9 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
drive.google.com
142.250.186.174
clean

IPs

IP
Domain
Country
Malicious
142.250.186.174
drive.google.com
United States
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
F00000
unkown
page execute and read and write
malicious
7FF510AF0000
unkown image
page readonly
clean
2C1D788D000
unkown
page read and write
clean
21C35C93000
unkown
page read and write
clean
1116000
unkown
page read and write
clean
1108000
unkown
page read and write
clean
1108000
unkown
page read and write
clean
1D7D848F000
unkown
page read and write
clean
107D000
unkown
page read and write
clean
5315CFD000
stack
page read and write
clean
1116000
unkown
page read and write
clean
1108000
unkown
page read and write
clean
1C639A85000
unkown
page read and write
clean
10C5000
unkown
page read and write
clean
110F000
unkown
page read and write
clean
107D000
unkown
page read and write
clean
1FD7E67E000
unkown
page read and write
clean
110F000
unkown
page read and write
clean
1FD7E0E5000
heap private
page read and write
clean
107D000
unkown
page read and write
clean
1108000
unkown
page read and write
clean
1116000
unkown
page read and write
clean
1FD7EDF5000
unkown
page read and write
clean
7FF58E0CD000
unkown image
page readonly
clean
557000
unkown
page read and write
clean
B44DC7C000
stack
page read and write
clean
7FF5B5EBF000
unkown image
page readonly
clean
7FF54B612000
unkown image
page readonly
clean
1061000
unkown
page read and write
clean
7DF502560000
unkown image
page readonly
clean
2DDBD902000
unkown
page read and write