IOC Report

loading gif

Files

File Path
Type
Category
Malicious
Hong Tak Engineering SB Payment Receipt 241121_PDF.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Temp\Agerhnsjagtfi\Countysygej.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\~DFDA925A6B9EAC6C8F.TMP
Composite Document File V2 Document, Cannot read section info
dropped
clean
C:\Users\user\AppData\Roaming\wifitskl\logs.dat
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Hong Tak Engineering SB Payment Receipt 241121_PDF.exe
"C:\Users\user\Desktop\Hong Tak Engineering SB Payment Receipt 241121_PDF.exe"
malicious
C:\Program Files (x86)\Internet Explorer\ieinstal.exe
"C:\Users\user\Desktop\Hong Tak Engineering SB Payment Receipt 241121_PDF.exe"
malicious

URLs

Name
IP
Malicious
https://onedrive.live.com/download?cid=7FA6B3539DFD0E74&resid=7FA6B3539DFD0E74%211122&authkey=AFlmPX
unknown
clean
https://7ybh4q.bn.files.1drv.com/D
unknown
clean
https://onedrive.live.com/download?cid=7FA6B3
clean
https://7ybh4q.bn.files.1drv.com/
unknown
clean
https://7ybh4q.bn.files.1drv.com/f
unknown
clean
https://7ybh4q.bn.files.1drv.com/y4mrYMhoGbjFe4lMap9L9LeL2yBCYdzRMAuRmtg6XK6YTbK2Pi7yHWQHU8EnZiLbINN
unknown
clean
https://onedrive.live.com/E
unknown
clean
https://onedrive.live.com/
unknown
clean

Domains

Name
IP
Malicious
olufem.ddns.net
124.82.81.98
malicious
onedrive.live.com
unknown
clean
7ybh4q.bn.files.1drv.com
unknown
clean

IPs

IP
Domain
Country
Malicious
124.82.81.98
olufem.ddns.net
Malaysia
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Tanadarforurenings
clean
HKEY_CURRENT_USER\SOFTWARE\audiotsk-5IOG84
exepath
clean
HKEY_CURRENT_USER\SOFTWARE\audiotsk-5IOG84
licence
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
302B000
heap default
page read and write
malicious
22D0000
unkown
page execute and read and write
malicious
2CE0000
unkown
page execute and read and write
malicious
183BEEC0000
unkown
page read and write
clean
732F5FF000
stack
page read and write
clean
2887A813000
unkown
page read and write
clean
225CA55F000
unkown
page read and write
clean
225CAB46000
unkown
page read and write
clean
1E6BD53D000
unkown
page read and write
clean
225CA4B6000
unkown
page read and write
clean
225CA56A000
unkown
page read and write
clean
225CA56E000
unkown
page read and write
clean
225CA603000
unkown
page read and write
clean
225CAE34000
unkown
page read and write
clean
7FF57814D000
unkown image
page readonly
clean
1FC154EA000
unkown
page read and write
clean
1FC154BB000
unkown
page read and write
clean
1B372800000
unkown
page read and write
clean
7FF4E889A000
unkown image
page readonly
clean
7FF4EA14B000
unkown image
page readonly
clean
29A924FA000
unkown
page read and write
clean
308E000
stack
page read and write
clean
7DF555A80000
unkown image
page readonly
clean
2BFA4006000
unkown
page read and write
clean
29A93FD0000
unkown
page read and write
clean
7FF53A01D000
unkown image
page readonly
clean
1FC14B50000
unkown
page read and write
clean
1FC1571A000
heap private
page read and write
clean
7FF53A000000
unkown image
page readonly
clean
7FF53CFEF000
unkown image
page readonly
clean
225CA5C6000
unkown
page read and write
clean
7FF4E882D000
unkown image
page readonly
clean
1F05F110000
unkown image
page readonly
clean
2AAE000
unkown image
page readonly
clean
7FF53CEFC000
unkown image
page readonly
clean
7FF57819D000
unkown image
page readonly
clean
7FF4F72D8000
unkown image
page readonly
clean
1EAEC000
stack
page read and write
clean
225CA4B7000
unkown
page read and write
clean
7FF4F7233000
unkown image
page readonly
clean
1E6BC9B0000
unkown image
page read and write
clean
24A71C50000
unkown image
page readonly
clean
1F05FB2A000
unkown
page read and write
clean
7FF509601000
unkown image
page readonly
clean
225CA62A000
unkown
page read and write
clean
1E6BCC7E000
unkown
page read and write
clean
1F05FB70000
unkown
page read and write
clean
225CA587000
unkown
page read and write
clean
7FF5075C1000
unkown image
page readonly
clean