IOC Report

loading gif

Files

File Path
Type
Category
Malicious
SK TAX INV.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\SK TAX INV.exe.log
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat
data
dropped
malicious
C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe:Zone.Identifier
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\catalog.dat
data
dropped
clean
C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\settings.bin
data
modified
clean
C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\storage.dat
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SK TAX INV.exe
"C:\Users\user\Desktop\SK TAX INV.exe"
malicious
C:\Users\user\Desktop\SK TAX INV.exe
C:\Users\user\Desktop\SK TAX INV.exe
malicious
C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe
"C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe"
malicious

URLs

Name
IP
Malicious
dera31.ddns.net
malicious
195.133.18.211
malicious
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
clean

Domains

Name
IP
Malicious
dera31.ddns.net
194.85.248.250
malicious

IPs

IP
Domain
Country
Malicious
194.85.248.250
dera31.ddns.net
Russian Federation
malicious

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
DHCP Monitor
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
402000
unkown
page execute and read and write
malicious
402000
unkown
page execute and read and write
malicious
3B11000
unkown
page read and write
malicious
402000
unkown
page execute and read and write
malicious
402000
unkown
page execute and read and write
malicious
28A1000
unkown
page read and write
malicious
2965000
unkown
page read and write
malicious
6261000
unkown
page read and write
clean
6261000
unkown
page read and write
clean
7F240000
unkown image
page readonly
clean
6E03000
unkown
page read and write
clean
57C0000
unkown
page read and write
clean
6E03000
unkown
page read and write
clean
7F250000
unkown image
page readonly
clean
128D000
unkown
page read and write
clean
6DF8000
unkown
page read and write
clean
6281000
unkown
page read and write
clean
14CB5290000
heap private
page read and write
clean
7CC1000
unkown
page read and write
clean
5520000
unkown
page read and write
clean
7040000
unkown
page read and write
clean
9A6000
unkown
page execute and read and write
clean
62A3000
unkown
page read and write
clean
7FF513BAF000
unkown image
page readonly
clean
2C6F77E000
stack
page read and write
clean
6261000
unkown
page read and write
clean
7F230000
unkown image
page readonly
clean
62A3000
unkown
page read and write
clean
7FF531CC4000
unkown image
page readonly
clean
5370000
unkown
page read and write
clean
6110000
unkown
page read and write
clean
6D91000
unkown
page read and write
clean
14CB537A000
unkown
page read and write
clean
6E22000
unkown
page read and write
clean
6E1E000
unkown
page read and write
clean
2234A06E000
unkown
page read and write
clean
6E1E000
unkown
page read and write
clean
A97000
unkown
page read and write
clean
D787977000
stack
page read and write
clean
5510000
unkown
page read and write
clean
7FF572474000
unkown image
page readonly
clean
6DF8000
unkown
page read and write
clean
6E26000
unkown
page read and write
clean