IOC Report

loading gif

Files

File Path
Type
Category
Malicious
Sipari#U015f formu.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Windows\System32\drivers\etc\hosts
ASCII text, with CRLF line terminators
modified
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Sipari#U015f formu.exe.log
ASCII text, with CRLF line terminators
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Sipari#U015f formu.exe
"C:\Users\user\Desktop\Sipari#U015f formu.exe"
malicious
C:\Users\user\Desktop\Sipari#U015f formu.exe
C:\Users\user\Desktop\Sipari#U015f formu.exe
malicious

URLs

Name
IP
Malicious
http://127.0.0.1:HTTP/1.1
unknown
clean
https://api.ipify.org%GETMozilla/5.0
unknown
clean
http://DynDns.comDynDNS
unknown
clean
https://api.telegram.org/bot2124462934:AAGr-L06waDdFGpnKJz3_DCOFcJpWDQ7WIM/sendDocumentdocument-----
unknown
clean
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
unknown
clean
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
clean
http://nQZIDO.com
unknown
clean
https://api.ipify.org%
unknown
clean
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
unknown
clean
https://api.telegram.org/bot2124462934:AAGr-L06waDdFGpnKJz3_DCOFcJpWDQ7WIM/
unknown
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
402000
unkown
page execute and read and write
malicious
402000
unkown
page execute and read and write
malicious
2D31000
unkown
page read and write
malicious
2A51000
unkown
page read and write
malicious
3D3D000
unkown
page read and write
malicious
2DF5000
unkown
page read and write
malicious
402000
unkown
page execute and read and write
malicious
402000
unkown
page execute and read and write
malicious
402000
unkown
page execute and read and write
malicious
6490000
unkown
page read and write
clean
BCB000
unkown
page read and write
clean
AF4000
unkown
page read and write
clean
20C1CE00000
unkown
page read and write
clean
AF4000
unkown
page read and write
clean
AF4000
unkown
page read and write
clean
AF4000
unkown
page read and write
clean
DE0000
stack
page read and write
clean
AF4000
unkown
page read and write
clean
7F280000
unkown image
page readonly
clean
AF4000
unkown
page read and write
clean
B00000
stack
page read and write
clean
299C000
unkown
page read and write
clean
AF4000
unkown
page read and write
clean
AF4000
unkown
page read and write
clean
1B2AA2B0000
unkown
page read and write
clean
7FF5CF86A000
unkown image
page readonly
clean
5605000
unkown
page read and write
clean
29D0000
unkown
page read and write
clean
AF4000
unkown
page read and write
clean
60E9000
unkown
page read and write
clean
2167A530000
unkown image
page readonly
clean
AF4000
unkown
page read and write
clean
27D18813000
unkown
page read and write
clean
55B0000
unkown
page read and write
clean
29D5000
unkown
page read and write
clean
AF4000
unkown
page read and write
clean
5450000
unkown
page read and write
clean
B00000
stack
page read and write
clean
7DF529782000
unkown image
page readonly
clean
5370000
heap private
page read and write
clean
AF4000
unkown
page read and write
clean
2D2F000
stack
page read and write
clean
2167AFB8000
unkown
page read and write
clean
AF4000
unkown
page read and write
clean
B10000
stack
page read and write
clean
AF4000
unkown
page read and write
clean
2167AFAD000
unkown
page read and write
clean
C40000
stack
page read and write
clean
C19000
unkown
page read and write
clean
2167B49D000
unkown
page read and write
clean
5D2F000
stack
page read and write
clean
6410000
unkown
page read and write
clean
AF4000
unkown
page read and write
clean
AF4000
unkown
page read and write
clean