IOC Report

loading gif

Files

File Path
Type
Category
Malicious
SecuriteInfo.com.MachineLearning.Anomalous.94.14541.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
data
dropped
clean
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_b1j2o2gx.24c.psm1
very short file (no magic)
dropped
clean
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_f0qsiy5n.jol.ps1
very short file (no magic)
dropped
clean
C:\Users\user\Documents\20211125\PowerShell_transcript.287400.d+yQR6Ej.20211125140539.txt
UTF-8 Unicode (with BOM) text, with CRLF line terminators
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.MachineLearning.Anomalous.94.14541.exe
"C:\Users\user\Desktop\SecuriteInfo.com.MachineLearning.Anomalous.94.14541.exe"
malicious
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\SecuriteInfo.com.MachineLearning.Anomalous.94.14541.exe
malicious
C:\Users\user\Desktop\SecuriteInfo.com.MachineLearning.Anomalous.94.14541.exe
C:\Users\user\Desktop\SecuriteInfo.com.MachineLearning.Anomalous.94.14541.exe
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
clean

URLs

Name
IP
Malicious
http://127.0.0.1:HTTP/1.1
unknown
clean
https://api.ipify.org%GETMozilla/5.0
unknown
clean
http://DynDns.comDynDNS
unknown
clean
http://XYJLds.com
unknown
clean
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
unknown
clean
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
clean
https://api.ipify.org%
unknown
clean
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
unknown
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
402000
unkown
page execute and read and write
malicious
2AA6000
unkown
page read and write
malicious
360D000
unkown
page read and write
malicious
402000
unkown
page execute and read and write
malicious
402000
unkown
page execute and read and write
malicious
29F1000
unkown
page read and write
malicious
402000
unkown
page execute and read and write
malicious
26CB000
unkown
page read and write
malicious
402000
unkown
page execute and read and write
malicious
2601000
unkown
page read and write
malicious
50E1000
unkown
page read and write
clean
1AC70A61000
heap default
page read and write
clean
50E1000
unkown
page read and write
clean
50E1000
unkown
page read and write
clean
B60000
stack
page read and write
clean
1C0000
unkown image
page readonly
clean
4C30000
unkown
page read and write
clean
2835000
unkown
page read and write
clean
7FF56DBD7000
unkown image
page readonly
clean
7FF549C3F000
unkown image
page readonly
clean
B60000
stack
page read and write
clean
4E45000
unkown
page read and write
clean
BE2000
unkown
page read and write
clean
5030000
unkown
page read and write
clean
A40000
stack
page read and write
clean
50E1000
unkown
page read and write
clean
4AA0000
unkown
page read and write
clean
A30000
stack
page read and write
clean
7B0000
unkown image
page readonly
clean
7FF52904A000
unkown image
page readonly
clean
A30000
stack
page read and write
clean
50E1000
unkown
page read and write
clean
5B5D000
stack
page read and write
clean
A30000
stack
page read and write
clean
50E1000
unkown
page read and write
clean
50E1000
unkown
page read and write
clean
7A8000
unkown
page read and write
clean
2688000
unkown
page read and write
clean
7FAA0000
unkown image
page readonly
clean
7FF5891C6000
unkown image
page readonly
clean
3DC827C000
stack
page read and write
clean
1FB634C0000
unkown
page read and write
clean
A21000
stack
page read and write
clean
1AC71540000
unkown
page read and write
clean
2830000
unkown
page read and write
clean
7FF5BA627000
unkown image
page readonly
clean
5E5D000
stack
page read and write
clean
50E1000
unkown
page read and write
clean
2854000
unkown
page read and write
clean
7FAA0000