Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
CI_PL_BL_ 4100675407_xls.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Users\user\AppData\Local\Temp\~DF3A963BF3568977ED.TMP
|
Composite Document File V2 Document, Cannot read section info
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\CI_PL_BL_ 4100675407_xls.exe
|
"C:\Users\user\Desktop\CI_PL_BL_ 4100675407_xls.exe"
|
||
C:\Users\user\Desktop\CI_PL_BL_ 4100675407_xls.exe
|
"C:\Users\user\Desktop\CI_PL_BL_ 4100675407_xls.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://bgreenidaho.com/
|
unknown
|
||
https://bgreenidaho.com/Crur/bin_TLiGMZYC180.bin
|
|||
https://bgreenidaho.com/Crur/bin_TLiGMZYC180.binF
|
unknown
|
||
https://bgreenidaho.com/R
|
unknown
|
||
https://bgreenidaho.com/ocal
|
unknown
|
||
https://bgreenidaho.com/v
|
unknown
|
||
https://bgreenidaho.com/3
|
unknown
|
||
https://bgreenidaho.com/Crur/bin_TLiGMZYC180.bin#
|
unknown
|
||
https://bgreenidaho.com/Crur/bin_TLiGMZY6
|
unknown
|
||
https://bgreenidaho.com/Crur/bin_TLiGMZYC180.binws
|
unknown
|
||
https://bgreenidaho.com/Crur/bin_TLiGMZYC180.binLMEMH
|
unknown
|
||
https://bgreenidaho.com/Crur/bin_TLiGMZYC180.bins
|
unknown
|
||
https://bgreenidaho.com/Hostbgre
|
unknown
|
||
https://bgreenidaho.com/Crur/bin_TLiGMZYC180.binn
|
unknown
|
||
https://bgreenidaho.com/1e03818b-e8b8-45f4-bd74-707e0f15a35d
|
unknown
|
||
https://bgreenidaho.com/Crur/bin_TLiGMZYC180.bindvmbusRFCOMM
|
unknown
|
||
https://bgreenidaho.com/g
|
unknown
|
||
https://bgreenidaho.com/8-45f4-bd74-707e0f15a35d0
|
unknown
|
||
https://bgreenidaho.com/Crur/bin_TLiGMZYC180.binJ
|
unknown
|
||
https://bgreenidaho.com/N
|
unknown
|
||
https://bgreenidaho.com/n
|
unknown
|
||
https://bgreenidaho.com/-
|
unknown
|
||
https://bgreenidaho.com/nidaho.com/:
|
unknown
|
There are 13 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
bgreenidaho.com
|
20.124.109.2
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
20.124.109.2
|
bgreenidaho.com
|
United States
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
2510000
|
unkown
|
page execute and read and write
|
||
560000
|
unkown
|
page execute and read and write
|
||
8588E8B000
|
unkown
|
page read and write
|
||
24BB73E0000
|
unkown image
|
page readonly
|
||
881000
|
unkown
|
page read and write
|
||
8A3000
|
unkown
|
page read and write
|
||
560000
|
heap default
|
page read and write
|
||
8B3000
|
unkown
|
page read and write
|
||
1A0000
|
unkown image
|
page readonly
|
||
8AF000
|
unkown
|
page read and write
|
||
7EE000
|
stack
|
page read and write
|
||
1D0000
|
unkown image
|
page readonly
|
||
7FF561DCB000
|
unkown image
|
page readonly
|
||
8AF000
|
unkown
|
page read and write
|
||
24BB73D0000
|
unkown image
|
page readonly
|
||
22D0000
|
unkown image
|
page readonly
|
||
8AF000
|
unkown
|
page read and write
|
||
7DF56F5D0000
|
unkown image
|
page readonly
|
||
7FF561969000
|
unkown image
|
page readonly
|
||
40000
|
unkown image
|
page readonly
|
||
89F000
|
unkown
|
page read and write
|
||
1E0000
|
heap default
|
page read and write
|
||
24BB7400000
|
unkown image
|
page readonly
|
||
858957E000
|
stack
|
page read and write
|
||
24BB7410000
|
unkown image
|
page readonly
|
||
337000
|
unkown
|
page read and write
|
||
8AD000
|
unkown
|
page read and write
|
||
A1E000
|
stack
|
page read and write
|
||
8B3000
|
unkown
|
page read and write
|
||
8A1000
|
unkown
|
page read and write
|
||
2400000
|
unkown
|
page read and write
|
||
400000
|
unkown image
|
page readonly
|
||
9C000
|
unkown
|
page read and write
|
||
7FFD0000
|
unkown image
|
page readonly
|
||
401000
|
unkown image
|
page execute read
|
||
630000
|
unkown
|
page execute read
|
||
7FF561D70000
|
unkown image
|
page readonly
|
||
8B3000
|
unkown
|
page read and write
|
||
89F000
|
unkown
|
page read and write
|
||
7FFD0000
|
unkown image
|
page readonly
|
||
879000
|
unkown
|
page read and write
|
||
7FF561D82000
|
unkown image
|
page readonly
|
||
8B3000
|
unkown
|
page read and write
|
||
2D30000
|
unkown image
|
page readonly
|
||
7FF561D7E000
|
unkown image
|
page readonly
|
||
7FF561DFE000
|
unkown image
|
page readonly
|
||
76E000
|
stack
|
page read and write
|
||
C1F000
|
stack
|
page read and write
|
||
1DF40000
|
unkown
|
page read and write
|
||
8A3000
|
unkown
|
page read and write
|
||
86F000
|
unkown
|
page read and write
|
||
24BB764E000
|
unkown
|
page read and write
|
||
7FFB0000
|
unkown image
|
page readonly
|
||
7FFC2000
|
unkown image
|
page readonly
|
||
8A3000
|
unkown
|
page read and write
|
||
7FF561DE8000
|
unkown image
|
page readonly
|
||
7FFC2000
|
unkown image
|
page readonly
|
||
7DF56F5C2000
|
unkown image
|
page readonly
|
||
7FF561D60000
|
unkown image
|
page readonly
|
||
7FF561CE1000
|
unkown image
|
page readonly
|
||
83B000
|
unkown
|
page read and write
|
||
7FFC0000
|
unkown image
|
page readonly
|
||
22E0000
|
unkown image
|
page readonly
|
||
8AA000
|
unkown
|
page read and write
|
||
89F000
|
unkown
|
page read and write
|
||
24BB7648000
|
unkown
|
page read and write
|
||
421000
|
unkown image
|
page read and write
|
||
25F0000
|
unkown
|
page read and write
|
||
7DF56F5B0000
|
unkown image
|
page readonly
|
||
8A1000
|
unkown
|
page read and write
|
||
7FFD0000
|
unkown image
|
page readonly
|
||
7FFB0000
|
unkown image
|
page readonly
|
||
7FFC0000
|
unkown image
|
page readonly
|
||
8AD000
|
unkown
|
page read and write
|
||
8AF000
|
unkown
|
page read and write
|
||
564000
|
unkown
|
page read and write
|
||
7FFC0000
|
unkown image
|
page readonly
|
||
8AA000
|
unkown
|
page read and write
|
||
86B000
|
unkown
|
page read and write
|
||
401000
|
unkown image
|
page execute read
|
||
2F04000
|
heap private
|
page read and write
|
||
2550000
|
unkown
|
page read and write
|
||
24BB7590000
|
unkown
|
page read and write
|
||
86F000
|
unkown
|
page read and write
|
||
8AF000
|
unkown
|
page read and write
|
||
E10000
|
unkown image
|
page readonly
|
||
3359000
|
unkown
|
page read and write
|
||
8AA000
|
unkown
|
page read and write
|
||
7AE000
|
stack
|
page read and write
|
||
1E290000
|
unkown
|
page read and write
|
||
7FFD0000
|
unkown image
|
page readonly
|
||
1C0000
|
unkown image
|
page readonly
|
||
86B000
|
unkown
|
page read and write
|
||
7FFD0000
|
unkown image
|
page readonly
|
||
400000
|
unkown image
|
page readonly
|
||
7DF46D470000
|
unkown image
|
page readonly
|
||
24BB767D000
|
unkown
|
page read and write
|
||
24BB7520000
|
unkown image
|
page readonly
|
||
24BB7640000
|
unkown
|
page read and write
|
||
7FF561C59000
|
unkown image
|
page readonly
|
||
7FFD0000
|
unkown image
|
page readonly
|
||
400000
|
unkown image
|
page readonly
|
||
E60000
|
unkown image
|
page readonly
|
||
7FF561DC4000
|
unkown image
|
page readonly
|
||
881000
|
unkown
|
page read and write
|
||
8AD000
|
unkown
|
page read and write
|
||
400000
|
unkown image
|
page readonly
|
||
7DF56F5D0000
|
unkown image
|
page readonly
|
||
1A0000
|
unkown image
|
page readonly
|
||
7FFC2000
|
unkown image
|
page readonly
|
||
858967A000
|
stack
|
page read and write
|
||
40000
|
unkown image
|
page readonly
|
||
24BB7702000
|
unkown
|
page read and write
|
||
7FF561DA8000
|
unkown image
|
page readonly
|
||
7FF561E08000
|
unkown image
|
page readonly
|
||
A8F000
|
stack
|
page read and write
|
||
10000
|
unkown image
|
page readonly
|
||
89F000
|
unkown
|
page read and write
|
||
87A000
|
unkown
|
page read and write
|
||
7FFD0000
|
unkown image
|
page readonly
|
||
1E290000
|
unkown
|
page read and write
|
||
8A1000
|
unkown
|
page read and write
|
||
400000
|
unkown image
|
page readonly
|
||
7FF561D18000
|
unkown image
|
page readonly
|
||
8AA000
|
unkown
|
page read and write
|
||
24BB7530000
|
unkown image
|
page readonly
|
||
7FFC0000
|
unkown image
|
page readonly
|
||
7F0000
|
unkown image
|
page readonly
|
||
7FFB2000
|
unkown image
|
page readonly
|
||
62E000
|
stack
|
page read and write
|
||
40000
|
unkown image
|
page readonly
|
||
88F000
|
stack
|
page read and write
|
||
41C000
|
unkown image
|
page execute read
|
||
7FFB0000
|
unkown image
|
page readonly
|
||
3320000
|
unkown
|
page read and write
|
||
7FFC2000
|
unkown image
|
page readonly
|
||
7FF561DAF000
|
unkown image
|
page readonly
|
||
1F0000
|
unkown image
|
page readonly
|
||
1B0000
|
unkown
|
page read and write
|
||
40000
|
unkown image
|
page readonly
|
||
7FF561DB6000
|
unkown image
|
page readonly
|
||
1DF2F000
|
stack
|
page read and write
|
||
8A3000
|
unkown
|
page read and write
|
||
401000
|
unkown image
|
page execute read
|
||
24BB7645000
|
unkown
|
page read and write
|
||
8A3000
|
unkown
|
page read and write
|
||
1DB8E000
|
stack
|
page read and write
|
||
871000
|
unkown
|
page read and write
|
||
8A3000
|
unkown
|
page read and write
|
||
881000
|
unkown
|
page read and write
|
||
41C000
|
unkown image
|
page execute read
|
||
8B3000
|
unkown
|
page read and write
|
||
33B000
|
unkown
|
page read and write
|
||
20000
|
unkown image
|
page readonly
|
||
8AF000
|
unkown
|
page read and write
|
||
7FFB2000
|
unkown image
|
page readonly
|
||
7FFB2000
|
unkown image
|
page readonly
|
||
24BB767F000
|
unkown
|
page read and write
|
||
423000
|
unkown image
|
page readonly
|
||
7FFC2000
|
unkown image
|
page readonly
|
||
8AA000
|
unkown
|
page read and write
|
||
8AD000
|
unkown
|
page read and write
|
||
1E0000
|
unkown image
|
page readonly
|
||
852000
|
unkown
|
page read and write
|
||
8A3000
|
unkown
|
page read and write
|
||
889000
|
unkown
|
page read and write
|
||
20000
|
unkown image
|
page readonly
|
||
7FFB0000
|
unkown image
|
page readonly
|
||
401000
|
unkown image
|
page execute read
|
||
1A0000
|
unkown image
|
page readonly
|
||
24CE000
|
stack
|
page read and write
|
||
2300000
|
unkown
|
page read and write
|
||
423000
|
unkown image
|
page readonly
|
||
8AA000
|
unkown
|
page read and write
|
||
7FFC0000
|
unkown image
|
page readonly
|
||
19B000
|
unkown
|
page read and write
|
||
2530000
|
heap private
|
page read and write
|
||
22F9000
|
heap private
|
page read and write
|
||
2589000
|
unkown
|
page read and write
|
||
7FE50000
|
unkown image
|
page readonly
|
||
1DE2E000
|
stack
|
page read and write
|
||
41C000
|
unkown image
|
page execute read
|
||
7DF56F5C0000
|
unkown image
|
page readonly
|
||
564000
|
unkown
|
page read and write
|
||
1A0000
|
unkown image
|
page readonly
|
||
89F000
|
unkown
|
page read and write
|
||
400000
|
unkown image
|
page readonly
|
||
2400000
|
heap private
|
page read and write
|
||
8A1000
|
unkown
|
page read and write
|
||
1C0000
|
unkown image
|
page readonly
|
||
423000
|
unkown image
|
page readonly
|
||
10000
|
unkown image
|
page readonly
|
||
423000
|
unkown image
|
page readonly
|
||
400000
|
unkown image
|
page readonly
|
||
820000
|
heap default
|
page read and write
|
||
7FF561D97000
|
unkown image
|
page readonly
|
||
24BB7690000
|
unkown
|
page read and write
|
||
89F000
|
unkown
|
page read and write
|
||
24BB7540000
|
heap private
|
page read and write
|
||
40000
|
unkown image
|
page readonly
|
||
89F000
|
unkown
|
page read and write
|
||
1A0000
|
unkown image
|
page readonly
|
||
401000
|
unkown image
|
page execute read
|
||
7FFC2000
|
unkown image
|
page readonly
|
||
7FFB2000
|
unkown image
|
page readonly
|
||
89F000
|
unkown
|
page read and write
|
||
24BB766D000
|
unkown
|
page read and write
|
||
8B0000
|
unkown
|
page read and write
|
||
7DF56F5C0000
|
unkown image
|
page readonly
|
||
800000
|
unkown image
|
page readonly
|
||
1F0000
|
unkown image
|
page readonly
|
||
7FFB0000
|
unkown image
|
page readonly
|
||
7FF561C18000
|
unkown image
|
page readonly
|
||
89E000
|
unkown
|
page read and write
|
||
24BB7A00000
|
unkown image
|
page readonly
|
||
24BB73E0000
|
unkown image
|
page readonly
|
||
8AF000
|
unkown
|
page read and write
|
||
560000
|
unkown
|
page execute and read and write
|
||
24BB7571000
|
unkown image
|
page readonly
|
||
889000
|
unkown
|
page read and write
|
||
24BB7B80000
|
unkown image
|
page readonly
|
||
690000
|
heap default
|
page read and write
|
||
1A0000
|
unkown image
|
page readonly
|
||
8AA000
|
unkown
|
page read and write
|
||
7FF561D87000
|
unkown image
|
page readonly
|
||
8A1000
|
unkown
|
page read and write
|
||
7FFB0000
|
unkown image
|
page readonly
|
||
40000
|
unkown image
|
page readonly
|
||
881000
|
unkown
|
page read and write
|
||
7FFB2000
|
unkown image
|
page readonly
|
||
5AE000
|
stack
|
page read and write
|
||
89E000
|
unkown
|
page read and write
|
||
7FFC0000
|
unkown image
|
page readonly
|
||
6B4000
|
heap default
|
page read and write
|
||
7FFC2000
|
unkown image
|
page readonly
|
||
2F10000
|
unkown image
|
page read and write
|
||
7FF561D65000
|
unkown image
|
page readonly
|
||
541000
|
unkown image
|
page readonly
|
||
25E0000
|
heap private
|
page read and write
|
||
2380000
|
unkown image
|
page readonly
|
||
22B0000
|
unkown image
|
page readonly
|
||
1E290000
|
unkown
|
page read and write
|
||
86F000
|
unkown
|
page read and write
|
||
650000
|
unkown
|
page read and write
|
||
500000
|
unkown
|
page read and write
|
||
858947F000
|
stack
|
page read and write
|
||
86F000
|
unkown
|
page read and write
|
||
423000
|
unkown image
|
page readonly
|
||
7FFB2000
|
unkown image
|
page readonly
|
||
86E000
|
unkown
|
page read and write
|
||
24BB768C000
|
unkown
|
page read and write
|
||
1A0000
|
unkown image
|
page readonly
|
||
3AC000
|
unkown
|
page read and write
|
||
8A6000
|
unkown
|
page read and write
|
||
83C000
|
unkown
|
page read and write
|
||
40000
|
unkown image
|
page readonly
|
||
401000
|
unkown image
|
page execute read
|
||
7FFB2000
|
unkown image
|
page readonly
|
||
8A3000
|
unkown
|
page read and write
|
||
7FF561D8A000
|
unkown image
|
page readonly
|
||
86F000
|
unkown
|
page read and write
|
||
30000
|
unkown image
|
page read and write
|
||
7FFD0000
|
unkown image
|
page readonly
|
||
83C000
|
unkown
|
page read and write
|
||
24BB7420000
|
heap default
|
page read and write
|
||
24BB7632000
|
unkown
|
page read and write
|
||
400000
|
unkown image
|
page readonly
|
||
2230000
|
unkown image
|
page read and write
|
||
8A6000
|
unkown
|
page read and write
|
||
889000
|
unkown
|
page read and write
|
||
550000
|
unkown
|
page read and write
|
||
8B0000
|
unkown
|
page read and write
|
||
871000
|
unkown
|
page read and write
|
||
7DF56F5B0000
|
unkown image
|
page readonly
|
||
B1E000
|
stack
|
page read and write
|
||
853000
|
unkown
|
page read and write
|
||
41C000
|
unkown image
|
page execute read
|
||
8B0000
|
unkown
|
page read and write
|
||
30000
|
unkown image
|
page read and write
|
||
7FFC0000
|
unkown image
|
page readonly
|
||
8A1000
|
unkown
|
page read and write
|
||
8A3000
|
unkown
|
page read and write
|
||
83C000
|
heap default
|
page read and write
|
||
89F000
|
unkown
|
page read and write
|
||
7FF561DA5000
|
unkown image
|
page readonly
|
||
7FF561E08000
|
unkown image
|
page readonly
|
||
8A3000
|
unkown
|
page read and write
|
||
FF1000
|
unkown image
|
page readonly
|
||
2410000
|
unkown
|
page read and write
|
||
1A0000
|
unkown image
|
page readonly
|
||
1E13E000
|
stack
|
page read and write
|
||
8AF000
|
unkown
|
page read and write
|
||
24BB7688000
|
unkown
|
page read and write
|
||
89E000
|
unkown
|
page read and write
|
||
828000
|
heap default
|
page read and write
|
||
24BB73C0000
|
unkown image
|
page read and write
|
||
C60000
|
unkown image
|
page readonly
|
||
7FFB0000
|
unkown image
|
page readonly
|
||
7FF561D4A000
|
unkown image
|
page readonly
|
||
8A6000
|
unkown
|
page read and write
|
||
1E421000
|
unkown
|
page read and write
|
||
8A3000
|
unkown
|
page read and write
|
||
1D651000
|
unkown
|
page read and write
|
||
19B000
|
unkown
|
page read and write
|
||
7FFB2000
|
unkown image
|
page readonly
|
||
8A1000
|
unkown
|
page read and write
|
||
7FFC2000
|
unkown image
|
page readonly
|
||
7FFC2000
|
unkown image
|
page readonly
|
||
97000
|
unkown
|
page read and write
|
||
810000
|
unkown image
|
page readonly
|
||
8AC000
|
unkown
|
page read and write
|
||
8A1000
|
unkown
|
page read and write
|
||
41C000
|
unkown image
|
page execute read
|
||
FE0000
|
unkown image
|
page readonly
|
||
89F000
|
unkown
|
page read and write
|
||
C90000
|
unkown image
|
page readonly
|
||
1D1000
|
unkown image
|
page readonly
|
||
7FFD0000
|
unkown image
|
page readonly
|
||
24BB7600000
|
unkown
|
page read and write
|
||
7FFB2000
|
unkown image
|
page readonly
|
||
24BB7800000
|
unkown image
|
page readonly
|
||
22F0000
|
heap private
|
page read and write
|
||
89F000
|
unkown
|
page read and write
|
||
40000
|
unkown image
|
page readonly
|
||
8A6000
|
unkown
|
page read and write
|
||
86B000
|
unkown
|
page read and write
|
||
7DF56F5C2000
|
unkown image
|
page readonly
|
||
871000
|
unkown
|
page read and write
|
||
24BB7684000
|
unkown
|
page read and write
|
||
7FE50000
|
unkown image
|
page readonly
|
||
853000
|
unkown
|
page read and write
|
||
1E23E000
|
stack
|
page read and write
|
||
1E4000
|
unkown
|
page read and write
|
||
2530000
|
unkown
|
page read and write
|
||
7FFD0000
|
unkown image
|
page readonly
|
||
8AA000
|
unkown
|
page read and write
|
||
7FFC0000
|
unkown image
|
page readonly
|
||
87F000
|
unkown
|
page read and write
|
||
69A000
|
heap default
|
page read and write
|
||
1E420000
|
unkown
|
page read and write
|
||
8A1000
|
unkown
|
page read and write
|
||
24BB7613000
|
unkown
|
page read and write
|
||
7FFB0000
|
unkown image
|
page readonly
|
||
8A1000
|
unkown
|
page read and write
|
||
8AF000
|
unkown
|
page read and write
|
||
8A1000
|
unkown
|
page read and write
|
||
83C000
|
unkown
|
page read and write
|
||
8AF000
|
unkown
|
page read and write
|
||
8AA000
|
unkown
|
page read and write
|
||
8A6000
|
unkown
|
page read and write
|
||
7FFC0000
|
unkown image
|
page readonly
|
||
3B0000
|
unkown
|
page read and write
|
||
40000
|
unkown image
|
page readonly
|
||
7DF56F5B2000
|
unkown image
|
page readonly
|
||
23E0000
|
heap private
|
page read and write
|
||
1E421000
|
unkown
|
page read and write
|
||
889000
|
unkown
|
page read and write
|
||
2F00000
|
heap private
|
page read and write
|
||
1D650000
|
unkown
|
page read and write
|
||
8A3000
|
unkown
|
page read and write
|
||
8B3000
|
unkown
|
page read and write
|
||
7DF56F5B2000
|
unkown image
|
page readonly
|
||
24BB7E02000
|
unkown
|
page read and write
|
||
A90000
|
unkown image
|
page readonly
|
||
89F000
|
unkown
|
page read and write
|
||
24BB762A000
|
unkown
|
page read and write
|
||
7FF561C4B000
|
unkown image
|
page readonly
|
||
7FFC0000
|
unkown image
|
page readonly
|
||
41C000
|
unkown image
|
page execute read
|
||
2390000
|
unkown
|
page read and write
|
||
423000
|
unkown image
|
page readonly
|
||
7FFB2000
|
unkown image
|
page readonly
|
||
69D000
|
heap default
|
page read and write
|
||
24BB766F000
|
unkown
|
page read and write
|
||
C20000
|
unkown
|
page read and write
|
||
24BB7654000
|
unkown
|
page read and write
|
||
40000
|
unkown image
|
page readonly
|
||
7FFB0000
|
unkown image
|
page readonly
|
||
7FFC2000
|
unkown image
|
page readonly
|
||
7FFB0000
|
unkown image
|
page readonly
|
||
24BB763C000
|
unkown
|
page read and write
|
||
86B000
|
unkown
|
page read and write
|
There are 372 hidden memdumps, click here to show them.