IOC Report

loading gif

Files

File Path
Type
Category
Malicious
SWIFT_ACK-89813.02.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Temp\~DFA1C4850DA9C6EF9A.TMP
Composite Document File V2 Document, Cannot read section info
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SWIFT_ACK-89813.02.exe
"C:\Users\user\Desktop\SWIFT_ACK-89813.02.exe"
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\subideal\Eyeliners
HARNISKKLDT
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
23F0000
unkown
page execute and read and write
malicious
400000
unkown image
page readonly
clean
2011F51F000
unkown
page read and write
clean
7DF5C9182000
unkown image
page readonly
clean
16F9FBA0000
unkown image
page readonly
clean
216F9FF000
stack
page read and write
clean
7DF5B5AE2000
unkown image
page readonly
clean
16F9FCFF000
unkown
page read and write
clean
2011EC00000
heap default
page read and write
clean
2011F557000
unkown
page read and write
clean
7DF5E8990000
unkown image
page readonly
clean
216FAFF000
stack
page read and write
clean
7DF5E89B0000
unkown image
page readonly
clean
7FF5DAD2A000
unkown image
page readonly
clean
A385578000
stack
page read and write
clean
2011EF16000
unkown
page read and write
clean
7FF5DAC67000
unkown image
page readonly
clean
7FF5A76FE000
unkown image
page readonly
clean
429000
unkown image
page read and write
clean
7DF5C9190000
unkown image
page readonly
clean
7FF5A7D76000
unkown image
page readonly
clean
3C9000
unkown
page read and write
clean
7FF513C87000
unkown image
page readonly
clean
7FF5BB423000
unkown image
page readonly
clean
16FA0260000
unkown image
page readonly
clean
2011F5C3000
unkown
page read and write
clean
2011F380000
unkown image
page readonly
clean
7FF5BB079000
unkown image
page readonly
clean
2420000
heap private
page read and write
clean
7FF5BB50A000
unkown image
page readonly
clean
7FF5BB21B000
unkown image
page readonly
clean
16FA5580000
unkown
page read and write
clean
7DF5ABDA0000
unkown image
page readonly
clean
25F16FF000
stack
page read and write
clean
2011F5AC000
unkown
page read and write
clean
7DF5B5AE2000
unkown image
page readonly
clean
7FF5DC6E1000
unkown image
page readonly
clean
7DF52D682000
unkown image
page readonly
clean
216F8FF000
stack
page read and write
clean
2011F960000
unkown
page read and write
clean
7FF59E047000
unkown image
page readonly
clean
216FB7E000
stack
page read and write
clean
16FA00D0000
unkown image
page readonly
clean
16FA5242000
unkown
page read and write
clean
7FF5BAE7B000
unkown image
page readonly
clean
269D2600000
unkown image
page readonly
clean
68A000
heap default
page read and write
clean
7FF5134BD000
unkown image
page readonly
clean
2011F5D1000
unkown
page read and write
clean
1C328500000
unkown image
page readonly
clean
1F38864B000
unkown
page read and write
clean
7FF5BB322000
unkown image
page readonly
clean
26EBA700000
unkown
page read and write
clean
A3853F7000
stack
page read and write
clean
7FF5DC63E000
unkown image
page readonly
clean
7FF59E040000
unkown image
page readonly
clean
E596C7B000
stack
page read and write
clean
7DF521972000
unkown image
page readonly
clean
2011F5C2000
unkown
page read and write
clean
7FF5BB430000
unkown image
page readonly
clean
CD7B17F000
stack
page read and write
clean
16FA00E0000
unkown image
page readonly
clean
560000
heap default
page read and write
clean
7DF52D672000
unkown image
page readonly
clean
7FF51F81F000
unkown image
page readonly
clean
7FF51F930000
unkown image
page readonly
clean
2011F529000
unkown
page read and write
clean
401000
unkown image
page execute read
clean
25F1679000
stack
page read and write
clean
2011F589000
unkown
page read and write
clean
7FF59E10A000
unkown image
page readonly
clean
1F388570000
unkown image
page readonly
clean
26EBA64C000
unkown
page read and write
clean