IOC Report

loading gif

Files

File Path
Type
Category
Malicious
FACTURAS.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Temp\M9XgMRXaN30mgEl56ja236
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF503944F8FF7253A1.TMP
Composite Document File V2 Document, Cannot read section info
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\FACTURAS.exe
"C:\Users\user\Desktop\FACTURAS.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
"C:\Users\user\Desktop\FACTURAS.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
"C:\Users\user\Desktop\FACTURAS.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
clean

URLs

Name
IP
Malicious
https://doc-0g-7s-docs.googleusercontent.com/
unknown
clean
http://127.0.0.1:HTTP/1.1
unknown
clean
http://DynDns.comDynDNS
unknown
clean
https://doc-0g-7s-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/09s7mqju06nhfef03e9jkahgn04c8qp1/1639485750000/01707528263340534167/*/1e3nVGX3LlhNn9Zf6RwTjDw6FKTCAih9T?e=download
142.250.181.225
clean
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
unknown
clean
https://drive.google.com/
unknown
clean
https://drive.google.com/st
unknown
clean
https://doc-0g-7s-docs.googleusercontent.com/e
unknown
clean
https://doc-0g-7s-docs.googleusercontent.com/1
unknown
clean
http://kFWRbv.com
unknown
clean
https://doc-0g-7s-docs.googleusercontent.com/u
unknown
clean
https://doc-0g-7s-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/09s7mqju
unknown
clean
https://csp.withgoogle.com/csp/report-to/gse_l9ocaq
unknown
clean
There are 3 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
drive.google.com
142.250.181.238
clean
googlehosted.l.googleusercontent.com
142.250.181.225
clean
doc-0g-7s-docs.googleusercontent.com
unknown
clean

IPs

IP
Domain
Country
Malicious
142.250.181.238
drive.google.com
United States
clean
142.250.181.225
googlehosted.l.googleusercontent.com
United States
clean

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\VB and VBA Program Settings\Turcize6\Sacrocotyloidean8
SLIDFAST
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
1DF31000
unkown
page read and write
malicious
E10000
unkown
page execute and read and write
malicious
1EF59000
unkown
page read and write
clean
424000
unkown image
page readonly
clean
1CD51000
unkown
page read and write
clean
1CD51000
unkown
page read and write
clean
2370000
heap private
page read and write
clean
1CD51000
unkown
page read and write
clean
1DEE0000
unkown
page read and write
clean
1CD51000
unkown
page read and write
clean
20265000
unkown
page read and write
clean
201EE000
unkown
page read and write
clean
1CD51000
unkown
page read and write
clean
7F220000
unkown image
page readonly
clean
20400000
heap private
page execute and read and write
clean
7F240000
unkown image
page readonly
clean
B40000
unkown
page read and write
clean
1CD51000
unkown
page read and write
clean
2C50000
heap private
page read and write
clean
1CD51000
unkown
page read and write
clean
1CD51000
unkown
page read and write
clean
B41000
unkown
page read and write
clean
BF0000
unkown image
page readonly
clean
1DFE3000
unkown
page read and write
clean
1DFF6000
unkown
page read and write
clean
BE0000
unkown image
page readonly
clean
1DCC7000
stack
page read and write
clean
7F7E0000
unkown image
page readonly
clean
7F240000
unkown image
page readonly
clean
A10000
unkown image
page readonly
clean
BF0000
unkown image
page readonly
clean
1DF10000
unkown image
page readonly
clean
7FFB0000
unkown image
page readonly
clean
1DED0000
unkown
page execute and read and write
clean
1CD51000
unkown
page read and write
clean
20260000
unkown
page read and write
clean
1CD51000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
1CD51000
unkown
page read and write
clean
1CD51000
unkown
page read and write
clean
1DD26000
unkown
page execute and read and write
clean
3239000
unkown
page read and write
clean
7F222000
unkown image
page readonly
clean
1D2F1000
unkown
page read and write