IOC Report

loading gif

Files

File Path
Type
Category
Malicious
PKO_TRANS_DETAILS_20211216_0809521.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Temp\~DF96836616C4B0B991.TMP
Composite Document File V2 Document, Cannot read section info
dropped
clean
C:\Users\user\AppData\Roaming\u2trkkyb.crc\Chrome\Default\Cookies
SQLite 3.x database, last written using SQLite version 3035005
dropped
clean
C:\Users\user\AppData\Roaming\u2trkkyb.crc\Firefox\Profiles\ol7uiqa8.default-release\cookies.sqlite
SQLite 3.x database, user version 12, last written using SQLite version 3036000
modified
clean
\Device\ConDrv
ASCII text, with CRLF line terminators
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\PKO_TRANS_DETAILS_20211216_0809521.exe
"C:\Users\user\Desktop\PKO_TRANS_DETAILS_20211216_0809521.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
"C:\Users\user\Desktop\PKO_TRANS_DETAILS_20211216_0809521.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
"C:\Users\user\Desktop\PKO_TRANS_DETAILS_20211216_0809521.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
clean

URLs

Name
IP
Malicious
https://drive.google.com/~
unknown
clean
https://ffT40WCIhVVniAbESQ.comt-
unknown
clean
http://127.0.0.1:HTTP/1.1
unknown
clean
http://DynDns.comDynDNS
unknown
clean
http://repository.certum.pl/ctnca.cer09
unknown
clean
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
unknown
clean
http://crl.certum.pl/ctnca.crl0k
unknown
clean
http://yandex.crl.certum.pl/ycasha2.crl0q
unknown
clean
https://ffT40WCIhVVniAbESQ.com
unknown
clean
https://support.google.com/chrome/?p=plugin_flash
unknown
clean
https://doc-00-10-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/1h4vdo343qt36t0eav1jpdhsqf81bcjc/1639657200000/05069790638565246300/*/1byST7n55z6cYoUjFqb0Ef6QjVn6HNywC?e=download
142.250.185.129
clean
https://www.certum.pl/CPS0
unknown
clean
http://smtp.yandex.com
unknown
clean
http://yandex.ocsp-responder.com03
unknown
clean
http://subca.ocsp-certum.com0.
unknown
clean
http://repository.certum.pl/ca.cer09
unknown
clean
http://crls.yandex.net/certum/ycasha2.crl0-
unknown
clean
http://eVxhAq.com
unknown
clean
https://drive.google.com/
unknown
clean
http://subca.ocsp-certum.com01
unknown
clean
http://crl.certum.pl/ca.crl0h
unknown
clean
http://www.certum.pl/CPS0
unknown
clean
https://doc-00-10-docs.googleusercontent.com/
unknown
clean
http://repository.certum.pl/ycasha2.cer0
unknown
clean
https://csp.withgoogle.com/csp/report-to/gse_l9ocaq
unknown
clean
https://doc-00-10-docs.googleusercontent.com/2
unknown
clean
https://doc-00-10-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/1h4vdo34
unknown
clean
There are 17 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
smtp.yandex.ru
77.88.21.158
clean
drive.google.com
216.58.212.174
clean
googlehosted.l.googleusercontent.com
142.250.185.129
clean
doc-00-10-docs.googleusercontent.com
unknown
clean
smtp.yandex.com
unknown
clean

IPs

IP
Domain
Country
Malicious
142.250.185.129
googlehosted.l.googleusercontent.com
United States
clean
77.88.21.158
smtp.yandex.ru
Russian Federation
clean
216.58.212.174
drive.google.com
United States
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
1DD01000
unkown
page read and write
malicious
BC0000
unkown
page execute and read and write
malicious
2B70000
unkown
page execute and read and write
malicious
1CC31000
unkown
page read and write
clean
1DBB0000
unkown
page read and write
clean
550000
unkown image
page readonly
clean
1CC31000
unkown
page read and write
clean
64E000
unkown
page read and write
clean
F50000
stack
page read and write
clean
1CC31000
unkown
page read and write
clean
1DBB0000
unkown
page read and write
clean
64E000
unkown
page read and write
clean
64E000
unkown
page read and write
clean
1CC31000
unkown
page read and write
clean
1CC31000
unkown
page read and write
clean
213A0000
unkown
page read and write
clean
1CC31000
unkown
page read and write
clean
1DBB0000
unkown
page read and write
clean
1CC31000
unkown
page read and write
clean
1CC31000
unkown
page read and write
clean
1CC31000
unkown
page read and write
clean
1CC31000
unkown
page read and write
clean
235DA06C000
unkown
page read and write
clean
F91000
stack
page read and write
clean
E45000
heap default
page read and write
clean
F90000
stack
page read and write
clean
64E000
unkown
page read and write
clean