IOC Report

loading gif

Files

File Path
Type
Category
Malicious
fw8ex1BNek.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\DB56.exe.log
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Local\Temp\4924.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\8CE5.exe
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
dropped
malicious
C:\Users\user\AppData\Local\Temp\DB56.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
modified
malicious
C:\Users\user\AppData\Roaming\acgvitw
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Roaming\acgvitw:Zone.Identifier
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Local\Temp\Wamozart6.dat
DOS executable (COM)
dropped
clean
C:\Users\user\AppData\Local\Temp\a.txt
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\nsn7A92.tmp\System.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\fw8ex1BNek.exe
"C:\Users\user\Desktop\fw8ex1BNek.exe"
malicious
C:\Windows\explorer.exe
C:\Windows\Explorer.EXE
malicious
C:\Users\user\AppData\Roaming\acgvitw
C:\Users\user\AppData\Roaming\acgvitw
malicious
C:\Users\user\AppData\Local\Temp\DB56.exe
C:\Users\user\AppData\Local\Temp\DB56.exe
malicious
C:\Users\user\AppData\Local\Temp\DB56.exe
C:\Users\user\AppData\Local\Temp\DB56.exe
malicious
C:\Users\user\AppData\Local\Temp\4924.exe
C:\Users\user\AppData\Local\Temp\4924.exe
malicious
C:\Users\user\AppData\Local\Temp\8CE5.exe
C:\Users\user\AppData\Local\Temp\8CE5.exe
malicious

URLs

Name
IP
Malicious
http://45.9.20.240:7769/Igno.exe
45.9.20.240
malicious
http://e-lanpengeonline.com/upload/
malicious
http://185.112.83.8/InjectHollowing.bin
malicious
http://185.112.83.8/install3.exe
185.112.83.8
malicious
http://galala.ru/upload/
malicious
http://witra.ru/upload/
malicious
http://rcacademy.at/upload/
211.59.14.90
malicious
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Text
unknown
clean
http://schemas.xmlsoap.org/ws/2005/02/sc/sct
unknown
clean
https://duckduckgo.com/chrome_newtab
unknown
clean
http://service.r
unknown
clean
http://schemas.xmlsoap.org/ws/2004/04/security/sc/dk
unknown
clean
https://duckduckgo.com/ac/?q=
unknown
clean
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#HexBinary
unknown
clean
http://tempuri.org/Entity/Id12Response
unknown
clean
http://tempuri.org/
unknown
clean
http://tempuri.org/Entity/Id2Response
unknown
clean
http://schemas.xmlsoap.org/ws/2005/02/sc/dk/p_sha1
unknown
clean
http://tempuri.org/Entity/Id21Response
unknown
clean
http://schemas.xmlsoap.org/2005/02/trust/spnego#GSS_Wrap
unknown
clean
http://tempuri.org/Entity/Id9
unknown
clean
http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLID
unknown
clean
http://tempuri.org/Entity/Id8
unknown
clean
http://tempuri.org/Entity/Id5
unknown
clean
http://schemas.xmlsoap.org/ws/2004/10/wsat/Prepare
unknown
clean
http://tempuri.org/Entity/Id4
unknown
clean
http://tempuri.org/Entity/Id7
unknown
clean
http://tempuri.org/Entity/Id6
unknown
clean
http://schemas.xmlsoap.org/ws/2005/02/trust#BinarySecret
unknown
clean
https://support.google.com/chrome/?p=plugin_real
unknown
clean
http://tempuri.org/Entity/Id19Response
unknown
clean
http://docs.oasis-open.org/wss/oasis-wss-rel-token-profile-1.0.pdf#license
unknown
clean
http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/Issue
unknown
clean
http://www.interoperabilitybridges.com/wmp-extension-for-chrome
unknown
clean
http://schemas.xmlsoap.org/ws/2004/10/wsat/Aborted
unknown
clean
http://schemas.xmlsoap.org/ws/2005/02/rm/TerminateSequence
unknown
clean
https://support.google.com/chrome/?p=plugin_pdf
unknown
clean
http://schemas.xmlsoap.org/ws/2004/10/wsat/fault
unknown
clean
http://schemas.xmlsoap.org/ws/2004/10/wsat
unknown
clean
http://docs.oasis-open.org/wss/oasis-wss-soap-message-security-1.1#EncryptedKey
unknown
clean
http://tempuri.org/Entity/Id15Response
unknown
clean
https://bastinscustomfab.com/veldolore/scc.exe
50.62.140.96
clean
https://cdn.discordapp.com/attachments/921473641538027521/921473810035793960/Vorticism.exe
162.159.134.233
clean
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
clean
http://forms.real.com/real/realone/download.html?type=rpsp_us
unknown
clean
http://support.a
unknown
clean
http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/SCT/Renew
unknown
clean