IOC Report

loading gif

Files

File Path
Type
Category
Malicious
Original Doc Ref SN02853801324189923.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Temp\IXP000.TMP\Semiha.exe
PE32 executable (GUI) Intel 80386, for MS Windows
modified
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Original Doc Ref SN02853801324189923.exe
"C:\Users\user\Desktop\Original Doc Ref SN02853801324189923.exe"
malicious
C:\Users\user\AppData\Local\Temp\IXP000.TMP\Semiha.exe
C:\Users\user~1\AppData\Local\Temp\IXP000.TMP\Semiha.exe
malicious
C:\Users\user\AppData\Local\Temp\IXP000.TMP\Semiha.exe
C:\Users\user~1\AppData\Local\Temp\IXP000.TMP\Semiha.exe
malicious
C:\Windows\explorer.exe
C:\Windows\Explorer.EXE
malicious
C:\Windows\System32\rundll32.exe
C:\Windows\system32\rundll32.exe" C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\user~1\AppData\Local\Temp\IXP000.TMP\
clean

URLs

Name
IP
Malicious
www.thesocialmediacreator.com/i638/
malicious
https://doc-10-80-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/v1hb64q8i4krmmckqtjah3e0j55ac599/1640006700000/05208698352720309252/*/1vqWz_R4BQMLYr0EwMvVJ53NsyRGjMpKl?e=download
172.217.168.1
clean
http://www.autoitscript.com/autoit3/J
unknown
clean
https://doc-10-80-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/v1hb64q8
unknown
clean
https://doc-10-80-docs.googleusercontent.com/
unknown
clean
https://doc-10-80-docs.googleusercontent.com/g
unknown
clean
https://doc-10-80-docs.googleusercontent.com/z
unknown
clean
https://csp.withgoogle.com/csp/report-to/gse_l9ocaq
unknown
clean

Domains

Name
IP
Malicious
drive.google.com
172.217.168.46
clean
googlehosted.l.googleusercontent.com
172.217.168.1
clean
doc-10-80-docs.googleusercontent.com
unknown
clean

IPs

IP
Domain
Country
Malicious
172.217.168.46
drive.google.com
United States
clean
172.217.168.1
googlehosted.l.googleusercontent.com
United States
clean

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce
wextract_cleanup0
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
29E0000
unkown
page execute and read and write
malicious
560000
unkown
page execute and read and write
malicious
1E460000
unkown image
page execute and read and write
malicious
560000
unkown
page execute and read and write
malicious
4680000
unkown
page read and write
clean
7FF5B69C6000
unkown image
page readonly
clean
7FF5B694C000
unkown image
page readonly
clean
7FFB2000
unkown image
page readonly
clean
7FF559AC9000
unkown image
page readonly
clean
7DF497FA0000
unkown image
page readonly
clean
21A24013000
unkown
page read and write
clean
7FFF97C40000
unkown image
page readonly
clean
7FF566F21000
unkown image
page readonly
clean
1C8D318A000
unkown
page read and write
clean
7FFB0000
unkown image
page readonly
clean
1BF9FCE0000
unkown
page read and write
clean
1040000
unkown image
page readonly
clean
1C8D26B0000
heap default
page read and write
clean
4840000
unkown
page read and write
clean
31CD279000
stack
page read and write
clean
7FF566AFB000
unkown image
page readonly
clean
1C8D2680000
unkown image
page readonly
clean
4FD0000
unkown image
page readonly
clean
1C8D3188000
unkown
page read and write
clean
F936000
unkown
page read and write
clean
25978F20000
unkown image
page readonly
clean
1C8D3100000
unkown
page read and write
clean
270C7457000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
B2E8000
unkown
page read and write
clean
2590EA13000
unkown
page read and write
clean
7FF540DD5000
unkown image
page readonly
clean
7DF56E4C2000
unkown image
page readonly
clean
4FC0000
unkown image
page readonly
clean
2590EFA0000
unkown image
page readonly
clean
2BBF000
unkown image
page readonly
clean
7FF5D1F43000
unkown image
page readonly
clean
7FF5777BC000
unkown image
page readonly
clean
E30000
unkown image
page readonly
clean
7FF5D1AF9000
unkown image
page readonly
clean
1C8D28EF000
unkown
page read and write
clean
1010000
unkown image
page readonly
clean
BD6A000
unkown
page read and write
clean
7FF566AAA000
unkown image
page readonly
clean