IOC Report

loading gif

Files

File Path
Type
Category
Malicious
gunzipped.exe
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
initial sample
malicious
C:\ProgramData\834793065949733\_8347930659.zip
Zip archive data, at least v2.0 to extract
dropped
clean
C:\ProgramData\834793065949733\cookies\Google Chrome_Default.txt
ASCII text, with CRLF line terminators
dropped
clean
C:\ProgramData\834793065949733\screenshot.jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 1280x1024, frames 3
dropped
clean
C:\ProgramData\834793065949733\system.txt
ISO-8859 text, with CRLF line terminators
dropped
clean
C:\ProgramData\834793065949733\temp
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\ProgramData\freebl3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\ProgramData\mozglue.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\ProgramData\msvcp140.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\ProgramData\nss3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\ProgramData\softokn3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
clean
C:\ProgramData\sqlite3.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\ProgramData\vcruntime140.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
C:\Users\user\AppData\Local\Temp\3lzr9t8b2fewpx2
data
dropped
clean
C:\Users\user\AppData\Local\Temp\dxaqqkiiu
data
dropped
clean
C:\Users\user\AppData\Local\Temp\nsy255F.tmp\qhvek.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
clean
There are 6 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\gunzipped.exe
"C:\Users\user\Desktop\gunzipped.exe"
malicious
C:\Users\user\Desktop\gunzipped.exe
"C:\Users\user\Desktop\gunzipped.exe"
malicious
C:\Windows\SysWOW64\cmd.exe
"C:\Windows\System32\cmd.exe" /c taskkill /pid 1068 & erase C:\Users\user\Desktop\gunzipped.exe & RD /S /Q C:\\ProgramData\\834793065949733\\* & exit
clean
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
clean
C:\Windows\SysWOW64\taskkill.exe
taskkill /pid 1068
clean

URLs

Name
IP
Malicious
http://2.56.57.108/osk//4.jpg
2.56.57.108
malicious
http://2.56.57.108/osk//5.jpg
2.56.57.108
malicious
http://2.56.57.108/osk//main.php
2.56.57.108
malicious
http://ocsp.thawte.com0
unknown
malicious
http://www.mozilla.com0
unknown
malicious
http://2.56.57.108/osk//1.jpg
2.56.57.108
malicious
http://2.56.57.108/osk//6.jpg
2.56.57.108
malicious
http://2.56.57.108/osk//2.jpg
2.56.57.108
malicious
http://2.56.57.108/osk//7.jpg
2.56.57.108
malicious
http://2.56.57.108/osk//1.jpghttp://2.56.57.108/osk//4.jpghttp://2.56.57.108/osk//7.jpghttp://2.56.5
unknown
malicious
http://2.56.57.108/osk//3.jpg
2.56.57.108
malicious
http://2.56.57.108/osk//5.jpg2
unknown
malicious
http://2.56.57.108/osk/
2.56.57.108
malicious
http://2.56.57.108/osk//2.jpghttp://2.56.57.108/osk//6.jpghttp://2.56.57.108/osk//3.jpghttp://2.56.5
unknown
malicious
http://2.56.57.108/osk//7.jpgB
unknown
malicious
https://duckduckgo.com/chrome_newtab
unknown
clean
http://www.mozilla.com/en-US/blocklist/
unknown
clean
https://duckduckgo.com/ac/?q=
unknown
clean
https://www.google.com/images/branding/product/ico/googleg_lodp.ico
unknown
clean
https://support.google.com/chrome/answer/6258784
unknown
clean
https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
unknown
clean
https://support.google.com/chrome/?p=plugin_flash
unknown
clean
https://search.yahoo.com/favicon.icohttps://search.yahoo.com/search
unknown
clean
http://nsis.sf.net/NSIS_ErrorError
unknown
clean
https://ac.ecosia.org/autocomplete?q=
unknown
clean
http://nsis.sf.net/NSIS_Error
unknown
clean
http://crl.thawte.com/ThawteTimestampingCA.crl0
unknown
clean
https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
unknown
clean
https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
unknown
clean
There are 19 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
2.56.57.108
unknown
Netherlands
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
2CB0000
unkown
page read and write
malicious
7B0000
unkown
page execute and read and write
malicious
7B0000
unkown
page execute and read and write
malicious
7B0000
unkown
page execute and read and write
malicious
7B0000
unkown
page execute and read and write
malicious
2725000
heap private
page read and write
malicious
7B0000
unkown
page execute and read and write
malicious
38D0000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
E16000
unkown image
page readonly
clean
400000
unkown image
page readonly
clean
407000
unkown image
page readonly
clean
7FFC2000
unkown image
page readonly
clean
25AE000
stack
page read and write
clean
2F9B000
unkown
page read and write
clean
33F1000
unkown
page read and write
clean
6F301000
unkown image
page execute read
clean
400000
unkown image
page readonly
clean
3626000
heap private
page read and write
clean
2581000
unkown
page read and write
clean
C9A000
unkown
page read and write
clean
3626000
heap private
page read and write
clean
7FFB0000
unkown image
page readonly
clean
25E0000
heap private
page read and write
clean
409000
unkown image
page write copy
clean
40000
unkown image
page readonly
clean
7FC12000
unkown image
page readonly
clean
2F9B000
unkown
page read and write
clean
FE0000
unkown image
page readonly
clean
7FFC2000
unkown image
page readonly
clean
7FFB2000
unkown image
page readonly
clean
2674000
unkown
page read and write
clean
7AB000
unkown image
page readonly
clean
7FFD0000
unkown image
page readonly
clean
C3C000
heap default
page read and write
clean
2BA8000
unkown
page read and write
clean
7AB000
unkown image
page readonly
clean
7FFC2000
unkown image
page readonly
clean
2DEF000
stack
page read and write
clean
3ABA000
heap private
page read and write
clean
CA5000
unkown
page read and write
clean
94A000
unkown
page read and write
clean
2E06000
unkown
page read and write
clean
7AB000
unkown image
page readonly
clean
7AB000
unkown image
page readonly
clean
7FFD0000
unkown image
page readonly
clean
33F0000
unkown
page read and write
clean
2CF0000
unkown
page read and write
clean
C6F000
stack
page read and write
clean
407000
unkown image
page readonly
clean
2F9F000
unkown
page read and write
clean
7FFC0000
unkown image
page readonly
clean
A40000
unkown
page read and write
clean
C9A000
unkown
page read and write
clean
C9A000
unkown
page read and write
clean
1B0000
unkown image
page readonly
clean
1A0000
unkown image
page readonly
clean
409000
unkown image
page write copy
clean
2E80000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
409000
unkown image
page write copy
clean
2768000
heap private
page read and write
clean
1160000
unkown image
page readonly
clean
7FFB0000
unkown image
page readonly
clean
CA5000
unkown
page read and write
clean
BD0000
unkown image
page readonly
clean
2CF0000
unkown
page read and write
clean
2B90000
unkown
page read and write
clean
2E80000
unkown
page read and write
clean
2E80000
unkown
page read and write
clean
A2E000
stack
page read and write
clean
7FFB2000
unkown image
page readonly
clean
31F1000
unkown
page read and write
clean
7FC20000
unkown image
page readonly
clean
BD0000
unkown image
page readonly
clean
FB0000
unkown image
page readonly
clean
2B7000
unkown
page read and write
clean
3170000
heap default
page read and write
clean
3622000
heap private
page read and write
clean
C9A000
unkown
page read and write
clean
2675000
unkown
page read and write
clean
2BB3000
unkown image
page readonly
clean
7FFD0000
unkown image
page readonly
clean
7E5000
unkown
page execute and read and write
clean
7FFB0000
unkown image
page readonly
clean
3A60000
unkown image
page readonly
clean
6F346000
unkown image
page read and write
clean
1B0000
unkown image
page readonly
clean
7FFC0000
unkown image
page readonly
clean
400000
unkown image
page readonly
clean
7FC22000
unkown image
page readonly
clean
7AB000
unkown image
page readonly
clean
1A0000
unkown image
page readonly
clean
7FFB0000
unkown image
page readonly
clean
2E06000
unkown
page read and write
clean
409000
unkown image
page write copy
clean
400000
unkown image
page readonly
clean
C9A000
unkown
page read and write
clean
30AE000
stack
page read and write
clean
7FFD0000
unkown image
page readonly
clean
7FC22000
unkown image
page readonly
clean
26FE000
stack
page read and write
clean
7FC12000
unkown image
page readonly
clean
37F0000
unkown
page read and write
clean
BD0000
unkown image
page readonly
clean
C44000
heap default
page read and write
clean
B6D000
stack
page read and write
clean
40000
unkown image
page readonly
clean
2E06000
unkown
page read and write
clean
8D0000
heap private
page read and write
clean
7FFB0000
unkown image
page readonly
clean
26BE000
stack
page read and write
clean
2F9F000
unkown
page read and write
clean
CA5000
unkown
page read and write
clean
2550000
unkown
page read and write
clean
8FA000
heap default
page read and write
clean
C8E000
heap default
page read and write
clean
2F2F000
stack
page read and write
clean
7D7000
unkown
page readonly
clean
CA5000
unkown
page read and write
clean
31F0000
unkown
page read and write
clean
2F9F000
unkown
page read and write
clean
784000
unkown image
page read and write
clean
7FFB2000
unkown image
page readonly
clean
3C90000
heap private
page read and write
clean
2E06000
unkown
page read and write
clean
2E80000
unkown
page read and write
clean
BE8000
heap default
page read and write
clean
31F1000
unkown
page read and write
clean
7FFD0000
unkown image
page readonly
clean
7E0000
heap default
page read and write
clean
7FFC2000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
31B000
unkown
page read and write
clean
948000
heap default
page read and write
clean
2674000
unkown
page read and write
clean
C82000
unkown
page read and write
clean
7FFD0000
unkown image
page readonly
clean
91C000
stack
page read and write
clean
2AF5000
unkown image
page readonly
clean
BE0000
heap default
page read and write
clean
C9A000
unkown
page read and write
clean
409000
unkown image
page write copy
clean
401000
unkown image
page execute read
clean
1A0000
unkown image
page readonly
clean
CAA000
unkown
page read and write
clean
CA5000
unkown
page read and write
clean
D70000
unkown
page read and write
clean
C9A000
unkown
page read and write
clean
D30000
unkown image
page readonly
clean
1B0000
unkown image
page readonly
clean
6F300000
unkown image
page readonly
clean
324000
unkown
page read and write
clean
3409000
unkown
page read and write
clean
D40000
unkown image
page readonly
clean
D40000
unkown image
page readonly
clean
7FFC2000
unkown image
page readonly
clean
1B0000
unkown image
page readonly
clean
2E06000
unkown
page read and write
clean
303E000
stack
page read and write
clean
328D000
unkown
page read and write
clean
2A6E000
stack
page read and write
clean
CA5000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
CA5000
unkown
page read and write
clean
30F000
unkown
page read and write
clean
401000
unkown image
page execute read
clean
C9A000
unkown
page read and write
clean
407000
unkown image
page readonly
clean
2E80000
unkown
page read and write
clean
401000
unkown image
page execute read
clean
7FFD0000
unkown image
page readonly
clean
30000
unkown image
page read and write
clean
332B000
unkown
page read and write
clean
7FFC2000
unkown image
page readonly
clean
C97000
unkown
page read and write
clean
25D0000
heap private
page read and write
clean
C2D000
unkown
page read and write
clean
A60000
heap default
page read and write
clean
2E80000
unkown
page read and write
clean
1A0000
unkown image
page readonly
clean
7E0000
unkown
page execute and read and write
clean
7FC12000
unkown image
page readonly
clean
7FC12000
unkown image
page readonly
clean
7FC20000
unkown image
page readonly
clean
7FFB2000
unkown image
page readonly
clean
2B12000
unkown image
page readonly
clean
780000
unkown image
page read and write
clean
7FFB2000
unkown image
page readonly
clean
D30000
unkown image
page readonly
clean
31F1000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
D30000
unkown image
page readonly
clean
3626000
heap private
page read and write
clean
C9A000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
25B0000
unkown
page read and write
clean
8F0000
stack
page read and write
clean
C9A000
unkown
page read and write
clean
BAE000
stack
page read and write
clean
7FEB0000
unkown image
page readonly
clean
2BB8000
unkown image
page readonly
clean
948000
unkown
page read and write
clean
7FFB2000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
2F9B000
unkown
page read and write
clean
CA5000
unkown
page read and write
clean
401000
unkown image
page execute read
clean
7FC22000
unkown image
page readonly
clean
407000
unkown image
page readonly
clean
3341000
unkown
page read and write
clean
C93000
unkown
page read and write
clean
1A0000
unkown image
page readonly
clean
1B0000
unkown image
page readonly
clean
7FFC2000
unkown image
page readonly
clean
7FFB2000
unkown image
page readonly
clean
2CF0000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
6F341000
unkown image
page readonly
clean
332A000
unkown
page read and write
clean
7FC10000
unkown image
page readonly
clean
407000
unkown image
page readonly
clean
30000
unkown image
page read and write
clean
A3E000
stack
page read and write
clean
7FFC0000
unkown image
page readonly
clean
2580000
unkown
page read and write
clean
37F0000
unkown
page read and write
clean
3443000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
2F6C000
stack
page read and write
clean
926000
heap default
page read and write
clean
7FFC0000
unkown image
page readonly
clean
DAE000
stack
page read and write
clean
948000
unkown
page read and write
clean
7E5000
heap default
page read and write
clean
2760000
heap private
page read and write
clean
7FFD0000
unkown image
page readonly
clean
E16000
unkown image
page readonly
clean
7AB000
unkown image
page readonly
clean
401000
unkown image
page execute read
clean
2F9F000
unkown
page read and write
clean
7B0000
unkown
page execute and read and write
clean
7FFC2000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
D50000
unkown
page read and write
clean
7FFB2000
unkown image
page readonly
clean
D2E000
unkown
page read and write
clean
6F349000
unkown image
page readonly
clean
7FC30000
unkown image
page readonly
clean
409000
unkown image
page write copy
clean
7FFB2000
unkown image
page readonly
clean
7FFD0000
unkown image
page readonly
clean
8F0000
heap default
page read and write
clean
7FFB2000
unkown image
page readonly
clean
2F7B000
unkown
page read and write
clean
60900000
unkown image
page readonly
clean
3178000
unkown
page read and write
clean
7FFC0000
unkown image
page readonly
clean
31AF000
stack
page read and write
clean
2E2E000
stack
page read and write
clean
C9A000
unkown
page read and write
clean
1A0000
unkown image
page readonly
clean
345B000
unkown
page read and write
clean
C9A000
unkown
page read and write
clean
7FFC2000
unkown image
page readonly
clean
400000
unkown image
page readonly
clean
2CEE000
stack
page read and write
clean
2720000
heap private
page read and write
clean
CA5000
unkown
page read and write
clean
C9A000
unkown
page read and write
clean
7FC30000
unkown image
page readonly
clean
C87000
unkown
page read and write
clean
1B0000
unkown image
page readonly
clean
1A0000
unkown image
page readonly
clean
7FC30000
unkown image
page readonly
clean
409000
unkown image
page write copy
clean
7B0000
unkown
page read and write
clean
7E5000
unkown
page readonly
clean
2CA0000
unkown image
page readonly
clean
318A000
unkown
page read and write
clean
2B98000
unkown
page read and write
clean
2B6F000
stack
page read and write
clean
2F7F000
unkown
page read and write
clean
7FFB0000
unkown image
page readonly
clean
1B0000
unkown image
page readonly
clean
3447000
unkown
page read and write
clean
401000
unkown image
page execute read
clean
B2F000
stack
page read and write
clean
409000
unkown image
page write copy
clean
2E06000
unkown
page read and write
clean
407000
unkown image
page readonly
clean
1B0000
unkown image
page readonly
clean
400000
unkown image
page readonly
clean
401000
unkown image
page execute read
clean
3920000
unkown
page read and write
clean
407000
unkown image
page readonly
clean
40000
unkown image
page readonly
clean
344A000
unkown
page read and write
clean
3AEE000
unkown
page read and write
clean
409000
unkown image
page write copy
clean
19A000
unkown
page read and write
clean
92E000
stack
page read and write
clean
2F9B000
unkown
page read and write
clean
2F9F000
unkown
page read and write
clean
7FFD0000
unkown image
page readonly
clean
409000
unkown image
page write copy
clean
CA5000
unkown
page read and write
clean
401000
unkown image
page execute read
clean
7FFB2000
unkown image
page readonly
clean
7FC10000
unkown image
page readonly
clean
327000
unkown
page read and write
clean
7AB000
unkown image
page readonly
clean
82C000
stack
page read and write
clean
31F1000
unkown
page read and write
clean
CA5000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
407000
unkown image
page readonly
clean
D40000
unkown image
page readonly
clean
2BB8000
unkown image
page readonly
clean
7FFB0000
unkown image
page readonly
clean
3620000
heap private
page read and write
clean
31F7000
unkown
page read and write
clean
2CF0000
unkown
page read and write
clean
A50000
unkown image
page readonly
clean
DE0000
unkown image
page readonly
clean
7C0000
unkown image
page readonly
clean
A65000
heap default
page read and write
clean
CA5000
unkown
page read and write
clean
38F0000
unkown
page read and write
clean
7FFC0000
unkown image
page readonly
clean
37F0000
unkown
page read and write
clean
7AB000
unkown image
page readonly
clean
C4A000
heap default
page read and write
clean
1B0000
unkown image
page readonly
clean
786000
unkown image
page read and write
clean
306C000
stack
page read and write
clean
7AB000
unkown image
page readonly
clean
401000
unkown image
page execute read
clean
920000
heap default
page read and write
clean
7A0000
unkown image
page read and write
clean
7FFB0000
unkown image
page readonly
clean
CA5000
unkown
page read and write
clean
C8A000
unkown
page read and write
clean
2CF0000
unkown
page read and write
clean
7FB10000
unkown image
page readonly
clean
7FFD0000
unkown image
page readonly
clean
7FC10000
unkown image
page readonly
clean
1A0000
unkown image
page readonly
clean
C9A000
unkown
page read and write
clean
7B0000
unkown
page execute and read and write
clean
BD0000
unkown image
page readonly
clean
2BB8000
unkown image
page readonly
clean
CA5000
unkown
page read and write
clean
3189000
unkown
page read and write
clean
318000
unkown
page read and write
clean
2F9F000
unkown
page read and write
clean
2CF0000
unkown
page read and write
clean
31F1000
unkown
page read and write
clean
343C000
unkown
page read and write
clean
332B000
unkown
page read and write
clean
DDF000
stack
page read and write
clean
31F1000
unkown
page read and write
clean
7FC30000
unkown image
page readonly
clean
332A000
unkown
page read and write
clean
33F0000
unkown
page read and write
clean
6F300000
unkown image
page readonly
clean
2A2F000
stack
page read and write
clean
40000
unkown image
page readonly
clean
326F000
unkown
page read and write
clean
31F1000
unkown
page read and write
clean
B6E000
stack
page read and write
clean
C9A000
unkown
page read and write
clean
CA5000
unkown
page read and write
clean
7FC20000
unkown image
page readonly
clean
2BB8000
unkown image
page readonly
clean
308000
unkown
page read and write
clean
30C0000
heap default
page read and write
clean
2E80000
unkown
page read and write
clean
7FFC0000
unkown image
page readonly
clean
7FC20000
unkown image
page readonly
clean
BC0000
unkown image
page read and write
clean
7E5000
unkown
page execute and read and write
clean
401000
unkown image
page execute read
clean
3451000
unkown
page read and write
clean
2BAF000
stack
page read and write
clean
7FFB0000
unkown image
page readonly
clean
3BED000
stack
page read and write
clean
E16000
unkown image
page readonly
clean
7AB000
unkown image
page readonly
clean
E16000
unkown image
page readonly
clean
31F1000
unkown
page read and write
clean
7FC22000
unkown image
page readonly
clean
7FFB0000
unkown image
page readonly
clean
CA5000
unkown
page read and write
clean
2CF0000
unkown
page read and write
clean
2E06000
unkown
page read and write
clean
407000
unkown image
page readonly
clean
7E5000
unkown
page execute and read and write
clean
77A000
unkown image
page read and write
clean
7FFC0000
unkown image
page readonly
clean
7FC10000
unkown image
page readonly
clean
CA5000
unkown
page read and write
clean
1130000
unkown image
page readonly
clean
31F1000
unkown
page read and write
clean
7FFC0000
unkown image
page readonly
clean
7FFB0000
unkown image
page readonly
clean
7FFC2000
unkown image
page readonly
clean
31F1000
unkown
page read and write
clean
1A0000
unkown image
page readonly
clean
7FFC0000
unkown image
page readonly
clean
D40000
unkown image
page readonly
clean
CAE000
stack
page read and write
clean
2F9B000
unkown
page read and write
clean
40000
unkown image
page readonly
clean
2B1B000
unkown image
page readonly
clean
7B0000
unkown
page execute and read and write
clean
407000
unkown image
page readonly
clean
7FFC2000
unkown image
page readonly
clean
326F000
unkown
page read and write
clean
2F9F000
unkown
page read and write
clean
DB0000
unkown image
page readonly
clean
3189000
heap default
page read and write
clean
400000
unkown image
page readonly
clean
9C000
unkown
page read and write
clean
2B3000
unkown
page read and write
clean
7FEB0000
unkown image
page readonly
clean
3AB0000
heap private
page read and write
clean
2730000
unkown
page read and write
clean
D30000
unkown image
page readonly
clean
3451000
unkown
page read and write
clean
7AB000
unkown image
page readonly
clean
7FFC0000
unkown image
page readonly
clean
7B1000
unkown
page execute read
clean
3207000
unkown
page read and write
clean
7A8000
unkown image
page read and write
clean
409000
unkown image
page read and write
clean
407000
unkown image
page readonly
clean
401000
unkown image
page execute read
clean
3341000
unkown
page read and write
clean
31F1000
unkown
page read and write
clean
BB0000
unkown
page read and write
clean
2B17000
unkown image
page readonly
clean
2F9B000
unkown
page read and write
clean
343F000
stack
page read and write
clean
3445000
unkown
page read and write
clean
2F9B000
unkown
page read and write
clean
19E000
unkown
page execute and read and write
clean
31F7000
unkown
page read and write
clean
2CAF000
stack
page read and write
clean
400000
unkown image
page readonly
clean
There are 440 hidden memdumps, click here to show them.