Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\Launcher.exe
|
C:\Users\user\Desktop\Launcher.exe
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://www.impallari.comThis
|
unknown
|
||
http://foo/bar/images/img_downloadwhite.png
|
unknown
|
||
http://foo/Images/img_downloadWhite.png
|
unknown
|
||
https://api.telegram.org
|
unknown
|
||
https://api.telegram.org/bot5802716616:AAH_P81FtM2pxxnBzX9bl8iFQfHnI4qwKEs/sendMessage
|
unknown
|
||
https://api.telegram.org/bot
|
unknown
|
||
http://scripts.sil.org/OFLhttp://scripts.sil.org/OFLMontserratThinMontserratRomanWeightExtraLightLig
|
unknown
|
||
http://foo/bar/fonts/dosis.ttf
|
unknown
|
||
https://universe-city.io/
|
unknown
|
||
http://defaultcontainer/UniverseCity;component/Images/img_downloadWhite.png
|
unknown
|
||
http://defaultcontainer/UniverseCity;component/Fonts/montserrat-variablefont_wght.ttf
|
unknown
|
||
http://foo/bar/fonts/montserrat-variablefont_wght.ttf
|
unknown
|
||
https://twitter.com/UniverseCityP2E
|
unknown
|
||
https://api.telegram.org/bot5802716616:AAH_P81FtM2pxxnBzX9bl8iFQfHnI4qwKEs/sendMessage?chat_id=-1001
|
unknown
|
||
http://foo/Fonts/dosis.ttf
|
unknown
|
||
http://www.zkysky.com.ar/This
|
unknown
|
||
http://www.zkysky.com.ar/
|
unknown
|
||
http://defaultcontainer/UniverseCity;component/Fonts/dosis.ttf
|
unknown
|
||
https://api.telegram
|
unknown
|
||
https://github.com/JulietaUla/Montserrat)
|
unknown
|
||
http://scripts.sil.org/OFLhttp://scripts.sil.org/OFLDosisExtraLightWeightLightMediumSemiBoldBoldExtr
|
unknown
|
||
https://discord.com/invite/universecity
|
unknown
|
||
http://foo/Fonts/montserrat-variablefont_wght.ttf
|
unknown
|
||
http://www.impallari.com
|
unknown
|
||
http://scripts.sil.org/OFL
|
unknown
|
||
http://api.telegram.org
|
unknown
|
||
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
|
unknown
|
||
https://discord.com/invite/universecityGhttps://twitter.com/UniverseCityP2E3https://universe-city.io
|
unknown
|
||
https://universe-city.io/download/UniverseCity.zip
|
unknown
|
||
https://api.telegram.org/bot5802716616:AAH_P81FtM2pxxnBzX9bl8iFQfHnI4qwKEs/sendMessage?chat_id=-1001729137879&text=5.0%20NEW%2020.11.2022%0A%E2%9C%85%D0%A3%D1%81%D0%BF%D0%B5%D1%88%D0%BD%D1%8B%D0%B9%20%D0%B7%D0%B0%D0%BF%D1%83%D1%81%D0%BA%20%D0%BB%D0%B0%D1%83%D0%BD%D1%87%D0%B5%D1%80%D0%B0:%20user%0A%D0%A1%D0%B0%D0%B9%D1%82:%20universecity%0A%D0%94%D0%B0%D1%82%D0%B0%2011/24/2022%207:35:59%20PM&parse_mode=Markdown&disable_web_page_preview=True
|
149.154.167.220
|
||
https://github.com/JulietaUla/Montserrat)Montserrat
|
unknown
|
There are 21 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
api.telegram.org
|
149.154.167.220
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
149.154.167.220
|
api.telegram.org
|
United Kingdom
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing
|
EnableConsoleTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASAPI32
|
EnableFileTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASAPI32
|
EnableAutoFileTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASAPI32
|
EnableConsoleTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASAPI32
|
FileTracingMask
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASAPI32
|
ConsoleTracingMask
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASAPI32
|
MaxFileSize
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASAPI32
|
FileDirectory
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASMANCS
|
EnableFileTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASMANCS
|
EnableAutoFileTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASMANCS
|
EnableConsoleTracing
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASMANCS
|
FileTracingMask
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASMANCS
|
ConsoleTracingMask
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASMANCS
|
MaxFileSize
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASMANCS
|
FileDirectory
|
There are 5 hidden registries, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
A440000
|
trusted library allocation
|
page read and write
|
||
20253E13000
|
heap
|
page read and write
|
||
59EF000
|
trusted library allocation
|
page read and write
|
||
740000
|
heap
|
page read and write
|
||
4A80000
|
trusted library allocation
|
page read and write
|
||
29E0000
|
trusted library allocation
|
page read and write
|
||
5B3B000
|
trusted library allocation
|
page read and write
|
||
550E000
|
stack
|
page read and write
|
||
3011EFD000
|
stack
|
page read and write
|
||
10F0000
|
trusted library allocation
|
page execute and read and write
|
||
2C10000
|
trusted library allocation
|
page read and write
|
||
201C6302000
|
heap
|
page read and write
|
||
1B63666B000
|
heap
|
page read and write
|
||
E1277C000
|
stack
|
page read and write
|
||
2CA5CF9000
|
stack
|
page read and write
|
||
A2A0000
|
trusted library allocation
|
page read and write
|
||
A5E2000
|
trusted library allocation
|
page read and write
|
||
A5EB000
|
trusted library allocation
|
page read and write
|
||
2AC098B9000
|
heap
|
page read and write
|
||
159FFA50000
|
heap
|
page read and write
|
||
5BAE000
|
trusted library allocation
|
page read and write
|
||
1829D030000
|
trusted library allocation
|
page read and write
|
||
6582000
|
trusted library allocation
|
page read and write
|
||
FF0000
|
trusted library allocation
|
page read and write
|
||
5A12000
|
trusted library allocation
|
page read and write
|
||
2AC09913000
|
heap
|
page read and write
|
||
58CC000
|
stack
|
page read and write
|
||
5B55000
|
trusted library allocation
|
page read and write
|
||
A136000
|
trusted library allocation
|
page read and write
|
||
1B63665A000
|
heap
|
page read and write
|
||
2CA5D7E000
|
stack
|
page read and write
|
||
5B4A000
|
trusted library allocation
|
page read and write
|
||
A2D0000
|
trusted library allocation
|
page read and write
|
||
20253E02000
|
heap
|
page read and write
|
||
A3BC000
|
trusted library allocation
|
page read and write
|
||
DE7C4FC000
|
stack
|
page read and write
|
||
144ED013000
|
heap
|
page read and write
|
||
5AD0000
|
trusted library allocation
|
page read and write
|
||
20253BC0000
|
heap
|
page read and write
|
||
5360000
|
trusted library allocation
|
page read and write
|
||
20253D80000
|
trusted library allocation
|
page read and write
|
||
1829CD40000
|
heap
|
page read and write
|
||
201C6A02000
|
trusted library allocation
|
page read and write
|
||
FCD78FE000
|
stack
|
page read and write
|
||
1829DCB0000
|
trusted library allocation
|
page read and write
|
||
A0C0000
|
trusted library allocation
|
page read and write
|
||
5B68000
|
trusted library allocation
|
page read and write
|
||
5B42000
|
trusted library allocation
|
page read and write
|
||
DE7C2FD000
|
stack
|
page read and write
|
||
235BC30D000
|
heap
|
page read and write
|
||
1000000
|
trusted library allocation
|
page read and write
|
||
1829D060000
|
heap
|
page read and write
|
||
235BBC79000
|
heap
|
page read and write
|
||
A530000
|
heap
|
page read and write
|
||
A503000
|
trusted library allocation
|
page read and write
|
||
9CA2000
|
trusted library allocation
|
page read and write
|