IOC Report
Launcher.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Launcher.exe
C:\Users\user\Desktop\Launcher.exe
malicious

URLs

Name
IP
Malicious
http://www.impallari.comThis
unknown
http://foo/bar/images/img_downloadwhite.png
unknown
http://foo/Images/img_downloadWhite.png
unknown
https://api.telegram.org
unknown
https://api.telegram.org/bot5802716616:AAH_P81FtM2pxxnBzX9bl8iFQfHnI4qwKEs/sendMessage
unknown
https://api.telegram.org/bot
unknown
http://scripts.sil.org/OFLhttp://scripts.sil.org/OFLMontserratThinMontserratRomanWeightExtraLightLig
unknown
http://foo/bar/fonts/dosis.ttf
unknown
https://universe-city.io/
unknown
http://defaultcontainer/UniverseCity;component/Images/img_downloadWhite.png
unknown
http://defaultcontainer/UniverseCity;component/Fonts/montserrat-variablefont_wght.ttf
unknown
http://foo/bar/fonts/montserrat-variablefont_wght.ttf
unknown
https://twitter.com/UniverseCityP2E
unknown
https://api.telegram.org/bot5802716616:AAH_P81FtM2pxxnBzX9bl8iFQfHnI4qwKEs/sendMessage?chat_id=-1001
unknown
http://foo/Fonts/dosis.ttf
unknown
http://www.zkysky.com.ar/This
unknown
http://www.zkysky.com.ar/
unknown
http://defaultcontainer/UniverseCity;component/Fonts/dosis.ttf
unknown
https://api.telegram
unknown
https://github.com/JulietaUla/Montserrat)
unknown
http://scripts.sil.org/OFLhttp://scripts.sil.org/OFLDosisExtraLightWeightLightMediumSemiBoldBoldExtr
unknown
https://discord.com/invite/universecity
unknown
http://foo/Fonts/montserrat-variablefont_wght.ttf
unknown
http://www.impallari.com
unknown
http://scripts.sil.org/OFL
unknown
http://api.telegram.org
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
https://discord.com/invite/universecityGhttps://twitter.com/UniverseCityP2E3https://universe-city.io
unknown
https://universe-city.io/download/UniverseCity.zip
unknown
https://api.telegram.org/bot5802716616:AAH_P81FtM2pxxnBzX9bl8iFQfHnI4qwKEs/sendMessage?chat_id=-1001729137879&text=5.0%20NEW%2020.11.2022%0A%E2%9C%85%D0%A3%D1%81%D0%BF%D0%B5%D1%88%D0%BD%D1%8B%D0%B9%20%D0%B7%D0%B0%D0%BF%D1%83%D1%81%D0%BA%20%D0%BB%D0%B0%D1%83%D0%BD%D1%87%D0%B5%D1%80%D0%B0:%20user%0A%D0%A1%D0%B0%D0%B9%D1%82:%20universecity%0A%D0%94%D0%B0%D1%82%D0%B0%2011/24/2022%207:35:59%20PM&parse_mode=Markdown&disable_web_page_preview=True
149.154.167.220
https://github.com/JulietaUla/Montserrat)Montserrat
unknown
There are 21 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
api.telegram.org
149.154.167.220

IPs

IP
Domain
Country
Malicious
149.154.167.220
api.telegram.org
United Kingdom

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASAPI32
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASAPI32
EnableAutoFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASAPI32
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASAPI32
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASAPI32
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASAPI32
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASAPI32
FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASMANCS
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASMANCS
EnableAutoFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASMANCS
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASMANCS
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASMANCS
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASMANCS
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Launcher_RASMANCS
FileDirectory
There are 5 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
A440000
trusted library allocation
page read and write
20253E13000
heap
page read and write
59EF000
trusted library allocation
page read and write
740000
heap
page read and write
4A80000
trusted library allocation
page read and write
29E0000
trusted library allocation
page read and write
5B3B000
trusted library allocation
page read and write
550E000
stack
page read and write
3011EFD000
stack
page read and write
10F0000
trusted library allocation
page execute and read and write
2C10000
trusted library allocation
page read and write
201C6302000
heap
page read and write
1B63666B000
heap
page read and write
E1277C000
stack
page read and write
2CA5CF9000
stack
page read and write
A2A0000
trusted library allocation
page read and write
A5E2000
trusted library allocation
page read and write
A5EB000
trusted library allocation
page read and write
2AC098B9000
heap
page read and write
159FFA50000
heap
page read and write
5BAE000
trusted library allocation
page read and write
1829D030000
trusted library allocation
page read and write
6582000
trusted library allocation
page read and write
FF0000
trusted library allocation
page read and write
5A12000
trusted library allocation
page read and write
2AC09913000
heap
page read and write
58CC000
stack
page read and write
5B55000
trusted library allocation
page read and write
A136000
trusted library allocation
page read and write
1B63665A000
heap
page read and write
2CA5D7E000
stack
page read and write
5B4A000
trusted library allocation
page read and write
A2D0000
trusted library allocation
page read and write
20253E02000
heap
page read and write
A3BC000
trusted library allocation
page read and write
DE7C4FC000
stack
page read and write
144ED013000
heap
page read and write
5AD0000
trusted library allocation
page read and write
20253BC0000
heap
page read and write
5360000
trusted library allocation
page read and write
20253D80000
trusted library allocation
page read and write
1829CD40000
heap
page read and write
201C6A02000
trusted library allocation
page read and write
FCD78FE000
stack
page read and write
1829DCB0000
trusted library allocation
page read and write
A0C0000
trusted library allocation
page read and write
5B68000
trusted library allocation
page read and write
5B42000
trusted library allocation
page read and write
DE7C2FD000
stack
page read and write
235BC30D000
heap
page read and write
1000000
trusted library allocation
page read and write
1829D060000
heap
page read and write
235BBC79000
heap
page read and write
A530000
heap
page read and write
A503000
trusted library allocation
page read and write
9CA2000
trusted library allocation
page read and write