IOC Report
https://www.adobe.com/go/ConnectShell11

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\eyup\AppData\Local\Microsoft\Windows\INetCache\IE\R9BYEINB\Payload11_2022_10_42[1].zip
Zip archive data, at least v2.0 to extract, compression method=deflate
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\AForge.Video.DirectShow.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\AForge.Video.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\AForge.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\BouncyCastle.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\CRClient.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\CRLogTransport.exe
PE32 executable (console) Intel 80386, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\CRWindowsClientService.exe
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\Connect.exe
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\ConnectDetector.exe
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\EncoderHelper.exe
PE32 executable (console) Intel 80386, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\FM.LiveSwitch.AForge.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\FM.LiveSwitch.AudioProcessing.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\FM.LiveSwitch.Dmo.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\FM.LiveSwitch.JsonNet.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\FM.LiveSwitch.Log4Net.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\FM.LiveSwitch.NAudio.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\FM.LiveSwitch.Nvidia.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\FM.LiveSwitch.OpenH264.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\FM.LiveSwitch.Opus.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\FM.LiveSwitch.SharpDX.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\FM.LiveSwitch.Vpx.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\FM.LiveSwitch.WinForms.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\FM.LiveSwitch.Wpf.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\FM.LiveSwitch.XirSys.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
modified
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\FM.LiveSwitch.Yuv.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\FM.LiveSwitch.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\chrome_100_percent.pak
data
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\chrome_200_percent.pak
data
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\chrome_elf.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\concrt140.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\cr_win_client_config.cfg
ASCII text, with CRLF line terminators
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\d3dcompiler_47.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\digest.s
data
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\libEGL.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\libGLESv2.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\libaudioprocessingfm.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\libcef.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\libcrypto-1_1-x64.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\libnvidiafm.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\libopenh264fm.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\libopusfm.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\librnnoise.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\libssl-1_1-x64.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\libvpxfm.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\eyup\AppData\Local\Temp\ConB14B.tmp\libyuvfm.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Users\eyup\Downloads\6bcc8cff-6afa-4c34-b8b1-3a042b0a5bd0.tmp
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
C:\Users\eyup\Downloads\ConnectShellSetup11.exe (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
C:\Users\eyup\Downloads\Unconfirmed 658627.crdownload
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
unknown (copy)
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
There are 41 hidden files, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.186.67
unknown
United States
142.250.185.78
unknown
United States
1.1.1.1
unknown
Australia
34.104.35.123
unknown
United States
192.168.2.1
unknown
unknown
2.16.238.27
unknown
European Union
172.217.18.4
unknown
United States
2.19.126.84
unknown
European Union
2.16.238.9
unknown
European Union
2.19.126.92
unknown
European Union
239.255.255.250
unknown
Reserved
142.250.184.205
unknown
United States
127.0.0.1
unknown
unknown
142.250.186.99
unknown
United States
142.250.74.196
unknown
United States
There are 5 hidden IPs, click here to show them.