IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
malicious

URLs

Name
IP
Malicious
demonstationfukewko.shop
malicious
incredibleextedwj.shop
malicious
greetclassifytalk.shop
malicious
shortsvelventysjo.shop
malicious
productivelookewr.shop
malicious
tolerateilusidjukl.shop
malicious
https://greetclassifytalk.shop/api
172.67.177.98
malicious
liabilitynighstjsko.shop
malicious
shatterbreathepsw.shop
malicious
alcojoldwograpciw.shop
malicious
https://greetclassifytalk.shop//
unknown
https://greetclassifytalk.shop/apiM
unknown
https://greetclassifytalk.shop:443/api
unknown
https://greetclassifytalk.shop/
unknown
There are 4 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
greetclassifytalk.shop
172.67.177.98
malicious

IPs

IP
Domain
Country
Malicious
172.67.177.98
greetclassifytalk.shop
United States
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
400000
remote allocation
page execute and read and write
malicious
52E000
stack
page read and write
9D8000
heap
page read and write
29C0000
trusted library allocation
page read and write
BBF000
stack
page read and write
410000
unkown
page readonly
530000
heap
page read and write
2A33000
trusted library allocation
page read and write
708000
heap
page read and write
330000
heap
page read and write
6BA000
heap
page read and write
73C000
heap
page read and write
274E000
stack
page read and write
765000
heap
page read and write
21AE000
stack
page read and write
716000
heap
page read and write
40E000
unkown
page execute and read and write
391000
unkown
page execute read
391000
unkown
page execute read
320000
heap
page read and write
490000
heap
page read and write
535000
heap
page read and write
9CA000
heap
page read and write
990000
heap
page read and write
1CD000
stack
page read and write
2A02000
trusted library allocation
page read and write
284F000
stack
page read and write
4A0000
heap
page read and write
410000
unkown
page readonly
390000
unkown
page readonly
2DF0000
heap
page read and write
20AF000
stack
page read and write
77C000
heap
page read and write
78F000
heap
page read and write
3BB000
unkown
page write copy
64E000
stack
page read and write
8FF000
stack
page read and write
3AF000
unkown
page readonly
701000
heap
page read and write
288E000
stack
page read and write
CB000
stack
page read and write
9CE000
heap
page read and write
37E000
stack
page read and write
550000
heap
page read and write
97E000
stack
page read and write
22AD000
stack
page read and write
3AF000
unkown
page readonly
3B9000
unkown
page write copy
29A0000
trusted library allocation
page read and write
6FC000
heap
page read and write
23AF000
stack
page read and write
3B9000
unkown
page read and write
9C0000
heap
page read and write
711000
heap
page read and write
2A2C000
trusted library allocation
page read and write
390000
unkown
page readonly
2AA0000
heap
page read and write
6B0000
heap
page read and write
50E000
stack
page read and write
6E6000
heap
page read and write
2CD000
stack
page read and write
29E2000
trusted library allocation
page read and write
1C9000
stack
page read and write
298E000
stack
page read and write
510000
heap
page read and write
2CFF000
stack
page read and write
76B000
heap
page read and write
9B0000
heap
page read and write
68D000
stack
page read and write
2BFE000
stack
page read and write
459000
remote allocation
page execute and read and write
There are 61 hidden memdumps, click here to show them.