IOC Report
SecuriteInfo.com.Trojan.DownLoad3.33216.13863.20878.exe

loading gif

Files

File Path
Type
Category
Malicious
SecuriteInfo.com.Trojan.DownLoad3.33216.13863.20878.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Temp\denis.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\1305UKdw[1].htm
HTML document, ASCII text
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ZVZFKMB9\1305UKdw[1].htm
HTML document, ASCII text
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoad3.33216.13863.20878.exe
"C:\Users\user\Desktop\SecuriteInfo.com.Trojan.DownLoad3.33216.13863.20878.exe"
malicious
C:\Users\user\AppData\Local\Temp\denis.exe
"C:\Users\user\AppData\Local\Temp\denis.exe"
malicious

URLs

Name
IP
Malicious
http://download.luxesydiseno.com/images/powerslide/Concha/1305UKdw.zipS
unknown
http://www.paulaggg.com/drawings/index.php?page=fast
unknown
http://paulagail.etsy.com/
unknown
http://www.w3c.org/TR/html4/strict.dtd
unknown
http://paulaggg.com/css/1305UKdw.zip9c77b0923665da6f1LMEM
unknown
http://www.cafepress.com/paulagail
unknown
http://download.luxesydiseno.com/images/powerslide/Concha/1305UKdw.zipvY
unknown
http://paulaggg.com/css/1305UKdw.zipEd
unknown
http://luxesydiseno.com/images/powerslide/Concha/1305UKdw.zip
192.254.232.193
http://paulaggg.com/css/1305UKdw.zippp
unknown
http://luxesydiseno.com/images/powerslide/Concha/1305UKdw.zipmp
unknown
http://luxesydiseno.com/images/powerslide/Concha/1305UKdw.zipshqos.dll.muiBc
unknown
http://paulaggg.com/css/1305UKdw.zipp2
unknown
http://paulaggg.com/css/1305UKdw.zippw
unknown
http://download.luxesydiseno.com/images/powerslide/Concha/1305UKdw.zipG
unknown
http://www.paulaggg.com/paulagail2009/
unknown
http://paulaggg.com/css/1305UKdw.zipes/powerslide/Concha/1305UKdw.zip
unknown
http://paulaggg.com/css/1305UKdw.zip$
unknown
http://paulaggg.com/css/1305UKdw.zipw.zip
unknown
http://download.luxesydiseno.com/images/powerslide/Concha/1305UKdw.zip=
unknown
http://download.luxesydiseno.com/images/powerslide/Concha/1305UKdw.zip3
unknown
http://luxesydiseno.com/images/powerslide/Concha/1305UKdw.zip9
unknown
http://paulaggg.com/css/1305UKdw.zip
198.54.115.45
http://paulaggg.com/css/1305UKdw.zipp
unknown
http://download.luxesydiseno.com/images/powerslide/Concha/1305UKdw.zip
192.254.232.193
http://paulaggg.com/css/1305UKdw.zipt
unknown
http://paulaggg.com/css/1305UKdw.zipxdy
unknown
http://www.stencilletta.com
unknown
http://paulaggg.com/css/1305UKdw.zip5
unknown
http://www.paulaggg.com/digitaldrawings/
unknown
http://download.luxesydiseno.com/images/powerslide/Concha/1305UKdw.zip3Z
unknown
http://paulaggg.com/
unknown
http://download.luxesydiseno.com/images/powerslide/Concha/1305UKdw.zipOY
unknown
http://luxesydiseno.com/images/powerslide/Concha/1305UKdw.zipH
unknown
http://www.paulaggg.com/preciousmetaldrawing/
unknown
http://paulaggg.com/css/1305UKdw.zip=
unknown
http://paulaggg.com/css/1305UKdw.zipLMEM
unknown
http://luxesydiseno.com/images/powerslide/Concha/1305UKdw.zipO
unknown
http://www.paulastinypottery.com/
unknown
http://luxesydiseno.com/images/powerslide/Concha/1305UKdw.zipswsock.dll.mui
unknown
There are 30 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
luxesydiseno.com
192.254.232.193
download.luxesydiseno.com
192.254.232.193
paulaggg.com
198.54.115.45

IPs

IP
Domain
Country
Malicious
198.54.115.45
paulaggg.com
United States
192.254.232.193
luxesydiseno.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
8B0000
heap
page read and write
293F000
stack
page read and write
2CFC000
stack
page read and write
1F0000
heap
page read and write
2CBF000
stack
page read and write
227E000
heap
page read and write
556000
heap
page read and write
560000
heap
page read and write
1F0000
heap
page read and write
401000
unkown
page execute read
401000
unkown
page execute read
2A3F000
stack
page read and write
2BBE000
stack
page read and write
402000
unkown
page readonly
8C0000
heap
page read and write
2DDE000
stack
page read and write
990000
heap
page read and write
484000
heap
page read and write
402000
unkown
page readonly
2C8B000
stack
page read and write
401000
unkown
page execute read
27FE000
stack
page read and write
6BF000
heap
page read and write
7AE000
stack
page read and write
2B8D000
stack
page read and write
400000
unkown
page readonly
404000
unkown
page readonly
232E000
heap
page read and write
2E31000
heap
page read and write
66E000
stack
page read and write
2830000
heap
page read and write
400000
unkown
page readonly
404000
unkown
page readonly
2B4D000
stack
page read and write
420000
heap
page read and write
2A4E000
stack
page read and write
6CB000
heap
page read and write
4E0000
heap
page read and write
670000
heap
page read and write
404000
unkown
page readonly
6EE000
heap
page read and write
2DFC000
stack
page read and write
9B000
stack
page read and write
400000
unkown
page readonly
42A000
heap
page read and write
19C000
stack
page read and write
67E000
heap
page read and write
99E000
stack
page read and write
402000
unkown
page readonly
290E000
stack
page read and write
9C0000
heap
page read and write
28CF000
stack
page read and write
19A000
stack
page read and write
277E000
stack
page read and write
27BE000
stack
page read and write
404000
unkown
page readonly
402000
unkown
page readonly
565000
heap
page read and write
679000
heap
page read and write
2A7E000
stack
page read and write
410000
heap
page read and write
550000
heap
page read and write
400000
unkown
page readonly
2A0F000
stack
page read and write
450000
heap
page read and write
8AF000
stack
page read and write
2180000
heap
page read and write
401000
unkown
page execute read
2B7F000
stack
page read and write
9C000
stack
page read and write
2230000
heap
page read and write
76D000
stack
page read and write
42E000
heap
page read and write
6DA000
heap
page read and write
2CDE000
stack
page read and write
222E000
stack
page read and write
There are 66 hidden memdumps, click here to show them.