IOC Report
1Tkf1dTh5K.dll

loading gif

Processes

Path
Cmdline
Malicious
C:\Windows\System32\loaddll32.exe
loaddll32.exe "C:\Users\user\Desktop\1Tkf1dTh5K.dll"
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe C:\Users\user\Desktop\1Tkf1dTh5K.dll,main
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe "C:\Users\user\Desktop\1Tkf1dTh5K.dll",#1
malicious
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe "C:\Users\user\Desktop\1Tkf1dTh5K.dll",main
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd.exe /C rundll32.exe "C:\Users\user\Desktop\1Tkf1dTh5K.dll",#1

URLs

Name
IP
Malicious
http://47.110.247.171/login/jizhi2_m.php
47.110.247.171
malicious
http://47.110.247.171/login/ver_m.php
47.110.247.171
malicious
http://47.110.247.171/login/t.php
47.110.247.171
malicious
http://47.110.247.171/Re
unknown
http://47.110.247.171/login/jizhi2_m.php;
unknown
http://47.110.247.171/login/t.php&x-
unknown
http://47.110.247.171/login/t.php&x
unknown
http://www.eyuyan.com)DVarFileInfo$
unknown
http://47.110.247.171/J
unknown
http://47.110.247.171/login/ver_m.phpZ
unknown
http://47.110.247.171/login/t.phpj
unknown
http://47.110.247.171/login/jizhi2_m.php/h
unknown
http://47.110.247.171/login/t.phpd
unknown
http://47.110.247.171/6
unknown
http://47.110.247.171/login/t.phpfa(
unknown
http://47.110.247.171/login/jizhi2_m.phpi
unknown
http://47.110.247.171/login/ver_m.phpO
unknown
http://47.110.247.171/login/jizhi2_m.php/
unknown
http://47.110.247.171/login/t.php;A-
unknown
http://www.super-ec.cn
unknown
http://47.110.247.171/login/t.php=
unknown
http://47.110.247.171/login/jizhi2_m.phpm
unknown
http://47.110.247.171/x
unknown
http://47.110.
unknown
http://47.110.247.171/login/t.php1c%
unknown
http://47.110.247.171/login/t.phpx
unknown
http://47.110.247.171/?
unknown
http://47.110.247.171/C
unknown
http://47.110.247.171/login/t.php4g
unknown
http://47.110.247.171/login/t.phpTMT
unknown
http://47.110.247.171/login/ver_m.php:
unknown
http://47.110.247.171:80/login/t.php_m.phpcd56ec472546541c80af5d1615d7
unknown
http://47.110.247.171/h
unknown
http://47.110.247.171/?K
unknown
http://47.110.247.171/login/t.phpRM
unknown
http://47.110.247.171/login/t.phpJ
unknown
http://47.110.247.171/s
unknown
http://47.110.247.171/
unknown
http://47.110.247.171:80/login/t.php
unknown
http://47.110.247.171/login/jizhi2_m.phpK
unknown
http://47.110.247.171/hK3j
unknown
http://47.110.247.171/login/t.phpDe)
unknown
http://47.110.247.171/login/t.phpc
unknown
http://&managingpasswords_s=data=/login/t.php&type=getime2
unknown
http://47.110.247.17x
unknown
http://ec.360bc.cnhttp://www.eyybc.com/forumdisplay.php?fid=17/memcp.php/ip.asp/time.asp/gonggao.txt
unknown
There are 36 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
47.110.247.171
unknown
China
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
3334000
heap
page read and write
2FE0000
heap
page read and write
46A0000
trusted library allocation
page read and write
98D000
heap
page read and write
1560000
heap
page read and write
4F90000
heap
page read and write
1556000
heap
page read and write
1460000
heap
page read and write
4DE1000
heap
page read and write
4121000
heap
page read and write
328A000
heap
page read and write
524000
heap
page read and write
854000
heap
page read and write
5907000
heap
page read and write
7280000
trusted library allocation
page read and write
17B0000
heap
page read and write
3313000
heap
page read and write
2BB0000
heap
page read and write
154D000
heap
page read and write
337E000
heap
page read and write
1450000
trusted library allocation
page read and write
4030000
heap
page read and write
1023F000
unkown
page read and write
951000
heap
page read and write
720000
heap
page read and write
1566000
heap
page read and write
7D6000
heap
page read and write
962000
heap
page read and write
14E0000
heap
page read and write
951000
heap
page read and write
4EF0000
heap
page read and write
33B0000
heap
page read and write
3334000
heap
page read and write
7D5000
heap
page read and write
337C000
heap
page read and write
4F00000
heap
page read and write
4DD1000
heap
page read and write
96D000
heap
page read and write
9A8000
heap
page read and write
970000
heap
page read and write
44B1000
heap
page read and write
993000
heap
page read and write
4DC0000
heap
page read and write
7CC000
heap
page read and write
951000
heap
page read and write
2FD1000
heap
page read and write
3361000
heap
page read and write
80D000
heap
page read and write
10001000
unkown
page execute read
4D3E000
stack
page read and write
14E3000
heap
page read and write
7D5000
heap
page read and write
4DD1000
heap
page read and write
58E4000
heap
page read and write
155D000
heap
page read and write
4121000
heap
page read and write
497C000
stack
page read and write
524000
heap
page read and write
4121000
heap
page read and write
96B000
heap
page read and write
2FD1000
heap
page read and write
10CC9000
unkown
page execute read
337C000
heap
page read and write
3230000
heap
page read and write
854000
heap
page read and write
10FF6000
unkown
page readonly
98B000
heap
page read and write
14BB000
heap
page read and write
37D1000
heap
page read and write
158B000
heap
page read and write
4A98000
heap
page read and write
524000
heap
page read and write
4121000
heap
page read and write
3517000
heap
page read and write
938000
heap
page read and write
4E60000
remote allocation
page read and write
4EEE000
stack
page read and write
3510000
heap
page read and write
8AE000
stack
page read and write
854000
heap
page read and write
7B7000
heap
page read and write
7C1000
heap
page read and write
962000
heap
page read and write
970000
heap
page read and write
4C90000
heap
page read and write
4F1D000
heap
page read and write
4C91000
heap
page read and write
FD4000
heap
page read and write
94A000
heap
page read and write
99C000
heap
page read and write
33B4000
heap
page read and write
7D2000
heap
page read and write
12FC000
stack
page read and write
1566000
heap
page read and write
951000
heap
page read and write
94B000
heap
page read and write
98F000
heap
page read and write
2FD1000
heap
page read and write
4ABD000
stack
page read and write
1556000
heap
page read and write
1826000
heap
page read and write
970000
heap
page read and write
4EF6000
heap
page read and write
335C000
heap
page read and write
158B000
heap
page read and write
98D000
heap
page read and write
524000
heap
page read and write
44CB000
heap
page read and write
524000
heap
page read and write
7FE000
heap
page read and write
967000
heap
page read and write
3F9E000
stack
page read and write
4FA0000
trusted library allocation
page read and write
50D0000
remote allocation
page read and write
3314000
heap
page read and write
FD4000
heap
page read and write
331D000
heap
page read and write
4010000
heap
page read and write
3316000
heap
page read and write
FD4000
heap
page read and write
7BB000
heap
page read and write
44B1000
heap
page read and write
1566000
heap
page read and write
9A8000
heap
page read and write
10001000
unkown
page execute read
9A8000
heap
page read and write
159C000
heap
page read and write
10214000
unkown
page read and write
43FE000
stack
page read and write
493A000
stack
page read and write
4DD0000
heap
page read and write
979000
heap
page read and write
153A000
heap
page read and write
50E4000
heap
page read and write
9A8000
heap
page read and write
102C3000
unkown
page read and write
98B000
heap
page read and write
351C000
heap
page read and write
524000
heap
page read and write
854000
heap
page read and write
10CC9000
unkown
page execute read
970000
heap
page read and write
4C94000
heap
page read and write
99A000
heap
page read and write
4A90000
trusted library allocation
page read and write
FD4000
heap
page read and write
2FD1000
heap
page read and write
7E4000
heap
page read and write
962000
heap
page read and write
92C000
heap
page read and write
31B0000
remote allocation
page read and write
970000
heap
page read and write
951000
heap
page read and write
17F0000
heap
page read and write
2FD1000
heap
page read and write
14E3000
heap
page read and write
3220000
heap
page read and write
1559000
heap
page read and write
57DD000
stack
page read and write
80A000
heap
page read and write
10FF6000
unkown
page readonly
1566000
heap
page read and write
3180000
heap
page read and write
801000
heap
page read and write
3359000
heap
page read and write
962000
heap
page read and write
3359000
heap
page read and write
1587000
heap
page read and write
50D0000
remote allocation
page read and write
43B0000
trusted library allocation
page read and write
99A000
heap
page read and write
1559000
heap
page read and write
94C000
heap
page read and write
854000
heap
page read and write
4B98000
heap
page read and write
7D2000
heap
page read and write
2FD1000
heap
page read and write
970000
heap
page read and write
17B0000
trusted library allocation
page read and write
1550000
heap
page read and write
58E0000
heap
page read and write
2FBC000
stack
page read and write
4020000
heap
page read and write
9A8000
heap
page read and write
4DA0000
heap
page read and write
1023F000
unkown
page read and write
7B8000
heap
page read and write
32F9000
heap
page read and write
3334000
heap
page read and write
10297000
unkown
page read and write
1029C000
unkown
page read and write
2FD1000
heap
page read and write
337C000
heap
page read and write
524000
heap
page read and write
4A90000
trusted library allocation
page read and write
2BC0000
heap
page read and write
524000
heap
page read and write
155D000
heap
page read and write
967000
heap
page read and write
156A000
heap
page read and write
418E000
stack
page read and write
159B000
heap
page read and write
524000
heap
page read and write
72A000
heap
page read and write
154E000
heap
page read and write
FD4000
heap
page read and write
4330000
heap
page read and write
4121000
heap
page read and write
337C000
heap
page read and write
44B1000
heap
page read and write
154D000
heap
page read and write
182B000
heap
page read and write
98F000
heap
page read and write
3DCE000
stack
page read and write
524000
heap
page read and write
49FD000
stack
page read and write
962000
heap
page read and write
34CE000
stack
page read and write
9A8000
heap
page read and write
32A4000
heap
page read and write
FD4000
heap
page read and write
2FD1000
heap
page read and write
10231000
unkown
page read and write
156A000
heap
page read and write
4D0000
heap
page read and write
330A000
heap
page read and write
524000
heap
page read and write
157A000
heap
page read and write
4690000
heap
page read and write
4C94000
heap
page read and write
4F10000
heap
page read and write
32AA000
heap
page read and write
7C1000
heap
page read and write
581E000
stack
page read and write
331D000
heap
page read and write
967000
heap
page read and write
44B1000
heap
page read and write
4E4E000
stack
page read and write
4D50000
heap
page read and write
9A8000
heap
page read and write
1559000
heap
page read and write
2FD1000
heap
page read and write
3313000
heap
page read and write
4FA0000
trusted library allocation
page read and write
10214000
unkown
page read and write
33B4000
heap
page read and write
7FE000
heap
page read and write
102C3000
unkown
page read and write
962000
heap
page read and write
9A8000
heap
page read and write
50D0000
remote allocation
page read and write
42FD000
stack
page read and write
33B4000
heap
page read and write
946000
heap
page read and write
5903000
heap
page read and write
3361000
heap
page read and write
94C000
heap
page read and write
809000
heap
page read and write
FD4000
heap
page read and write
7CC000
heap
page read and write
5030000
heap
page read and write
962000
heap
page read and write
17C0000
heap
page read and write
4F20000
heap
page read and write
806000
heap
page read and write
4D40000
trusted library allocation
page read and write
FD4000
heap
page read and write
2FD0000
heap
page read and write
962000
heap
page read and write
158E000
heap
page read and write
ABF000
stack
page read and write
4A7E000
stack
page read and write
3F5D000
stack
page read and write
10000000
unkown
page readonly
4C91000
heap
page read and write
4744000
heap
page read and write
FD4000
heap
page read and write
7B7000
heap
page read and write
10000000
unkown
page readonly
9A8000
heap
page read and write
4F26000
heap
page read and write
3359000
heap
page read and write
159B000
heap
page read and write
337C000
heap
page read and write
4A3E000
stack
page read and write
17AF000
stack
page read and write
1567000
heap
page read and write
590B000
heap
page read and write
4B80000
heap
page read and write
524000
heap
page read and write
102C9000
unkown
page execute read
7B7000
heap
page read and write
1820000
heap
page read and write
4CFE000
stack
page read and write
4121000
heap
page read and write
5A10000
heap
page read and write
2C0C000
heap
page read and write
4EE0000
heap
page read and write
7D8000
heap
page read and write
FD4000
heap
page read and write
7C1000
heap
page read and write
10FB3000
unkown
page readonly
1029E000
unkown
page execute read
590B000
heap
page read and write
4334000
heap
page read and write
32FC000
heap
page read and write
149000
stack
page read and write
7D2000
heap
page read and write
4CCA000
stack
page read and write
335C000
heap
page read and write
331D000
heap
page read and write
3280000
heap
page read and write
4DD1000
heap
page read and write
8B0000
heap
page read and write
4F10000
trusted library allocation
page read and write
33B4000
heap
page read and write
806000
heap
page read and write
3316000
heap
page read and write
854000
heap
page read and write
155D000
heap
page read and write
7FE000
heap
page read and write
7D8000
heap
page read and write
102C3000
unkown
page read and write
33B4000
heap
page read and write
335E000
heap
page read and write
4A90000
heap
page read and write
14B0000
heap
page read and write
46A0000
heap
page read and write
99C000
heap
page read and write
7FE000
heap
page read and write
44B1000
heap
page read and write
951000
heap
page read and write
2FD1000
heap
page read and write
7C1000
heap
page read and write
46A0000
trusted library allocation
page read and write
3F0E000
stack
page read and write
854000
heap
page read and write
37D0000
heap
page read and write
1029C000
unkown
page read and write
335E000
heap
page read and write
1593000
heap
page read and write
4DD1000
heap
page read and write
10231000
unkown
page read and write
333D000
heap
page read and write
155D000
heap
page read and write
4121000
heap
page read and write
331D000
heap
page read and write
4E0D000
stack
page read and write
3361000
heap
page read and write
10199000
unkown
page readonly
4110000
heap
page read and write
10214000
unkown
page read and write
32A4000
heap
page read and write
560000
heap
page read and write
4F29000
heap
page read and write
F2A000
stack
page read and write
3D4C000
stack
page read and write
33B4000
heap
page read and write
18C000
stack
page read and write
10000000
unkown
page readonly
33B4000
heap
page read and write
3361000
heap
page read and write
579E000
stack
page read and write
938000
heap
page read and write
4EAE000
stack
page read and write
7FE000
heap
page read and write
7C1000
heap
page read and write
10CC9000
unkown
page execute read
7C1000
heap
page read and write
157B000
heap
page read and write
337C000
heap
page read and write
92D000
heap
page read and write
102C9000
unkown
page execute read
99A000
heap
page read and write
FD4000
heap
page read and write
4F24000
heap
page read and write
FD4000
heap
page read and write
7D5000
heap
page read and write
962000
heap
page read and write
44B1000
heap
page read and write
1596000
heap
page read and write
4DD1000
heap
page read and write
154A000
heap
page read and write
FD4000
heap
page read and write
4121000
heap
page read and write
938000
heap
page read and write
10FB3000
unkown
page readonly
94C000
heap
page read and write
5A20000
heap
page read and write
428E000
stack
page read and write
4DCD000
stack
page read and write
FD4000
heap
page read and write
79E000
heap
page read and write
7DA000
heap
page read and write
7D2000
heap
page read and write
33B4000
heap
page read and write
335E000
heap
page read and write
4F26000
heap
page read and write
333D000
heap
page read and write
6790000
trusted library allocation
page read and write
98F000
heap
page read and write
1561000
heap
page read and write
414E000
stack
page read and write
571C000
stack
page read and write
153D000
heap
page read and write
809000
heap
page read and write
569000
stack
page read and write
FD4000
heap
page read and write
970000
heap
page read and write
520000
heap
page read and write
A9E000
stack
page read and write
156D000
heap
page read and write
333D000
heap
page read and write
807000
heap
page read and write
7D6000
heap
page read and write
4AC0000
remote allocation
page read and write
4480000
heap
page read and write
4B0E000
stack
page read and write
854000
heap
page read and write
155D000
heap
page read and write
854000
heap
page read and write
350E000
stack
page read and write
589E000
stack
page read and write
99A000
heap
page read and write
1566000
heap
page read and write
80D000
heap
page read and write
3FDE000
stack
page read and write
ADD000
stack
page read and write
7CC000
heap
page read and write
5020000
heap
page read and write
99A000
heap
page read and write
809000
heap
page read and write
4D0C000
stack
page read and write
967000
heap
page read and write
4DD1000
heap
page read and write
153D000
heap
page read and write
4AC0000
remote allocation
page read and write
1559000
heap
page read and write
333D000
heap
page read and write
31B0000
remote allocation
page read and write
330A000
heap
page read and write
1592000
heap
page read and write
3ECC000
stack
page read and write
7CC000
heap
page read and write
31B0000
remote allocation
page read and write
854000
heap
page read and write
33B4000
heap
page read and write
7CC000
heap
page read and write
585E000
stack
page read and write
44B1000
heap
page read and write
43C0000
heap
page read and write
14E1000
heap
page read and write
79A000
heap
page read and write
969000
heap
page read and write
4121000
heap
page read and write
7D2000
heap
page read and write
58DF000
stack
page read and write
962000
heap
page read and write
4DD1000
heap
page read and write
33B4000
heap
page read and write
10FF6000
unkown
page readonly
144E000
stack
page read and write
947000
heap
page read and write
98F000
heap
page read and write
4CB5000
heap
page read and write
10231000
unkown
page read and write
964000
heap
page read and write
40E0000
heap
page read and write
3316000
heap
page read and write
5034000
heap
page read and write
1556000
heap
page read and write
802000
heap
page read and write
802000
heap
page read and write
3334000
heap
page read and write
98F000
heap
page read and write
2C07000
heap
page read and write
3359000
heap
page read and write
850000
heap
page read and write
5B60000
trusted library allocation
page read and write
4C99000
heap
page read and write
10199000
unkown
page readonly
43B0000
trusted library allocation
page read and write
2F79000
stack
page read and write
4D8D000
stack
page read and write
4024000
heap
page read and write
1557000
heap
page read and write
96D000
heap
page read and write
4DD1000
heap
page read and write
50E0000
heap
page read and write
FD0000
heap
page read and write
33B4000
heap
page read and write
96D000
heap
page read and write
33B4000
heap
page read and write
99A000
heap
page read and write
854000
heap
page read and write
31C0000
heap
page read and write
7D4000
heap
page read and write
5903000
heap
page read and write
5AC000
stack
page read and write
157D000
heap
page read and write
951000
heap
page read and write
102C9000
unkown
page execute read
13D0000
trusted library allocation
page read and write
400F000
stack
page read and write
7D6000
heap
page read and write
7B8000
heap
page read and write
8BA000
heap
page read and write
1596000
heap
page read and write
4AC0000
remote allocation
page read and write
4020000
trusted library allocation
page read and write
155D000
heap
page read and write
156D000
heap
page read and write
946000
heap
page read and write
4F21000
heap
page read and write
14BF000
heap
page read and write
98F000
heap
page read and write
7FE000
heap
page read and write
5907000
heap
page read and write
99A000
heap
page read and write
567000
heap
page read and write
10199000
unkown
page readonly
1566000
heap
page read and write
1029E000
unkown
page execute read
1592000
heap
page read and write
33B4000
heap
page read and write
153D000
heap
page read and write
951000
heap
page read and write
2B4D000
stack
page read and write
56C000
heap
page read and write
3290000
heap
page read and write
4450000
heap
page read and write
30E0000
heap
page read and write
4B4F000
stack
page read and write
854000
heap
page read and write
9AD000
heap
page read and write
8DB000
heap
page read and write
951000
heap
page read and write
94B000
heap
page read and write
820000
heap
page read and write
5905000
heap
page read and write
1029C000
unkown
page read and write
4DD1000
heap
page read and write
156D000
heap
page read and write
5903000
heap
page read and write
807000
heap
page read and write
4120000
heap
page read and write
4E60000
remote allocation
page read and write
44B0000
heap
page read and write
3190000
heap
page read and write
98B000
heap
page read and write
2B8F000
stack
page read and write
140E000
stack
page read and write
44A0000
heap
page read and write
4121000
heap
page read and write
64F0000
trusted library allocation
page read and write
44B1000
heap
page read and write
33B4000
heap
page read and write
710000
heap
page read and write
36D0000
heap
page read and write
4020000
trusted library allocation
page read and write
155D000
heap
page read and write
7CC000
heap
page read and write
1559000
heap
page read and write
1596000
heap
page read and write
33B4000
heap
page read and write
335C000
heap
page read and write
7D2000
heap
page read and write
4454000
heap
page read and write
1592000
heap
page read and write
1599000
heap
page read and write
33B4000
heap
page read and write
4121000
heap
page read and write
10297000
unkown
page read and write
10FB3000
unkown
page readonly
1F0000
heap
page read and write
17C4000
heap
page read and write
947000
heap
page read and write
970000
heap
page read and write
FA0000
heap
page read and write
7A3000
heap
page read and write
3C4A000
stack
page read and write
9A8000
heap
page read and write
13D0000
trusted library allocation
page read and write
4131000
heap
page read and write
2C00000
heap
page read and write
80A000
heap
page read and write
36D8000
heap
page read and write
16AF000
stack
page read and write
967000
heap
page read and write
5900000
heap
page read and write
1538000
heap
page read and write
99A000
heap
page read and write
1578000
heap
page read and write
56DA000
stack
page read and write
4B90000
heap
page read and write
3294000
heap
page read and write
404E000
stack
page read and write
590B000
heap
page read and write
FD4000
heap
page read and write
F90000
heap
page read and write
951000
heap
page read and write
3313000
heap
page read and write
1023F000
unkown
page read and write
A5E000
stack
page read and write
337E000
heap
page read and write
99A000
heap
page read and write
2FD1000
heap
page read and write
5A28000
heap
page read and write
80A000
heap
page read and write
10001000
unkown
page execute read
810000
heap
page read and write
4E60000
remote allocation
page read and write
33B4000
heap
page read and write
10297000
unkown
page read and write
99A000
heap
page read and write
14E8000
heap
page read and write
98B000
heap
page read and write
330A000
heap
page read and write
4740000
heap
page read and write
3316000
heap
page read and write
1566000
heap
page read and write
4DD1000
heap
page read and write
33B4000
heap
page read and write
1029E000
unkown
page execute read
74C000
heap
page read and write
There are 615 hidden memdumps, click here to show them.