Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
YY#U6302#U53f7#U534f#U8bae.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Users\user\AppData\Local\Temp\iext1.fnr.bbs.125.la
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\YY#U6302#U53f7#U534f#U8bae.exe
|
"C:\Users\user\Desktop\YY#U6302#U53f7#U534f#U8bae.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://www.openssl.org/support/faq.html....................rbwb.rndC:HOMERANDFILEPRNG
|
unknown
|
||
https://ysapi.yy.com/api/internal/nobleQuery/QueryUserInfoReq.json?data=
|
unknown
|
||
http://hgame.yy.com/action/getUserLoginInfo.jsondata.ownChannels
|
unknown
|
||
https://www.yy.com/zone/assets/total.json
|
unknown
|
||
http://www.yy.com/search-
|
unknown
|
||
http://120.26.95.191:5659/
|
unknown
|
||
http://www.openssl.org/V
|
unknown
|
||
http://www.yy.com/
|
unknown
|
||
http://peipei.yy.com/web/account/internal/account/list
|
unknown
|
||
https://www.yy.com/u/
|
unknown
|
||
http://bbs.125.la/
|
unknown
|
||
https://bbs.125.la/thread-14738139-1-1.html
|
unknown
|
||
http://vip.yy.com/service/web/user/info?_time=vipLevel
|
unknown
|
||
http://hgame.yy.com/action/getUserLoginInfo.json
|
unknown
|
||
https://captcha.yy.com/baidu/submit.do?appid=
|
unknown
|
||
https://www.dmdaili.com/yaoqing/33405.html
|
unknown
|
||
https://passport.baidu.com/viewlog/getstyle?ak=
|
unknown
|
||
https://www.yy.com/zone/userinfo/getUserInfo.json
|
unknown
|
||
http://www.openssl.org/support/faq.html
|
unknown
|
||
https://hd.vip.yy.com/service/hdplatform/drawgift/202402ee1a8f/giftpagingp?drawGiftGroupId=202402ee1
|
unknown
|
||
https://iexui.com/downexui
|
unknown
|
||
http://do-dw.yy.com/user.php?sids=
|
unknown
|
||
https://hgame.yy.com/person/p_account
|
unknown
|
||
https://captcha.yy.com/baidu/submit.do?appid=obj
|
unknown
|
||
https://yyfkw.cn
|
unknown
|
||
http://117.72.34.175:1011/?OrderID=4BA33E0B1BE84295&ipnumber=50
|
unknown
|
||
http://120.26.95.191:5658/
|
unknown
|
||
https://lxcode.bs2cdn.yy.com/a413808b-e679-47f1-9380-be7b3ebf8813.xml?from=yywebconfigData/giftDatac
|
unknown
|
||
http://vip.yy.com/service/web/user/info?_time=
|
unknown
|
||
http://vip.yy.com/vip/vcard/indexrest?_time=
|
unknown
|
||
http://www.yy.com/sid
|
unknown
|
||
https://www.xiequ.cn/index.html?dc1bbee2
|
unknown
|
||
http://www.uc.cn/ip
|
unknown
|
||
https://udb.yy.com/authentication.do?action=authenticate&appid=5060&busiUrl=http%3A%2F%2Fwww.yy.com&
|
unknown
|
||
https://www.yy.com/gu/
|
unknown
|
||
http://www.uc.cn/ipIP:http://
|
unknown
|
||
https://nfnba.lanzoub.com/ietaw0udyhid
|
unknown
|
||
https://yyfkw.cn999https://nfnba.lanzoub.com/ietaw0udyhid
|
unknown
|
||
http://120.26.95.191:5658/http://120.26.95.191:5659/qq17336171577b2cc005c28c42472000e7863283a212&_=h
|
unknown
|
||
https://lxcode.bs2cdn.yy.com/a413808b-e679-47f1-9380-be7b3ebf8813.xml?from=yyweb
|
unknown
|
||
https://passport.baidu.com/viewlog?ak=
|
unknown
|
||
http://channel.yy.com/ajax/member/indexAction
|
unknown
|
There are 32 hidden URLs, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
1349000
|
heap
|
page read and write
|
||
1369000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
6CF97000
|
unkown
|
page read and write
|
||
6CEF0000
|
unkown
|
page readonly
|
||
2FC1000
|
heap
|
page read and write
|
||
1393000
|
heap
|
page read and write
|
||
1393000
|
heap
|
page read and write
|
||
2F09000
|
heap
|
page read and write
|
||
1376000
|
heap
|
page read and write
|
||
19C000
|
stack
|
page read and write
|
||
2CD0000
|
heap
|
page read and write
|
||
1305000
|
heap
|
page read and write
|
||
F98000
|
unkown
|
page execute and write copy
|
||
1195000
|
heap
|
page read and write
|
||
B88000
|
unkown
|
page readonly
|
||
F97000
|
unkown
|
page execute and read and write
|
||
2CB0000
|
heap
|
page read and write
|
||
1373000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
1130000
|
heap
|
page read and write
|
||
1376000
|
heap
|
page read and write
|
||
6CF91000
|
unkown
|
page read and write
|
||
1309000
|
heap
|
page read and write
|
||
5A0000
|
unkown
|
page readonly
|
||
2E04000
|
heap
|
page read and write
|
||
99000
|
stack
|
page read and write
|
||
1342000
|
heap
|
page read and write
|
||
131E000
|
heap
|
page read and write
|
||
1377000
|
heap
|
page read and write
|
||
1376000
|
heap
|
page read and write
|
||
9DD000
|
unkown
|
page readonly
|
||
1376000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
12DE000
|
stack
|
page read and write
|
||
2FC0000
|
heap
|
page read and write
|
||
12E0000
|
heap
|
page read and write
|
||
117E000
|
stack
|
page read and write
|
||
33DE000
|
stack
|
page read and write
|
||
1351000
|
heap
|
page read and write
|
||
6CF98000
|
unkown
|
page write copy
|
||
2E00000
|
heap
|
page read and write
|
||
1310000
|
heap
|
page read and write
|
||
B86000
|
unkown
|
page read and write
|
||
1300000
|
heap
|
page read and write
|
||
B93000
|
unkown
|
page execute and read and write
|
||
6CF9F000
|
unkown
|
page readonly
|
||
138A000
|
heap
|
page read and write
|
||
B88000
|
unkown
|
page readonly
|
||
136E000
|
heap
|
page read and write
|
||
34DF000
|
stack
|
page read and write
|
||
329E000
|
stack
|
page read and write
|
||
30C0000
|
trusted library allocation
|
page read and write
|
||
136E000
|
heap
|
page read and write
|
||
1376000
|
heap
|
page read and write
|
||
3268000
|
heap
|
page read and write
|
||
150F000
|
stack
|
page read and write
|
||
B94000
|
unkown
|
page execute and write copy
|
||
1197000
|
heap
|
page read and write
|
||
6CF92000
|
unkown
|
page write copy
|
||
1361000
|
heap
|
page read and write
|
||
30FC000
|
stack
|
page read and write
|
||
1393000
|
heap
|
page read and write
|
||
B47000
|
unkown
|
page read and write
|
||
B80000
|
unkown
|
page read and write
|
||
2DF0000
|
heap
|
page read and write
|
||
6CEF1000
|
unkown
|
page execute read
|
||
133F000
|
heap
|
page read and write
|
||
131A000
|
heap
|
page read and write
|
||
339F000
|
stack
|
page read and write
|
||
136E000
|
heap
|
page read and write
|
||
325E000
|
stack
|
page read and write
|
||
6CF60000
|
unkown
|
page readonly
|
||
4E60000
|
trusted library allocation
|
page read and write
|
||
1190000
|
heap
|
page read and write
|
||
6CF9D000
|
unkown
|
page read and write
|
||
B18000
|
unkown
|
page read and write
|
||
3100000
|
heap
|
page read and write
|
||
B93000
|
unkown
|
page execute and write copy
|
||
2CD5000
|
heap
|
page read and write
|
||
3150000
|
heap
|
page read and write
|
||
1050000
|
heap
|
page read and write
|
||
B39000
|
unkown
|
page read and write
|
||
1393000
|
heap
|
page read and write
|
||
1393000
|
heap
|
page read and write
|
||
1366000
|
heap
|
page read and write
|
||
1349000
|
heap
|
page read and write
|
||
129F000
|
stack
|
page read and write
|
||
136E000
|
heap
|
page read and write
|
||
6CFA3000
|
unkown
|
page readonly
|
||
B8F000
|
unkown
|
page execute read
|
There are 81 hidden memdumps, click here to show them.