IOC Report
YY#U6302#U53f7#U534f#U8bae.exe

loading gif

Files

File Path
Type
Category
Malicious
YY#U6302#U53f7#U534f#U8bae.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Temp\iext1.fnr.bbs.125.la
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\YY#U6302#U53f7#U534f#U8bae.exe
"C:\Users\user\Desktop\YY#U6302#U53f7#U534f#U8bae.exe"
malicious

URLs

Name
IP
Malicious
http://www.openssl.org/support/faq.html....................rbwb.rndC:HOMERANDFILEPRNG
unknown
https://ysapi.yy.com/api/internal/nobleQuery/QueryUserInfoReq.json?data=
unknown
http://hgame.yy.com/action/getUserLoginInfo.jsondata.ownChannels
unknown
https://www.yy.com/zone/assets/total.json
unknown
http://www.yy.com/search-
unknown
http://120.26.95.191:5659/
unknown
http://www.openssl.org/V
unknown
http://www.yy.com/
unknown
http://peipei.yy.com/web/account/internal/account/list
unknown
https://www.yy.com/u/
unknown
http://bbs.125.la/
unknown
https://bbs.125.la/thread-14738139-1-1.html
unknown
http://vip.yy.com/service/web/user/info?_time=vipLevel
unknown
http://hgame.yy.com/action/getUserLoginInfo.json
unknown
https://captcha.yy.com/baidu/submit.do?appid=
unknown
https://www.dmdaili.com/yaoqing/33405.html
unknown
https://passport.baidu.com/viewlog/getstyle?ak=
unknown
https://www.yy.com/zone/userinfo/getUserInfo.json
unknown
http://www.openssl.org/support/faq.html
unknown
https://hd.vip.yy.com/service/hdplatform/drawgift/202402ee1a8f/giftpagingp?drawGiftGroupId=202402ee1
unknown
https://iexui.com/downexui
unknown
http://do-dw.yy.com/user.php?sids=
unknown
https://hgame.yy.com/person/p_account
unknown
https://captcha.yy.com/baidu/submit.do?appid=obj
unknown
https://yyfkw.cn
unknown
http://117.72.34.175:1011/?OrderID=4BA33E0B1BE84295&ipnumber=50
unknown
http://120.26.95.191:5658/
unknown
https://lxcode.bs2cdn.yy.com/a413808b-e679-47f1-9380-be7b3ebf8813.xml?from=yywebconfigData/giftDatac
unknown
http://vip.yy.com/service/web/user/info?_time=
unknown
http://vip.yy.com/vip/vcard/indexrest?_time=
unknown
http://www.yy.com/sid
unknown
https://www.xiequ.cn/index.html?dc1bbee2
unknown
http://www.uc.cn/ip
unknown
https://udb.yy.com/authentication.do?action=authenticate&appid=5060&busiUrl=http%3A%2F%2Fwww.yy.com&
unknown
https://www.yy.com/gu/
unknown
http://www.uc.cn/ipIP:http://
unknown
https://nfnba.lanzoub.com/ietaw0udyhid
unknown
https://yyfkw.cn999https://nfnba.lanzoub.com/ietaw0udyhid
unknown
http://120.26.95.191:5658/http://120.26.95.191:5659/qq17336171577b2cc005c28c42472000e7863283a212&_=h
unknown
https://lxcode.bs2cdn.yy.com/a413808b-e679-47f1-9380-be7b3ebf8813.xml?from=yyweb
unknown
https://passport.baidu.com/viewlog?ak=
unknown
http://channel.yy.com/ajax/member/indexAction
unknown
There are 32 hidden URLs, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
1349000
heap
page read and write
1369000
heap
page read and write
400000
unkown
page readonly
6CF97000
unkown
page read and write
6CEF0000
unkown
page readonly
2FC1000
heap
page read and write
1393000
heap
page read and write
1393000
heap
page read and write
2F09000
heap
page read and write
1376000
heap
page read and write
19C000
stack
page read and write
2CD0000
heap
page read and write
1305000
heap
page read and write
F98000
unkown
page execute and write copy
1195000
heap
page read and write
B88000
unkown
page readonly
F97000
unkown
page execute and read and write
2CB0000
heap
page read and write
1373000
heap
page read and write
401000
unkown
page execute read
1130000
heap
page read and write
1376000
heap
page read and write
6CF91000
unkown
page read and write
1309000
heap
page read and write
5A0000
unkown
page readonly
2E04000
heap
page read and write
99000
stack
page read and write
1342000
heap
page read and write
131E000
heap
page read and write
1377000
heap
page read and write
1376000
heap
page read and write
9DD000
unkown
page readonly
1376000
heap
page read and write
400000
unkown
page readonly
12DE000
stack
page read and write
2FC0000
heap
page read and write
12E0000
heap
page read and write
117E000
stack
page read and write
33DE000
stack
page read and write
1351000
heap
page read and write
6CF98000
unkown
page write copy
2E00000
heap
page read and write
1310000
heap
page read and write
B86000
unkown
page read and write
1300000
heap
page read and write
B93000
unkown
page execute and read and write
6CF9F000
unkown
page readonly
138A000
heap
page read and write
B88000
unkown
page readonly
136E000
heap
page read and write
34DF000
stack
page read and write
329E000
stack
page read and write
30C0000
trusted library allocation
page read and write
136E000
heap
page read and write
1376000
heap
page read and write
3268000
heap
page read and write
150F000
stack
page read and write
B94000
unkown
page execute and write copy
1197000
heap
page read and write
6CF92000
unkown
page write copy
1361000
heap
page read and write
30FC000
stack
page read and write
1393000
heap
page read and write
B47000
unkown
page read and write
B80000
unkown
page read and write
2DF0000
heap
page read and write
6CEF1000
unkown
page execute read
133F000
heap
page read and write
131A000
heap
page read and write
339F000
stack
page read and write
136E000
heap
page read and write
325E000
stack
page read and write
6CF60000
unkown
page readonly
4E60000
trusted library allocation
page read and write
1190000
heap
page read and write
6CF9D000
unkown
page read and write
B18000
unkown
page read and write
3100000
heap
page read and write
B93000
unkown
page execute and write copy
2CD5000
heap
page read and write
3150000
heap
page read and write
1050000
heap
page read and write
B39000
unkown
page read and write
1393000
heap
page read and write
1393000
heap
page read and write
1366000
heap
page read and write
1349000
heap
page read and write
129F000
stack
page read and write
136E000
heap
page read and write
6CFA3000
unkown
page readonly
B8F000
unkown
page execute read
There are 81 hidden memdumps, click here to show them.