IOC Report
8yprhxqBVs.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\8yprhxqBVs.exe
"C:\Users\user\Desktop\8yprhxqBVs.exe"
malicious

URLs

Name
IP
Malicious
cooperatvassquaidmew.xyzn
malicious
grandcommonyktsju.xyz
malicious
exuberanttjdkwo.xyz
malicious
qualificationjdwko.xyz
malicious
wordingnatturedowo.xyz
malicious
deadtrainingactioniw.xyzn
malicious
crisisrottenyjs.xyz
malicious
sweetcalcutangkdow.xyz
malicious
https://sweetcalcutangkdow.xyz/
unknown
https://cooperatvassquaidmew.xyz/
unknown
https://crisisrottenyjs.xyz/SOR
unknown
https://qualificationjdwko.xyz/api
unknown
https://sweetcalcutangkdow.xyz/api
unknown
https://turbosms.ua
unknown
https://deadtrainingactioniw.xyz/api
unknown
https://deadtrainingactioniw.xyz:443/api
unknown
https://qualificationjdwko.xyz/
unknown
https://wordingnatturedowo.xyz/
unknown
https://crisisrottenyjs.xyz/api
unknown
https://deadtrainingactioniw.xyz/
unknown
https://wordingnatturedowo.xyz/apisX
unknown
https://exuberanttjdkwo.xyz/es(
unknown
https://qualificationjdwko.xyz/api4
unknown
https://wordingnatturedowo.xyz/api
unknown
https://qualificationjdwko.xyz/a
unknown
https://deadtrainingactioniw.xyz/)G4
unknown
https://deadtrainingactioniw.xyz/api(
unknown
https://grandcommonyktsju.xyz/B
unknown
There are 18 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
qualificationjdwko.xyz
unknown
malicious
crisisrottenyjs.xyz
unknown
malicious
deadtrainingactioniw.xyz
unknown
malicious
grandcommonyktsju.xyz
unknown
malicious
cooperatvassquaidmew.xyz
unknown
malicious
sweetcalcutangkdow.xyz
unknown
malicious
wordingnatturedowo.xyz
unknown
malicious
exuberanttjdkwo.xyz
unknown
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
EBB000
unkown
page readonly
malicious
39BE000
stack
page read and write
E81000
unkown
page execute read
35EE000
stack
page read and write
179F000
unkown
page readonly
B5C000
stack
page read and write
34ED000
stack
page read and write
195B000
heap
page read and write
194B000
heap
page read and write
1958000
heap
page read and write
366E000
stack
page read and write
EBE000
unkown
page read and write
E80000
unkown
page readonly
1961000
heap
page read and write
1CEE000
stack
page read and write
BC0000
heap
page read and write
39D0000
remote allocation
page read and write
197A000
heap
page read and write
192A000
heap
page read and write
1966000
heap
page read and write
11B0000
unkown
page read and write
1974000
heap
page read and write
1971000
heap
page read and write
1BEF000
stack
page read and write
362D000
stack
page read and write
198B000
heap
page read and write
BC5000
heap
page read and write
1965000
heap
page read and write
190C000
stack
page read and write
39D0000
remote allocation
page read and write
1992000
heap
page read and write
198E000
heap
page read and write
1920000
heap
page read and write
197D000
heap
page read and write
1974000
heap
page read and write
11B1000
unkown
page execute read
ED0000
unkown
page execute read
39D0000
remote allocation
page read and write
BD0000
heap
page read and write
1948000
heap
page read and write
E3E000
stack
page read and write
38BE000
stack
page read and write
11B0000
unkown
page write copy
17A8000
unkown
page readonly
1992000
heap
page read and write
3490000
trusted library allocation
page read and write
E7E000
stack
page read and write
1986000
heap
page read and write
1943000
heap
page read and write
377D000
stack
page read and write
192E000
heap
page read and write
1994000
heap
page read and write
3E5E000
stack
page read and write
BE0000
heap
page read and write
1952000
heap
page read and write
387F000
stack
page read and write
1987000
heap
page read and write
1952000
heap
page read and write
3670000
heap
page read and write
3D5D000
stack
page read and write
3490000
heap
page read and write
There are 51 hidden memdumps, click here to show them.