IOC Report
Loader.exe

loading gif

Files

File Path
Type
Category
Malicious
Loader.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Loader.exe.log
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\d3d9.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Loader.exe
"C:\Users\user\Desktop\Loader.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
grandcommonyktsju.xyz
malicious
cooperatvassquaidmew.xyz
malicious
exuberanttjdkwo.xyz
malicious
qualificationjdwko.xyz
malicious
wordingnatturedowo.xyz
malicious
deadtrainingactioniw.xyz
malicious
crisisrottenyjs.xyz
malicious
sweetcalcutangkdow.xyz
malicious
https://sweetcalcutangkdow.xyz/
unknown
https://cooperatvassquaidmew.xyz/
unknown
https://qualificationjdwko.xyz/api
unknown
https://sweetcalcutangkdow.xyz/api
unknown
https://sweetcalcutangkdow.xyz/apiz9
unknown
https://exuberanttjdkwo.xyz/api
unknown
https://grandcommonyktsju.xyz/
unknown
https://deadtrainingactioniw.xyz/api
unknown
https://grandcommonyktsju.xyz/api
unknown
https://qualificationjdwko.xyz/apidO
unknown
https://qualificationjdwko.xyz/A
unknown
https://grandcommonyktsju.xyz/apiz?
unknown
https://qualificationjdwko.xyz/
unknown
https://crisisrottenyjs.xyz/api
unknown
https://deadtrainingactioniw.xyz/0
unknown
https://qualificationjdwko.xyz/7
unknown
https://cooperatvassquaidmew.xyz/api
unknown
https://deadtrainingactioniw.xyz/
unknown
https://qualificationjdwko.xyz/apizC
unknown
There are 17 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
qualificationjdwko.xyz
unknown
malicious
crisisrottenyjs.xyz
unknown
malicious
deadtrainingactioniw.xyz
unknown
malicious
grandcommonyktsju.xyz
unknown
malicious
cooperatvassquaidmew.xyz
unknown
malicious
sweetcalcutangkdow.xyz
unknown
malicious
exuberanttjdkwo.xyz
unknown
malicious
wordingnatturedowo.xyz
unknown
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
58D000
remote allocation
page readonly
malicious
14B8000
heap
page read and write
12C7000
trusted library allocation
page execute and read and write
497E000
stack
page read and write
5FB000
heap
page read and write
301F000
stack
page read and write
42AD000
stack
page read and write
43AE000
stack
page read and write
132E000
stack
page read and write
6D38E000
unkown
page readonly
590000
remote allocation
page execute and read and write
299F000
stack
page read and write
5FB000
heap
page read and write
6D321000
unkown
page execute read
C72000
unkown
page readonly
638000
heap
page read and write
30D7000
trusted library allocation
page read and write
551000
remote allocation
page execute read
1561000
heap
page read and write
60D000
heap
page read and write
63F000
heap
page read and write
639000
heap
page read and write
60D000
heap
page read and write
56BE000
stack
page read and write
43C000
stack
page read and write
16AF000
stack
page read and write
60D000
heap
page read and write
780000
heap
page read and write
5E0000
heap
page read and write
5F6000
heap
page read and write
DE0000
heap
page read and write
51BE000
stack
page read and write
53C000
stack
page read and write
77E000
stack
page read and write
14DD000
heap
page read and write
30A0000
trusted library section
page read and write
638000
heap
page read and write
624000
heap
page read and write
14F2000
heap
page read and write
DD0000
heap
page read and write
43ED000
stack
page read and write
12B0000
heap
page read and write
44F0000
remote allocation
page read and write
63B000
heap
page read and write
1770000
heap
page read and write
30B0000
heap
page execute and read and write
1330000
heap
page read and write
1571000
heap
page read and write
14B0000
heap
page read and write
C72000
unkown
page execute and read and write
14DF000
heap
page read and write
157B000
heap
page read and write
1294000
trusted library allocation
page read and write
550000
remote allocation
page execute and read and write
1390000
trusted library allocation
page read and write
10FB000
stack
page read and write
1270000
trusted library allocation
page read and write
309E000
stack
page read and write
30C1000
trusted library allocation
page read and write
730000
heap
page read and write
13A0000
heap
page read and write
305E000
stack
page read and write
624000
heap
page read and write
487D000
stack
page read and write
1290000
trusted library allocation
page read and write
735000
heap
page read and write
AD3E000
stack
page read and write
607000
heap
page read and write
1284000
trusted library allocation
page read and write
6D320000
unkown
page readonly
44F0000
remote allocation
page read and write
151C000
heap
page read and write
14AF000
stack
page read and write
4260000
heap
page read and write
7B3E000
stack
page read and write
638000
heap
page read and write
1380000
trusted library allocation
page execute and read and write
CDA000
unkown
page readonly
155B000
heap
page read and write
14BE000
heap
page read and write
124E000
stack
page read and write
622000
heap
page read and write
5A2000
remote allocation
page readonly
44ED000
stack
page read and write
72E000
stack
page read and write
553E000
stack
page read and write
137D000
stack
page read and write
622000
heap
page read and write
1554000
heap
page read and write
12C0000
trusted library allocation
page read and write
14E6000
heap
page read and write
5E8000
heap
page read and write
6E0000
heap
page read and write
624000
heap
page read and write
30CB000
trusted library allocation
page read and write
12CB000
trusted library allocation
page execute and read and write
55B0000
heap
page execute and read and write
40C1000
trusted library allocation
page read and write
120E000
stack
page read and write
D6C000
stack
page read and write
AC3D000
stack
page read and write
C70000
unkown
page readonly
30D3000
trusted library allocation
page read and write
622000
heap
page read and write
12E0000
trusted library allocation
page read and write
1750000
trusted library allocation
page read and write
558E000
stack
page read and write
1283000
trusted library allocation
page execute and read and write
2A9F000
stack
page read and write
6D340000
unkown
page read and write
6D339000
unkown
page readonly
7A0000
heap
page read and write
48C5000
trusted library allocation
page read and write
44F0000
remote allocation
page read and write
609000
heap
page read and write
C70000
unkown
page execute and read and write
1292000
trusted library allocation
page read and write
There are 107 hidden memdumps, click here to show them.