Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
Loader.exe
|
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
|
initial sample
|
||
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Loader.exe.log
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Roaming\d3d9.dll
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\Loader.exe
|
"C:\Users\user\Desktop\Loader.exe"
|
||
C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe
|
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
grandcommonyktsju.xyz
|
|||
cooperatvassquaidmew.xyz
|
|||
exuberanttjdkwo.xyz
|
|||
qualificationjdwko.xyz
|
|||
wordingnatturedowo.xyz
|
|||
deadtrainingactioniw.xyz
|
|||
crisisrottenyjs.xyz
|
|||
sweetcalcutangkdow.xyz
|
|||
https://sweetcalcutangkdow.xyz/
|
unknown
|
||
https://cooperatvassquaidmew.xyz/
|
unknown
|
||
https://qualificationjdwko.xyz/api
|
unknown
|
||
https://sweetcalcutangkdow.xyz/api
|
unknown
|
||
https://sweetcalcutangkdow.xyz/apiz9
|
unknown
|
||
https://exuberanttjdkwo.xyz/api
|
unknown
|
||
https://grandcommonyktsju.xyz/
|
unknown
|
||
https://deadtrainingactioniw.xyz/api
|
unknown
|
||
https://grandcommonyktsju.xyz/api
|
unknown
|
||
https://qualificationjdwko.xyz/apidO
|
unknown
|
||
https://qualificationjdwko.xyz/A
|
unknown
|
||
https://grandcommonyktsju.xyz/apiz?
|
unknown
|
||
https://qualificationjdwko.xyz/
|
unknown
|
||
https://crisisrottenyjs.xyz/api
|
unknown
|
||
https://deadtrainingactioniw.xyz/0
|
unknown
|
||
https://qualificationjdwko.xyz/7
|
unknown
|
||
https://cooperatvassquaidmew.xyz/api
|
unknown
|
||
https://deadtrainingactioniw.xyz/
|
unknown
|
||
https://qualificationjdwko.xyz/apizC
|
unknown
|
There are 17 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
qualificationjdwko.xyz
|
unknown
|
||
crisisrottenyjs.xyz
|
unknown
|
||
deadtrainingactioniw.xyz
|
unknown
|
||
grandcommonyktsju.xyz
|
unknown
|
||
cooperatvassquaidmew.xyz
|
unknown
|
||
sweetcalcutangkdow.xyz
|
unknown
|
||
exuberanttjdkwo.xyz
|
unknown
|
||
wordingnatturedowo.xyz
|
unknown
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
58D000
|
remote allocation
|
page readonly
|
||
14B8000
|
heap
|
page read and write
|
||
12C7000
|
trusted library allocation
|
page execute and read and write
|
||
497E000
|
stack
|
page read and write
|
||
5FB000
|
heap
|
page read and write
|
||
301F000
|
stack
|
page read and write
|
||
42AD000
|
stack
|
page read and write
|
||
43AE000
|
stack
|
page read and write
|
||
132E000
|
stack
|
page read and write
|
||
6D38E000
|
unkown
|
page readonly
|
||
590000
|
remote allocation
|
page execute and read and write
|
||
299F000
|
stack
|
page read and write
|
||
5FB000
|
heap
|
page read and write
|
||
6D321000
|
unkown
|
page execute read
|
||
C72000
|
unkown
|
page readonly
|
||
638000
|
heap
|
page read and write
|
||
30D7000
|
trusted library allocation
|
page read and write
|
||
551000
|
remote allocation
|
page execute read
|
||
1561000
|
heap
|
page read and write
|
||
60D000
|
heap
|
page read and write
|
||
63F000
|
heap
|
page read and write
|
||
639000
|
heap
|
page read and write
|
||
60D000
|
heap
|
page read and write
|
||
56BE000
|
stack
|
page read and write
|
||
43C000
|
stack
|
page read and write
|
||
16AF000
|
stack
|
page read and write
|
||
60D000
|
heap
|
page read and write
|
||
780000
|
heap
|
page read and write
|
||
5E0000
|
heap
|
page read and write
|
||
5F6000
|
heap
|
page read and write
|
||
DE0000
|
heap
|
page read and write
|
||
51BE000
|
stack
|
page read and write
|
||
53C000
|
stack
|
page read and write
|
||
77E000
|
stack
|
page read and write
|
||
14DD000
|
heap
|
page read and write
|
||
30A0000
|
trusted library section
|
page read and write
|
||
638000
|
heap
|
page read and write
|
||
624000
|
heap
|
page read and write
|
||
14F2000
|
heap
|
page read and write
|
||
DD0000
|
heap
|
page read and write
|
||
43ED000
|
stack
|
page read and write
|
||
12B0000
|
heap
|
page read and write
|
||
44F0000
|
remote allocation
|
page read and write
|
||
63B000
|
heap
|
page read and write
|
||
1770000
|
heap
|
page read and write
|
||
30B0000
|
heap
|
page execute and read and write
|
||
1330000
|
heap
|
page read and write
|
||
1571000
|
heap
|
page read and write
|
||
14B0000
|
heap
|
page read and write
|
||
C72000
|
unkown
|
page execute and read and write
|
||
14DF000
|
heap
|
page read and write
|
||
157B000
|
heap
|
page read and write
|
||
1294000
|
trusted library allocation
|
page read and write
|
||
550000
|
remote allocation
|
page execute and read and write
|
||
1390000
|
trusted library allocation
|
page read and write
|
||
10FB000
|
stack
|
page read and write
|
||
1270000
|
trusted library allocation
|
page read and write
|
||
309E000
|
stack
|
page read and write
|
||
30C1000
|
trusted library allocation
|
page read and write
|
||
730000
|
heap
|
page read and write
|
||
13A0000
|
heap
|
page read and write
|
||
305E000
|
stack
|
page read and write
|
||
624000
|
heap
|
page read and write
|
||
487D000
|
stack
|
page read and write
|
||
1290000
|
trusted library allocation
|
page read and write
|
||
735000
|
heap
|
page read and write
|
||
AD3E000
|
stack
|
page read and write
|
||
607000
|
heap
|
page read and write
|
||
1284000
|
trusted library allocation
|
page read and write
|
||
6D320000
|
unkown
|
page readonly
|
||
44F0000
|
remote allocation
|
page read and write
|
||
151C000
|
heap
|
page read and write
|
||
14AF000
|
stack
|
page read and write
|
||
4260000
|
heap
|
page read and write
|
||
7B3E000
|
stack
|
page read and write
|
||
638000
|
heap
|
page read and write
|
||
1380000
|
trusted library allocation
|
page execute and read and write
|
||
CDA000
|
unkown
|
page readonly
|
||
155B000
|
heap
|
page read and write
|
||
14BE000
|
heap
|
page read and write
|
||
124E000
|
stack
|
page read and write
|
||
622000
|
heap
|
page read and write
|
||
5A2000
|
remote allocation
|
page readonly
|
||
44ED000
|
stack
|
page read and write
|
||
72E000
|
stack
|
page read and write
|
||
553E000
|
stack
|
page read and write
|
||
137D000
|
stack
|
page read and write
|
||
622000
|
heap
|
page read and write
|
||
1554000
|
heap
|
page read and write
|
||
12C0000
|
trusted library allocation
|
page read and write
|
||
14E6000
|
heap
|
page read and write
|
||
5E8000
|
heap
|
page read and write
|
||
6E0000
|
heap
|
page read and write
|
||
624000
|
heap
|
page read and write
|
||
30CB000
|
trusted library allocation
|
page read and write
|
||
12CB000
|
trusted library allocation
|
page execute and read and write
|
||
55B0000
|
heap
|
page execute and read and write
|
||
40C1000
|
trusted library allocation
|
page read and write
|
||
120E000
|
stack
|
page read and write
|
||
D6C000
|
stack
|
page read and write
|
||
AC3D000
|
stack
|
page read and write
|
||
C70000
|
unkown
|
page readonly
|
||
30D3000
|
trusted library allocation
|
page read and write
|
||
622000
|
heap
|
page read and write
|
||
12E0000
|
trusted library allocation
|
page read and write
|
||
1750000
|
trusted library allocation
|
page read and write
|
||
558E000
|
stack
|
page read and write
|
||
1283000
|
trusted library allocation
|
page execute and read and write
|
||
2A9F000
|
stack
|
page read and write
|
||
6D340000
|
unkown
|
page read and write
|
||
6D339000
|
unkown
|
page readonly
|
||
7A0000
|
heap
|
page read and write
|
||
48C5000
|
trusted library allocation
|
page read and write
|
||
44F0000
|
remote allocation
|
page read and write
|
||
609000
|
heap
|
page read and write
|
||
C70000
|
unkown
|
page execute and read and write
|
||
1292000
|
trusted library allocation
|
page read and write
|
There are 107 hidden memdumps, click here to show them.