IOC Report
6d8fc5485484ff3a0efee3b5961dd07882f7ab55b472b5884a0a5199ca26f68e_dump.exe

loading gif

Files

File Path
Type
Category
Malicious
6d8fc5485484ff3a0efee3b5961dd07882f7ab55b472b5884a0a5199ca26f68e_dump.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\6d8fc5485484ff3a0efee3b5961dd07882f7ab55b472b5884a0a5199ca26f68e_dump.exe.log
ASCII text, with CRLF line terminators
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\6d8fc5485484ff3a0efee3b5961dd07882f7ab55b472b5884a0a5199ca26f68e_dump.exe
"C:\Users\user\Desktop\6d8fc5485484ff3a0efee3b5961dd07882f7ab55b472b5884a0a5199ca26f68e_dump.exe"
malicious

URLs

Name
IP
Malicious
185.196.9.26:6302
malicious
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Text
unknown
http://schemas.xmlsoap.org/ws/2005/02/sc/sct
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/sc/dk
unknown
http://tempuri.org/Entity/Id23ResponseD
unknown
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#HexBinary
unknown
http://tempuri.org/Entity/Id12Response
unknown
http://tempuri.org/
unknown
http://tempuri.org/Entity/Id2Response
unknown
http://schemas.xmlsoap.org/ws/2005/02/sc/dk/p_sha1
unknown
http://tempuri.org/Entity/Id21Response
unknown
http://schemas.xmlsoap.org/2005/02/trust/spnego#GSS_Wrap
unknown
http://tempuri.org/Entity/Id9
unknown
http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLID
unknown
http://tempuri.org/Entity/Id8
unknown
http://tempuri.org/Entity/Id5
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Prepare
unknown
http://tempuri.org/Entity/Id4
unknown
http://tempuri.org/Entity/Id7
unknown
http://tempuri.org/Entity/Id6
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust#BinarySecret
unknown
http://tempuri.org/Entity/Id19Response
unknown
http://docs.oasis-open.org/wss/oasis-wss-rel-token-profile-1.0.pdf#license
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/Issue
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Aborted
unknown
http://schemas.xmlsoap.org/ws/2005/02/rm/TerminateSequence
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/fault
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat
unknown
http://docs.oasis-open.org/wss/oasis-wss-soap-message-security-1.1#EncryptedKey
unknown
http://tempuri.org/Entity/Id15Response
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/SCT/Renew
unknown
http://schemas.xmlsoap.org/ws/2004/10/wscoor/Register
unknown
http://tempuri.org/Entity/Id6Response
unknown
http://schemas.xmlsoap.org/ws/2004/04/trust/SymmetricKey
unknown
https://api.ip.sb/ip
unknown
http://schemas.xmlsoap.org/ws/2004/04/sc
unknown
http://tempuri.org/Entity/Id1ResponseD
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Volatile2PC
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/SCT/Cancel
unknown
http://tempuri.org/Entity/Id9Response
unknown
http://tempuri.org/Entity/Id20
unknown
http://tempuri.org/Entity/Id21
unknown
http://tempuri.org/Entity/Id22
unknown
http://docs.oasis-open.org/wss/oasis-wss-kerberos-token-profile-1.1#Kerberosv5APREQSHA1
unknown
http://tempuri.org/Entity/Id23
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/CK/PSHA1
unknown
http://tempuri.org/Entity/Id24
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/RSTR/Issue
unknown
http://tempuri.org/Entity/Id24Response
unknown
http://tempuri.org/Entity/Id1Response
unknown
http://schemas.xmlsoap.org/ws/2005/02/rm/AckRequested
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/ReadOnly
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Replay
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/tlsnego
unknown
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Base64Binary
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Durable2PC
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/SymmetricKey
unknown
http://schemas.xmlsoap.org/ws/2004/08/addressing
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RST/Issue
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Completion
unknown
http://schemas.xmlsoap.org/ws/2004/04/trust
unknown
http://tempuri.org/Entity/Id10
unknown
http://tempuri.org/Entity/Id11
unknown
http://tempuri.org/Entity/Id12
unknown
http://tempuri.org/Entity/Id16Response
unknown
http://schemas.xmlsoap.org/ws/2004/10/wscoor/CreateCoordinationContextResponse
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RST/SCT/Cancel
unknown
http://tempuri.org/Entity/Id13
unknown
http://tempuri.org/Entity/Id14
unknown
http://tempuri.org/Entity/Id15
unknown
http://tempuri.org/Entity/Id16
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/Nonce
unknown
http://tempuri.org/Entity/Id17
unknown
http://tempuri.org/Entity/Id18
unknown
http://tempuri.org/Entity/Id5Response
unknown
http://tempuri.org/Entity/Id19
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/dns
unknown
http://tempuri.org/Entity/Id10Response
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/Renew
unknown
http://tempuri.org/Entity/Id8Response
unknown
http://schemas.xmlsoap.org/ws/2004/04/trust/PublicKey
unknown
http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLV2.0
unknown
http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.0#SAMLAssertionID
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/RST/SCT
unknown
http://schemas.xmlsoap.org/ws/2006/02/addressingidentity
unknown
http://schemas.xmlsoap.org/soap/envelope/
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/PublicKey
unknown
http://docs.oasis-open.org/wss/oasis-wss-soap-message-security-1.1#EncryptedKeySHA1
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Rollback
unknown
http://tempuri.org/Entity/Id3ResponseD
unknown
http://tempuri.org/Entity/Id23Response
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/RSTR/SCT
unknown
http://tempuri.org/D
unknown
http://schemas.xmlsoap.org/ws/2004/06/addressingex
unknown
http://schemas.xmlsoap.org/ws/2004/10/wscoor
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/Nonce
unknown
http://schemas.xmlsoap.org/ws/2005/02/rm/CreateSequenceResponse
unknown
http://schemas.xmlsoap.org/ws/2004/08/addressing/fault
unknown
There are 90 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
185.196.9.26
unknown
Switzerland
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFiles0000
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFilesHash

Memdumps

Base Address
Regiontype
Protect
Malicious
26C4000
trusted library allocation
page read and write
malicious
292000
unkown
page readonly
malicious
2895000
trusted library allocation
page read and write
591C000
heap
page read and write
6AE6000
heap
page read and write
2958000
trusted library allocation
page read and write
2BBA000
trusted library allocation
page read and write
76FE000
stack
page read and write
28A1000
trusted library allocation
page read and write
6F7000
stack
page read and write
36A2000
trusted library allocation
page read and write
5CAC000
stack
page read and write
378E000
trusted library allocation
page read and write
671F000
trusted library allocation
page read and write
4DD2000
trusted library allocation
page read and write
2620000
heap
page read and write
2BB1000
trusted library allocation
page read and write
3D0000
heap
page read and write
4AB0000
trusted library allocation
page read and write
4DC6000
trusted library allocation
page read and write
27E5000
trusted library allocation
page read and write
6830000
trusted library allocation
page execute and read and write
3683000
trusted library allocation
page read and write
27C9000
trusted library allocation
page read and write
4B70000
trusted library allocation
page read and write
8AD000
trusted library allocation
page execute and read and write
6745000
trusted library allocation
page read and write
3697000
trusted library allocation
page read and write
25F0000
trusted library allocation
page read and write
2883000
trusted library allocation
page read and write
66A0000
trusted library allocation
page read and write
3806000
trusted library allocation
page read and write
5C54000
trusted library allocation
page read and write
2B19000
trusted library allocation
page read and write
2C18000
trusted library allocation
page read and write
2D4000
unkown
page readonly
5985000
heap
page read and write
5949000
heap
page read and write
6AFE000
heap
page read and write
592C000
heap
page read and write
371C000
trusted library allocation
page read and write
25E0000
heap
page execute and read and write
4B90000
trusted library allocation
page read and write
6718000
trusted library allocation
page read and write
6B2F000
heap
page read and write
285B000
trusted library allocation
page read and write
5B2E000
stack
page read and write
4E30000
trusted library allocation
page read and write
36E5000
trusted library allocation
page read and write
672A000
trusted library allocation
page read and write
28B1000
trusted library allocation
page read and write
6709000
trusted library allocation
page read and write
6702000
trusted library allocation
page read and write
BF0000
trusted library allocation
page read and write
4AD6000
trusted library allocation
page read and write
4DC1000
trusted library allocation
page read and write
295C000
trusted library allocation
page read and write
A17000
heap
page read and write
5C30000
trusted library allocation
page read and write
36DC000
trusted library allocation
page read and write
5AEE000
stack
page read and write
25C0000
trusted library allocation
page read and write
9CF000
stack
page read and write
36EB000
trusted library allocation
page read and write
58ED000
heap
page read and write
50BE000
stack
page read and write
6AF2000
heap
page read and write
6740000
trusted library allocation
page read and write
2AC8000
trusted library allocation
page read and write
4DB0000
trusted library allocation
page read and write
3651000
trusted library allocation
page read and write
5957000
heap
page read and write
58F8000
heap
page read and write
6AE2000
heap
page read and write
4AD1000
trusted library allocation
page read and write
AE9000
heap
page read and write
6B2A000
heap
page read and write
50C0000
trusted library allocation
page execute and read and write
AE6000
heap
page read and write
2AED000
trusted library allocation
page read and write
AE3000
heap
page read and write
4B9A000
trusted library allocation
page read and write
4DAE000
stack
page read and write
4E0E000
trusted library allocation
page read and write
58B0000
heap
page read and write
5964000
heap
page read and write
27AB000
trusted library allocation
page read and write
37D6000
trusted library allocation
page read and write
366A000
trusted library allocation
page read and write
2778000
trusted library allocation
page read and write
2940000
trusted library allocation
page read and write
4B60000
heap
page read and write
6B6F000
heap
page read and write
2615000
trusted library allocation
page read and write
4DF1000
trusted library allocation
page read and write
CE0000
heap
page read and write
6700000
trusted library allocation
page read and write
6B56000
heap
page read and write
67BD000
stack
page read and write
5000000
trusted library allocation
page execute and read and write
36A9000
trusted library allocation
page read and write
2C0000
unkown
page readonly
5947000
heap
page read and write
27C4000
trusted library allocation
page read and write
25D0000
trusted library allocation
page read and write
2BB4000
trusted library allocation
page read and write
6B14000
heap
page read and write
376E000
trusted library allocation
page read and write
4B10000
trusted library allocation
page read and write
6F6D000
stack
page read and write
2B4F000
trusted library allocation
page read and write
2869000
trusted library allocation
page read and write
4E20000
trusted library allocation
page read and write
4BD0000
trusted library allocation
page read and write
883000
trusted library allocation
page execute and read and write
8BA000
trusted library allocation
page execute and read and write
2AF0000
trusted library allocation
page read and write
276F000
trusted library allocation
page read and write
655E000
stack
page read and write
36F8000
trusted library allocation
page read and write
596F000
heap
page read and write
4E50000
heap
page execute and read and write
58CF000
heap
page read and write
66A3000
trusted library allocation
page read and write
466C000
stack
page read and write
2853000
trusted library allocation
page read and write
2BA8000
trusted library allocation
page read and write
59A0000
heap
page read and write
6F1E000
stack
page read and write
8B0000
trusted library allocation
page read and write
6705000
trusted library allocation
page read and write
4DDE000
trusted library allocation
page read and write
4AB4000
trusted library allocation
page read and write
2BAA000
trusted library allocation
page read and write
36D6000
trusted library allocation
page read and write
5901000
heap
page read and write
36E9000
trusted library allocation
page read and write
3690000
trusted library allocation
page read and write
6F90000
trusted library allocation
page read and write
4B30000
heap
page read and write
5050000
trusted library allocation
page read and write
36E0000
trusted library allocation
page read and write
4AE2000
trusted library allocation
page read and write
6B1A000
heap
page read and write
4ACE000
trusted library allocation
page read and write
8B6000
trusted library allocation
page execute and read and write
890000
heap
page read and write
595D000
heap
page read and write
36BF000
trusted library allocation
page read and write
59A8000
heap
page read and write
377B000
trusted library allocation
page read and write
29F4000
trusted library allocation
page read and write
7F5C0000
trusted library allocation
page execute and read and write
4DE1000
trusted library allocation
page read and write
36AE000
trusted library allocation
page read and write
66A6000
trusted library allocation
page read and write
5060000
trusted library allocation
page read and write
D10000
heap
page read and write
3631000
trusted library allocation
page read and write
6820000
trusted library allocation
page execute and read and write
6742000
trusted library allocation
page read and write
279E000
trusted library allocation
page read and write
289C000
trusted library allocation
page read and write
2783000
trusted library allocation
page read and write
3791000
trusted library allocation
page read and write
2AF7000
trusted library allocation
page read and write
373D000
trusted library allocation
page read and write
9FE000
heap
page read and write
880000
trusted library allocation
page read and write
288A000
trusted library allocation
page read and write
2956000
trusted library allocation
page read and write
8B2000
trusted library allocation
page read and write
8A0000
trusted library allocation
page read and write
67FE000
stack
page read and write
9D0000
trusted library allocation
page read and write
4BA0000
heap
page read and write
6725000
trusted library allocation
page read and write
688E000
stack
page read and write
4AF0000
trusted library allocation
page read and write
6730000
trusted library allocation
page read and write
5070000
trusted library allocation
page execute and read and write
25BE000
stack
page read and write
4E05000
trusted library allocation
page read and write
C48000
trusted library allocation
page read and write
2BA4000
trusted library allocation
page read and write
2986000
trusted library allocation
page read and write
4F90000
trusted library allocation
page execute and read and write
5020000
trusted library allocation
page read and write
286B000
trusted library allocation
page read and write
3775000
trusted library allocation
page read and write
665D000
stack
page read and write
6B0A000
heap
page read and write
4BC0000
trusted library allocation
page read and write
3E0000
heap
page read and write
4B72000
trusted library allocation
page read and write
5010000
trusted library allocation
page execute and read and write
4F5F000
stack
page read and write
6B81000
heap
page read and write
58D3000
heap
page read and write
2791000
trusted library allocation
page read and write
3736000
trusted library allocation
page read and write
28A6000
trusted library allocation
page read and write
5918000
heap
page read and write
590D000
heap
page read and write
36F3000
trusted library allocation
page read and write
8C6000
heap
page read and write
374F000
trusted library allocation
page read and write
6B5C000
heap
page read and write
3799000
trusted library allocation
page read and write
5960000
heap
page read and write
671A000
trusted library allocation
page read and write
4B95000
trusted library allocation
page read and write
2876000
trusted library allocation
page read and write
593D000
heap
page read and write
672F000
trusted library allocation
page read and write
3754000
trusted library allocation
page read and write
2950000
trusted library allocation
page read and write
597F000
heap
page read and write
37AD000
trusted library allocation
page read and write
27CE000
trusted library allocation
page read and write
2BB6000
trusted library allocation
page read and write
2813000
trusted library allocation
page read and write
3676000
trusted library allocation
page read and write
6AA0000
heap
page read and write
2738000
trusted library allocation
page read and write
6D9E000
stack
page read and write
6B0F000
heap
page read and write
36B3000
trusted library allocation
page read and write
4E40000
trusted library allocation
page read and write
4E00000
trusted library allocation
page read and write
63DC000
stack
page read and write
36CF000
trusted library allocation
page read and write
4B80000
trusted library allocation
page execute and read and write
2BBF000
trusted library allocation
page read and write
9D7000
trusted library allocation
page execute and read and write
2B5B000
trusted library allocation
page read and write
28BD000
trusted library allocation
page read and write
290000
unkown
page readonly
3793000
trusted library allocation
page read and write
641E000
stack
page read and write
36EE000
trusted library allocation
page read and write
84E000
stack
page read and write
2944000
trusted library allocation
page read and write
294E000
trusted library allocation
page read and write
2793000
trusted library allocation
page read and write
6840000
trusted library allocation
page read and write
2AF2000
trusted library allocation
page read and write
4DEA000
trusted library allocation
page read and write
80E000
stack
page read and write
4FB0000
trusted library allocation
page read and write
59EE000
stack
page read and write
6B3E000
heap
page read and write
378B000
trusted library allocation
page read and write
27BD000
trusted library allocation
page read and write
5C2E000
stack
page read and write
6B46000
heap
page read and write
88D000
trusted library allocation
page execute and read and write
2C2A000
trusted library allocation
page read and write
2A84000
trusted library allocation
page read and write
6B6A000
heap
page read and write
6DDE000
stack
page read and write
6B25000
heap
page read and write
651C000
stack
page read and write
4E10000
trusted library allocation
page read and write
AC9000
heap
page read and write
4ADD000
trusted library allocation
page read and write
293A000
trusted library allocation
page read and write
C3E000
stack
page read and write
9D5000
trusted library allocation
page execute and read and write
2AE6000
trusted library allocation
page read and write
6810000
trusted library allocation
page read and write
58B5000
heap
page read and write
36A000
stack
page read and write
5030000
trusted library allocation
page read and write
2608000
trusted library allocation
page read and write
3764000
trusted library allocation
page read and write
4B98000
trusted library allocation
page read and write
2926000
trusted library allocation
page read and write
27B2000
trusted library allocation
page read and write
5928000
heap
page read and write
5040000
trusted library allocation
page execute and read and write
4B33000
heap
page read and write
A32000
heap
page read and write
27D9000
trusted library allocation
page read and write
2610000
trusted library allocation
page read and write
7500000
heap
page read and write
3710000
trusted library allocation
page read and write
59AE000
heap
page read and write
681F000
trusted library allocation
page read and write
5C50000
trusted library allocation
page read and write
68CE000
stack
page read and write
4DBB000
trusted library allocation
page read and write
4E0B000
trusted library allocation
page read and write
6E1E000
stack
page read and write
6670000
trusted library allocation
page execute and read and write
3748000
trusted library allocation
page read and write
9F0000
heap
page read and write
884000
trusted library allocation
page read and write
BEE000
stack
page read and write
4F80000
trusted library allocation
page read and write
284A000
trusted library allocation
page read and write
2BD4000
trusted library allocation
page read and write
5975000
heap
page read and write
2631000
trusted library allocation
page read and write
2903000
trusted library allocation
page read and write
2600000
trusted library allocation
page read and write
8C0000
heap
page read and write
36C9000
trusted library allocation
page read and write
6750000
trusted library allocation
page read and write
2AFB000
trusted library allocation
page read and write
5C60000
trusted library allocation
page execute and read and write
5991000
heap
page read and write
D00000
trusted library allocation
page execute and read and write
4ABB000
trusted library allocation
page read and write
9DB000
trusted library allocation
page execute and read and write
2C5000
unkown
page readonly
3782000
trusted library allocation
page read and write
3785000
trusted library allocation
page read and write
6734000
trusted library allocation
page read and write
3729000
trusted library allocation
page read and write
9D2000
trusted library allocation
page read and write
58AE000
stack
page read and write
4FA0000
trusted library allocation
page read and write
295E000
trusted library allocation
page read and write
3759000
trusted library allocation
page read and write
476B000
stack
page read and write
870000
trusted library allocation
page read and write
9FB000
heap
page read and write
5938000
heap
page read and write
363F000
trusted library allocation
page read and write
28F3000
trusted library allocation
page read and write
6800000
trusted library allocation
page read and write
There are 322 hidden memdumps, click here to show them.