Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
mG31YklE0k.exe
|
PE32+ executable (console) x86-64, for MS Windows
|
initial sample
|
||
C:\Users\user\AppData\Local\Temp\Tmp13AC.tmp
|
PEM certificate
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-2246122658-3693405117-2476756634-1003\1d921b7dbd459b1bfc7fa12af4fbde00_9e146be9-c76a-4720-bcdb-53011b87bd06
|
data
|
dropped
|
||
\Device\Null
|
ASCII text, with CRLF line terminators
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\mG31YklE0k.exe
|
"C:\Users\user\Desktop\mG31YklE0k.exe"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
||
C:\Windows\System32\cmd.exe
|
cmd.exe /C "chcp 65001 > NUL & wmic os get Name,OSArchitecture /format:rawxml"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
||
C:\Windows\System32\chcp.com
|
chcp 65001
|
||
C:\Windows\System32\wbem\WMIC.exe
|
wmic os get Name,OSArchitecture /format:rawxml
|
||
C:\Windows\System32\cmd.exe
|
cmd.exe /C "chcp 65001 > NUL & wmic cpu get Name /format:rawxml"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
||
C:\Windows\System32\chcp.com
|
chcp 65001
|
||
C:\Windows\System32\wbem\WMIC.exe
|
wmic cpu get Name /format:rawxml
|
||
C:\Windows\System32\cmd.exe
|
cmd.exe /C "chcp 65001 > NUL & wmic os get TotalVisibleMemorySize /format:rawxml"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
||
C:\Windows\System32\chcp.com
|
chcp 65001
|
||
C:\Windows\System32\wbem\WMIC.exe
|
wmic os get TotalVisibleMemorySize /format:rawxml
|
There are 4 hidden processes, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
47.236.8.208
|
unknown
|
United States
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
21351FD2000
|
heap
|
page read and write
|
||
2135260C000
|
heap
|
page read and write
|
||
1C8CE4FE000
|
heap
|
page read and write
|
||
1F7AC965000
|
heap
|
page read and write
|
||
1F7AC49A000
|
heap
|
page read and write
|
||
1F7AC493000
|
heap
|
page read and write
|
||
1F7AC22D000
|
heap
|
page read and write
|
||
21352058000
|
heap
|
page read and write
|
||
975287F000
|
stack
|
page read and write
|
||
1F7AC1FF000
|
heap
|
page read and write
|
||
1C8CE042000
|
heap
|
page read and write
|
||
1F7AC96B000
|
heap
|
page read and write
|
||
2135206C000
|
heap
|
page read and write
|
||
1F7AC492000
|
heap
|
page read and write
|
||
800BC7F000
|
stack
|
page read and write
|
||
1F7AC3C0000
|
heap
|
page read and write
|
||
1C8CDE07000
|
heap
|
page read and write
|
||
1C8CDE99000
|
heap
|
page read and write
|
||
1F7AC95C000
|
heap
|
page read and write
|
||
1C8CDE87000
|
heap
|
page read and write
|
||
1C8CDE29000
|
heap
|
page read and write
|
||
1C8CDE30000
|
heap
|
page read and write
|
||
2135205C000
|
heap
|
page read and write
|
||
800BCFF000
|
stack
|
page read and write
|
||
1C8CE04A000
|
heap
|
page read and write
|
||
2135203D000
|
heap
|
page read and write
|
||
1C8CDE8B000
|
heap
|
page read and write
|
||
1C8CE518000
|
heap
|
page read and write
|
||
1C8CE020000
|
heap
|
page read and write
|
||
1F7AC96B000
|
heap
|
page read and write
|
||
213520C0000
|
trusted library allocation
|
page read and write
|
||
1C8CE04E000
|
heap
|
page read and write
|
||
1F7AC977000
|
heap
|
page read and write
|
||
1F7AC225000
|
heap
|
page read and write
|
||
21352608000
|
heap
|
page read and write
|
||
24AB1E5C000
|
heap
|
page read and write
|
||
1F7AC977000
|
heap
|
page read and write
|
||
FC7950C000
|
stack
|
page read and write
|
||
1F7AC202000
|
heap
|
page read and write
|
||
7FF792320000
|
unkown
|
page readonly
|
||
1C8CDE8F000
|
heap
|
page read and write
|
||
21352629000
|
heap
|
page read and write
|
||
21352103000
|
heap
|
page read and write
|
||
1F7AC97C000
|
heap
|
page read and write
|
||
1C8CDE02000
|
heap
|
page read and write
|
||
1F7AC1CF000
|
heap
|
page read and write
|
||
1F7AC227000
|
heap
|
page read and write
|
||
2135206A000
|
heap
|
page read and write
|
||
21352016000
|
heap
|
page read and write
|
||
1C8CDE25000
|
heap
|
page read and write
|
||
1C8CE500000
|
heap
|
page read and write
|
||
1C8CDE25000
|
heap
|
page read and write
|
||
1DDF3790000
|
heap
|
page read and write
|
||
A0544FF000
|
stack
|
page read and write
|
||
21352059000
|
heap
|
page read and write
|
||
21351FD7000
|
heap
|
page read and write
|
||
21352629000
|
heap
|
page read and write
|
||
23958FB0000
|
heap
|
page read and write
|
||
1C8CDE4B000
|
heap
|
page read and write
|
||
213520E0000
|
heap
|
page read and write
|
||
24AB2040000
|
heap
|
page read and write
|
||
1F7AC206000
|
heap
|
page read and write
|
||
21352607000
|
heap
|
page read and write
|
||
92F6198000
|
stack
|
page read and write
|
||
2135206C000
|
heap
|
page read and write
|
||
1C8CDE6B000
|
heap
|
page read and write
|
||
2135260F000
|
heap
|
page read and write
|
||
1F7AC1F6000
|
heap
|
page read and write
|
||
1C8CDE07000
|
heap
|
page read and write
|
||
1F7AC490000
|
heap
|
page read and write
|
||
800BD7E000
|
stack
|
page read and write
|
||
A0541BB000
|
stack
|
page read and write
|
||
23958FB5000
|
heap
|
page read and write
|
||
1C8CDE25000
|
heap
|
page read and write
|
||
2135205F000
|
heap
|
page read and write
|
||
1F7AE2A0000
|
heap
|
page read and write
|
||
21351FC0000
|
heap
|
page read and write
|
||
21351F90000
|
heap
|
page read and write
|
||
21352016000
|
heap
|
page read and write
|
||
1F7AC21F000
|
heap
|
page read and write
|
||
21353EF0000
|
heap
|
page read and write
|
||
2135206A000
|
heap
|
page read and write
|
||
5430E7E000
|
stack
|
page read and write
|
||
1F7AC1FF000
|
heap
|
page read and write
|
||
800B9B7000
|
stack
|
page read and write
|
||
5430B2D000
|
stack
|
page read and write
|
||
1C8CE50D000
|
heap
|
page read and write
|
||
1C8CE4F8000
|
heap
|
page read and write
|
||
1F7AC1FF000
|
heap
|
page read and write
|
||
22C22040000
|
heap
|
page read and write
|
||
A52DC7F000
|
stack
|
page read and write
|
||
1C8CDE4C000
|
heap
|
page read and write
|
||
21352614000
|
heap
|
page read and write
|
||
1F7AC1F6000
|
heap
|
page read and write
|
||
1C8CE000000
|
trusted library allocation
|
page read and write
|
||
21352631000
|
heap
|
page read and write
|
||
1F7AC235000
|
heap
|
page read and write
|
||
1F7AC49A000
|
heap
|
page read and write
|
||
1F7AC97A000
|
heap
|
page read and write
|
||
1C8CDE4D000
|
heap
|
page read and write
|
||
1F7AC49E000
|
heap
|
page read and write
|
||
5430AA8000
|
stack
|
page read and write
|
||
21352611000
|
heap
|
page read and write
|
||
1F7AC960000
|
heap
|
page read and write
|
||
1C8CDE30000
|
heap
|
page read and write
|
||
1F7AC96B000
|
heap
|
page read and write
|
||
1F7AC235000
|
heap
|
page read and write
|
||
21352011000
|
heap
|
page read and write
|
||
2135206C000
|
heap
|
page read and write
|
||
2135210B000
|
heap
|
page read and write
|
||
23958E18000
|
heap
|
page read and write
|
||
1F7AC957000
|
heap
|
page read and write
|
||
24AB3C60000
|
heap
|
page read and write
|
||
1C8CE040000
|
heap
|
page read and write
|
||
21352107000
|
heap
|
page read and write
|
||
1C8CDFC0000
|
heap
|
page read and write
|
||
21352016000
|
heap
|
page read and write
|
||
1F7AC1F7000
|
heap
|
page read and write
|
||
1C8CE50D000
|
heap
|
page read and write
|
||
1C8CE044000
|
heap
|
page read and write
|
||
1C8CE04A000
|
heap
|
page read and write
|
||
21352065000
|
heap
|
page read and write
|
||
1C8CDE87000
|
heap
|
page read and write
|
||
1C8CE060000
|
heap
|
page read and write
|
||
23958E1B000
|
heap
|
page read and write
|
||
21351FF7000
|
heap
|
page read and write
|
||
21351FF5000
|
heap
|
page read and write
|
||
1C8CDDE0000
|
trusted library allocation
|
page read and write
|
||
2135201F000
|
heap
|
page read and write
|
||
1C8CDE87000
|
heap
|
page read and write
|
||
1F7AC390000
|
trusted library allocation
|
page read and write
|
||
1C8CE065000
|
heap
|
page read and write
|
||
1F7AC1D8000
|
heap
|
page read and write
|
||
21353EE0000
|
heap
|
page read and write
|
||
21352016000
|
heap
|
page read and write
|
||
23958DE0000
|
heap
|
page read and write
|
||
1F7AC21A000
|
heap
|
page read and write
|
||
1DDF39B0000
|
heap
|
page read and write
|
||
1F7AC1F6000
|
heap
|
page read and write
|
||
1F7AC232000
|
heap
|
page read and write
|
||
1F7AC202000
|
heap
|
page read and write
|
||
92F65FF000
|
stack
|
page read and write
|
||
1F7AC95E000
|
heap
|
page read and write
|
||
1C8CE51C000
|
heap
|
page read and write
|
||
1F7AC21A000
|
heap
|
page read and write
|
||
1DDF3690000
|
heap
|
page read and write
|
||
24AB2030000
|
heap
|
page read and write
|
||
1F7AC967000
|
heap
|
page read and write
|
||
213520C0000
|
trusted library allocation
|
page read and write
|
||
1C8CFE40000
|
heap
|
page read and write
|
||
1C8CDE30000
|
heap
|
page read and write
|
||
2135203C000
|
heap
|
page read and write
|
||
7FF79232A000
|
unkown
|
page readonly
|
||
1F7AC494000
|
heap
|
page read and write
|
||
1F7AC238000
|
heap
|
page read and write
|
||
21351FF7000
|
heap
|
page read and write
|
||
2135210E000
|
heap
|
page read and write
|
||
7FF792321000
|
unkown
|
page execute read
|
||
21351FF7000
|
heap
|
page read and write
|
||
1F7AC1D3000
|
heap
|
page read and write
|
||
21351FD7000
|
heap
|
page read and write
|
||
1C8CE04E000
|
heap
|
page read and write
|
||
1F7AC220000
|
heap
|
page read and write
|
||
22C21D60000
|
heap
|
page read and write
|
||
1C8CDFE0000
|
heap
|
page read and write
|
||
24AB1E10000
|
heap
|
page read and write
|
||
A52D9AF000
|
stack
|
page read and write
|
||
1C8CDDF0000
|
heap
|
page read and write
|
||
1F7AC950000
|
heap
|
page read and write
|
||
1C8CE04A000
|
heap
|
page read and write
|
||
2135206C000
|
heap
|
page read and write
|
||
2135206C000
|
heap
|
page read and write
|
||
7FF79232A000
|
unkown
|
page readonly
|
||
2135205C000
|
heap
|
page read and write
|
||
21352016000
|
heap
|
page read and write
|
||
21352600000
|
heap
|
page read and write
|
||
1C8CDE99000
|
heap
|
page read and write
|
||
21352013000
|
heap
|
page read and write
|
||
24AB3B40000
|
heap
|
page read and write
|
||
1C8CDDD0000
|
heap
|
page read and write
|
||
21352105000
|
heap
|
page read and write
|
||
1F7AC4CB000
|
heap
|
page read and write
|
||
1F7AC49B000
|
heap
|
page read and write
|
||
2135206C000
|
heap
|
page read and write
|
||
1F7AC49E000
|
heap
|
page read and write
|
||
1C8CE045000
|
heap
|
page read and write
|
||
1F7AC95C000
|
heap
|
page read and write
|
||
1C8CDE45000
|
heap
|
page read and write
|
||
21352058000
|
heap
|
page read and write
|
||
1C8CDE94000
|
heap
|
page read and write
|
||
22C21D6B000
|
heap
|
page read and write
|
||
21351FF7000
|
heap
|
page read and write
|
||
A0547FE000
|
stack
|
page read and write
|
||
23958E10000
|
heap
|
page read and write
|
||
21352102000
|
heap
|
page read and write
|
||
1F7AC495000
|
heap
|
page read and write
|
||
1C8CE047000
|
heap
|
page read and write
|
||
2135206C000
|
heap
|
page read and write
|
||
2135262A000
|
heap
|
page read and write
|
||
24AB1E99000
|
heap
|
page read and write
|
||
21351FEA000
|
heap
|
page read and write
|
||
1C8CE4FC000
|
heap
|
page read and write
|
||
1F7AC49A000
|
heap
|
page read and write
|
||
1F7AC233000
|
heap
|
page read and write
|
||
1C8CDE8B000
|
heap
|
page read and write
|
||
21352038000
|
heap
|
page read and write
|
||
1F7AC390000
|
trusted library allocation
|
page read and write
|
||
1C8CDE99000
|
heap
|
page read and write
|
||
1C8CDE7A000
|
heap
|
page read and write
|
||
23958CE0000
|
heap
|
page read and write
|
||
24AB2035000
|
heap
|
page read and write
|
||
21351FEA000
|
heap
|
page read and write
|
||
1C8CE50D000
|
heap
|
page read and write
|
||
21352617000
|
heap
|
page read and write
|
||
1F7AC235000
|
heap
|
page read and write
|
||
2135210A000
|
heap
|
page read and write
|
||
1C8CDE42000
|
heap
|
page read and write
|
||
1C8CDE88000
|
heap
|
page read and write
|
||
92F657F000
|
stack
|
page read and write
|
||
1F7AC213000
|
heap
|
page read and write
|
||
213522B5000
|
heap
|
page read and write
|
||
1C8CDE45000
|
heap
|
page read and write
|
||
21352104000
|
heap
|
page read and write
|
||
21351F70000
|
heap
|
page read and write
|
||
7FF792328000
|
unkown
|
page read and write
|
||
1F7AC215000
|
heap
|
page read and write
|
||
97528FF000
|
stack
|
page read and write
|
||
A0548FE000
|
stack
|
page read and write
|
||
1F7AC964000
|
heap
|
page read and write
|
||
1C8CDE45000
|
heap
|
page read and write
|
||
1F7AC215000
|
heap
|
page read and write
|
||
1F7AC180000
|
heap
|
page read and write
|
||
1C8CE4FC000
|
heap
|
page read and write
|
||
800BDFF000
|
stack
|
page read and write
|
||
1F7AC215000
|
heap
|
page read and write
|
||
1C8CDE8E000
|
heap
|
page read and write
|
||
21352100000
|
heap
|
page read and write
|
||
21352065000
|
heap
|
page read and write
|
||
2135205C000
|
heap
|
page read and write
|
||
2135201D000
|
heap
|
page read and write
|
||
2135210A000
|
heap
|
page read and write
|
||
92F64FE000
|
stack
|
page read and write
|
||
21351FFA000
|
heap
|
page read and write
|
||
1DDF3770000
|
heap
|
page read and write
|
||
1F7AC4C0000
|
heap
|
page read and write
|
||
24AB1E50000
|
heap
|
page read and write
|
||
1F7AC215000
|
heap
|
page read and write
|
||
21352058000
|
heap
|
page read and write
|
||
1C8CDE4B000
|
heap
|
page read and write
|
||
1F7AC225000
|
heap
|
page read and write
|
||
1C8CDE8F000
|
heap
|
page read and write
|
||
2135201A000
|
heap
|
page read and write
|
||
1F7AC958000
|
heap
|
page read and write
|
||
213522B0000
|
heap
|
page read and write
|
||
21351FEA000
|
heap
|
page read and write
|
||
1F7AC97B000
|
heap
|
page read and write
|
||
22C22045000
|
heap
|
page read and write
|
||
1C8CE503000
|
heap
|
page read and write
|
||
FC7958F000
|
stack
|
page read and write
|
||
21351FB0000
|
trusted library allocation
|
page read and write
|
||
1C8CE50D000
|
heap
|
page read and write
|
||
5430F7F000
|
stack
|
page read and write
|
||
5430EFF000
|
stack
|
page read and write
|
||
2135205E000
|
heap
|
page read and write
|
||
2135204C000
|
heap
|
page read and write
|
||
21352013000
|
heap
|
page read and write
|
||
1F7AC202000
|
heap
|
page read and write
|
||
1C8CE047000
|
heap
|
page read and write
|
||
2135206A000
|
heap
|
page read and write
|
||
92F667F000
|
stack
|
page read and write
|
||
21352629000
|
heap
|
page read and write
|
||
1C8CDE25000
|
heap
|
page read and write
|
||
1C8CDDE0000
|
trusted library allocation
|
page read and write
|
||
1F7AC977000
|
heap
|
page read and write
|
||
1C8CE518000
|
heap
|
page read and write
|
||
1F7AC977000
|
heap
|
page read and write
|
||
1C8CE043000
|
heap
|
page read and write
|
||
7FF792321000
|
unkown
|
page execute read
|
||
1C8CDE27000
|
heap
|
page read and write
|
||
1F7AC170000
|
heap
|
page read and write
|
||
1C8CDE66000
|
heap
|
page read and write
|
||
22C21D10000
|
heap
|
page read and write
|
||
1C8CDE6A000
|
heap
|
page read and write
|
||
1C8CE518000
|
heap
|
page read and write
|
||
1DDF39B5000
|
heap
|
page read and write
|
||
21351FB0000
|
trusted library allocation
|
page read and write
|
||
1F7AC210000
|
heap
|
page read and write
|
||
1F7AC215000
|
heap
|
page read and write
|
||
1C8CDE99000
|
heap
|
page read and write
|
||
21352013000
|
heap
|
page read and write
|
||
1C8CE518000
|
heap
|
page read and write
|
||
1C8CDE41000
|
heap
|
page read and write
|
||
2135210A000
|
heap
|
page read and write
|
||
A52D92C000
|
stack
|
page read and write
|
||
21351E90000
|
heap
|
page read and write
|
||
1F7AC497000
|
heap
|
page read and write
|
||
1C8CE000000
|
trusted library allocation
|
page read and write
|
||
2135206A000
|
heap
|
page read and write
|
||
1C8CDE8B000
|
heap
|
page read and write
|
||
1C8CFE30000
|
heap
|
page read and write
|
||
FC7987E000
|
stack
|
page read and write
|
||
21352619000
|
heap
|
page read and write
|
||
1DDF37DB000
|
heap
|
page read and write
|
||
1C8CE04B000
|
heap
|
page read and write
|
||
21351FF8000
|
heap
|
page read and write
|
||
21352614000
|
heap
|
page read and write
|
||
1F7AC1F5000
|
heap
|
page read and write
|
||
2135206A000
|
heap
|
page read and write
|
||
1F7AC96B000
|
heap
|
page read and write
|
||
1C8CE504000
|
heap
|
page read and write
|
||
7FF792320000
|
unkown
|
page readonly
|
||
1F7AC215000
|
heap
|
page read and write
|
||
1F7AC96B000
|
heap
|
page read and write
|
||
1F7AC1F9000
|
heap
|
page read and write
|
||
21351FC9000
|
heap
|
page read and write
|
||
1F7AC390000
|
trusted library allocation
|
page read and write
|
||
21352058000
|
heap
|
page read and write
|
||
1F7AC225000
|
heap
|
page read and write
|
||
21352629000
|
heap
|
page read and write
|
||
21352629000
|
heap
|
page read and write
|
||
21352067000
|
heap
|
page read and write
|
||
21352618000
|
heap
|
page read and write
|
||
2135262C000
|
heap
|
page read and write
|
||
2135206A000
|
heap
|
page read and write
|
||
1F7AC211000
|
heap
|
page read and write
|
||
2135260D000
|
heap
|
page read and write
|
||
1C8CE4F7000
|
heap
|
page read and write
|
||
1DDF37D7000
|
heap
|
page read and write
|
||
1F7AC963000
|
heap
|
page read and write
|
||
1F7AE290000
|
heap
|
page read and write
|
||
1C8CDE27000
|
heap
|
page read and write
|
||
2135205C000
|
heap
|
page read and write
|
||
97525BC000
|
stack
|
page read and write
|
||
800BE7E000
|
stack
|
page read and write
|
||
21351FF7000
|
heap
|
page read and write
|
||
21352631000
|
heap
|
page read and write
|
||
21352107000
|
heap
|
page read and write
|
||
1C8CE50D000
|
heap
|
page read and write
|
||
2135206C000
|
heap
|
page read and write
|
||
7FF792328000
|
unkown
|
page write copy
|
||
213522BB000
|
heap
|
page read and write
|
||
1F7AC4C5000
|
heap
|
page read and write
|
||
23958DC0000
|
heap
|
page read and write
|
||
24AB3B60000
|
heap
|
page read and write
|
||
1F7AC390000
|
trusted library allocation
|
page read and write
|
||
1C8CE518000
|
heap
|
page read and write
|
||
22C21D40000
|
heap
|
page read and write
|
||
1F7AC497000
|
heap
|
page read and write
|
||
1F7AC1C9000
|
heap
|
page read and write
|
||
24AB1E20000
|
heap
|
page read and write
|
||
2135210E000
|
heap
|
page read and write
|
||
92F647D000
|
stack
|
page read and write
|
||
1F7AC977000
|
heap
|
page read and write
|
||
1F7AC21E000
|
heap
|
page read and write
|
||
1C8CE4F0000
|
heap
|
page read and write
|
||
22C21D20000
|
heap
|
page read and write
|
||
1F7AC205000
|
heap
|
page read and write
|
||
21352019000
|
heap
|
page read and write
|
||
21352013000
|
heap
|
page read and write
|
||
1C8CE06B000
|
heap
|
page read and write
|
||
1DDF37D0000
|
heap
|
page read and write
|
||
5430BAE000
|
stack
|
page read and write
|
||
1F7AC1D8000
|
heap
|
page read and write
|
||
22C21D68000
|
heap
|
page read and write
|
||
1F7AC1C0000
|
heap
|
page read and write
|
||
1F7AC1A0000
|
heap
|
page read and write
|
||
2135260C000
|
heap
|
page read and write
|
||
1C8CDE25000
|
heap
|
page read and write
|
There are 358 hidden memdumps, click here to show them.