IOC Report
mG31YklE0k

loading gif

Files

File Path
Type
Category
Malicious
mG31YklE0k.exe
PE32+ executable (console) x86-64, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Temp\Tmp13AC.tmp
PEM certificate
dropped
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-2246122658-3693405117-2476756634-1003\1d921b7dbd459b1bfc7fa12af4fbde00_9e146be9-c76a-4720-bcdb-53011b87bd06
data
dropped
\Device\Null
ASCII text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\mG31YklE0k.exe
"C:\Users\user\Desktop\mG31YklE0k.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\cmd.exe
cmd.exe /C "chcp 65001 > NUL & wmic os get Name,OSArchitecture /format:rawxml"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\chcp.com
chcp 65001
C:\Windows\System32\wbem\WMIC.exe
wmic os get Name,OSArchitecture /format:rawxml
C:\Windows\System32\cmd.exe
cmd.exe /C "chcp 65001 > NUL & wmic cpu get Name /format:rawxml"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\chcp.com
chcp 65001
C:\Windows\System32\wbem\WMIC.exe
wmic cpu get Name /format:rawxml
C:\Windows\System32\cmd.exe
cmd.exe /C "chcp 65001 > NUL & wmic os get TotalVisibleMemorySize /format:rawxml"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\chcp.com
chcp 65001
C:\Windows\System32\wbem\WMIC.exe
wmic os get TotalVisibleMemorySize /format:rawxml
There are 4 hidden processes, click here to show them.

IPs

IP
Domain
Country
Malicious
47.236.8.208
unknown
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
21351FD2000
heap
page read and write
2135260C000
heap
page read and write
1C8CE4FE000
heap
page read and write
1F7AC965000
heap
page read and write
1F7AC49A000
heap
page read and write
1F7AC493000
heap
page read and write
1F7AC22D000
heap
page read and write
21352058000
heap
page read and write
975287F000
stack
page read and write
1F7AC1FF000
heap
page read and write
1C8CE042000
heap
page read and write
1F7AC96B000
heap
page read and write
2135206C000
heap
page read and write
1F7AC492000
heap
page read and write
800BC7F000
stack
page read and write
1F7AC3C0000
heap
page read and write
1C8CDE07000
heap
page read and write
1C8CDE99000
heap
page read and write
1F7AC95C000
heap
page read and write
1C8CDE87000
heap
page read and write
1C8CDE29000
heap
page read and write
1C8CDE30000
heap
page read and write
2135205C000
heap
page read and write
800BCFF000
stack
page read and write
1C8CE04A000
heap
page read and write
2135203D000
heap
page read and write
1C8CDE8B000
heap
page read and write
1C8CE518000
heap
page read and write
1C8CE020000
heap
page read and write
1F7AC96B000
heap
page read and write
213520C0000
trusted library allocation
page read and write
1C8CE04E000
heap
page read and write
1F7AC977000
heap
page read and write
1F7AC225000
heap
page read and write
21352608000
heap
page read and write
24AB1E5C000
heap
page read and write
1F7AC977000
heap
page read and write
FC7950C000
stack
page read and write
1F7AC202000
heap
page read and write
7FF792320000
unkown
page readonly
1C8CDE8F000
heap
page read and write
21352629000
heap
page read and write
21352103000
heap
page read and write
1F7AC97C000
heap
page read and write
1C8CDE02000
heap
page read and write
1F7AC1CF000
heap
page read and write
1F7AC227000
heap
page read and write
2135206A000
heap
page read and write
21352016000
heap
page read and write
1C8CDE25000
heap
page read and write
1C8CE500000
heap
page read and write
1C8CDE25000
heap
page read and write
1DDF3790000
heap
page read and write
A0544FF000
stack
page read and write
21352059000
heap
page read and write
21351FD7000
heap
page read and write
21352629000
heap
page read and write
23958FB0000
heap
page read and write
1C8CDE4B000
heap
page read and write
213520E0000
heap
page read and write
24AB2040000
heap
page read and write
1F7AC206000
heap
page read and write
21352607000
heap
page read and write
92F6198000
stack
page read and write
2135206C000
heap
page read and write
1C8CDE6B000
heap
page read and write
2135260F000
heap
page read and write
1F7AC1F6000
heap
page read and write
1C8CDE07000
heap
page read and write
1F7AC490000
heap
page read and write
800BD7E000
stack
page read and write
A0541BB000
stack
page read and write
23958FB5000
heap
page read and write
1C8CDE25000
heap
page read and write
2135205F000
heap
page read and write
1F7AE2A0000
heap
page read and write
21351FC0000
heap
page read and write
21351F90000
heap
page read and write
21352016000
heap
page read and write
1F7AC21F000
heap
page read and write
21353EF0000
heap
page read and write
2135206A000
heap
page read and write
5430E7E000
stack
page read and write
1F7AC1FF000
heap
page read and write
800B9B7000
stack
page read and write
5430B2D000
stack
page read and write
1C8CE50D000
heap
page read and write
1C8CE4F8000
heap
page read and write
1F7AC1FF000
heap
page read and write
22C22040000
heap
page read and write
A52DC7F000
stack
page read and write
1C8CDE4C000
heap
page read and write
21352614000
heap
page read and write
1F7AC1F6000
heap
page read and write
1C8CE000000
trusted library allocation
page read and write
21352631000
heap
page read and write
1F7AC235000
heap
page read and write
1F7AC49A000
heap
page read and write
1F7AC97A000
heap
page read and write
1C8CDE4D000
heap
page read and write
1F7AC49E000
heap
page read and write
5430AA8000
stack
page read and write
21352611000
heap
page read and write
1F7AC960000
heap
page read and write
1C8CDE30000
heap
page read and write
1F7AC96B000
heap
page read and write
1F7AC235000
heap
page read and write
21352011000
heap
page read and write
2135206C000
heap
page read and write
2135210B000
heap
page read and write
23958E18000
heap
page read and write
1F7AC957000
heap
page read and write
24AB3C60000
heap
page read and write
1C8CE040000
heap
page read and write
21352107000
heap
page read and write
1C8CDFC0000
heap
page read and write
21352016000
heap
page read and write
1F7AC1F7000
heap
page read and write
1C8CE50D000
heap
page read and write
1C8CE044000
heap
page read and write
1C8CE04A000
heap
page read and write
21352065000
heap
page read and write
1C8CDE87000
heap
page read and write
1C8CE060000
heap
page read and write
23958E1B000
heap
page read and write
21351FF7000
heap
page read and write
21351FF5000
heap
page read and write
1C8CDDE0000
trusted library allocation
page read and write
2135201F000
heap
page read and write
1C8CDE87000
heap
page read and write
1F7AC390000
trusted library allocation
page read and write
1C8CE065000
heap
page read and write
1F7AC1D8000
heap
page read and write
21353EE0000
heap
page read and write
21352016000
heap
page read and write
23958DE0000
heap
page read and write
1F7AC21A000
heap
page read and write
1DDF39B0000
heap
page read and write
1F7AC1F6000
heap
page read and write
1F7AC232000
heap
page read and write
1F7AC202000
heap
page read and write
92F65FF000
stack
page read and write
1F7AC95E000
heap
page read and write
1C8CE51C000
heap
page read and write
1F7AC21A000
heap
page read and write
1DDF3690000
heap
page read and write
24AB2030000
heap
page read and write
1F7AC967000
heap
page read and write
213520C0000
trusted library allocation
page read and write
1C8CFE40000
heap
page read and write
1C8CDE30000
heap
page read and write
2135203C000
heap
page read and write
7FF79232A000
unkown
page readonly
1F7AC494000
heap
page read and write
1F7AC238000
heap
page read and write
21351FF7000
heap
page read and write
2135210E000
heap
page read and write
7FF792321000
unkown
page execute read
21351FF7000
heap
page read and write
1F7AC1D3000
heap
page read and write
21351FD7000
heap
page read and write
1C8CE04E000
heap
page read and write
1F7AC220000
heap
page read and write
22C21D60000
heap
page read and write
1C8CDFE0000
heap
page read and write
24AB1E10000
heap
page read and write
A52D9AF000
stack
page read and write
1C8CDDF0000
heap
page read and write
1F7AC950000
heap
page read and write
1C8CE04A000
heap
page read and write
2135206C000
heap
page read and write
2135206C000
heap
page read and write
7FF79232A000
unkown
page readonly
2135205C000
heap
page read and write
21352016000
heap
page read and write
21352600000
heap
page read and write
1C8CDE99000
heap
page read and write
21352013000
heap
page read and write
24AB3B40000
heap
page read and write
1C8CDDD0000
heap
page read and write
21352105000
heap
page read and write
1F7AC4CB000
heap
page read and write
1F7AC49B000
heap
page read and write
2135206C000
heap
page read and write
1F7AC49E000
heap
page read and write
1C8CE045000
heap
page read and write
1F7AC95C000
heap
page read and write
1C8CDE45000
heap
page read and write
21352058000
heap
page read and write
1C8CDE94000
heap
page read and write
22C21D6B000
heap
page read and write
21351FF7000
heap
page read and write
A0547FE000
stack
page read and write
23958E10000
heap
page read and write
21352102000
heap
page read and write
1F7AC495000
heap
page read and write
1C8CE047000
heap
page read and write
2135206C000
heap
page read and write
2135262A000
heap
page read and write
24AB1E99000
heap
page read and write
21351FEA000
heap
page read and write
1C8CE4FC000
heap
page read and write
1F7AC49A000
heap
page read and write
1F7AC233000
heap
page read and write
1C8CDE8B000
heap
page read and write
21352038000
heap
page read and write
1F7AC390000
trusted library allocation
page read and write
1C8CDE99000
heap
page read and write
1C8CDE7A000
heap
page read and write
23958CE0000
heap
page read and write
24AB2035000
heap
page read and write
21351FEA000
heap
page read and write
1C8CE50D000
heap
page read and write
21352617000
heap
page read and write
1F7AC235000
heap
page read and write
2135210A000
heap
page read and write
1C8CDE42000
heap
page read and write
1C8CDE88000
heap
page read and write
92F657F000
stack
page read and write
1F7AC213000
heap
page read and write
213522B5000
heap
page read and write
1C8CDE45000
heap
page read and write
21352104000
heap
page read and write
21351F70000
heap
page read and write
7FF792328000
unkown
page read and write
1F7AC215000
heap
page read and write
97528FF000
stack
page read and write
A0548FE000
stack
page read and write
1F7AC964000
heap
page read and write
1C8CDE45000
heap
page read and write
1F7AC215000
heap
page read and write
1F7AC180000
heap
page read and write
1C8CE4FC000
heap
page read and write
800BDFF000
stack
page read and write
1F7AC215000
heap
page read and write
1C8CDE8E000
heap
page read and write
21352100000
heap
page read and write
21352065000
heap
page read and write
2135205C000
heap
page read and write
2135201D000
heap
page read and write
2135210A000
heap
page read and write
92F64FE000
stack
page read and write
21351FFA000
heap
page read and write
1DDF3770000
heap
page read and write
1F7AC4C0000
heap
page read and write
24AB1E50000
heap
page read and write
1F7AC215000
heap
page read and write
21352058000
heap
page read and write
1C8CDE4B000
heap
page read and write
1F7AC225000
heap
page read and write
1C8CDE8F000
heap
page read and write
2135201A000
heap
page read and write
1F7AC958000
heap
page read and write
213522B0000
heap
page read and write
21351FEA000
heap
page read and write
1F7AC97B000
heap
page read and write
22C22045000
heap
page read and write
1C8CE503000
heap
page read and write
FC7958F000
stack
page read and write
21351FB0000
trusted library allocation
page read and write
1C8CE50D000
heap
page read and write
5430F7F000
stack
page read and write
5430EFF000
stack
page read and write
2135205E000
heap
page read and write
2135204C000
heap
page read and write
21352013000
heap
page read and write
1F7AC202000
heap
page read and write
1C8CE047000
heap
page read and write
2135206A000
heap
page read and write
92F667F000
stack
page read and write
21352629000
heap
page read and write
1C8CDE25000
heap
page read and write
1C8CDDE0000
trusted library allocation
page read and write
1F7AC977000
heap
page read and write
1C8CE518000
heap
page read and write
1F7AC977000
heap
page read and write
1C8CE043000
heap
page read and write
7FF792321000
unkown
page execute read
1C8CDE27000
heap
page read and write
1F7AC170000
heap
page read and write
1C8CDE66000
heap
page read and write
22C21D10000
heap
page read and write
1C8CDE6A000
heap
page read and write
1C8CE518000
heap
page read and write
1DDF39B5000
heap
page read and write
21351FB0000
trusted library allocation
page read and write
1F7AC210000
heap
page read and write
1F7AC215000
heap
page read and write
1C8CDE99000
heap
page read and write
21352013000
heap
page read and write
1C8CE518000
heap
page read and write
1C8CDE41000
heap
page read and write
2135210A000
heap
page read and write
A52D92C000
stack
page read and write
21351E90000
heap
page read and write
1F7AC497000
heap
page read and write
1C8CE000000
trusted library allocation
page read and write
2135206A000
heap
page read and write
1C8CDE8B000
heap
page read and write
1C8CFE30000
heap
page read and write
FC7987E000
stack
page read and write
21352619000
heap
page read and write
1DDF37DB000
heap
page read and write
1C8CE04B000
heap
page read and write
21351FF8000
heap
page read and write
21352614000
heap
page read and write
1F7AC1F5000
heap
page read and write
2135206A000
heap
page read and write
1F7AC96B000
heap
page read and write
1C8CE504000
heap
page read and write
7FF792320000
unkown
page readonly
1F7AC215000
heap
page read and write
1F7AC96B000
heap
page read and write
1F7AC1F9000
heap
page read and write
21351FC9000
heap
page read and write
1F7AC390000
trusted library allocation
page read and write
21352058000
heap
page read and write
1F7AC225000
heap
page read and write
21352629000
heap
page read and write
21352629000
heap
page read and write
21352067000
heap
page read and write
21352618000
heap
page read and write
2135262C000
heap
page read and write
2135206A000
heap
page read and write
1F7AC211000
heap
page read and write
2135260D000
heap
page read and write
1C8CE4F7000
heap
page read and write
1DDF37D7000
heap
page read and write
1F7AC963000
heap
page read and write
1F7AE290000
heap
page read and write
1C8CDE27000
heap
page read and write
2135205C000
heap
page read and write
97525BC000
stack
page read and write
800BE7E000
stack
page read and write
21351FF7000
heap
page read and write
21352631000
heap
page read and write
21352107000
heap
page read and write
1C8CE50D000
heap
page read and write
2135206C000
heap
page read and write
7FF792328000
unkown
page write copy
213522BB000
heap
page read and write
1F7AC4C5000
heap
page read and write
23958DC0000
heap
page read and write
24AB3B60000
heap
page read and write
1F7AC390000
trusted library allocation
page read and write
1C8CE518000
heap
page read and write
22C21D40000
heap
page read and write
1F7AC497000
heap
page read and write
1F7AC1C9000
heap
page read and write
24AB1E20000
heap
page read and write
2135210E000
heap
page read and write
92F647D000
stack
page read and write
1F7AC977000
heap
page read and write
1F7AC21E000
heap
page read and write
1C8CE4F0000
heap
page read and write
22C21D20000
heap
page read and write
1F7AC205000
heap
page read and write
21352019000
heap
page read and write
21352013000
heap
page read and write
1C8CE06B000
heap
page read and write
1DDF37D0000
heap
page read and write
5430BAE000
stack
page read and write
1F7AC1D8000
heap
page read and write
22C21D68000
heap
page read and write
1F7AC1C0000
heap
page read and write
1F7AC1A0000
heap
page read and write
2135260C000
heap
page read and write
1C8CDE25000
heap
page read and write
There are 358 hidden memdumps, click here to show them.