Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
ViKing-R2.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Users\user\Desktop\libCzf.dll
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\ViKing-R2.exe
|
"C:\Users\user\Desktop\ViKing-R2.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://www.baidu.com/
|
103.235.47.188
|
||
http://crl.sectigo.com/SectigoPublicCodeSigningCAEVR36.crl0
|
unknown
|
||
http://ocsp.sectigo.com00
|
unknown
|
||
https://api.ip138.com/ip/?token=http://api.ip138.com/ip/?token=retokip
|
unknown
|
||
https://sectigo.com/CPS0
|
unknown
|
||
http://.https
|
unknown
|
||
http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0
|
unknown
|
||
http://ocsp.sectigo.com0
|
unknown
|
||
http://whois.pconline.com.cn/ipJson.jsp
|
14.29.101.160
|
||
http://ocsp.thawte.com0
|
unknown
|
||
http://whois.pconline.com.cn/
|
unknown
|
||
http://crt.sectigo.com/SectigoPublicCodeSigningCAEVR36.crt0#
|
unknown
|
||
https://2023.ipchaxun.com/
|
unknown
|
||
https://api.ip138.com/ip/?token=
|
unknown
|
||
https://searchplugin.csdn.net/api/v1/ip/get
|
unknown
|
||
http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#
|
unknown
|
||
https://www.adeds.com
|
unknown
|
||
http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
|
unknown
|
||
https://www.thawte.com/cps0/
|
unknown
|
||
http://crl.thawte.com/ThawtePCA.crl0
|
unknown
|
||
http://whois.pconline.com.cn/Y
|
unknown
|
||
http://www.adeds.com
|
unknown
|
||
http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
|
unknown
|
||
http://api.ip138.com/ip/?token=
|
unknown
|
||
https://www.thawte.com/repository0
|
unknown
|
||
https://searchplugin.csdn.net/api/v1/ip/getaddress:----
|
unknown
|
There are 16 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
www.wshifen.com
|
103.235.47.188
|
||
whois.pconline.com.cn.ctadns.cn
|
14.29.101.160
|
||
whois.pconline.com.cn
|
unknown
|
||
www.baidu.com
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
103.235.47.188
|
www.wshifen.com
|
Hong Kong
|
||
14.29.101.160
|
whois.pconline.com.cn.ctadns.cn
|
China
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
93E000
|
unkown
|
page execute and write copy
|
||
A32000
|
unkown
|
page execute and write copy
|
||
2ED9000
|
heap
|
page read and write
|
||
3C7B000
|
trusted library allocation
|
page read and write
|
||
3D6F000
|
trusted library allocation
|
page read and write
|
||
3269000
|
trusted library allocation
|
page read and write
|
||
401000
|
unkown
|
page execute and write copy
|
||
5B8000
|
unkown
|
page execute and write copy
|
||
A5B000
|
unkown
|
page execute and write copy
|
||
39FF000
|
trusted library allocation
|
page read and write
|
||
F0A000
|
unkown
|
page execute and write copy
|
||
3C7D000
|
trusted library allocation
|
page read and write
|
||
960000
|
unkown
|
page execute and write copy
|
||
400000
|
unkown
|
page readonly
|
||
1106000
|
heap
|
page read and write
|
||
159A000
|
heap
|
page read and write
|
||
10F2000
|
heap
|
page read and write
|
||
324B000
|
trusted library allocation
|
page read and write
|
||
38F5000
|
trusted library allocation
|
page read and write
|
||
434B000
|
trusted library allocation
|
page read and write
|
||
F0C000
|
unkown
|
page execute and write copy
|
||
1017000
|
unkown
|
page readonly
|
||
4247000
|
trusted library allocation
|
page read and write
|
||
940000
|
unkown
|
page execute and write copy
|
||
533E000
|
trusted library allocation
|
page read and write
|
||
1012000
|
unkown
|
page write copy
|
||
A5B000
|
unkown
|
page execute and write copy
|
||
10EE000
|
heap
|
page read and write
|
||
6C2000
|
unkown
|
page execute and write copy
|
||
93E000
|
unkown
|
page execute and write copy
|
||
3248000
|
trusted library allocation
|
page read and write
|
||
3127000
|
heap
|
page read and write
|
||
3FFC000
|
trusted library allocation
|
page read and write
|
||
323B000
|
trusted library allocation
|
page read and write
|
||
3244000
|
trusted library allocation
|
page read and write
|
||
326C000
|
trusted library allocation
|
page read and write
|
||
3D98000
|
trusted library allocation
|
page read and write
|
||
401000
|
unkown
|
page execute and write copy
|
||
373D000
|
trusted library allocation
|
page read and write
|
||
2DB6000
|
heap
|
page read and write
|
||
325C000
|
trusted library allocation
|
page read and write
|
||
110F000
|
heap
|
page read and write
|
||
3C9D000
|
trusted library allocation
|
page read and write
|
||
1508000
|
heap
|
page read and write
|
||
4249000
|
trusted library allocation
|
page read and write
|
||
960000
|
unkown
|
page execute and write copy
|
||
3120000
|
trusted library allocation
|
page read and write
|
||
A32000
|
unkown
|
page execute and write copy
|
||
6C2000
|
unkown
|
page execute and write copy
|
||
5B8000
|
unkown
|
page execute and write copy
|
||
100E000
|
unkown
|
page execute and write copy
|
||
940000
|
unkown
|
page execute and write copy
|
There are 42 hidden memdumps, click here to show them.