IOC Report
ViKing-R2.exe

loading gif

Files

File Path
Type
Category
Malicious
ViKing-R2.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\Desktop\libCzf.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\ViKing-R2.exe
"C:\Users\user\Desktop\ViKing-R2.exe"
malicious

URLs

Name
IP
Malicious
http://www.baidu.com/
103.235.47.188
malicious
http://crl.sectigo.com/SectigoPublicCodeSigningCAEVR36.crl0
unknown
http://ocsp.sectigo.com00
unknown
https://api.ip138.com/ip/?token=http://api.ip138.com/ip/?token=retokip
unknown
https://sectigo.com/CPS0
unknown
http://.https
unknown
http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0
unknown
http://ocsp.sectigo.com0
unknown
http://whois.pconline.com.cn/ipJson.jsp
14.29.101.160
http://ocsp.thawte.com0
unknown
http://whois.pconline.com.cn/
unknown
http://crt.sectigo.com/SectigoPublicCodeSigningCAEVR36.crt0#
unknown
https://2023.ipchaxun.com/
unknown
https://api.ip138.com/ip/?token=
unknown
https://searchplugin.csdn.net/api/v1/ip/get
unknown
http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#
unknown
https://www.adeds.com
unknown
http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
unknown
https://www.thawte.com/cps0/
unknown
http://crl.thawte.com/ThawtePCA.crl0
unknown
http://whois.pconline.com.cn/Y
unknown
http://www.adeds.com
unknown
http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
unknown
http://api.ip138.com/ip/?token=
unknown
https://www.thawte.com/repository0
unknown
https://searchplugin.csdn.net/api/v1/ip/getaddress:----
unknown
There are 16 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
www.wshifen.com
103.235.47.188
malicious
whois.pconline.com.cn.ctadns.cn
14.29.101.160
whois.pconline.com.cn
unknown
www.baidu.com
unknown

IPs

IP
Domain
Country
Malicious
103.235.47.188
www.wshifen.com
Hong Kong
malicious
14.29.101.160
whois.pconline.com.cn.ctadns.cn
China

Memdumps

Base Address
Regiontype
Protect
Malicious
93E000
unkown
page execute and write copy
A32000
unkown
page execute and write copy
2ED9000
heap
page read and write
3C7B000
trusted library allocation
page read and write
3D6F000
trusted library allocation
page read and write
3269000
trusted library allocation
page read and write
401000
unkown
page execute and write copy
5B8000
unkown
page execute and write copy
A5B000
unkown
page execute and write copy
39FF000
trusted library allocation
page read and write
F0A000
unkown
page execute and write copy
3C7D000
trusted library allocation
page read and write
960000
unkown
page execute and write copy
400000
unkown
page readonly
1106000
heap
page read and write
159A000
heap
page read and write
10F2000
heap
page read and write
324B000
trusted library allocation
page read and write
38F5000
trusted library allocation
page read and write
434B000
trusted library allocation
page read and write
F0C000
unkown
page execute and write copy
1017000
unkown
page readonly
4247000
trusted library allocation
page read and write
940000
unkown
page execute and write copy
533E000
trusted library allocation
page read and write
1012000
unkown
page write copy
A5B000
unkown
page execute and write copy
10EE000
heap
page read and write
6C2000
unkown
page execute and write copy
93E000
unkown
page execute and write copy
3248000
trusted library allocation
page read and write
3127000
heap
page read and write
3FFC000
trusted library allocation
page read and write
323B000
trusted library allocation
page read and write
3244000
trusted library allocation
page read and write
326C000
trusted library allocation
page read and write
3D98000
trusted library allocation
page read and write
401000
unkown
page execute and write copy
373D000
trusted library allocation
page read and write
2DB6000
heap
page read and write
325C000
trusted library allocation
page read and write
110F000
heap
page read and write
3C9D000
trusted library allocation
page read and write
1508000
heap
page read and write
4249000
trusted library allocation
page read and write
960000
unkown
page execute and write copy
3120000
trusted library allocation
page read and write
A32000
unkown
page execute and write copy
6C2000
unkown
page execute and write copy
5B8000
unkown
page execute and write copy
100E000
unkown
page execute and write copy
940000
unkown
page execute and write copy
There are 42 hidden memdumps, click here to show them.