IOC Report
1lAxaLKP7E.exe

loading gif

Files

File Path
Type
Category
Malicious
1lAxaLKP7E.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\Desktop\._cache_svchost.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\ProgramData\Synaptics\Synaptics.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\Melber
data
dropped
C:\Users\user\AppData\Local\Temp\aut6951.tmp
data
dropped
C:\Users\user\AppData\Local\Temp\aut6A3C.tmp
data
dropped
C:\Users\user\AppData\Local\Temp\selectee
ASCII text, with very long lines (65536), with no line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\1lAxaLKP7E.exe
"C:\Users\user\Desktop\1lAxaLKP7E.exe"
malicious
C:\Windows\SysWOW64\svchost.exe
"C:\Users\user\Desktop\1lAxaLKP7E.exe"
malicious
C:\Users\user\Desktop\._cache_svchost.exe
"C:\Users\user\Desktop\._cache_svchost.exe"
malicious
C:\ProgramData\Synaptics\Synaptics.exe
"C:\ProgramData\Synaptics\Synaptics.exe" InjUpdate
C:\ProgramData\Synaptics\Synaptics.exe
"C:\ProgramData\Synaptics\Synaptics.exe"

URLs

Name
IP
Malicious
http://xred.site50.net/syn/SSLLibrary.dll
unknown
malicious
http://xred.site50.net/syn/SSLLibrary.dl
unknown
http://xred.site50.net/syn/Synaptics.rar
unknown
https://www.dropbox.com/s/fzj752whr3ontsm/SSLLibrary.dll?dl=1
unknown
https://www.dropbox.com/s/n1w4p8gc6jzo0sg/SUpdate.ini?dl=1
unknown
https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1
unknown
https://www.dropbox.com/s/fzj752whr3ontsm/SSLLibrary.dll?dl=T
unknown
http://xred.site50.net/syn/SUpdate.iniH)
unknown
http://xred.site50.net/syn/SUpdate.ini
unknown
https://www.dropbox.com/s/n1w4p8gc6jzo0sg/SUpdate.ini?dl
unknown
http://freedns.afraid.org/api/?action=getdyndns&sha=a30fa98efc092684e8d1c5cff797bcc613562978
unknown
There are 1 hidden URLs, click here to show them.

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
Synaptics Pointing Device Driver

Memdumps

Base Address
Regiontype
Protect
Malicious
3640000
direct allocation
page read and write
malicious
631000
unkown
page execute and read and write
malicious
400000
system
page execute and read and write
malicious
E20000
direct allocation
page read and write
malicious
DE2000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
30A3000
heap
page read and write
E0B000
heap
page read and write
E0B000
heap
page read and write
EFA000
heap
page read and write
E0B000
heap
page read and write
7B000
unkown
page readonly
71000
unkown
page execute read
DE2000
heap
page read and write
660000
heap
page read and write
7B000
unkown
page readonly
DF7000
heap
page read and write
2E2C000
heap
page read and write
E0B000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
DF8000
heap
page read and write
E37000
heap
page read and write
2C70000
heap
page read and write
DE2000
heap
page read and write
E37000
heap
page read and write
DE2000
heap
page read and write
E37000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
3873000
direct allocation
page read and write
E0B000
heap
page read and write
E0B000
heap
page read and write
E37000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
2E2C000
heap
page read and write
DE2000
heap
page read and write
E37000
heap
page read and write
2E2C000
heap
page read and write
70000
unkown
page readonly
E37000
heap
page read and write
DF7000
heap
page read and write
671000
unkown
page execute read
DE2000
heap
page read and write
71000
unkown
page execute read
DE2000
heap
page read and write
72BE000
stack
page read and write
EE0000
heap
page read and write
DF7000
heap
page read and write
F36000
heap
page read and write
C1F000
stack
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
DF7000
heap
page read and write
DE2000
heap
page read and write
300F000
heap
page read and write
DE2000
heap
page read and write
D14000
heap
page read and write
3860000
direct allocation
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
110F000
heap
page read and write
DFD000
heap
page read and write
714C000
stack
page read and write
E0B000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
3B9E000
direct allocation
page read and write
E37000
heap
page read and write
EEE000
heap
page read and write
3A8E000
direct allocation
page read and write
700E000
stack
page read and write
DF7000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
3B2D000
direct allocation
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
E37000
heap
page read and write
1B70000
heap
page read and write
3A1D000
direct allocation
page read and write
E37000
heap
page read and write
4F10000
direct allocation
page execute and read and write
73BE000
stack
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
E70000
direct allocation
page read and write
308A000
heap
page read and write
3A19000
direct allocation
page read and write
3B2D000
direct allocation
page read and write
DF7000
heap
page read and write
333E000
stack
page read and write
E37000
heap
page read and write
DE2000
heap
page read and write
DF7000
heap
page read and write
630000
unkown
page readonly
DE2000
heap
page read and write
25F0000
heap
page read and write
19BF000
stack
page read and write
DF7000
heap
page read and write
C0F000
stack
page read and write
E37000
heap
page read and write
DE2000
heap
page read and write
DF7000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
D2B000
heap
page read and write
302C000
heap
page read and write
DE2000
heap
page read and write
DF7000
heap
page read and write
DE2000
heap
page read and write
73C000
unkown
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
3B9E000
direct allocation
page read and write
DE2000
heap
page read and write
2DF0000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
DF7000
heap
page read and write
C2B000
stack
page read and write
DE2000
heap
page read and write
2E02000
heap
page read and write
E0B000
heap
page read and write
DF7000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
DF7000
heap
page read and write
29DA000
stack
page read and write
3100000
heap
page read and write
E37000
heap
page read and write
E37000
heap
page read and write
2E2C000
heap
page read and write
DE2000
heap
page read and write
E37000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
E37000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
70C000
unkown
page readonly
DF7000
heap
page read and write
3B9E000
direct allocation
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
E0B000
heap
page read and write
DF7000
heap
page read and write
FE2000
heap
page read and write
D2B000
heap
page read and write
E70000
direct allocation
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
3A1D000
direct allocation
page read and write
DF7000
heap
page read and write
E0B000
heap
page read and write
EFF000
heap
page read and write
E70000
direct allocation
page read and write
DE2000
heap
page read and write
2CFD000
stack
page read and write
DE2000
heap
page read and write
4C01000
heap
page read and write
3061000
heap
page read and write
29F7000
heap
page read and write
6E8F000
stack
page read and write
12BD000
direct allocation
page execute and read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
E07000
heap
page read and write
CD0000
heap
page read and write
2DE0000
heap
page read and write
DF7000
heap
page read and write
2E00000
heap
page read and write
EFF000
heap
page read and write
2E2C000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
2E2C000
heap
page read and write
EF6000
heap
page read and write
E0B000
heap
page read and write
E70000
direct allocation
page read and write
3983000
direct allocation
page read and write
C70000
direct allocation
page read and write
F4B000
heap
page read and write
DE2000
heap
page read and write
302C000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
3750000
direct allocation
page read and write
724C000
stack
page read and write
DF7000
heap
page read and write
DE8000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
DB8000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
38F0000
direct allocation
page read and write
2E2C000
heap
page read and write
252D000
stack
page read and write
DE2000
heap
page read and write
E5B000
heap
page read and write
EFF000
heap
page read and write
DE2000
heap
page read and write
2E24000
heap
page read and write
DE2000
heap
page read and write
2DCE000
stack
page read and write
73C000
unkown
page write copy
3641000
heap
page read and write
E37000
heap
page read and write
DE2000
heap
page read and write
2DA0000
heap
page read and write
E37000
heap
page read and write
390000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
DF7000
heap
page read and write
E37000
heap
page read and write
10DF000
stack
page read and write
3120000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
F5F000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
343E000
stack
page read and write
E0B000
heap
page read and write
EFF000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
2E2C000
heap
page read and write
D14000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
2E2C000
heap
page read and write
E3D000
heap
page read and write
2D3D000
stack
page read and write
E0B000
heap
page read and write
E0B000
heap
page read and write
3860000
direct allocation
page read and write
DF7000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
B80000
heap
page read and write
DE2000
heap
page read and write
4D01000
heap
page read and write
DF7000
heap
page read and write
DE2000
heap
page read and write
E48000
heap
page read and write
DE2000
heap
page read and write
3025000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
DF7000
heap
page read and write
DF7000
heap
page read and write
D10000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
DF7000
heap
page read and write
DF7000
heap
page read and write
DE2000
heap
page read and write
E08000
heap
page read and write
DE2000
heap
page read and write
DF8000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
E37000
heap
page read and write
DE2000
heap
page read and write
2E2C000
heap
page read and write
DF7000
heap
page read and write
3B29000
direct allocation
page read and write
DF7000
heap
page read and write
630000
unkown
page readonly
DF7000
heap
page read and write
DC9000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
EFB000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
3A0000
heap
page read and write
E37000
heap
page read and write
110B000
heap
page read and write
3A00000
direct allocation
page read and write
DE2000
heap
page read and write
B3C000
stack
page read and write
3052000
heap
page read and write
DE2000
heap
page read and write
D21000
heap
page read and write
2E2C000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
3644000
heap
page read and write
C60000
heap
page read and write
DF7000
heap
page read and write
DE2000
heap
page read and write
E65000
heap
page read and write
E70000
direct allocation
page read and write
E0B000
heap
page read and write
2E2C000
heap
page read and write
E0B000
heap
page read and write
3D0000
heap
page read and write
E0B000
heap
page read and write
E0B000
heap
page read and write
E0B000
heap
page read and write
2C3C000
stack
page read and write
4BF0000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
3000000
heap
page read and write
3750000
direct allocation
page read and write
D20000
heap
page read and write
EFF000
heap
page read and write
DE2000
heap
page read and write
70000
unkown
page readonly
3983000
direct allocation
page read and write
EEA000
heap
page read and write
E0B000
heap
page read and write
E3D000
heap
page read and write
E37000
heap
page read and write
E0B000
heap
page read and write
3873000
direct allocation
page read and write
DE2000
heap
page read and write
3B29000
direct allocation
page read and write
E37000
heap
page read and write
25B0000
heap
page read and write
CF0000
heap
page read and write
E37000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
2D80000
heap
page readonly
E0B000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
2DF0000
heap
page read and write
DF7000
heap
page read and write
E0B000
heap
page read and write
E0B000
heap
page read and write
D21000
heap
page read and write
DE2000
heap
page read and write
F05000
heap
page read and write
E37000
heap
page read and write
E37000
heap
page read and write
6ECE000
stack
page read and write
E0B000
heap
page read and write
E37000
heap
page read and write
E0B000
heap
page read and write
3B29000
direct allocation
page read and write
E58000
heap
page read and write
DE2000
heap
page read and write
670000
unkown
page readonly
3216000
heap
page read and write
C8E000
stack
page read and write
DF7000
heap
page read and write
7B000
unkown
page readonly
D21000
heap
page read and write
78000
unkown
page readonly
E37000
heap
page read and write
DE2000
heap
page read and write
F05000
heap
page read and write
DF8000
heap
page read and write
E0B000
heap
page read and write
1190000
direct allocation
page execute and read and write
E37000
heap
page read and write
DE2000
heap
page read and write
D21000
heap
page read and write
E0B000
heap
page read and write
E37000
heap
page read and write
C4F000
stack
page read and write
3A8E000
direct allocation
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
D2B000
heap
page read and write
744000
unkown
page readonly
3860000
direct allocation
page read and write
DF7000
heap
page read and write
E0B000
heap
page read and write
DF7000
heap
page read and write
DF8000
heap
page read and write
DE2000
heap
page read and write
29F0000
heap
page read and write
3211000
heap
page read and write
E0B000
heap
page read and write
3A1D000
direct allocation
page read and write
1710000
heap
page read and write
E37000
heap
page read and write
3A19000
direct allocation
page read and write
CD4000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
DF7000
heap
page read and write
2E2C000
heap
page read and write
CF8000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
DF7000
heap
page read and write
E0B000
heap
page read and write
E0B000
heap
page read and write
E0B000
heap
page read and write
E37000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
145D000
direct allocation
page execute and read and write
E0B000
heap
page read and write
E0B000
heap
page read and write
E37000
heap
page read and write
D31000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
F21000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
3750000
direct allocation
page read and write
DE2000
heap
page read and write
3099000
heap
page read and write
DF7000
heap
page read and write
2E2C000
heap
page read and write
DE2000
heap
page read and write
DB8000
heap
page read and write
71000
unkown
page execute read
E37000
heap
page read and write
3A00000
direct allocation
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
6FCE000
stack
page read and write
CAE000
stack
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
3031000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
E0B000
heap
page read and write
DF7000
heap
page read and write
744000
unkown
page readonly
E37000
heap
page read and write
E0B000
heap
page read and write
CA0000
direct allocation
page execute and read and write
303C000
heap
page read and write
3127000
heap
page read and write
E0B000
heap
page read and write
E37000
heap
page read and write
DE2000
heap
page read and write
631000
unkown
page execute read
DE2000
heap
page read and write
DE2000
heap
page read and write
63E000
stack
page read and write
DE2000
heap
page read and write
E37000
heap
page read and write
DE2000
heap
page read and write
70C000
unkown
page readonly
E0B000
heap
page read and write
E0B000
heap
page read and write
3A8E000
direct allocation
page read and write
E37000
heap
page read and write
E37000
heap
page read and write
15DF000
stack
page read and write
E37000
heap
page read and write
E0B000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
3090000
heap
page read and write
DE2000
heap
page read and write
132E000
direct allocation
page execute and read and write
732000
unkown
page readonly
E0B000
heap
page read and write
E0B000
heap
page read and write
7B000
unkown
page readonly
32FE000
stack
page read and write
E0B000
heap
page read and write
E0B000
heap
page read and write
2CA0000
heap
page read and write
DE2000
heap
page read and write
4A5000
system
page execute and read and write
1461000
direct allocation
page execute and read and write
329000
stack
page read and write
71000
unkown
page execute read
DE2000
heap
page read and write
12B9000
direct allocation
page execute and read and write
3A19000
direct allocation
page read and write
DE2000
heap
page read and write
D2C000
heap
page read and write
E0B000
heap
page read and write
DF7000
heap
page read and write
F70000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
3012000
heap
page read and write
3873000
direct allocation
page read and write
DE2000
heap
page read and write
E37000
heap
page read and write
E0B000
heap
page read and write
15BD000
stack
page read and write
1180000
heap
page read and write
DE2000
heap
page read and write
EBF000
heap
page read and write
3983000
direct allocation
page read and write
DE2000
heap
page read and write
732000
unkown
page readonly
DE2000
heap
page read and write
A3D000
stack
page read and write
DE2000
heap
page read and write
E37000
heap
page read and write
E37000
heap
page read and write
2E2C000
heap
page read and write
D2B000
heap
page read and write
2E2C000
heap
page read and write
670000
unkown
page readonly
DF7000
heap
page read and write
3047000
heap
page read and write
F4A000
heap
page read and write
3112000
heap
page read and write
DF7000
heap
page read and write
DF7000
heap
page read and write
DE2000
heap
page read and write
E37000
heap
page read and write
E0B000
heap
page read and write
EFA000
heap
page read and write
DE2000
heap
page read and write
DC8000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
E37000
heap
page read and write
DE2000
heap
page read and write
DF7000
heap
page read and write
309E000
heap
page read and write
DF7000
heap
page read and write
DE2000
heap
page read and write
2E2C000
heap
page read and write
78000
unkown
page readonly
E37000
heap
page read and write
25E0000
heap
page read and write
CEE000
stack
page read and write
DE2000
heap
page read and write
EF4000
heap
page read and write
671000
unkown
page execute read
DE2000
heap
page read and write
DF7000
heap
page read and write
F2B000
heap
page read and write
DE2000
heap
page read and write
78000
unkown
page readonly
DE2000
heap
page read and write
4E00000
direct allocation
page read and write
3B2D000
direct allocation
page read and write
38F0000
direct allocation
page read and write
DE2000
heap
page read and write
E37000
heap
page read and write
DE2000
heap
page read and write
3A00000
direct allocation
page read and write
E0B000
heap
page read and write
DF7000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
DF7000
heap
page read and write
EF4000
heap
page read and write
DF7000
heap
page read and write
E0B000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
2C50000
heap
page read and write
DE2000
heap
page read and write
710E000
stack
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
E37000
heap
page read and write
DE2000
heap
page read and write
E37000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
14D2000
direct allocation
page execute and read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
6D8E000
stack
page read and write
DE2000
heap
page read and write
E37000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
256D000
stack
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
E37000
heap
page read and write
DE2000
heap
page read and write
E37000
heap
page read and write
DF7000
heap
page read and write
E70000
direct allocation
page read and write
DF7000
heap
page read and write
DE2000
heap
page read and write
70000
unkown
page readonly
D25000
heap
page read and write
38F0000
direct allocation
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
70000
unkown
page readonly
DE2000
heap
page read and write
DE2000
heap
page read and write
DE2000
heap
page read and write
2E2F000
heap
page read and write
DE2000
heap
page read and write
307E000
heap
page read and write
E0B000
heap
page read and write
DE8000
heap
page read and write
DF7000
heap
page read and write
DE2000
heap
page read and write
DE8000
heap
page read and write
DF7000
heap
page read and write
DF7000
heap
page read and write
740000
unkown
page write copy
78000
unkown
page readonly
C3F000
stack
page read and write
DE2000
heap
page read and write
E0B000
heap
page read and write
E0B000
heap
page read and write
DE2000
heap
page read and write
E37000
heap
page read and write
EFF000
heap
page read and write
2E2C000
heap
page read and write
DE2000
heap
page read and write
F40000
heap
page read and write
There are 665 hidden memdumps, click here to show them.