IOC Report
OLHskBFtS1.exe

loading gif

Files

File Path
Type
Category
Malicious
OLHskBFtS1.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
\Device\ConDrv
ASCII text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\OLHskBFtS1.exe
"C:\Users\user\Desktop\OLHskBFtS1.exe"
malicious
C:\Windows\SysWOW64\netsh.exe
netsh firewall add allowedprogram "C:\Users\user\Desktop\OLHskBFtS1.exe" "OLHskBFtS1.exe" ENABLE
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

Domains

Name
IP
Malicious
0.tcp.eu.ngrok.io
3.74.27.83
malicious

IPs

IP
Domain
Country
Malicious
18.192.31.30
unknown
United States
malicious
3.74.27.83
0.tcp.eu.ngrok.io
United States
malicious
18.153.198.123
unknown
United States
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER
di
malicious
HKEY_CURRENT_USER\Environment
SEE_MASK_NOZONECHECKS
malicious
HKEY_CURRENT_USER\SOFTWARE\4f7098563ca32e152a50bf8bea3737b3
[kl]

Memdumps

Base Address
Regiontype
Protect
Malicious
692000
unkown
page readonly
malicious
FD2000
trusted library allocation
page read and write
4E91000
heap
page read and write
9B9000
heap
page read and write
8ED000
stack
page read and write
9DD000
heap
page read and write
FBA000
trusted library allocation
page execute and read and write
A59000
heap
page read and write
3EB000
stack
page read and write
9F1000
heap
page read and write
997000
heap
page read and write
5AE7000
heap
page read and write
9A5000
heap
page read and write
E7E000
stack
page read and write
4E6E000
stack
page read and write
9AA000
heap
page read and write
9E9000
heap
page read and write
A03000
heap
page read and write
FC2000
trusted library allocation
page execute and read and write
9DD000
heap
page read and write
5AE4000
heap
page read and write
A32000
heap
page read and write
A5E000
heap
page read and write
9B4000
heap
page read and write
9DD000
heap
page read and write
981000
heap
page read and write
9AC000
heap
page read and write
1060000
heap
page execute and read and write
790000
heap
page read and write
9B1000
heap
page read and write
4EA7000
heap
page read and write
A10000
heap
page read and write
C60000
heap
page read and write
F80000
trusted library allocation
page read and write
9E6000
heap
page read and write
5450000
trusted library allocation
page execute and read and write
E16000
heap
page read and write
A10000
heap
page read and write
2D3C000
trusted library allocation
page read and write
55C0000
heap
page read and write
9EC000
heap
page read and write
9EC000
heap
page read and write
4E93000
heap
page read and write
A5E000
heap
page read and write
A36000
heap
page read and write
9DE000
heap
page read and write
E10000
heap
page read and write
9A6000
heap
page read and write
D74000
heap
page read and write
9AA000
heap
page read and write
9EE000
heap
page read and write
D6F000
heap
page read and write
AF6000
stack
page read and write
A03000
heap
page read and write
4EAB000
heap
page read and write
50BE000
stack
page read and write
FDB000
trusted library allocation
page execute and read and write
9A9000
heap
page read and write
9D9000
heap
page read and write
A5B000
heap
page read and write
9EC000
heap
page read and write
506F000
stack
page read and write
9A5000
heap
page read and write
6FE000
stack
page read and write
2CC3000
trusted library allocation
page read and write
760000
heap
page read and write
A03000
heap
page read and write
5620000
heap
page read and write
9A7000
heap
page read and write
56EC000
stack
page read and write
D68000
heap
page read and write
11FE000
stack
page read and write
5BC0000
heap
page read and write
7B0000
heap
page read and write
592E000
stack
page read and write
297F000
stack
page read and write
9AF000
heap
page read and write
9DD000
heap
page read and write
4E95000
heap
page read and write
57EA000
stack
page read and write
A56000
heap
page read and write
9E0000
heap
page read and write
5BB0000
heap
page read and write
9CE000
heap
page read and write
9BA000
heap
page read and write
A54000
heap
page read and write
9A7000
heap
page read and write
9E3000
heap
page read and write
930000
heap
page read and write
6FB000
stack
page read and write
9D9000
heap
page read and write
4EA9000
heap
page read and write
8AE000
unkown
page read and write
101E000
stack
page read and write
4E92000
heap
page read and write
A5E000
heap
page read and write
9E6000
heap
page read and write
FA0000
trusted library allocation
page read and write
C88000
heap
page read and write
9DE000
heap
page read and write
9E9000
heap
page read and write
FAA000
trusted library allocation
page execute and read and write
9CC000
heap
page read and write
5AED000
heap
page read and write
9D7000
heap
page read and write
A10000
heap
page read and write
A51000
heap
page read and write
9B6000
heap
page read and write
A08000
heap
page read and write
FB7000
trusted library allocation
page execute and read and write
9B9000
heap
page read and write
A13000
heap
page read and write
D53000
heap
page read and write
9E5000
heap
page read and write
4FD0000
trusted library allocation
page read and write
A50000
heap
page read and write
2D05000
trusted library allocation
page read and write
4E5E000
stack
page read and write
A50000
heap
page read and write
A10000
heap
page read and write
FA2000
trusted library allocation
page execute and read and write
5AFB000
heap
page read and write
9E8000
heap
page read and write
4FC9000
stack
page read and write
9B6000
heap
page read and write
A08000
heap
page read and write
A36000
heap
page read and write
9EB000
heap
page read and write
4F4A000
stack
page read and write
9E3000
heap
page read and write
4EA7000
heap
page read and write
9AD000
heap
page read and write
A36000
heap
page read and write
A03000
heap
page read and write
9B8000
heap
page read and write
1260000
heap
page read and write
9AD000
heap
page read and write
2D17000
trusted library allocation
page read and write
9E9000
heap
page read and write
A50000
heap
page read and write
A11000
heap
page read and write
9CF000
heap
page read and write
4E94000
heap
page read and write
1050000
trusted library allocation
page read and write
9A8000
heap
page read and write
4FE0000
trusted library allocation
page execute and read and write
5013000
heap
page read and write
A50000
heap
page read and write
9E1000
heap
page read and write
A5E000
heap
page read and write
1250000
trusted library allocation
page execute and read and write
AF9000
stack
page read and write
4EA8000
heap
page read and write
A03000
heap
page read and write
4820000
heap
page read and write
9B9000
heap
page read and write
750000
heap
page read and write
9B5000
heap
page read and write
4E60000
trusted library allocation
page read and write
9AA000
heap
page read and write
9D0000
heap
page read and write
9CC000
heap
page read and write
55D0000
heap
page read and write
72A000
stack
page read and write
2CC1000
trusted library allocation
page read and write
9CC000
heap
page read and write
4F8C000
stack
page read and write
4E70000
heap
page read and write
9B7000
heap
page read and write
9B6000
heap
page read and write
51BE000
stack
page read and write
4CC8000
trusted library allocation
page read and write
7F3E0000
trusted library allocation
page execute and read and write
9EB000
heap
page read and write
9BA000
heap
page read and write
9ED000
heap
page read and write
9D8000
heap
page read and write
A54000
heap
page read and write
582E000
stack
page read and write
994000
heap
page read and write
690000
unkown
page readonly
9D2000
heap
page read and write
C30000
heap
page read and write
A08000
heap
page read and write
A35000
heap
page read and write
C8E000
heap
page read and write
5AB0000
heap
page read and write
119E000
stack
page read and write
9D9000
heap
page read and write
9EE000
heap
page read and write
A10000
heap
page read and write
9AD000
heap
page read and write
9DD000
heap
page read and write
9BA000
heap
page read and write
4E9D000
heap
page read and write
10AC000
stack
page read and write
9EC000
heap
page read and write
9D9000
heap
page read and write
A53000
heap
page read and write
4EA8000
heap
page read and write
795000
heap
page read and write
790000
heap
page read and write
4930000
heap
page read and write
D0D000
heap
page read and write
FCA000
trusted library allocation
page execute and read and write
A36000
heap
page read and write
4E93000
heap
page read and write
9E1000
heap
page read and write
9A5000
heap
page read and write
F9A000
trusted library allocation
page execute and read and write
5A90000
trusted library allocation
page execute and read and write
4E92000
heap
page read and write
A5E000
heap
page read and write
A5E000
heap
page read and write
F92000
trusted library allocation
page execute and read and write
9E4000
heap
page read and write
A50000
heap
page read and write
A32000
heap
page read and write
7A0000
heap
page read and write
770000
heap
page read and write
6EE000
stack
page read and write
4EA0000
heap
page read and write
3CC1000
trusted library allocation
page read and write
325A000
trusted library allocation
page read and write
9D9000
heap
page read and write
CBF000
heap
page read and write
9EB000
heap
page read and write
9D8000
heap
page read and write
9E1000
heap
page read and write
B5E000
unkown
page read and write
9E0000
heap
page read and write
C80000
heap
page read and write
4F0C000
stack
page read and write
960000
heap
page read and write
5AB5000
heap
page read and write
4FF0000
unclassified section
page read and write
9BB000
heap
page read and write
4E91000
heap
page read and write
9ED000
heap
page read and write
4E94000
heap
page read and write
9AA000
heap
page read and write
795000
heap
page read and write
10B6000
heap
page read and write
9EB000
heap
page read and write
A36000
heap
page read and write
A5E000
heap
page read and write
C5E000
stack
page read and write
4E98000
heap
page read and write
10B0000
heap
page read and write
C0E000
stack
page read and write
A08000
heap
page read and write
9E8000
heap
page read and write
9BB000
heap
page read and write
10B0000
heap
page read and write
9E8000
heap
page read and write
6F4000
stack
page read and write
FD7000
trusted library allocation
page execute and read and write
9D8000
heap
page read and write
9CC000
heap
page read and write
9E9000
heap
page read and write
A08000
heap
page read and write
5010000
heap
page read and write
There are 252 hidden memdumps, click here to show them.