Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
OLHskBFtS1.exe
|
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
initial sample
|
||
\Device\ConDrv
|
ASCII text, with CRLF line terminators
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\OLHskBFtS1.exe
|
"C:\Users\user\Desktop\OLHskBFtS1.exe"
|
||
C:\Windows\SysWOW64\netsh.exe
|
netsh firewall add allowedprogram "C:\Users\user\Desktop\OLHskBFtS1.exe" "OLHskBFtS1.exe" ENABLE
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
0.tcp.eu.ngrok.io
|
3.74.27.83
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
18.192.31.30
|
unknown
|
United States
|
||
3.74.27.83
|
0.tcp.eu.ngrok.io
|
United States
|
||
18.153.198.123
|
unknown
|
United States
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER
|
di
|
||
HKEY_CURRENT_USER\Environment
|
SEE_MASK_NOZONECHECKS
|
||
HKEY_CURRENT_USER\SOFTWARE\4f7098563ca32e152a50bf8bea3737b3
|
[kl]
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
692000
|
unkown
|
page readonly
|
||
FD2000
|
trusted library allocation
|
page read and write
|
||
4E91000
|
heap
|
page read and write
|
||
9B9000
|
heap
|
page read and write
|
||
8ED000
|
stack
|
page read and write
|
||
9DD000
|
heap
|
page read and write
|
||
FBA000
|
trusted library allocation
|
page execute and read and write
|
||
A59000
|
heap
|
page read and write
|
||
3EB000
|
stack
|
page read and write
|
||
9F1000
|
heap
|
page read and write
|
||
997000
|
heap
|
page read and write
|
||
5AE7000
|
heap
|
page read and write
|
||
9A5000
|
heap
|
page read and write
|
||
E7E000
|
stack
|
page read and write
|
||
4E6E000
|
stack
|
page read and write
|
||
9AA000
|
heap
|
page read and write
|
||
9E9000
|
heap
|
page read and write
|
||
A03000
|
heap
|
page read and write
|
||
FC2000
|
trusted library allocation
|
page execute and read and write
|
||
9DD000
|
heap
|
page read and write
|
||
5AE4000
|
heap
|
page read and write
|
||
A32000
|
heap
|
page read and write
|
||
A5E000
|
heap
|
page read and write
|
||
9B4000
|
heap
|
page read and write
|
||
9DD000
|
heap
|
page read and write
|
||
981000
|
heap
|
page read and write
|
||
9AC000
|
heap
|
page read and write
|
||
1060000
|
heap
|
page execute and read and write
|
||
790000
|
heap
|
page read and write
|
||
9B1000
|
heap
|
page read and write
|
||
4EA7000
|
heap
|
page read and write
|
||
A10000
|
heap
|
page read and write
|
||
C60000
|
heap
|
page read and write
|
||
F80000
|
trusted library allocation
|
page read and write
|
||
9E6000
|
heap
|
page read and write
|
||
5450000
|
trusted library allocation
|
page execute and read and write
|
||
E16000
|
heap
|
page read and write
|
||
A10000
|
heap
|
page read and write
|
||
2D3C000
|
trusted library allocation
|
page read and write
|
||
55C0000
|
heap
|
page read and write
|
||
9EC000
|
heap
|
page read and write
|
||
9EC000
|
heap
|
page read and write
|
||
4E93000
|
heap
|
page read and write
|
||
A5E000
|
heap
|
page read and write
|
||
A36000
|
heap
|
page read and write
|
||
9DE000
|
heap
|
page read and write
|
||
E10000
|
heap
|
page read and write
|
||
9A6000
|
heap
|
page read and write
|
||
D74000
|
heap
|
page read and write
|
||
9AA000
|
heap
|
page read and write
|
||
9EE000
|
heap
|
page read and write
|
||
D6F000
|
heap
|
page read and write
|
||
AF6000
|
stack
|
page read and write
|
||
A03000
|
heap
|
page read and write
|
||
4EAB000
|
heap
|
page read and write
|
||
50BE000
|
stack
|
page read and write
|
||
FDB000
|
trusted library allocation
|
page execute and read and write
|
||
9A9000
|
heap
|
page read and write
|
||
9D9000
|
heap
|
page read and write
|
||
A5B000
|
heap
|
page read and write
|
||
9EC000
|
heap
|
page read and write
|
||
506F000
|
stack
|
page read and write
|
||
9A5000
|
heap
|
page read and write
|
||
6FE000
|
stack
|
page read and write
|
||
2CC3000
|
trusted library allocation
|
page read and write
|
||
760000
|
heap
|
page read and write
|
||
A03000
|
heap
|
page read and write
|
||
5620000
|
heap
|
page read and write
|
||
9A7000
|
heap
|
page read and write
|
||
56EC000
|
stack
|
page read and write
|
||
D68000
|
heap
|
page read and write
|
||
11FE000
|
stack
|
page read and write
|
||
5BC0000
|
heap
|
page read and write
|
||
7B0000
|
heap
|
page read and write
|
||
592E000
|
stack
|
page read and write
|
||
297F000
|
stack
|
page read and write
|
||
9AF000
|
heap
|
page read and write
|
||
9DD000
|
heap
|
page read and write
|
||
4E95000
|
heap
|
page read and write
|
||
57EA000
|
stack
|
page read and write
|
||
A56000
|
heap
|
page read and write
|
||
9E0000
|
heap
|
page read and write
|
||
5BB0000
|
heap
|
page read and write
|
||
9CE000
|
heap
|
page read and write
|
||
9BA000
|
heap
|
page read and write
|
||
A54000
|
heap
|
page read and write
|
||
9A7000
|
heap
|
page read and write
|
||
9E3000
|
heap
|
page read and write
|
||
930000
|
heap
|
page read and write
|
||
6FB000
|
stack
|
page read and write
|
||
9D9000
|
heap
|
page read and write
|
||
4EA9000
|
heap
|
page read and write
|
||
8AE000
|
unkown
|
page read and write
|
||
101E000
|
stack
|
page read and write
|
||
4E92000
|
heap
|
page read and write
|
||
A5E000
|
heap
|
page read and write
|
||
9E6000
|
heap
|
page read and write
|
||
FA0000
|
trusted library allocation
|
page read and write
|
||
C88000
|
heap
|
page read and write
|
||
9DE000
|
heap
|
page read and write
|
||
9E9000
|
heap
|
page read and write
|
||
FAA000
|
trusted library allocation
|
page execute and read and write
|
||
9CC000
|
heap
|
page read and write
|
||
5AED000
|
heap
|
page read and write
|
||
9D7000
|
heap
|
page read and write
|
||
A10000
|
heap
|
page read and write
|
||
A51000
|
heap
|
page read and write
|
||
9B6000
|
heap
|
page read and write
|
||
A08000
|
heap
|
page read and write
|
||
FB7000
|
trusted library allocation
|
page execute and read and write
|
||
9B9000
|
heap
|
page read and write
|
||
A13000
|
heap
|
page read and write
|
||
D53000
|
heap
|
page read and write
|
||
9E5000
|
heap
|
page read and write
|
||
4FD0000
|
trusted library allocation
|
page read and write
|
||
A50000
|
heap
|
page read and write
|
||
2D05000
|
trusted library allocation
|
page read and write
|
||
4E5E000
|
stack
|
page read and write
|
||
A50000
|
heap
|
page read and write
|
||
A10000
|
heap
|
page read and write
|
||
FA2000
|
trusted library allocation
|
page execute and read and write
|
||
5AFB000
|
heap
|
page read and write
|
||
9E8000
|
heap
|
page read and write
|
||
4FC9000
|
stack
|
page read and write
|
||
9B6000
|
heap
|
page read and write
|
||
A08000
|
heap
|
page read and write
|
||
A36000
|
heap
|
page read and write
|
||
9EB000
|
heap
|
page read and write
|
||
4F4A000
|
stack
|
page read and write
|
||
9E3000
|
heap
|
page read and write
|
||
4EA7000
|
heap
|
page read and write
|
||
9AD000
|
heap
|
page read and write
|
||
A36000
|
heap
|
page read and write
|
||
A03000
|
heap
|
page read and write
|
||
9B8000
|
heap
|
page read and write
|
||
1260000
|
heap
|
page read and write
|
||
9AD000
|
heap
|
page read and write
|
||
2D17000
|
trusted library allocation
|
page read and write
|
||
9E9000
|
heap
|
page read and write
|
||
A50000
|
heap
|
page read and write
|
||
A11000
|
heap
|
page read and write
|
||
9CF000
|
heap
|
page read and write
|
||
4E94000
|
heap
|
page read and write
|
||
1050000
|
trusted library allocation
|
page read and write
|
||
9A8000
|
heap
|
page read and write
|
||
4FE0000
|
trusted library allocation
|
page execute and read and write
|
||
5013000
|
heap
|
page read and write
|
||
A50000
|
heap
|
page read and write
|
||
9E1000
|
heap
|
page read and write
|
||
A5E000
|
heap
|
page read and write
|
||
1250000
|
trusted library allocation
|
page execute and read and write
|
||
AF9000
|
stack
|
page read and write
|
||
4EA8000
|
heap
|
page read and write
|
||
A03000
|
heap
|
page read and write
|
||
4820000
|
heap
|
page read and write
|
||
9B9000
|
heap
|
page read and write
|
||
750000
|
heap
|
page read and write
|
||
9B5000
|
heap
|
page read and write
|
||
4E60000
|
trusted library allocation
|
page read and write
|
||
9AA000
|
heap
|
page read and write
|
||
9D0000
|
heap
|
page read and write
|
||
9CC000
|
heap
|
page read and write
|
||
55D0000
|
heap
|
page read and write
|
||
72A000
|
stack
|
page read and write
|
||
2CC1000
|
trusted library allocation
|
page read and write
|
||
9CC000
|
heap
|
page read and write
|
||
4F8C000
|
stack
|
page read and write
|
||
4E70000
|
heap
|
page read and write
|
||
9B7000
|
heap
|
page read and write
|
||
9B6000
|
heap
|
page read and write
|
||
51BE000
|
stack
|
page read and write
|
||
4CC8000
|
trusted library allocation
|
page read and write
|
||
7F3E0000
|
trusted library allocation
|
page execute and read and write
|
||
9EB000
|
heap
|
page read and write
|
||
9BA000
|
heap
|
page read and write
|
||
9ED000
|
heap
|
page read and write
|
||
9D8000
|
heap
|
page read and write
|
||
A54000
|
heap
|
page read and write
|
||
582E000
|
stack
|
page read and write
|
||
994000
|
heap
|
page read and write
|
||
690000
|
unkown
|
page readonly
|
||
9D2000
|
heap
|
page read and write
|
||
C30000
|
heap
|
page read and write
|
||
A08000
|
heap
|
page read and write
|
||
A35000
|
heap
|
page read and write
|
||
C8E000
|
heap
|
page read and write
|
||
5AB0000
|
heap
|
page read and write
|
||
119E000
|
stack
|
page read and write
|
||
9D9000
|
heap
|
page read and write
|
||
9EE000
|
heap
|
page read and write
|
||
A10000
|
heap
|
page read and write
|
||
9AD000
|
heap
|
page read and write
|
||
9DD000
|
heap
|
page read and write
|
||
9BA000
|
heap
|
page read and write
|
||
4E9D000
|
heap
|
page read and write
|
||
10AC000
|
stack
|
page read and write
|
||
9EC000
|
heap
|
page read and write
|
||
9D9000
|
heap
|
page read and write
|
||
A53000
|
heap
|
page read and write
|
||
4EA8000
|
heap
|
page read and write
|
||
795000
|
heap
|
page read and write
|
||
790000
|
heap
|
page read and write
|
||
4930000
|
heap
|
page read and write
|
||
D0D000
|
heap
|
page read and write
|
||
FCA000
|
trusted library allocation
|
page execute and read and write
|
||
A36000
|
heap
|
page read and write
|
||
4E93000
|
heap
|
page read and write
|
||
9E1000
|
heap
|
page read and write
|
||
9A5000
|
heap
|
page read and write
|
||
F9A000
|
trusted library allocation
|
page execute and read and write
|
||
5A90000
|
trusted library allocation
|
page execute and read and write
|
||
4E92000
|
heap
|
page read and write
|
||
A5E000
|
heap
|
page read and write
|
||
A5E000
|
heap
|
page read and write
|
||
F92000
|
trusted library allocation
|
page execute and read and write
|
||
9E4000
|
heap
|
page read and write
|
||
A50000
|
heap
|
page read and write
|
||
A32000
|
heap
|
page read and write
|
||
7A0000
|
heap
|
page read and write
|
||
770000
|
heap
|
page read and write
|
||
6EE000
|
stack
|
page read and write
|
||
4EA0000
|
heap
|
page read and write
|
||
3CC1000
|
trusted library allocation
|
page read and write
|
||
325A000
|
trusted library allocation
|
page read and write
|
||
9D9000
|
heap
|
page read and write
|
||
CBF000
|
heap
|
page read and write
|
||
9EB000
|
heap
|
page read and write
|
||
9D8000
|
heap
|
page read and write
|
||
9E1000
|
heap
|
page read and write
|
||
B5E000
|
unkown
|
page read and write
|
||
9E0000
|
heap
|
page read and write
|
||
C80000
|
heap
|
page read and write
|
||
4F0C000
|
stack
|
page read and write
|
||
960000
|
heap
|
page read and write
|
||
5AB5000
|
heap
|
page read and write
|
||
4FF0000
|
unclassified section
|
page read and write
|
||
9BB000
|
heap
|
page read and write
|
||
4E91000
|
heap
|
page read and write
|
||
9ED000
|
heap
|
page read and write
|
||
4E94000
|
heap
|
page read and write
|
||
9AA000
|
heap
|
page read and write
|
||
795000
|
heap
|
page read and write
|
||
10B6000
|
heap
|
page read and write
|
||
9EB000
|
heap
|
page read and write
|
||
A36000
|
heap
|
page read and write
|
||
A5E000
|
heap
|
page read and write
|
||
C5E000
|
stack
|
page read and write
|
||
4E98000
|
heap
|
page read and write
|
||
10B0000
|
heap
|
page read and write
|
||
C0E000
|
stack
|
page read and write
|
||
A08000
|
heap
|
page read and write
|
||
9E8000
|
heap
|
page read and write
|
||
9BB000
|
heap
|
page read and write
|
||
10B0000
|
heap
|
page read and write
|
||
9E8000
|
heap
|
page read and write
|
||
6F4000
|
stack
|
page read and write
|
||
FD7000
|
trusted library allocation
|
page execute and read and write
|
||
9D8000
|
heap
|
page read and write
|
||
9CC000
|
heap
|
page read and write
|
||
9E9000
|
heap
|
page read and write
|
||
A08000
|
heap
|
page read and write
|
||
5010000
|
heap
|
page read and write
|
There are 252 hidden memdumps, click here to show them.