IOC Report
21FuuTyh3g.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\21FuuTyh3g.exe
"C:\Users\user\Desktop\21FuuTyh3g.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe"
malicious
C:\Windows\SysWOW64\WerFault.exe
C:\Windows\SysWOW64\WerFault.exe -u -p 5016 -s 12

URLs

Name
IP
Malicious
104.168.34.185:2819
malicious
https://github.com/mgravell/protobuf-net
unknown
https://api.ip.sb/ip
unknown
https://github.com/mgravell/protobuf-neti
unknown
https://stackoverflow.com/q/14436606/23354
unknown
https://github.com/mgravell/protobuf-netJ
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
https://stackoverflow.com/q/11564914/23354;
unknown
https://stackoverflow.com/q/2152978/23354
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
45B8000
trusted library allocation
page read and write
malicious
4351000
trusted library allocation
page read and write
malicious
64E0000
trusted library section
page read and write
malicious
802000
remote allocation
page execute and read and write
malicious
46D5000
trusted library allocation
page read and write
malicious
3351000
trusted library allocation
page read and write
malicious
38B6000
trusted library allocation
page read and write
35EA000
trusted library allocation
page read and write
38C3000
trusted library allocation
page read and write
5920000
trusted library allocation
page read and write
1574000
trusted library allocation
page read and write
3A16000
trusted library allocation
page read and write
363A000
trusted library allocation
page read and write
37ED000
trusted library allocation
page read and write
362C000
trusted library allocation
page read and write
3655000
trusted library allocation
page read and write
15C2000
heap
page read and write
5860000
trusted library allocation
page read and write
64A0000
trusted library allocation
page read and write
3628000
trusted library allocation
page read and write
39BC000
trusted library allocation
page read and write
381D000
trusted library allocation
page read and write
35DF000
trusted library allocation
page read and write
35EE000
trusted library allocation
page read and write
3574000
trusted library allocation
page read and write
377E000
trusted library allocation
page read and write
FDA000
stack
page read and write
35A9000
trusted library allocation
page read and write
3672000
trusted library allocation
page read and write
1588000
heap
page read and write
6610000
trusted library allocation
page execute and read and write
3990000
trusted library allocation
page read and write
3883000
trusted library allocation
page read and write
35A7000
trusted library allocation
page read and write
38B8000
trusted library allocation
page read and write
3920000
trusted library allocation
page read and write
388D000
trusted library allocation
page read and write
37D0000
trusted library allocation
page read and write
36B0000
trusted library allocation
page read and write
3609000
trusted library allocation
page read and write
3636000
trusted library allocation
page read and write
3889000
trusted library allocation
page read and write
351D000
trusted library allocation
page read and write
366A000
trusted library allocation
page read and write
381F000
trusted library allocation
page read and write
3700000
trusted library allocation
page read and write
3878000
trusted library allocation
page read and write
3A27000
trusted library allocation
page read and write
389A000
trusted library allocation
page read and write
69A0000
trusted library allocation
page read and write
39B1000
trusted library allocation
page read and write
3630000
trusted library allocation
page read and write
37B2000
trusted library allocation
page read and write
3763000
trusted library allocation
page read and write
64D0000
trusted library allocation
page read and write
35AD000
trusted library allocation
page read and write
65B0000
trusted library allocation
page read and write
F27000
unkown
page readonly
84E000
remote allocation
page execute and read and write
37DD000
trusted library allocation
page read and write
3634000
trusted library allocation
page read and write
5B50000
heap
page read and write
585D000
trusted library allocation
page read and write
3806000
trusted library allocation
page read and write
147E000
stack
page read and write
388B000
trusted library allocation
page read and write
35BC000
trusted library allocation
page read and write
4697000
trusted library allocation
page read and write
3765000
trusted library allocation
page read and write
366E000
trusted library allocation
page read and write
1A10000
heap
page read and write
35C4000
trusted library allocation
page read and write
37FA000
trusted library allocation
page read and write
36DA000
trusted library allocation
page read and write
6560000
trusted library section
page read and write
1996000
trusted library allocation
page execute and read and write
167C000
heap
page read and write
6620000
trusted library allocation
page execute and read and write
36DC000
trusted library allocation
page read and write
3570000
trusted library allocation
page read and write
35C2000
trusted library allocation
page read and write
384A000
trusted library allocation
page read and write
3230000
heap
page execute and read and write
37D6000
trusted library allocation
page read and write
3846000
trusted library allocation
page read and write
3815000
trusted library allocation
page read and write
64B0000
trusted library allocation
page execute and read and write
3623000
trusted library allocation
page read and write
63AC000
heap
page read and write
380A000
trusted library allocation
page read and write
3786000
trusted library allocation
page read and write
36F3000
trusted library allocation
page read and write
37D2000
trusted library allocation
page read and write
35C0000
trusted library allocation
page read and write
354F000
trusted library allocation
page read and write
14BE000
stack
page read and write
388F000
trusted library allocation
page read and write
3895000
trusted library allocation
page read and write
3681000
trusted library allocation
page read and write
391C000
trusted library allocation
page read and write
365C000
trusted library allocation
page read and write
3702000
trusted library allocation
page read and write
1990000
trusted library allocation
page read and write
35CD000
trusted library allocation
page read and write
379D000
trusted library allocation
page read and write
35FC000
trusted library allocation
page read and write
36AE000
trusted library allocation
page read and write
3625000
trusted library allocation
page read and write
36D8000
trusted library allocation
page read and write
3952000
trusted library allocation
page read and write
1623000
heap
page read and write
37B6000
trusted library allocation
page read and write
37EF000
trusted library allocation
page read and write
38D7000
trusted library allocation
page read and write
38EC000
trusted library allocation
page read and write
479B000
trusted library allocation
page read and write
394C000
trusted library allocation
page read and write
38BE000
trusted library allocation
page read and write
800000
remote allocation
page execute and read and write
36F9000
trusted library allocation
page read and write
38AA000
trusted library allocation
page read and write
35AB000
trusted library allocation
page read and write
37E7000
trusted library allocation
page read and write
398A000
trusted library allocation
page read and write
3932000
trusted library allocation
page read and write
37F1000
trusted library allocation
page read and write
5888000
trusted library allocation
page read and write
38F2000
trusted library allocation
page read and write
357C000
trusted library allocation
page read and write
6780000
trusted library section
page read and write
3910000
trusted library allocation
page read and write
38C9000
trusted library allocation
page read and write
38C1000
trusted library allocation
page read and write
36A2000
trusted library allocation
page read and write
38CD000
trusted library allocation
page read and write
3576000
trusted library allocation
page read and write
36FB000
trusted library allocation
page read and write
3977000
trusted library allocation
page read and write
354C000
trusted library allocation
page read and write
3867000
trusted library allocation
page read and write
1420000
heap
page read and write
3563000
trusted library allocation
page read and write
3973000
trusted library allocation
page read and write
14FE000
stack
page read and write
36E2000
trusted library allocation
page read and write
394A000
trusted library allocation
page read and write
37DA000
trusted library allocation
page read and write
35E8000
trusted library allocation
page read and write
3A14000
trusted library allocation
page read and write
39CD000
trusted library allocation
page read and write
3804000
trusted library allocation
page read and write
1340000
heap
page read and write
353A000
trusted library allocation
page read and write
E02000
unkown
page readonly
3546000
trusted library allocation
page read and write
39E3000
trusted library allocation
page read and write
39D1000
trusted library allocation
page read and write
3979000
trusted library allocation
page read and write
3675000
trusted library allocation
page read and write
197F000
stack
page read and write
3531000
trusted library allocation
page read and write
5CCE000
stack
page read and write
3548000
trusted library allocation
page read and write
38D1000
trusted library allocation
page read and write
1510000
heap
page read and write
3870000
trusted library allocation
page read and write
3527000
trusted library allocation
page read and write
3A0C000
trusted library allocation
page read and write
376C000
trusted library allocation
page read and write
35FA000
trusted library allocation
page read and write
3761000
trusted library allocation
page read and write
3A08000
trusted library allocation
page read and write
36B5000
trusted library allocation
page read and write
677E000
stack
page read and write
1A0E000
stack
page read and write
3857000
trusted library allocation
page read and write
3811000
trusted library allocation
page read and write
357A000
trusted library allocation
page read and write
64C0000
trusted library allocation
page execute and read and write
3A2F000
trusted library allocation
page read and write
1430000
heap
page read and write
391E000
trusted library allocation
page read and write
832000
remote allocation
page execute and read and write
583E000
trusted library allocation
page read and write
452D000
trusted library allocation
page read and write
39C2000
trusted library allocation
page read and write
39D9000
trusted library allocation
page read and write
355D000
trusted library allocation
page read and write
3662000
trusted library allocation
page read and write
3950000
trusted library allocation
page read and write
3829000
trusted library allocation
page read and write
375F000
trusted library allocation
page read and write
38FF000
trusted library allocation
page read and write
3813000
trusted library allocation
page read and write
3660000
trusted library allocation
page read and write
3842000
trusted library allocation
page read and write
3901000
trusted library allocation
page read and write
34B4000
trusted library allocation
page read and write
38D5000
trusted library allocation
page read and write
3767000
trusted library allocation
page read and write
384F000
trusted library allocation
page read and write
39CA000
trusted library allocation
page read and write
3536000
trusted library allocation
page read and write
35F8000
trusted library allocation
page read and write
3834000
trusted library allocation
page read and write
19A7000
trusted library allocation
page execute and read and write
347C000
trusted library allocation
page read and write
363E000
trusted library allocation
page read and write
359B000
trusted library allocation
page read and write
3780000
trusted library allocation
page read and write
36A6000
trusted library allocation
page read and write
3340000
heap
page read and write
385F000
trusted library allocation
page read and write
37BB000
trusted library allocation
page read and write
3791000
trusted library allocation
page read and write
36AA000
trusted library allocation
page read and write
583B000
trusted library allocation
page read and write
3957000
trusted library allocation
page read and write
5862000
trusted library allocation
page read and write
37AC000
trusted library allocation
page read and write
63D2000
heap
page read and write
3664000
trusted library allocation
page read and write
37B0000
trusted library allocation
page read and write
39BE000
trusted library allocation
page read and write
3959000
trusted library allocation
page read and write
6600000
trusted library allocation
page read and write
3220000
trusted library allocation
page read and write
39C0000
trusted library allocation
page read and write
35A3000
trusted library allocation
page read and write
356E000
trusted library allocation
page read and write
3557000
trusted library allocation
page read and write
3683000
trusted library allocation
page read and write
36EF000
trusted library allocation
page read and write
3821000
trusted library allocation
page read and write
37CE000
trusted library allocation
page read and write
381B000
trusted library allocation
page read and write
65E0000
trusted library allocation
page execute and read and write
1980000
trusted library allocation
page read and write
36E0000
trusted library allocation
page read and write
65C0000
trusted library allocation
page execute and read and write
38C5000
trusted library allocation
page read and write
3817000
trusted library allocation
page read and write
358F000
trusted library allocation
page read and write
3621000
trusted library allocation
page read and write
6950000
trusted library allocation
page execute and read and write
39A9000
trusted library allocation
page read and write
37D8000
trusted library allocation
page read and write
35D9000
trusted library allocation
page read and write
3848000
trusted library allocation
page read and write
39E1000
trusted library allocation
page read and write
5895000
trusted library allocation
page read and write
3651000
trusted library allocation
page read and write
37B4000
trusted library allocation
page read and write
35DD000
trusted library allocation
page read and write
38E6000
trusted library allocation
page read and write
3992000
trusted library allocation
page read and write
3572000
trusted library allocation
page read and write
3642000
trusted library allocation
page read and write
3685000
trusted library allocation
page read and write
391A000
trusted library allocation
page read and write
35A5000
trusted library allocation
page read and write
36F7000
trusted library allocation
page read and write
398E000
trusted library allocation
page read and write
3638000
trusted library allocation
page read and write
380D000
trusted library allocation
page read and write
357E000
trusted library allocation
page read and write
198D000
trusted library allocation
page execute and read and write
39AD000
trusted library allocation
page read and write
3659000
trusted library allocation
page read and write
39C6000
trusted library allocation
page read and write
375B000
trusted library allocation
page read and write
39AF000
trusted library allocation
page read and write
387A000
trusted library allocation
page read and write
38A8000
trusted library allocation
page read and write
3797000
trusted library allocation
page read and write
37E9000
trusted library allocation
page read and write
3525000
trusted library allocation
page read and write
333E000
stack
page read and write
3578000
trusted library allocation
page read and write
38DC000
trusted library allocation
page read and write
397C000
trusted library allocation
page read and write
3668000
trusted library allocation
page read and write
39DD000
trusted library allocation
page read and write
390D000
trusted library allocation
page read and write
35AF000
trusted library allocation
page read and write
3799000
trusted library allocation
page read and write
3593000
trusted library allocation
page read and write
3757000
trusted library allocation
page read and write
36C5000
trusted library allocation
page read and write
385B000
trusted library allocation
page read and write
58A0000
trusted library allocation
page read and write
1425000
heap
page read and write
1550000
heap
page read and write
1573000
trusted library allocation
page execute and read and write
39DF000
trusted library allocation
page read and write
35BA000
trusted library allocation
page read and write
355F000
trusted library allocation
page read and write
49C000
stack
page read and write
15B6000
heap
page read and write
15A8000
heap
page read and write
35F6000
trusted library allocation
page read and write
36C3000
trusted library allocation
page read and write
3698000
trusted library allocation
page read and write
34A6000
trusted library allocation
page read and write
3922000
trusted library allocation
page read and write
3905000
trusted library allocation
page read and write
39D3000
trusted library allocation
page read and write
1580000
heap
page read and write
385D000
trusted library allocation
page read and write
39AB000
trusted library allocation
page read and write
35B4000
trusted library allocation
page read and write
3935000
trusted library allocation
page read and write
5CD0000
trusted library section
page read and write
35EC000
trusted library allocation
page read and write
3994000
trusted library allocation
page read and write
3A0A000
trusted library allocation
page read and write
5890000
trusted library allocation
page read and write
3876000
trusted library allocation
page read and write
166A000
heap
page read and write
37F5000
trusted library allocation
page read and write
352F000
trusted library allocation
page read and write
358D000
trusted library allocation
page read and write
5B1E000
stack
page read and write
36C7000
trusted library allocation
page read and write
3529000
trusted library allocation
page read and write
37B9000
trusted library allocation
page read and write
35E4000
trusted library allocation
page read and write
3853000
trusted library allocation
page read and write
54EE000
stack
page read and write
5E0000
remote allocation
page read and write
1992000
trusted library allocation
page read and write
19A0000
trusted library allocation
page read and write
3840000
trusted library allocation
page read and write
37EB000
trusted library allocation
page read and write
5358000
trusted library allocation
page read and write
6550000
trusted library allocation
page read and write
3691000
trusted library allocation
page read and write
F22000
unkown
page readonly
1560000
trusted library allocation
page read and write
58B0000
trusted library allocation
page read and write
38F0000
trusted library allocation
page read and write
37E1000
trusted library allocation
page read and write
1570000
trusted library allocation
page read and write
3782000
trusted library allocation
page read and write
36A4000
trusted library allocation
page read and write
3770000
trusted library allocation
page read and write
351B000
trusted library allocation
page read and write
65F0000
trusted library allocation
page execute and read and write
39DB000
trusted library allocation
page read and write
5880000
trusted library allocation
page read and write
3954000
trusted library allocation
page read and write
38EE000
trusted library allocation
page read and write
39C4000
trusted library allocation
page read and write
3210000
trusted library allocation
page read and write
19C0000
trusted library allocation
page read and write
3795000
trusted library allocation
page read and write
3A10000
trusted library allocation
page read and write
3649000
trusted library allocation
page read and write
3695000
trusted library allocation
page read and write
38D9000
trusted library allocation
page read and write
3827000
trusted library allocation
page read and write
38AC000
trusted library allocation
page read and write
354A000
trusted library allocation
page read and write
3534000
trusted library allocation
page read and write
38F9000
trusted library allocation
page read and write
5870000
trusted library allocation
page read and write
5851000
trusted library allocation
page read and write
67E0000
heap
page read and write
5834000
trusted library allocation
page read and write
667E000
stack
page read and write
3607000
trusted library allocation
page read and write
19AB000
trusted library allocation
page execute and read and write
3617000
trusted library allocation
page read and write
3793000
trusted library allocation
page read and write
38BA000
trusted library allocation
page read and write
177F000
stack
page read and write
5856000
trusted library allocation
page read and write
3A12000
trusted library allocation
page read and write
35F0000
trusted library allocation
page read and write
5B53000
heap
page read and write
67D0000
trusted library allocation
page read and write
35BE000
trusted library allocation
page read and write
3893000
trusted library allocation
page read and write
39A3000
trusted library allocation
page read and write
387C000
trusted library allocation
page read and write
35C8000
trusted library allocation
page read and write
3591000
trusted library allocation
page read and write
58F0000
heap
page execute and read and write
584E000
trusted library allocation
page read and write
369C000
trusted library allocation
page read and write
383E000
trusted library allocation
page read and write
395B000
trusted library allocation
page read and write
3581000
trusted library allocation
page read and write
3A23000
trusted library allocation
page read and write
352B000
trusted library allocation
page read and write
187E000
stack
page read and write
3A2D000
trusted library allocation
page read and write
38B2000
trusted library allocation
page read and write
3897000
trusted library allocation
page read and write
5842000
trusted library allocation
page read and write
3891000
trusted library allocation
page read and write
3836000
trusted library allocation
page read and write
36FD000
trusted library allocation
page read and write
356A000
trusted library allocation
page read and write
36B2000
trusted library allocation
page read and write
3823000
trusted library allocation
page read and write
39BA000
trusted library allocation
page read and write
35E2000
trusted library allocation
page read and write
37E5000
trusted library allocation
page read and write
384D000
trusted library allocation
page read and write
352D000
trusted library allocation
page read and write
3907000
trusted library allocation
page read and write
19A2000
trusted library allocation
page read and write
3A25000
trusted library allocation
page read and write
3769000
trusted library allocation
page read and write
3887000
trusted library allocation
page read and write
6398000
heap
page read and write
3997000
trusted library allocation
page read and write
3544000
trusted library allocation
page read and write
3666000
trusted library allocation
page read and write
36DE000
trusted library allocation
page read and write
36A0000
trusted library allocation
page read and write
5830000
trusted library allocation
page read and write
361F000
trusted library allocation
page read and write
38CF000
trusted library allocation
page read and write
3693000
trusted library allocation
page read and write
361B000
trusted library allocation
page read and write
363C000
trusted library allocation
page read and write
38A6000
trusted library allocation
page read and write
3640000
trusted library allocation
page read and write
36AC000
trusted library allocation
page read and write
3653000
trusted library allocation
page read and write
157D000
trusted library allocation
page execute and read and write
36CF000
trusted library allocation
page read and write
3819000
trusted library allocation
page read and write
158E000
heap
page read and write
37F7000
trusted library allocation
page read and write
3865000
trusted library allocation
page read and write
35F4000
trusted library allocation
page read and write
36F5000
trusted library allocation
page read and write
36CB000
trusted library allocation
page read and write
3861000
trusted library allocation
page read and write
37C8000
trusted library allocation
page read and write
36A8000
trusted library allocation
page read and write
5B20000
trusted library allocation
page read and write
3A0E000
trusted library allocation
page read and write
38D3000
trusted library allocation
page read and write
390B000
trusted library allocation
page read and write
361D000
trusted library allocation
page read and write
6390000
heap
page read and write
35B8000
trusted library allocation
page read and write
366C000
trusted library allocation
page read and write
398C000
trusted library allocation
page read and write
35CA000
trusted library allocation
page read and write
5B30000
heap
page read and write
3844000
trusted library allocation
page read and write
12F7000
stack
page read and write
3975000
trusted library allocation
page read and write
31FD000
stack
page read and write
5900000
heap
page read and write
39A5000
trusted library allocation
page read and write
65D0000
trusted library allocation
page read and write
3200000
trusted library allocation
page execute and read and write
395D000
trusted library allocation
page read and write
199A000
trusted library allocation
page execute and read and write
39C8000
trusted library allocation
page read and write
38FD000
trusted library allocation
page read and write
5910000
trusted library allocation
page execute and read and write
379B000
trusted library allocation
page read and write
377C000
trusted library allocation
page read and write
F36000
unkown
page readonly
3909000
trusted library allocation
page read and write
37AA000
trusted library allocation
page read and write
38BC000
trusted library allocation
page read and write
3619000
trusted library allocation
page read and write
3825000
trusted library allocation
page read and write
393C000
trusted library allocation
page read and write
375D000
trusted library allocation
page read and write
3A31000
trusted library allocation
page read and write
35E6000
trusted library allocation
page read and write
39A7000
trusted library allocation
page read and write
3542000
trusted library allocation
page read and write
36C1000
trusted library allocation
page read and write
35F2000
trusted library allocation
page read and write
39D7000
trusted library allocation
page read and write
37BD000
trusted library allocation
page read and write
353E000
trusted library allocation
page read and write
3561000
trusted library allocation
page read and write
E00000
unkown
page readonly
3859000
trusted library allocation
page read and write
3863000
trusted library allocation
page read and write
3903000
trusted library allocation
page read and write
38B4000
trusted library allocation
page read and write
36E5000
trusted library allocation
page read and write
37D4000
trusted library allocation
page read and write
3670000
trusted library allocation
page read and write
There are 486 hidden memdumps, click here to show them.