IOC Report
MyTrustID.EXE

loading gif

Files

File Path
Type
Category
Malicious
MyTrustID.EXE
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\Public\Desktop\MyTrustIDv1.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Tue Jan 10 07:12:02 2023, mtime=Thu Oct 24 23:44:59 2024, atime=Tue Jan 10 07:12:02 2023, length=2592256, window=hide
dropped
malicious
C:\Users\user\AppData\Local\Temp\IXP000.TMP\CreateShortcut.vbs
ASCII text, with CRLF line terminators
modified
malicious
58626a.rbf (copy)
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
58626b.rbf (copy)
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
58626c.rbf (copy)
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
58626d.rbf (copy)
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
58626e.rbf (copy)
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
58626f.rbf (copy)
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Config.Msi\586269.rbs
data
modified
C:\Program Files (x86)\Trustgate\MyTrustID\32bit\eToken.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\BouncyCastle.Crypto.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\userburn.Micro.Platform.Core.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\userburn.Micro.Platform.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\userburn.Micro.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\CreateCSRdll.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\Hardcodet.Wpf.TaskbarNotification.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\ICSharpCode.SharpZipLib.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\IDPrimeTokenEngine.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\InstallCertdll.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\LicInfo.xml
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\MimeTypes.config
XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exe.config
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\Newtonsoft.Json.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\Pkcs11Interop.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Collections.Concurrent.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Collections.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.ComponentModel.Annotations.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.ComponentModel.EventBasedAsync.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.ComponentModel.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Diagnostics.Contracts.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Diagnostics.Debug.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Diagnostics.Tools.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Diagnostics.Tracing.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Dynamic.Runtime.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Globalization.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.IO.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Linq.Expressions.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Linq.Parallel.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Linq.Queryable.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Linq.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Net.Http.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Net.NetworkInformation.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Net.Primitives.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Net.Requests.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Net.WebHeaderCollection.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.ObjectModel.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Reflection.Emit.ILGeneration.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Reflection.Emit.Lightweight.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Reflection.Emit.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Reflection.Extensions.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Reflection.Primitives.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Reflection.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Resources.ResourceManager.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.Extensions.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.Handles.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.InteropServices.WindowsRuntime.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.InteropServices.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.Numerics.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.Serialization.Json.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.Serialization.Primitives.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.Serialization.Xml.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Security.Cryptography.Algorithms.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Security.Cryptography.Encoding.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Security.Cryptography.Primitives.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Security.Cryptography.X509Certificates.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Security.Principal.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.ServiceModel.Duplex.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.ServiceModel.Http.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.ServiceModel.NetTcp.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.ServiceModel.Primitives.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.ServiceModel.Security.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Text.Encoding.Extensions.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Text.Encoding.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Text.RegularExpressions.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Threading.Tasks.Parallel.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Threading.Tasks.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Threading.Timer.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Threading.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Windows.Interactivity.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Xml.ReaderWriter.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Xml.XDocument.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\System.Xml.XmlSerializer.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\Uninstall.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\WebSockets.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\client.html
HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\itextsharp.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\jquery-1.11.1.js
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\log4net.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\st3ace.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\st3ace_s.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\st3csp11.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\tg_shield.ico
MS Windows icon resource - 1 icon, -40x256, 32 bits/pixel
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\tg_shield_copy.ico
MS Windows icon resource - 1 icon, -40x256, 32 bits/pixel
dropped
C:\Program Files (x86)\Trustgate\MyTrustID\wss.txt
ASCII text, with very long lines (9772), with no line terminators
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyTrustID Apps\MyTrustIDv1.lnk
MS Windows shortcut, Item id list present, Has Relative path, Has Working directory, Icon number=0, ctime=Sun Dec 31 23:06:32 1600, mtime=Sun Dec 31 23:06:32 1600, atime=Sun Dec 31 23:06:32 1600, length=0, window=hide
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\MyTrustIDv1.lnk
MS Windows shortcut, Item id list present, Has Relative path, Has Working directory, Icon number=0, ctime=Sun Dec 31 23:06:32 1600, mtime=Sun Dec 31 23:06:32 1600, atime=Sun Dec 31 23:06:32 1600, length=0, window=hide
dropped
C:\Trustgate\MyTrustID\drivers\Trustgate.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
dropped
C:\Trustgate\MyTrustID\drivers\Trustgate.sig
data
dropped
C:\Trustgate\MyTrustID\drivers\Trustgate_s.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Trustgate\MyTrustID\logs\24.10.2024.log
CSV text
modified
C:\Users\user\AppData\Local\Temp\CFG64B9.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\IXP000.TMP\mytrustid.bat
DOS batch file, ASCII text, with CRLF line terminators
dropped
C:\Windows\Installer\586270.msi
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Create Time/Date: Mon Jun 21 08:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;1033, Number of Pages: 200, Revision Number: {515A415D-AD11-4005-A4FD-AD810EC31437}, Title: MyTrustID, Subject: Version 1.1, Author: MSC Trustgate.com Sdn Bhd, Comments: This application is develop by MSC Trustgate.com Sdn Bhd, Number of Words: 2, Last Saved Time/Date: Mon Jan 9 20:13:53 2023, Last Printed: Mon Jan 9 20:13:53 2023
dropped
C:\Windows\Installer\MSI64C9.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Windows\Installer\MSI6557.tmp
data
dropped
C:\Windows\Installer\SourceHash{A97F7040-544D-4857-B3ED-8ED1ED9AE368}
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Installer\{A97F7040-544D-4857-B3ED-8ED1ED9AE368}\_58D1171B4CA0552DFB6D1D.exe
MS Windows icon resource - 1 icon, -40x256, 32 bits/pixel
dropped
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Windows\Temp\~DF118E5FCD0A324909.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF14F1FE8D2044DA52.TMP
data
dropped
C:\Windows\Temp\~DF30417841F2FD983B.TMP
data
dropped
C:\Windows\Temp\~DF4B641695827FA498.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFA0F9AAAFCC690B16.TMP
data
dropped
\Device\Null
ASCII text, with CRLF line terminators
dropped
There are 107 hidden files, click here to show them.

Domains

Name
IP
Malicious
digitalid.msctrustgate.com
103.140.139.135
mtid.msctrustgate.com
127.0.0.1

IPs

IP
Domain
Country
Malicious
103.140.139.135
digitalid.msctrustgate.com
Malaysia
127.0.0.1
mtid.msctrustgate.com
unknown