IOC Report
dw7h7aQwVZ.exe

loading gif

Files

File Path
Type
Category
Malicious
dw7h7aQwVZ.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Roaming\188E93\31437F.lck
very short file (no magic)
dropped

URLs

Name
IP
Malicious
http://94.156.177.220/simple/five/fre.php
94.156.177.220
malicious

IPs

IP
Domain
Country
Malicious
94.156.177.220
unknown
Bulgaria
malicious