IOC Report
sample-20240612-unpacked.exe

loading gif

Files

File Path
Type
Category
Malicious
sample-20240612-unpacked.exe
PE32 executable (console) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\Pictures\pressica.exe
PE32 executable (console) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Pictures\pressica.exe:Zone.Identifier
ASCII text, with CRLF line terminators
modified
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\sample-20240612-unpacked.exe
"C:\Users\user\Desktop\sample-20240612-unpacked.exe"
malicious
C:\Windows\SysWOW64\mspaint.exe
mspaint.exe
malicious
C:\Users\user\Pictures\pressica.exe
"C:\Users\user\Pictures\pressica.exe"
malicious
C:\Windows\SysWOW64\mspaint.exe
mspaint.exe
malicious
C:\Users\user\Pictures\pressica.exe
"C:\Users\user\Pictures\pressica.exe"
malicious
C:\Windows\SysWOW64\mspaint.exe
mspaint.exe
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\xcopy.exe
"C:\Windows\System32\xcopy.exe" /f /y "C:\Users\user\Desktop\sample-20240612-unpacked.exe" "C:\Users\user\Pictures\pressica.exe*"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
There are 1 hidden processes, click here to show them.

Domains

Name
IP
Malicious
S(]H7p#}ho:P4p__.str4ng3l.ov
unknown
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
VirtualBox Guest Additions Manager

Memdumps

Base Address
Regiontype
Protect
Malicious
2EF0000
remote allocation
page execute and read and write
malicious
461000
heap
page read and write
malicious
2B00000
remote allocation
page execute and read and write
malicious
591000
heap
page read and write
malicious
3290000
remote allocation
page execute and read and write
malicious
6F1000
heap
page read and write
malicious
40B000
unkown
page readonly
19D000
stack
page read and write
2090000
heap
page read and write
20C4000
heap
page read and write
47FC000
stack
page read and write
40B000
unkown
page readonly
404000
unkown
page readonly
447000
heap
page read and write
41FF000
stack
page read and write
2080000
heap
page read and write
8CF000
stack
page read and write
3D30000
trusted library allocation
page read and write
401000
unkown
page execute read
589000
heap
page read and write
1F5000
heap
page read and write
596000
heap
page read and write
283D000
heap
page read and write
1D0000
heap
page read and write
510000
heap
page read and write
410000
heap
page read and write
3900000
trusted library allocation
page read and write
595000
heap
page read and write
18E000
stack
page read and write
1C0000
heap
page read and write
4D5000
heap
page read and write
400000
unkown
page readonly
19C000
stack
page read and write
40A000
unkown
page read and write
20A5000
heap
page read and write
40A000
unkown
page read and write
252E000
stack
page read and write
58E000
heap
page read and write
2070000
heap
page read and write
18E000
stack
page read and write
55E000
stack
page read and write
401000
unkown
page execute read
404000
unkown
page readonly
401000
unkown
page execute read
6EE000
heap
page read and write
5A0000
heap
page read and write
76F000
stack
page read and write
465000
heap
page read and write
404000
unkown
page readonly
4D0000
heap
page read and write
18E000
stack
page read and write
1F0000
heap
page read and write
440000
heap
page read and write
4A0000
heap
page read and write
40B000
unkown
page readonly
6D0000
heap
page read and write
20A0000
heap
page read and write
5EF000
stack
page read and write
467F000
stack
page read and write
4F0000
heap
page read and write
24CE000
stack
page read and write
8AE000
stack
page read and write
40B000
unkown
page readonly
214E000
stack
page read and write
3D30000
trusted library allocation
page read and write
49E000
stack
page read and write
2109000
heap
page read and write
6AF000
stack
page read and write
74E000
stack
page read and write
99000
stack
page read and write
6F1000
heap
page read and write
45E000
heap
page read and write
88F000
stack
page read and write
2828000
heap
page read and write
515000
heap
page read and write
40A000
unkown
page read and write
19D000
stack
page read and write
6E9000
heap
page read and write
462000
heap
page read and write
400000
unkown
page readonly
578000
heap
page read and write
24D0000
heap
page read and write
18C000
stack
page read and write
401000
unkown
page execute read
45E000
stack
page read and write
401000
unkown
page execute read
54D000
stack
page read and write
18C000
stack
page read and write
570000
heap
page read and write
18C000
stack
page read and write
2470000
heap
page read and write
224F000
stack
page read and write
640000
heap
page read and write
11D000
stack
page read and write
47BF000
stack
page read and write
3960000
heap
page read and write
400000
unkown
page readonly
282B000
heap
page read and write
401000
unkown
page execute read
48FD000
stack
page read and write
461000
heap
page read and write
404000
unkown
page readonly
404000
unkown
page readonly
47E000
heap
page read and write
6D8000
heap
page read and write
2205000
heap
page read and write
47E000
heap
page read and write
40B000
unkown
page readonly
430000
heap
page read and write
42FF000
stack
page read and write
2105000
heap
page read and write
21FE000
stack
page read and write
404000
unkown
page readonly
3964000
heap
page read and write
230F000
stack
page read and write
9A000
stack
page read and write
6C4000
heap
page read and write
400000
unkown
page readonly
400000
unkown
page readonly
40B000
unkown
page readonly
9A000
stack
page read and write
2080000
heap
page read and write
20A9000
heap
page read and write
24EE000
stack
page read and write
459000
heap
page read and write
2209000
heap
page read and write
6F5000
heap
page read and write
78E000
stack
page read and write
410000
heap
page read and write
2090000
heap
page read and write
420000
heap
page read and write
7AE000
stack
page read and write
400000
unkown
page readonly
5B8000
heap
page read and write
2100000
heap
page read and write
6F6000
heap
page read and write
70E000
heap
page read and write
64E000
stack
page read and write
15A000
stack
page read and write
58E000
stack
page read and write
591000
heap
page read and write
2080000
heap
page read and write
46BE000
stack
page read and write
457E000
stack
page read and write
466000
heap
page read and write
6C0000
heap
page read and write
20C0000
heap
page read and write
50D000
stack
page read and write
2820000
heap
page read and write
2200000
heap
page read and write
23CE000
stack
page read and write
2090000
heap
page read and write
There are 142 hidden memdumps, click here to show them.