Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
sample-20240612-unpacked.exe
|
PE32 executable (console) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Users\user\Pictures\pressica.exe
|
PE32 executable (console) Intel 80386, for MS Windows
|
dropped
|
||
C:\Users\user\Pictures\pressica.exe:Zone.Identifier
|
ASCII text, with CRLF line terminators
|
modified
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\sample-20240612-unpacked.exe
|
"C:\Users\user\Desktop\sample-20240612-unpacked.exe"
|
||
C:\Windows\SysWOW64\mspaint.exe
|
mspaint.exe
|
||
C:\Users\user\Pictures\pressica.exe
|
"C:\Users\user\Pictures\pressica.exe"
|
||
C:\Windows\SysWOW64\mspaint.exe
|
mspaint.exe
|
||
C:\Users\user\Pictures\pressica.exe
|
"C:\Users\user\Pictures\pressica.exe"
|
||
C:\Windows\SysWOW64\mspaint.exe
|
mspaint.exe
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
||
C:\Windows\SysWOW64\xcopy.exe
|
"C:\Windows\System32\xcopy.exe" /f /y "C:\Users\user\Desktop\sample-20240612-unpacked.exe" "C:\Users\user\Pictures\pressica.exe*"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
There are 1 hidden processes, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
S(]H7p#}ho:P4p__.str4ng3l.ov
|
unknown
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
|
VirtualBox Guest Additions Manager
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
2EF0000
|
remote allocation
|
page execute and read and write
|
||
461000
|
heap
|
page read and write
|
||
2B00000
|
remote allocation
|
page execute and read and write
|
||
591000
|
heap
|
page read and write
|
||
3290000
|
remote allocation
|
page execute and read and write
|
||
6F1000
|
heap
|
page read and write
|
||
40B000
|
unkown
|
page readonly
|
||
19D000
|
stack
|
page read and write
|
||
2090000
|
heap
|
page read and write
|
||
20C4000
|
heap
|
page read and write
|
||
47FC000
|
stack
|
page read and write
|
||
40B000
|
unkown
|
page readonly
|
||
404000
|
unkown
|
page readonly
|
||
447000
|
heap
|
page read and write
|
||
41FF000
|
stack
|
page read and write
|
||
2080000
|
heap
|
page read and write
|
||
8CF000
|
stack
|
page read and write
|
||
3D30000
|
trusted library allocation
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
589000
|
heap
|
page read and write
|
||
1F5000
|
heap
|
page read and write
|
||
596000
|
heap
|
page read and write
|
||
283D000
|
heap
|
page read and write
|
||
1D0000
|
heap
|
page read and write
|
||
510000
|
heap
|
page read and write
|
||
410000
|
heap
|
page read and write
|
||
3900000
|
trusted library allocation
|
page read and write
|
||
595000
|
heap
|
page read and write
|
||
18E000
|
stack
|
page read and write
|
||
1C0000
|
heap
|
page read and write
|
||
4D5000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
19C000
|
stack
|
page read and write
|
||
40A000
|
unkown
|
page read and write
|
||
20A5000
|
heap
|
page read and write
|
||
40A000
|
unkown
|
page read and write
|
||
252E000
|
stack
|
page read and write
|
||
58E000
|
heap
|
page read and write
|
||
2070000
|
heap
|
page read and write
|
||
18E000
|
stack
|
page read and write
|
||
55E000
|
stack
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
404000
|
unkown
|
page readonly
|
||
401000
|
unkown
|
page execute read
|
||
6EE000
|
heap
|
page read and write
|
||
5A0000
|
heap
|
page read and write
|
||
76F000
|
stack
|
page read and write
|
||
465000
|
heap
|
page read and write
|
||
404000
|
unkown
|
page readonly
|
||
4D0000
|
heap
|
page read and write
|
||
18E000
|
stack
|
page read and write
|
||
1F0000
|
heap
|
page read and write
|
||
440000
|
heap
|
page read and write
|
||
4A0000
|
heap
|
page read and write
|
||
40B000
|
unkown
|
page readonly
|
||
6D0000
|
heap
|
page read and write
|
||
20A0000
|
heap
|
page read and write
|
||
5EF000
|
stack
|
page read and write
|
||
467F000
|
stack
|
page read and write
|
||
4F0000
|
heap
|
page read and write
|
||
24CE000
|
stack
|
page read and write
|
||
8AE000
|
stack
|
page read and write
|
||
40B000
|
unkown
|
page readonly
|
||
214E000
|
stack
|
page read and write
|
||
3D30000
|
trusted library allocation
|
page read and write
|
||
49E000
|
stack
|
page read and write
|
||
2109000
|
heap
|
page read and write
|
||
6AF000
|
stack
|
page read and write
|
||
74E000
|
stack
|
page read and write
|
||
99000
|
stack
|
page read and write
|
||
6F1000
|
heap
|
page read and write
|
||
45E000
|
heap
|
page read and write
|
||
88F000
|
stack
|
page read and write
|
||
2828000
|
heap
|
page read and write
|
||
515000
|
heap
|
page read and write
|
||
40A000
|
unkown
|
page read and write
|
||
19D000
|
stack
|
page read and write
|
||
6E9000
|
heap
|
page read and write
|
||
462000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
578000
|
heap
|
page read and write
|
||
24D0000
|
heap
|
page read and write
|
||
18C000
|
stack
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
45E000
|
stack
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
54D000
|
stack
|
page read and write
|
||
18C000
|
stack
|
page read and write
|
||
570000
|
heap
|
page read and write
|
||
18C000
|
stack
|
page read and write
|
||
2470000
|
heap
|
page read and write
|
||
224F000
|
stack
|
page read and write
|
||
640000
|
heap
|
page read and write
|
||
11D000
|
stack
|
page read and write
|
||
47BF000
|
stack
|
page read and write
|
||
3960000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
282B000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
48FD000
|
stack
|
page read and write
|
||
461000
|
heap
|
page read and write
|
||
404000
|
unkown
|
page readonly
|
||
404000
|
unkown
|
page readonly
|
||
47E000
|
heap
|
page read and write
|
||
6D8000
|
heap
|
page read and write
|
||
2205000
|
heap
|
page read and write
|
||
47E000
|
heap
|
page read and write
|
||
40B000
|
unkown
|
page readonly
|
||
430000
|
heap
|
page read and write
|
||
42FF000
|
stack
|
page read and write
|
||
2105000
|
heap
|
page read and write
|
||
21FE000
|
stack
|
page read and write
|
||
404000
|
unkown
|
page readonly
|
||
3964000
|
heap
|
page read and write
|
||
230F000
|
stack
|
page read and write
|
||
9A000
|
stack
|
page read and write
|
||
6C4000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
400000
|
unkown
|
page readonly
|
||
40B000
|
unkown
|
page readonly
|
||
9A000
|
stack
|
page read and write
|
||
2080000
|
heap
|
page read and write
|
||
20A9000
|
heap
|
page read and write
|
||
24EE000
|
stack
|
page read and write
|
||
459000
|
heap
|
page read and write
|
||
2209000
|
heap
|
page read and write
|
||
6F5000
|
heap
|
page read and write
|
||
78E000
|
stack
|
page read and write
|
||
410000
|
heap
|
page read and write
|
||
2090000
|
heap
|
page read and write
|
||
420000
|
heap
|
page read and write
|
||
7AE000
|
stack
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
5B8000
|
heap
|
page read and write
|
||
2100000
|
heap
|
page read and write
|
||
6F6000
|
heap
|
page read and write
|
||
70E000
|
heap
|
page read and write
|
||
64E000
|
stack
|
page read and write
|
||
15A000
|
stack
|
page read and write
|
||
58E000
|
stack
|
page read and write
|
||
591000
|
heap
|
page read and write
|
||
2080000
|
heap
|
page read and write
|
||
46BE000
|
stack
|
page read and write
|
||
457E000
|
stack
|
page read and write
|
||
466000
|
heap
|
page read and write
|
||
6C0000
|
heap
|
page read and write
|
||
20C0000
|
heap
|
page read and write
|
||
50D000
|
stack
|
page read and write
|
||
2820000
|
heap
|
page read and write
|
||
2200000
|
heap
|
page read and write
|
||
23CE000
|
stack
|
page read and write
|
||
2090000
|
heap
|
page read and write
|
There are 142 hidden memdumps, click here to show them.