IOC Report
wd33g7Jan8.exe

loading gif

Files

File Path
Type
Category
Malicious
wd33g7Jan8.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\ProgramData\WindowsServices.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v2.0_32\UsageLogs\wd33g7Jan8.exe.log
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\3a242e02f9e01cc69f94bf51247fa2cb.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v2.0_32\UsageLogs\WindowsServices.exe.log
ASCII text, with CRLF line terminators
dropped
\Device\ConDrv
ASCII text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\wd33g7Jan8.exe
"C:\Users\user\Desktop\wd33g7Jan8.exe"
malicious
C:\ProgramData\WindowsServices.exe
"C:\ProgramData\WindowsServices.exe"
malicious
C:\Windows\SysWOW64\netsh.exe
netsh firewall add allowedprogram "C:\ProgramData\WindowsServices.exe" "WindowsServices.exe" ENABLE
malicious
C:\ProgramData\WindowsServices.exe
"C:\ProgramData\WindowsServices.exe" ..
malicious
C:\ProgramData\WindowsServices.exe
"C:\ProgramData\WindowsServices.exe" ..
malicious
C:\ProgramData\WindowsServices.exe
"C:\ProgramData\WindowsServices.exe" ..
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

IPs

IP
Domain
Country
Malicious
45.152.161.204
unknown
Germany
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER
di
malicious
HKEY_CURRENT_USER\Environment
SEE_MASK_NOZONECHECKS
malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
3a242e02f9e01cc69f94bf51247fa2cb
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
3a242e02f9e01cc69f94bf51247fa2cb
HKEY_CURRENT_USER\SOFTWARE\3a242e02f9e01cc69f94bf51247fa2cb
[kl]

Memdumps

Base Address
Regiontype
Protect
Malicious
842000
unkown
page readonly
malicious
2E31000
trusted library allocation
page read and write
malicious
30B1000
trusted library allocation
page read and write
malicious
127E000
stack
page read and write
5240000
trusted library allocation
page read and write
5A3B000
heap
page read and write
1680000
trusted library allocation
page read and write
1049000
heap
page read and write
1312000
trusted library allocation
page read and write
14BE000
heap
page read and write
1010000
trusted library allocation
page read and write
528E000
stack
page read and write
14D0000
heap
page read and write
14DA000
heap
page read and write
5A34000
heap
page read and write
14DD000
heap
page read and write
1524000
heap
page read and write
5320000
heap
page read and write
1139000
stack
page read and write
47F0000
trusted library allocation
page execute and read and write
E2E000
heap
page read and write
12F0000
trusted library allocation
page read and write
5A35000
heap
page read and write
584E000
stack
page read and write
53EC000
stack
page read and write
147B000
heap
page read and write
149A000
heap
page read and write
1160000
trusted library allocation
page read and write
1486000
heap
page read and write
149A000
heap
page read and write
43C4000
trusted library allocation
page read and write
1451000
heap
page read and write
152A000
heap
page read and write
14D7000
heap
page read and write
1458000
heap
page read and write
BF0000
heap
page read and write
5560000
trusted library allocation
page read and write
1489000
heap
page read and write
524E000
stack
page read and write
159E000
stack
page read and write
2B67000
trusted library allocation
page execute and read and write
1520000
heap
page read and write
147F000
heap
page read and write
8DB000
stack
page read and write
14C9000
heap
page read and write
18B0000
heap
page execute and read and write
14D0000
heap
page read and write
536C000
stack
page read and write
14BF000
heap
page read and write
149A000
heap
page read and write
524E000
stack
page read and write
48F0000
heap
page read and write
AD0000
heap
page read and write
6D9000
heap
page read and write
5A35000
heap
page read and write
1482000
heap
page read and write
14DE000
heap
page read and write
1197000
trusted library allocation
page execute and read and write
9D6000
stack
page read and write
14CD000
heap
page read and write
1486000
heap
page read and write
B6A000
stack
page read and write
5B0B000
stack
page read and write
2CAE000
stack
page read and write
4800000
trusted library allocation
page read and write
622000
trusted library allocation
page execute and read and write
14C3000
heap
page read and write
620000
trusted library allocation
page read and write
14D5000
heap
page read and write
1340000
heap
page execute and read and write
14CB000
heap
page read and write
14DE000
heap
page read and write
14D4000
heap
page read and write
1467000
heap
page read and write
D70000
heap
page read and write
B70000
heap
page read and write
1760000
heap
page read and write
385D000
stack
page read and write
12DA000
trusted library allocation
page execute and read and write
EF6000
stack
page read and write
6A4000
heap
page read and write
1672000
trusted library allocation
page execute and read and write
E8C000
heap
page read and write
1520000
heap
page read and write
3E34000
trusted library allocation
page read and write
600000
trusted library allocation
page read and write
147A000
heap
page read and write
14BE000
heap
page read and write
1507000
heap
page read and write
1660000
trusted library allocation
page read and write
EFB000
stack
page read and write
86F000
stack
page read and write
DBD000
stack
page read and write
1170000
heap
page read and write
15C0000
heap
page read and write
560E000
stack
page read and write
14DD000
heap
page read and write
5020000
trusted library allocation
page read and write
564E000
stack
page read and write
152C000
heap
page read and write
FA0000
heap
page read and write
147B000
heap
page read and write
E20000
heap
page read and write
14BD000
heap
page read and write
1180000
heap
page read and write
B80000
heap
page read and write
12C0000
trusted library allocation
page read and write
12B0000
heap
page read and write
8AE000
stack
page read and write
14CB000
heap
page read and write
168C000
trusted library allocation
page execute and read and write
1030000
trusted library allocation
page read and write
1441000
heap
page read and write
FF3000
stack
page read and write
14DE000
heap
page read and write
5930000
heap
page read and write
12A2000
trusted library allocation
page execute and read and write
15B0000
trusted library allocation
page read and write
103C000
trusted library allocation
page execute and read and write
642000
trusted library allocation
page execute and read and write
1507000
heap
page read and write
1424000
heap
page read and write
59FE000
stack
page read and write
13EF000
stack
page read and write
52C0000
heap
page read and write
13BE000
unkown
page read and write
14D2000
heap
page read and write
14A4000
heap
page read and write
1190000
heap
page read and write
1240000
heap
page execute and read and write
1375000
heap
page read and write
14D5000
heap
page read and write
62C000
trusted library allocation
page execute and read and write
2BAE000
stack
page read and write
1079000
heap
page read and write
14BF000
heap
page read and write
1166000
trusted library allocation
page execute and read and write
36C4000
trusted library allocation
page read and write
14CB000
heap
page read and write
152B000
heap
page read and write
1475000
heap
page read and write
152C000
heap
page read and write
12B0000
heap
page read and write
53D0000
heap
page read and write
5010000
trusted library allocation
page execute and read and write
1489000
heap
page read and write
14C8000
heap
page read and write
140F000
heap
page read and write
5890000
trusted library allocation
page execute and read and write
1270000
heap
page read and write
1486000
heap
page read and write
14BE000
heap
page read and write
61A000
trusted library allocation
page execute and read and write
4C7E000
stack
page read and write
1520000
heap
page read and write
14A4000
heap
page read and write
58FE000
stack
page read and write
14A4000
heap
page read and write
14D1000
heap
page read and write
536E000
stack
page read and write
36C1000
trusted library allocation
page read and write
5A46000
heap
page read and write
430000
heap
page read and write
152E000
stack
page read and write
5ED0000
trusted library allocation
page execute and read and write
4D5000
heap
page read and write
14C0000
heap
page read and write
1484000
heap
page read and write
1476000
heap
page read and write
5910000
heap
page read and write
570E000
stack
page read and write
14D0000
heap
page read and write
14DA000
heap
page read and write
1451000
heap
page read and write
FFE000
stack
page read and write
2B60000
trusted library allocation
page read and write
149D000
heap
page read and write
14D2000
heap
page read and write
1488000
heap
page read and write
5200000
heap
page read and write
1501000
heap
page read and write
1444000
heap
page read and write
12AE000
stack
page read and write
14DD000
heap
page read and write
1507000
heap
page read and write
14C8000
heap
page read and write
120E000
stack
page read and write
12E0000
trusted library allocation
page read and write
1451000
heap
page read and write
FDF000
heap
page read and write
5910000
heap
page read and write
1520000
heap
page read and write
105D000
heap
page read and write
14D1000
heap
page read and write
47E0000
trusted library allocation
page read and write
13F8000
heap
page read and write
1A50000
trusted library allocation
page execute and read and write
5A31000
heap
page read and write
103B000
stack
page read and write
14D9000
heap
page read and write
657000
trusted library allocation
page execute and read and write
100E000
stack
page read and write
1142000
trusted library allocation
page execute and read and write
12B0000
heap
page read and write
152C000
heap
page read and write
1486000
heap
page read and write
47C0000
heap
page read and write
BB5000
heap
page read and write
5AEF000
stack
page read and write
14BE000
heap
page read and write
C40000
heap
page read and write
15C6000
heap
page read and write
55CF000
stack
page read and write
11B0000
heap
page read and write
1036000
trusted library allocation
page execute and read and write
48AE000
stack
page read and write
51DF000
stack
page read and write
1136000
stack
page read and write
548E000
stack
page read and write
13BF000
stack
page read and write
12E2000
trusted library allocation
page execute and read and write
3880000
heap
page read and write
12E0000
heap
page read and write
12EA000
trusted library allocation
page execute and read and write
14D9000
heap
page read and write
EF6000
stack
page read and write
5A45000
heap
page read and write
147D000
heap
page read and write
14C8000
heap
page read and write
116C000
trusted library allocation
page execute and read and write
BE0000
heap
page read and write
555E000
stack
page read and write
1040000
heap
page read and write
14C3000
heap
page read and write
1630000
heap
page read and write
54A0000
unclassified section
page read and write
D30000
heap
page read and write
16B7000
trusted library allocation
page execute and read and write
670000
heap
page read and write
14CF000
heap
page read and write
568E000
stack
page read and write
101E000
stack
page read and write
5A31000
heap
page read and write
5A45000
heap
page read and write
367E000
unkown
page read and write
5A32000
heap
page read and write
4D0000
heap
page read and write
55DE000
stack
page read and write
149B000
heap
page read and write
16BB000
trusted library allocation
page execute and read and write
1484000
heap
page read and write
14DE000
heap
page read and write
54CE000
stack
page read and write
43C1000
trusted library allocation
page read and write
E28000
heap
page read and write
4004000
trusted library allocation
page read and write
1486000
heap
page read and write
1682000
trusted library allocation
page execute and read and write
14BE000
heap
page read and write
B0B000
stack
page read and write
16FE000
stack
page read and write
EAA000
heap
page read and write
4B3E000
stack
page read and write
1507000
heap
page read and write
47E4000
trusted library allocation
page read and write
116A000
trusted library allocation
page execute and read and write
59EE000
stack
page read and write
65B000
trusted library allocation
page execute and read and write
1022000
trusted library allocation
page execute and read and write
16B0000
trusted library allocation
page read and write
174E000
stack
page read and write
1032000
trusted library allocation
page execute and read and write
1350000
heap
page read and write
68D000
heap
page read and write
13F0000
heap
page read and write
14BD000
heap
page read and write
12D2000
trusted library allocation
page execute and read and write
1527000
heap
page read and write
14D6000
heap
page read and write
1A60000
heap
page read and write
49FF000
stack
page read and write
1520000
heap
page read and write
33C1000
trusted library allocation
page read and write
5940000
heap
page read and write
BB0000
heap
page read and write
1230000
trusted library allocation
page read and write
1317000
trusted library allocation
page execute and read and write
162F000
stack
page read and write
5A47000
heap
page read and write
626000
trusted library allocation
page execute and read and write
5310000
trusted library allocation
page execute and read and write
1529000
heap
page read and write
143B000
heap
page read and write
4C3E000
stack
page read and write
14E1000
heap
page read and write
119B000
trusted library allocation
page execute and read and write
14D5000
heap
page read and write
51E0000
heap
page read and write
14DE000
heap
page read and write
2AEE000
stack
page read and write
BE0000
heap
page read and write
2B6B000
trusted library allocation
page execute and read and write
108E000
heap
page read and write
3886000
heap
page read and write
5323000
heap
page read and write
1523000
heap
page read and write
14E2000
heap
page read and write
4CE000
stack
page read and write
1870000
heap
page read and write
16A2000
trusted library allocation
page execute and read and write
149C000
heap
page read and write
532E000
stack
page read and write
9DE000
stack
page read and write
1507000
heap
page read and write
1507000
heap
page read and write
14D0000
heap
page read and write
590F000
stack
page read and write
FAE000
heap
page read and write
26C1000
trusted library allocation
page read and write
BA5000
heap
page read and write
840000
unkown
page readonly
12F7000
trusted library allocation
page execute and read and write
149E000
stack
page read and write
574E000
stack
page read and write
1150000
heap
page read and write
12E5000
heap
page read and write
54DF000
stack
page read and write
40B1000
trusted library allocation
page read and write
1475000
heap
page read and write
5220000
trusted library allocation
page read and write
4001000
trusted library allocation
page read and write
1182000
trusted library allocation
page execute and read and write
500E000
stack
page read and write
1524000
heap
page read and write
1047000
heap
page read and write
560E000
stack
page read and write
FEE000
stack
page read and write
E49000
heap
page read and write
534E000
stack
page read and write
1484000
heap
page read and write
14D0000
heap
page read and write
3336000
trusted library allocation
page read and write
5A48000
heap
page read and write
CB000
stack
page read and write
167A000
trusted library allocation
page execute and read and write
1507000
heap
page read and write
5A32000
heap
page read and write
114A000
trusted library allocation
page execute and read and write
1C6000
stack
page read and write
102A000
trusted library allocation
page execute and read and write
D75000
heap
page read and write
14D4000
heap
page read and write
8D0000
heap
page read and write
480000
heap
page read and write
FFB000
stack
page read and write
1260000
heap
page read and write
1130000
trusted library allocation
page read and write
14CB000
heap
page read and write
FA8000
heap
page read and write
53AA000
stack
page read and write
5E0000
heap
page read and write
538E000
stack
page read and write
14BE000
heap
page read and write
11C0000
heap
page read and write
12FA000
trusted library allocation
page execute and read and write
5290000
trusted library allocation
page execute and read and write
237F000
stack
page read and write
149C000
heap
page read and write
4AFE000
stack
page read and write
4D7E000
stack
page read and write
1302000
trusted library allocation
page execute and read and write
3001000
trusted library allocation
page read and write
ABE000
stack
page read and write
1464000
heap
page read and write
588C000
stack
page read and write
EF9000
stack
page read and write
149A000
heap
page read and write
5A34000
heap
page read and write
14CB000
heap
page read and write
1521000
heap
page read and write
1350000
heap
page read and write
512E000
stack
page read and write
130A000
trusted library allocation
page execute and read and write
123F000
stack
page read and write
14BE000
heap
page read and write
7F6C0000
trusted library allocation
page execute and read and write
18A0000
trusted library allocation
page read and write
5490000
trusted library allocation
page read and write
1370000
heap
page read and write
5A10000
heap
page read and write
56DE000
stack
page read and write
BA0000
heap
page read and write
1520000
heap
page read and write
149C000
heap
page read and write
1686000
trusted library allocation
page execute and read and write
13FE000
stack
page read and write
1190000
trusted library allocation
page read and write
E5F000
heap
page read and write
F3E000
stack
page read and write
14C3000
heap
page read and write
D20000
heap
page read and write
186E000
stack
page read and write
145E000
stack
page read and write
149B000
heap
page read and write
660000
heap
page execute and read and write
48EE000
stack
page read and write
5429000
stack
page read and write
1430000
heap
page read and write
5230000
trusted library allocation
page execute and read and write
152E000
heap
page read and write
1520000
heap
page read and write
E00000
heap
page read and write
14D1000
heap
page read and write
149C000
heap
page read and write
377E000
stack
page read and write
52ED000
stack
page read and write
56F0000
heap
page read and write
598C000
stack
page read and write
57FE000
stack
page read and write
131B000
trusted library allocation
page execute and read and write
1487000
heap
page read and write
14BE000
heap
page read and write
1528000
heap
page read and write
1521000
heap
page read and write
5C0C000
stack
page read and write
14CC000
heap
page read and write
50B8000
trusted library allocation
page read and write
1340000
heap
page read and write
BF0000
heap
page read and write
1162000
trusted library allocation
page execute and read and write
3E31000
trusted library allocation
page read and write
14BD000
heap
page read and write
152B000
heap
page read and write
1C9000
stack
page read and write
1507000
heap
page read and write
18A4000
trusted library allocation
page read and write
14D2000
heap
page read and write
1540000
heap
page read and write
4F0E000
stack
page read and write
47BF000
stack
page read and write
111E000
stack
page read and write
1290000
heap
page execute and read and write
677000
heap
page read and write
14DC000
heap
page read and write
DFE000
stack
page read and write
52A0000
trusted library allocation
page read and write
1310000
trusted library allocation
page read and write
612000
trusted library allocation
page execute and read and write
518C000
stack
page read and write
50DE000
stack
page read and write
1520000
heap
page read and write
47E000
stack
page read and write
There are 442 hidden memdumps, click here to show them.