IOC Report
HUo09bfA3g.exe

loading gif

Files

File Path
Type
Category
Malicious
HUo09bfA3g.exe
initial sample
malicious
C:\Users\user\AppData\Roaming\omsecor.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Windows\SysWOW64\omsecor.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Windows\SysWOW64\merocz.xc6
data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\HUo09bfA3g.exe
"C:\Users\user\Desktop\HUo09bfA3g.exe"
malicious
C:\Users\user\AppData\Roaming\omsecor.exe
C:\Users\user\AppData\Roaming\omsecor.exe
malicious
C:\Windows\SysWOW64\omsecor.exe
C:\Windows\System32\omsecor.exe
malicious
C:\Windows\SysWOW64\omsecor.exe
C:\Windows\SysWOW64\omsecor.exe /nomove
malicious

URLs

Name
IP
Malicious
http://mkkuei4kdsz.com/17/791.html
15.197.204.56
malicious
http://mkkuei4kdsz.com/
malicious
http://lousta.net/680/970.html
193.166.255.171
malicious
http://lousta.net/339/417.html
193.166.255.171
malicious
http://lousta.net/68/533.html
193.166.255.171
malicious
http://lousta.net/763/48.html
193.166.255.171
malicious
http://lousta.net/140/265.html
193.166.255.171
malicious
http://lousta.net/989/145.html
193.166.255.171
malicious
http://lousta.net/802/499.html
193.166.255.171
malicious
ht:/r.irsf.o/
malicious
http://mkkuei4kdsz.com/966/777.html
15.197.204.56
malicious
http://lousta.net/262/971.html
193.166.255.171
malicious
http://mkkuei4kdsz.com/671/523.html
15.197.204.56
malicious
http://lousta.net/589/622.html
193.166.255.171
malicious
http://ow5dirasuek.com/145/281.html
52.34.198.229
malicious
http://ow5dirasuek.com/569/642.html
52.34.198.229
malicious
http://lousta.net/273/486.html
193.166.255.171
malicious
ht:/w.irsf.o/
malicious
http://lousta.net/164/753.html
193.166.255.171
malicious
http://ow5dirasuek.com/661/266.html
52.34.198.229
malicious
http://ow5dirasuek.com/417/147.html
52.34.198.229
malicious
http://lousta.net/
malicious
http://ow5dirasuek.com/663/854.html
52.34.198.229
malicious
http://lousta.net/89/483.html
193.166.255.171
malicious
http://lousta.net/741/863.html
193.166.255.171
malicious
http://ow5dirasuek.com/
malicious
http://mkkuei4kdsz.com/356/445.html
15.197.204.56
malicious
http://mkkuei4kdsz.com/164/577.html
15.197.204.56
malicious
http://lousta.net/610/631.html
193.166.255.171
malicious
http://ow5dirasuek.com/670/670.html
52.34.198.229
malicious
http://mkkuei4kdsz.com/680/793.html
15.197.204.56
malicious
http://mkkuei4kdsz.com/966/777.htmlU
unknown
http://lousta.net/589/622.htmlw
unknown
http://ow5dirasuek.com/Kw
unknown
http://lousta.net/741/863.htmlQ
unknown
http://mkkuei4kdsz.com/356/445.html4kdsz.com5
unknown
http://lousta.net/339/417.html36823da:933;c8c_b43e27:7
unknown
http://mkkuei4kdsz.com/164/577.html~
unknown
http://mkkuei4kdsz.com/356/445.htmlT
unknown
http://lousta.net/89/483.htmlm
unknown
http://mkkuei4kdsz.com/671/523.htmlh
unknown
http://ow5dirasuek.com/lousta.net
unknown
http://ow5dirasuek.com/663/854.html?
unknown
http://lousta.net/164/753.htmlV
unknown
http://ow5dirasuek.com/663/854.html9
unknown
http://ow5dirasuek.com/663/854.html8
unknown
http://ow5dirasuek.com/663/854.html-
unknown
http://lousta.net/262/971.htmlH
unknown
http://ow5dirasuek.com/3
unknown
http://lousta.net/989/145.htmli
unknown
http://mkkuei4kdsz.com/356/445.html0(m
unknown
http://mkkuei4kdsz.com/966/777.htmlc
unknown
http://mkkuei4kdsz.com/671/523.htmlox
unknown
http://mkkuei4kdsz.com/680/793.htmlZ
unknown
http://lousta.net/989/145.htmlb
unknown
http://lousta.net/com/p
unknown
http://lousta.net/989/145.htmlhtml
unknown
http://mkkuei4kdsz.com/356/445.htmlp
unknown
http://ow5dirasuek.com/569/642.htmlcxHS#
unknown
http://lousta.net/164/753.html=
unknown
http://mkkuei4kdsz.com/164/577.htmllv
unknown
http://mkkuei4kdsz.com/164/577.html0
unknown
http://mkkuei4kdsz.com/)
unknown
http://ow5dirasuek.com/670/670.htmlasuek.com
unknown
http://lousta.net/164/753.html36823da:933;c8c_b43e27:7
unknown
http://lousta.net/68/533.htmlJ
unknown
http://ow5dirasuek.com/417/147.htmlixBS$
unknown
http://lousta.net/989/145.html?
unknown
http://lousta.net/140/265.htmlshqos.dll.muiaH
unknown
http://lousta.net/989/145.html8
unknown
http://ow5dirasuek.com/417/147.htmlAxjS(
unknown
http://mkkuei4kdsz.com/680/793.html(mFv
unknown
http://ow5dirasuek.com/http://mkkuei4kdsz.com/http://lousta.net/http://lousta.net/begun.ruIueiOodcon
unknown
http://mkkuei4kdsz.com/ss
unknown
http://ow5dirasuek.com/663/854.html4kdsz.com5
unknown
http://mkkuei4kdsz.com/966/777.html#
unknown
http://mkkuei4kdsz.com/en-GB
unknown
http://ow5dirasuek.com/417/147.html56;x
unknown
http://lousta.net/989/145.html#
unknown
http://mkkuei4kdsz.com/966/777.html-
unknown
http://ow5dirasuek.com/569/642.html(
unknown
http://ow5dirasuek.com/145/281.html$
unknown
There are 72 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
lousta.net
193.166.255.171
malicious
mkkuei4kdsz.com
15.197.204.56
malicious
ow5dirasuek.com
52.34.198.229
malicious

IPs

IP
Domain
Country
Malicious
193.166.255.171
lousta.net
Finland
malicious
52.34.198.229
ow5dirasuek.com
United States
malicious
15.197.204.56
mkkuei4kdsz.com
United States
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
295E000
stack
page read and write
2A5D000
stack
page read and write
411000
unkown
page write copy
6D9000
heap
page read and write
60E000
heap
page read and write
400000
unkown
page readonly
5C0000
heap
page read and write
400000
unkown
page readonly
40E000
unkown
page readonly
26CE000
stack
page read and write
400000
unkown
page readonly
60C000
stack
page read and write
9D0000
heap
page read and write
22EE000
stack
page read and write
67E000
heap
page read and write
280E000
stack
page read and write
25BF000
stack
page read and write
620000
heap
page read and write
401000
unkown
page execute read
530000
heap
page read and write
401000
unkown
page execute read
2B9F000
stack
page read and write
58E000
stack
page read and write
93E000
stack
page read and write
58E000
stack
page read and write
40E000
unkown
page readonly
7CE000
heap
page read and write
40E000
unkown
page readonly
2B9D000
stack
page read and write
40E000
unkown
page readonly
194000
stack
page read and write
4B5000
heap
page read and write
430000
heap
page read and write
500000
heap
page read and write
258F000
stack
page read and write
400000
unkown
page readonly
2300000
heap
page read and write
195000
stack
page read and write
2A9E000
stack
page read and write
7C0000
heap
page read and write
2A5D000
stack
page read and write
411000
unkown
page write copy
8DF000
stack
page read and write
401000
unkown
page execute read
220D000
stack
page read and write
1F0000
heap
page read and write
54E000
stack
page read and write
57E000
stack
page read and write
6E0000
heap
page read and write
5EE000
heap
page read and write
9C000
stack
page read and write
9B000
stack
page read and write
19C000
stack
page read and write
226E000
stack
page read and write
400000
unkown
page readonly
4B0000
heap
page read and write
400000
unkown
page readonly
73E000
stack
page read and write
27CF000
stack
page read and write
401000
unkown
page execute read
67A000
heap
page read and write
401000
unkown
page execute read
2A9D000
stack
page read and write
401000
unkown
page execute read
6CD000
stack
page read and write
2B9D000
stack
page read and write
290F000
stack
page read and write
2BDE000
stack
page read and write
8FF000
stack
page read and write
40E000
unkown
page readonly
268F000
stack
page read and write
475000
heap
page read and write
7CA000
heap
page read and write
194000
stack
page read and write
8E0000
heap
page read and write
430000
heap
page read and write
280E000
stack
page read and write
2210000
heap
page read and write
670000
heap
page read and write
411000
unkown
page write copy
60A000
heap
page read and write
80F000
heap
page read and write
401000
unkown
page execute read
6AC000
heap
page read and write
470000
heap
page read and write
40E000
unkown
page readonly
619000
heap
page read and write
2A9E000
stack
page read and write
1F0000
heap
page read and write
5E0000
heap
page read and write
630000
heap
page read and write
500000
heap
page read and write
5CE000
stack
page read and write
819000
heap
page read and write
295D000
stack
page read and write
26BF000
stack
page read and write
411000
unkown
page read and write
9A0000
heap
page read and write
5C5000
heap
page read and write
274E000
stack
page read and write
5BE000
stack
page read and write
401000
unkown
page execute read
1F0000
heap
page read and write
2CDE000
stack
page read and write
40E000
unkown
page readonly
65A000
heap
page read and write
9BF000
stack
page read and write
66E000
stack
page read and write
7DF000
stack
page read and write
9C000
stack
page read and write
648000
heap
page read and write
5EA000
heap
page read and write
1F0000
heap
page read and write
600000
heap
page read and write
62D000
heap
page read and write
2A4F000
stack
page read and write
411000
unkown
page read and write
411000
unkown
page read and write
7FD000
stack
page read and write
B60000
heap
page read and write
400000
unkown
page readonly
411000
unkown
page read and write
27BF000
stack
page read and write
284F000
stack
page read and write
831000
heap
page read and write
400000
unkown
page readonly
77E000
stack
page read and write
672000
heap
page read and write
290F000
stack
page read and write
411000
unkown
page write copy
7BE000
stack
page read and write
6FD000
heap
page read and write
40E000
unkown
page readonly
9C000
stack
page read and write
66D000
heap
page read and write
6C1000
heap
page read and write
97E000
stack
page read and write
There are 127 hidden memdumps, click here to show them.