Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
HUo09bfA3g.exe
|
initial sample
|
|||
C:\Users\user\AppData\Roaming\omsecor.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Windows\SysWOW64\omsecor.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Windows\SysWOW64\merocz.xc6
|
data
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\HUo09bfA3g.exe
|
"C:\Users\user\Desktop\HUo09bfA3g.exe"
|
||
C:\Users\user\AppData\Roaming\omsecor.exe
|
C:\Users\user\AppData\Roaming\omsecor.exe
|
||
C:\Windows\SysWOW64\omsecor.exe
|
C:\Windows\System32\omsecor.exe
|
||
C:\Windows\SysWOW64\omsecor.exe
|
C:\Windows\SysWOW64\omsecor.exe /nomove
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://mkkuei4kdsz.com/17/791.html
|
15.197.204.56
|
||
http://mkkuei4kdsz.com/
|
|||
http://lousta.net/680/970.html
|
193.166.255.171
|
||
http://lousta.net/339/417.html
|
193.166.255.171
|
||
http://lousta.net/68/533.html
|
193.166.255.171
|
||
http://lousta.net/763/48.html
|
193.166.255.171
|
||
http://lousta.net/140/265.html
|
193.166.255.171
|
||
http://lousta.net/989/145.html
|
193.166.255.171
|
||
http://lousta.net/802/499.html
|
193.166.255.171
|
||
ht:/r.irsf.o/
|
|||
http://mkkuei4kdsz.com/966/777.html
|
15.197.204.56
|
||
http://lousta.net/262/971.html
|
193.166.255.171
|
||
http://mkkuei4kdsz.com/671/523.html
|
15.197.204.56
|
||
http://lousta.net/589/622.html
|
193.166.255.171
|
||
http://ow5dirasuek.com/145/281.html
|
52.34.198.229
|
||
http://ow5dirasuek.com/569/642.html
|
52.34.198.229
|
||
http://lousta.net/273/486.html
|
193.166.255.171
|
||
ht:/w.irsf.o/
|
|||
http://lousta.net/164/753.html
|
193.166.255.171
|
||
http://ow5dirasuek.com/661/266.html
|
52.34.198.229
|
||
http://ow5dirasuek.com/417/147.html
|
52.34.198.229
|
||
http://lousta.net/
|
|||
http://ow5dirasuek.com/663/854.html
|
52.34.198.229
|
||
http://lousta.net/89/483.html
|
193.166.255.171
|
||
http://lousta.net/741/863.html
|
193.166.255.171
|
||
http://ow5dirasuek.com/
|
|||
http://mkkuei4kdsz.com/356/445.html
|
15.197.204.56
|
||
http://mkkuei4kdsz.com/164/577.html
|
15.197.204.56
|
||
http://lousta.net/610/631.html
|
193.166.255.171
|
||
http://ow5dirasuek.com/670/670.html
|
52.34.198.229
|
||
http://mkkuei4kdsz.com/680/793.html
|
15.197.204.56
|
||
http://mkkuei4kdsz.com/966/777.htmlU
|
unknown
|
||
http://lousta.net/589/622.htmlw
|
unknown
|
||
http://ow5dirasuek.com/Kw
|
unknown
|
||
http://lousta.net/741/863.htmlQ
|
unknown
|
||
http://mkkuei4kdsz.com/356/445.html4kdsz.com5
|
unknown
|
||
http://lousta.net/339/417.html36823da:933;c8c_b43e27:7
|
unknown
|
||
http://mkkuei4kdsz.com/164/577.html~
|
unknown
|
||
http://mkkuei4kdsz.com/356/445.htmlT
|
unknown
|
||
http://lousta.net/89/483.htmlm
|
unknown
|
||
http://mkkuei4kdsz.com/671/523.htmlh
|
unknown
|
||
http://ow5dirasuek.com/lousta.net
|
unknown
|
||
http://ow5dirasuek.com/663/854.html?
|
unknown
|
||
http://lousta.net/164/753.htmlV
|
unknown
|
||
http://ow5dirasuek.com/663/854.html9
|
unknown
|
||
http://ow5dirasuek.com/663/854.html8
|
unknown
|
||
http://ow5dirasuek.com/663/854.html-
|
unknown
|
||
http://lousta.net/262/971.htmlH
|
unknown
|
||
http://ow5dirasuek.com/3
|
unknown
|
||
http://lousta.net/989/145.htmli
|
unknown
|
||
http://mkkuei4kdsz.com/356/445.html0(m
|
unknown
|
||
http://mkkuei4kdsz.com/966/777.htmlc
|
unknown
|
||
http://mkkuei4kdsz.com/671/523.htmlox
|
unknown
|
||
http://mkkuei4kdsz.com/680/793.htmlZ
|
unknown
|
||
http://lousta.net/989/145.htmlb
|
unknown
|
||
http://lousta.net/com/p
|
unknown
|
||
http://lousta.net/989/145.htmlhtml
|
unknown
|
||
http://mkkuei4kdsz.com/356/445.htmlp
|
unknown
|
||
http://ow5dirasuek.com/569/642.htmlcxHS#
|
unknown
|
||
http://lousta.net/164/753.html=
|
unknown
|
||
http://mkkuei4kdsz.com/164/577.htmllv
|
unknown
|
||
http://mkkuei4kdsz.com/164/577.html0
|
unknown
|
||
http://mkkuei4kdsz.com/)
|
unknown
|
||
http://ow5dirasuek.com/670/670.htmlasuek.com
|
unknown
|
||
http://lousta.net/164/753.html36823da:933;c8c_b43e27:7
|
unknown
|
||
http://lousta.net/68/533.htmlJ
|
unknown
|
||
http://ow5dirasuek.com/417/147.htmlixBS$
|
unknown
|
||
http://lousta.net/989/145.html?
|
unknown
|
||
http://lousta.net/140/265.htmlshqos.dll.muiaH
|
unknown
|
||
http://lousta.net/989/145.html8
|
unknown
|
||
http://ow5dirasuek.com/417/147.htmlAxjS(
|
unknown
|
||
http://mkkuei4kdsz.com/680/793.html(mFv
|
unknown
|
||
http://ow5dirasuek.com/http://mkkuei4kdsz.com/http://lousta.net/http://lousta.net/begun.ruIueiOodcon
|
unknown
|
||
http://mkkuei4kdsz.com/ss
|
unknown
|
||
http://ow5dirasuek.com/663/854.html4kdsz.com5
|
unknown
|
||
http://mkkuei4kdsz.com/966/777.html#
|
unknown
|
||
http://mkkuei4kdsz.com/en-GB
|
unknown
|
||
http://ow5dirasuek.com/417/147.html56;x
|
unknown
|
||
http://lousta.net/989/145.html#
|
unknown
|
||
http://mkkuei4kdsz.com/966/777.html-
|
unknown
|
||
http://ow5dirasuek.com/569/642.html(
|
unknown
|
||
http://ow5dirasuek.com/145/281.html$
|
unknown
|
There are 72 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
lousta.net
|
193.166.255.171
|
||
mkkuei4kdsz.com
|
15.197.204.56
|
||
ow5dirasuek.com
|
52.34.198.229
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
193.166.255.171
|
lousta.net
|
Finland
|
||
52.34.198.229
|
ow5dirasuek.com
|
United States
|
||
15.197.204.56
|
mkkuei4kdsz.com
|
United States
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
295E000
|
stack
|
page read and write
|
||
2A5D000
|
stack
|
page read and write
|
||
411000
|
unkown
|
page write copy
|
||
6D9000
|
heap
|
page read and write
|
||
60E000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
5C0000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
40E000
|
unkown
|
page readonly
|
||
26CE000
|
stack
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
60C000
|
stack
|
page read and write
|
||
9D0000
|
heap
|
page read and write
|
||
22EE000
|
stack
|
page read and write
|
||
67E000
|
heap
|
page read and write
|
||
280E000
|
stack
|
page read and write
|
||
25BF000
|
stack
|
page read and write
|
||
620000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
530000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
2B9F000
|
stack
|
page read and write
|
||
58E000
|
stack
|
page read and write
|
||
93E000
|
stack
|
page read and write
|
||
58E000
|
stack
|
page read and write
|
||
40E000
|
unkown
|
page readonly
|
||
7CE000
|
heap
|
page read and write
|
||
40E000
|
unkown
|
page readonly
|
||
2B9D000
|
stack
|
page read and write
|
||
40E000
|
unkown
|
page readonly
|
||
194000
|
stack
|
page read and write
|
||
4B5000
|
heap
|
page read and write
|
||
430000
|
heap
|
page read and write
|
||
500000
|
heap
|
page read and write
|
||
258F000
|
stack
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
2300000
|
heap
|
page read and write
|
||
195000
|
stack
|
page read and write
|
||
2A9E000
|
stack
|
page read and write
|
||
7C0000
|
heap
|
page read and write
|
||
2A5D000
|
stack
|
page read and write
|
||
411000
|
unkown
|
page write copy
|
||
8DF000
|
stack
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
220D000
|
stack
|
page read and write
|
||
1F0000
|
heap
|
page read and write
|
||
54E000
|
stack
|
page read and write
|
||
57E000
|
stack
|
page read and write
|
||
6E0000
|
heap
|
page read and write
|
||
5EE000
|
heap
|
page read and write
|
||
9C000
|
stack
|
page read and write
|
||
9B000
|
stack
|
page read and write
|
||
19C000
|
stack
|
page read and write
|
||
226E000
|
stack
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
4B0000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
73E000
|
stack
|
page read and write
|
||
27CF000
|
stack
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
67A000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
2A9D000
|
stack
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
6CD000
|
stack
|
page read and write
|
||
2B9D000
|
stack
|
page read and write
|
||
290F000
|
stack
|
page read and write
|
||
2BDE000
|
stack
|
page read and write
|
||
8FF000
|
stack
|
page read and write
|
||
40E000
|
unkown
|
page readonly
|
||
268F000
|
stack
|
page read and write
|
||
475000
|
heap
|
page read and write
|
||
7CA000
|
heap
|
page read and write
|
||
194000
|
stack
|
page read and write
|
||
8E0000
|
heap
|
page read and write
|
||
430000
|
heap
|
page read and write
|
||
280E000
|
stack
|
page read and write
|
||
2210000
|
heap
|
page read and write
|
||
670000
|
heap
|
page read and write
|
||
411000
|
unkown
|
page write copy
|
||
60A000
|
heap
|
page read and write
|
||
80F000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
6AC000
|
heap
|
page read and write
|
||
470000
|
heap
|
page read and write
|
||
40E000
|
unkown
|
page readonly
|
||
619000
|
heap
|
page read and write
|
||
2A9E000
|
stack
|
page read and write
|
||
1F0000
|
heap
|
page read and write
|
||
5E0000
|
heap
|
page read and write
|
||
630000
|
heap
|
page read and write
|
||
500000
|
heap
|
page read and write
|
||
5CE000
|
stack
|
page read and write
|
||
819000
|
heap
|
page read and write
|
||
295D000
|
stack
|
page read and write
|
||
26BF000
|
stack
|
page read and write
|
||
411000
|
unkown
|
page read and write
|
||
9A0000
|
heap
|
page read and write
|
||
5C5000
|
heap
|
page read and write
|
||
274E000
|
stack
|
page read and write
|
||
5BE000
|
stack
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
1F0000
|
heap
|
page read and write
|
||
2CDE000
|
stack
|
page read and write
|
||
40E000
|
unkown
|
page readonly
|
||
65A000
|
heap
|
page read and write
|
||
9BF000
|
stack
|
page read and write
|
||
66E000
|
stack
|
page read and write
|
||
7DF000
|
stack
|
page read and write
|
||
9C000
|
stack
|
page read and write
|
||
648000
|
heap
|
page read and write
|
||
5EA000
|
heap
|
page read and write
|
||
1F0000
|
heap
|
page read and write
|
||
600000
|
heap
|
page read and write
|
||
62D000
|
heap
|
page read and write
|
||
2A4F000
|
stack
|
page read and write
|
||
411000
|
unkown
|
page read and write
|
||
411000
|
unkown
|
page read and write
|
||
7FD000
|
stack
|
page read and write
|
||
B60000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
411000
|
unkown
|
page read and write
|
||
27BF000
|
stack
|
page read and write
|
||
284F000
|
stack
|
page read and write
|
||
831000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
77E000
|
stack
|
page read and write
|
||
672000
|
heap
|
page read and write
|
||
290F000
|
stack
|
page read and write
|
||
411000
|
unkown
|
page write copy
|
||
7BE000
|
stack
|
page read and write
|
||
6FD000
|
heap
|
page read and write
|
||
40E000
|
unkown
|
page readonly
|
||
9C000
|
stack
|
page read and write
|
||
66D000
|
heap
|
page read and write
|
||
6C1000
|
heap
|
page read and write
|
||
97E000
|
stack
|
page read and write
|
There are 127 hidden memdumps, click here to show them.