IOC Report
2hp5ee36OS.exe

loading gif

Files

File Path
Type
Category
Malicious
2hp5ee36OS.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Program Files\Common Files\System\symsrv.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, UPX compressed
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\2hp5ee36OS.exe
"C:\Users\user\Desktop\2hp5ee36OS.exe"
malicious

URLs

Name
IP
Malicious
http://5isohu.com/
unknown
http://5isohu.com/Z
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
680000
heap
page read and write
6A0000
direct allocation
page execute and read and write
10000000
unkown
page readonly
8BF000
stack
page read and write
6C0000
heap
page read and write
400000
unkown
page readonly
2161000
heap
page read and write
400000
unkown
page readonly
228E000
stack
page read and write
610000
heap
page read and write
684000
heap
page read and write
6CE000
heap
page read and write
9B000
stack
page read and write
19D000
stack
page read and write
486000
unkown
page read and write
22A0000
heap
page read and write
4A0000
heap
page read and write
224C000
stack
page read and write
5CE000
stack
page read and write
1002F000
unkown
page read and write
1002D000
unkown
page execute and write copy
690000
heap
page read and write
24AF000
stack
page read and write
406000
unkown
page execute and read and write
1002B000
unkown
page execute and read and write
10025000
unkown
page execute and read and write
10001000
unkown
page execute and read and write
9BF000
stack
page read and write
580000
heap
page read and write
28F0000
direct allocation
page read and write
483000
unkown
page execute and read and write
488000
unkown
page read and write
630000
heap
page read and write
60E000
stack
page read and write
401000
unkown
page execute read
48D000
unkown
page readonly
10020000
unkown
page execute and read and write
1001E000
unkown
page execute and read and write
23AE000
stack
page read and write
2B53000
heap
page read and write
2B50000
heap
page read and write
27F0000
heap
page read and write
6CA000
heap
page read and write
484000
unkown
page write copy
488000
unkown
page write copy
There are 35 hidden memdumps, click here to show them.