IOC Report
bd0wJGTae5.exe

loading gif

Files

File Path
Type
Category
Malicious
bd0wJGTae5.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Roaming\omsecor.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Windows\SysWOW64\omsecor.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Windows\SysWOW64\merocz.xc6
data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\bd0wJGTae5.exe
"C:\Users\user\Desktop\bd0wJGTae5.exe"
malicious
C:\Users\user\AppData\Roaming\omsecor.exe
C:\Users\user\AppData\Roaming\omsecor.exe
malicious
C:\Windows\SysWOW64\omsecor.exe
C:\Windows\System32\omsecor.exe
malicious
C:\Windows\SysWOW64\omsecor.exe
C:\Windows\SysWOW64\omsecor.exe /nomove
malicious

URLs

Name
IP
Malicious
http://mkkuei4kdsz.com/
malicious
http://lousta.net/956/959.html
193.166.255.171
malicious
http://lousta.net/508/485.html
193.166.255.171
malicious
http://lousta.net/562/252.html
193.166.255.171
malicious
http://mkkuei4kdsz.com/516/243.html
15.197.204.56
malicious
http://ow5dirasuek.com/776/947.html
52.34.198.229
malicious
ht:/r.irsf.o/
malicious
http://ow5dirasuek.com/537/167.html
52.34.198.229
malicious
http://mkkuei4kdsz.com/353/421.html
15.197.204.56
malicious
http://mkkuei4kdsz.com/978/939.html
15.197.204.56
malicious
http://ow5dirasuek.com/292/164.html
52.34.198.229
malicious
http://lousta.net/740/238.html
193.166.255.171
malicious
http://lousta.net/333/645.html
193.166.255.171
malicious
http://mkkuei4kdsz.com/781/119.html
15.197.204.56
malicious
http://lousta.net/734/112.html
193.166.255.171
malicious
http://mkkuei4kdsz.com/488/933.html
15.197.204.56
malicious
ht:/w.irsf.o/
malicious
http://lousta.net/875/87.html
193.166.255.171
malicious
http://ow5dirasuek.com/546/102.html
52.34.198.229
malicious
http://lousta.net/547/467.html
193.166.255.171
malicious
http://lousta.net/78/665.html
193.166.255.171
malicious
http://lousta.net/263/482.html
193.166.255.171
malicious
http://ow5dirasuek.com/434/722.html
52.34.198.229
malicious
http://lousta.net/908/776.html
193.166.255.171
malicious
http://lousta.net/
malicious
http://lousta.net/528/262.html
193.166.255.171
malicious
http://mkkuei4kdsz.com/785/70.html
15.197.204.56
malicious
http://ow5dirasuek.com/945/466.html
52.34.198.229
malicious
http://lousta.net/497/157.html
193.166.255.171
malicious
http://mkkuei4kdsz.com/457/998.html
15.197.204.56
malicious
http://ow5dirasuek.com/
malicious
http://ow5dirasuek.com/763/794.html
52.34.198.229
malicious
http://lousta.ne
unknown
malicious
http://lousta.net/527/338.html
193.166.255.171
malicious
http://ow5dirasuek.com/763/794.htmlZZ
unknown
http://mkkuei4kdsz.com/781/119.htmlf
unknown
http://lousta.net/562/252.htmlY
unknown
http://ow5dirasuek.com/546/102.html$
unknown
http://mkkuei4kdsz.com/516/243.html0
unknown
http://ow5dirasuek.com/776/947.htmlnZ
unknown
http://mkkuei4kdsz.com/516/243.html&
unknown
http://ow5dirasuek.com/776/947.htmlrZC-
unknown
http://ow5dirasuek.com/537/167.htmlwm
unknown
http://lousta.net/562/252.htmlf
unknown
http://ow5dirasuek.com/546/102.html;L
unknown
http://lousta.net/78/665.htmlH
unknown
http://ow5dirasuek.com/292/164.html.E
unknown
http://mkkuei4kdsz.com/488/933.htmldZI-&
unknown
http://ow5dirasuek.com/546/102.htmlD
unknown
http://lousta.net/956/959.html0473447
unknown
http://lousta.net/908/776.htmla0
unknown
http://ow5dirasuek.com/537/167.html;Q
unknown
http://lousta.net/956/959.htmlw
unknown
http://lousta.net/263/482.html3
unknown
http://mkkuei4kdsz.com/781/119.html)
unknown
http://lousta.net/740/238.htmlx
unknown
http://ow5dirasuek.com/945/466.htmlA
unknown
http://mkkuei4kdsz.com/781/119.html4
unknown
http://ow5dirasuek.com/945/466.htmlN
unknown
http://lousta.net/528/262.html9Tk-.
unknown
http://mkkuei4kdsz.com/457/998.html-559bf06f72796be679
unknown
http://ow5dirasuek.com/546/102.htmlf
unknown
http://mkkuei4kdsz.com/353/421.html$E
unknown
http://lousta.net/497/157.htmlB
unknown
http://ow5dirasuek.com/546/102.html#L
unknown
http://ow5dirasuek.com/546/102.htmlULV
unknown
http://mkkuei4kdsz.com/488/933.htmlasuek.com
unknown
http://ow5dirasuek.com/945/466.htmlasuek.com
unknown
http://lousta.net/562/252.html.
unknown
http://ow5dirasuek.com/http://mkkuei4kdsz.com/http://lousta.net/http://lousta.net/begun.ruIueiOodcon
unknown
http://lousta.net/562/252.htmlaba
unknown
http://ow5dirasuek.com/en-GB
unknown
http://ow5dirasuek.com/763/794.html6Z
unknown
http://ow5dirasuek.com/546/102.html5L
unknown
http://mkkuei4kdsz.com/488/933.htmlom
unknown
http://mkkuei4kdsz.com/516/243.htmlwLt
unknown
http://ow5dirasuek.com/945/466.html3
unknown
http://mkkuei4kdsz.com/457/998.html~
unknown
http://mkkuei4kdsz.com/8.htmlshqos.dll.mui
unknown
http://lousta.net/547/467.html4Wx
unknown
http://ow5dirasuek.com/945/466.html/
unknown
http://lousta.net/908/776.htmlFTv-1
unknown
http://ow5dirasuek.com/p
unknown
http://ow5dirasuek.com/776/947.htmlPZ
unknown
http://lousta.net/562/252.htmlB
unknown
http://ow5dirasuek.com/292/164.htmlam
unknown
http://ow5dirasuek.com/945/466.html7
unknown
http://lousta.net/734/112.htmlk
unknown
There are 78 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
lousta.net
193.166.255.171
malicious
mkkuei4kdsz.com
15.197.204.56
malicious
ow5dirasuek.com
52.34.198.229
malicious

IPs

IP
Domain
Country
Malicious
193.166.255.171
lousta.net
Finland
malicious
52.34.198.229
ow5dirasuek.com
United States
malicious
15.197.204.56
mkkuei4kdsz.com
United States
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
401000
unkown
page execute read
40E000
unkown
page readonly
5E0000
heap
page read and write
21B0000
heap
page read and write
6E1000
heap
page read and write
401000
unkown
page execute read
2A9E000
stack
page read and write
59E000
stack
page read and write
2A6D000
stack
page read and write
9C000
stack
page read and write
5B0000
heap
page read and write
2B9E000
stack
page read and write
70D000
heap
page read and write
27FE000
stack
page read and write
2D5E000
stack
page read and write
505000
heap
page read and write
58E000
stack
page read and write
40E000
unkown
page readonly
194000
stack
page read and write
411000
unkown
page write copy
195000
stack
page read and write
430000
heap
page read and write
6FC000
heap
page read and write
400000
unkown
page readonly
660000
heap
page read and write
28FF000
stack
page read and write
401000
unkown
page execute read
2CDD000
stack
page read and write
2A5D000
stack
page read and write
500000
heap
page read and write
401000
unkown
page execute read
80D000
stack
page read and write
411000
unkown
page read and write
88F000
stack
page read and write
401000
unkown
page execute read
400000
unkown
page readonly
296F000
stack
page read and write
610000
heap
page read and write
6BD000
heap
page read and write
291F000
stack
page read and write
1C0000
heap
page read and write
411000
unkown
page write copy
2A3F000
stack
page read and write
69E000
heap
page read and write
27DF000
stack
page read and write
1F0000
heap
page read and write
55E000
stack
page read and write
411000
unkown
page write copy
26DE000
stack
page read and write
40E000
unkown
page readonly
690000
heap
page read and write
68E000
heap
page read and write
87E000
stack
page read and write
9C000
stack
page read and write
286F000
stack
page read and write
6C0000
heap
page read and write
98E000
stack
page read and write
61A000
heap
page read and write
510000
heap
page read and write
276F000
stack
page read and write
97F000
stack
page read and write
259F000
stack
page read and write
281E000
stack
page read and write
699000
heap
page read and write
411000
unkown
page read and write
2BDE000
stack
page read and write
1F0000
heap
page read and write
400000
unkown
page readonly
2C4E000
stack
page read and write
2660000
heap
page read and write
269F000
stack
page read and write
9B0000
heap
page read and write
400000
unkown
page readonly
401000
unkown
page execute read
6DC000
heap
page read and write
680000
heap
page read and write
263D000
stack
page read and write
400000
unkown
page readonly
2B9F000
stack
page read and write
54E000
stack
page read and write
5C5000
heap
page read and write
194000
stack
page read and write
253D000
stack
page read and write
67A000
heap
page read and write
69A000
heap
page read and write
400000
unkown
page readonly
21AD000
stack
page read and write
58E000
stack
page read and write
68C000
heap
page read and write
5C0000
heap
page read and write
5E0000
heap
page read and write
266F000
stack
page read and write
500000
heap
page read and write
40E000
unkown
page readonly
40E000
unkown
page readonly
411000
unkown
page read and write
A1E000
stack
page read and write
400000
unkown
page readonly
26BE000
stack
page read and write
2D4E000
stack
page read and write
670000
heap
page read and write
2A9E000
stack
page read and write
9C000
stack
page read and write
1F0000
heap
page read and write
67E000
heap
page read and write
295D000
stack
page read and write
40E000
unkown
page readonly
411000
unkown
page read and write
67C000
heap
page read and write
20AC000
stack
page read and write
98F000
stack
page read and write
19C000
stack
page read and write
510000
heap
page read and write
40E000
unkown
page readonly
1C5000
heap
page read and write
94E000
stack
page read and write
500000
heap
page read and write
682000
heap
page read and write
90F000
stack
page read and write
63E000
stack
page read and write
293E000
stack
page read and write
40E000
unkown
page readonly
400000
unkown
page readonly
2BAD000
stack
page read and write
9B000
stack
page read and write
A80000
heap
page read and write
660000
heap
page read and write
6FB000
heap
page read and write
401000
unkown
page execute read
2AAE000
stack
page read and write
54E000
stack
page read and write
411000
unkown
page write copy
9CE000
stack
page read and write
A50000
heap
page read and write
67E000
stack
page read and write
713000
heap
page read and write
6EE000
heap
page read and write
401000
unkown
page execute read
27BF000
stack
page read and write
68A000
heap
page read and write
61E000
heap
page read and write
A6D000
stack
page read and write
2C5E000
stack
page read and write
There are 133 hidden memdumps, click here to show them.