IOC Report
PlasmaSetup@LR_2.exe

loading gif

Files

File Path
Type
Category
Malicious
PlasmaSetup@LR_2.exe
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
initial sample
C:\Plasma\Switcher.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Plasma\pbrowser.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Plasma\pmanager.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Plasma\pmarquee.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Plasma\uninst.exe
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
dropped
malicious
C:\Users\user\AppData\Local\Temp\nsc7F3F.tmp\InstallOptions.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\nsc7F3F.tmp\LangDLL.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Plasma\AKISDB.FDB
data
dropped
C:\Plasma\Arabicp.ini
ISO-8859 text, with CRLF, LF line terminators
dropped
C:\Plasma\Englishp.ini
ASCII text, with CRLF line terminators
dropped
C:\Plasma\Lithuansw.ini
ISO-8859 text, with CRLF line terminators
dropped
C:\Plasma\PLASMA.HLP
MS Windows 3.1 help, Thu Sep 14 12:44:24 2006, 5564 bytes
dropped
C:\Plasma\Plasma.url
MS Windows 95 Internet shortcut text (URL=<http://www.tipas.lt/>), ASCII text, with CRLF line terminators
dropped
C:\Plasma\Polishp.ini
Non-ISO extended-ASCII text, with CRLF line terminators
dropped
C:\Plasma\Polishsw.ini
ISO-8859 text, with CRLF line terminators
dropped
C:\Plasma\Russianp.ini
ISO-8859 text, with CRLF line terminators
dropped
C:\Plasma\Russiansw.ini
ISO-8859 text, with CRLF line terminators
dropped
C:\Plasma\TVTuner.htm
HTML document, ASCII text, with CRLF line terminators
dropped
C:\Plasma\dvd_template.htm
HTML document, ASCII text, with CRLF line terminators
dropped
C:\Plasma\empty_template.htm
HTML document, ASCII text, with CRLF line terminators
dropped
C:\Plasma\film_template.htm
HTML document, ASCII text, with CRLF line terminators
dropped
C:\Plasma\film_template_VLC.htm
HTML document, ASCII text, with CRLF line terminators
dropped
C:\Plasma\flash_template.htm
HTML document, ASCII text, with CRLF line terminators
dropped
C:\Plasma\img_template.htm
HTML document, ASCII text, with CRLF line terminators
dropped
C:\Plasma\pbrowser.LIC
ASCII text, with CRLF line terminators
dropped
C:\Plasma\unistr.ini
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_pmanager.exe_8fbfe26353771c42d2099f513f03c31e2638e2_78c312fa_105b4730-6843-4b6e-ac83-c949d0250b84\Report.wer
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_pmanager.exe_8fbfe26353771c42d2099f513f03c31e2638e2_78c312fa_15d6b9e6-acb0-424a-ac38-5fdc254995e6\Report.wer
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_pmanager.exe_8fbfe26353771c42d2099f513f03c31e2638e2_78c312fa_c2afb5d5-c6fd-4afc-b662-586a033862a7\Report.wer
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WER1350.tmp.dmp
Mini DuMP crash report, 14 streams, Sat Dec 21 13:27:49 2024, 0x1205a4 type
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WER13AF.tmp.WERInternalMetadata.xml
XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WER13CF.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERA06D.tmp.dmp
Mini DuMP crash report, 14 streams, Sat Dec 21 13:28:25 2024, 0x1205a4 type
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERA0AD.tmp.WERInternalMetadata.xml
XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERA0CD.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERF902.tmp.dmp
Mini DuMP crash report, 14 streams, Sat Dec 21 13:27:42 2024, 0x1205a4 type
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERF990.tmp.WERInternalMetadata.xml
XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WERF9B0.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\nsc7F3F.tmp\ioSpecial.ini
Generic INItialization configuration [Field 1]
modified
C:\Users\user\AppData\Local\Temp\nsc7F3F.tmp\modern-wizard.bmp
PC bitmap, Windows 3.x format, 164 x 314 x 4, image size 26376, resolution 2834 x 2834 px/m, cbSize 26494, bits offset 118
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plasma\Browser.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Fri Mar 19 11:26:08 2010, mtime=Sat Dec 21 12:27:31 2024, atime=Fri Mar 19 11:26:08 2010, length=551936, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plasma\Manager.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Fri Mar 19 11:26:28 2010, mtime=Sat Dec 21 12:27:31 2024, atime=Fri Mar 19 11:26:28 2010, length=647168, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plasma\Uninstall.lnk
MS Windows shortcut, Item id list present, Has Relative path, Has Working directory, ctime=Sun Dec 31 23:25:52 1600, mtime=Sun Dec 31 23:25:52 1600, atime=Sun Dec 31 23:25:52 1600, length=0, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plasma\Website.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Sat Dec 21 12:27:31 2024, mtime=Sat Dec 21 12:27:31 2024, atime=Sat Dec 21 12:27:31 2024, length=46, window=hide
dropped
C:\Users\user\Desktop\Browser.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Fri Mar 19 11:26:08 2010, mtime=Sat Dec 21 12:27:31 2024, atime=Fri Mar 19 11:26:08 2010, length=551936, window=hide
dropped
C:\Users\user\Desktop\Manager.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Fri Mar 19 11:26:28 2010, mtime=Sat Dec 21 12:27:31 2024, atime=Fri Mar 19 11:26:28 2010, length=647168, window=hide
dropped
There are 37 hidden files, click here to show them.

IPs

IP
Domain
Country
Malicious
52.182.143.212
unknown
United States
20.189.173.21
unknown
United States