IOC Report
utkin.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\utkin.exe
"C:\Users\user\Desktop\utkin.exe"
malicious

URLs

Name
IP
Malicious
https://api.ipify.org/
172.67.74.152
https://api.ipify.org/a
unknown
https://api.ipify.org_
unknown
https://api.ipify.org
unknown
https://api.ipify.org/A:
unknown
https://api.ipify.orgW
unknown

Domains

Name
IP
Malicious
api.ipify.org
172.67.74.152

IPs

IP
Domain
Country
Malicious
193.3.19.151
unknown
Denmark
malicious
172.67.74.152
api.ipify.org
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
1C737BAB000
heap
page read and write
malicious
1C739630000
direct allocation
page execute and read and write
malicious
1C737B30000
heap
page read and write
1C73995A000
heap
page read and write
1C7399EF000
heap
page read and write
1C737C13000
heap
page read and write
1C739925000
heap
page read and write
7FF681293000
unkown
page readonly
1C73952C000
heap
page read and write
27A57FF000
stack
page read and write
1C739620000
heap
page read and write
1C739940000
heap
page read and write
27A54FB000
stack
page read and write
27A50FE000
stack
page read and write
1C73A850000
heap
page read and write
1C73A7F0000
heap
page read and write
27A4BA7000
stack
page read and write
27A4FFE000
stack
page read and write
1C737C8A000
heap
page read and write
27A53FF000
stack
page read and write
1C739840000
heap
page read and write
1C739520000
heap
page read and write
1C739590000
heap
page read and write
27A52FE000
stack
page read and write
1C737A20000
heap
page read and write
1C737B50000
heap
page read and write
1C7399E9000
heap
page read and write
1C739B5A000
heap
page read and write
1C737C83000
heap
page read and write
1C739B51000
heap
page read and write
1C7399EC000
heap
page read and write
7FF68128E000
unkown
page readonly
1C739E66000
heap
page read and write
27A51FE000
stack
page read and write
7FF680FF0000
unkown
page readonly
1C737C98000
heap
page read and write
1C7399F9000
heap
page read and write
1C737B00000
heap
page read and write
1C739525000
heap
page read and write
7FF68127E000
unkown
page readonly
1C737BA0000
heap
page read and write
7FF680FF1000
unkown
page execute read
1C739921000
heap
page read and write
1C73B970000
heap
page read and write
1C739B40000
heap
page read and write
7FF68128A000
unkown
page write copy
1C737C0F000
heap
page read and write
1C737C4A000
heap
page read and write
1C739980000
heap
page read and write
7FF68103E000
unkown
page readonly
27A4EFE000
stack
page read and write
7FF68128A000
unkown
page read and write
1C739625000
heap
page read and write
27A56FE000
stack
page read and write
7FF68103E000
unkown
page readonly
27A55FE000
stack
page read and write
27A4B9D000
stack
page read and write
There are 47 hidden memdumps, click here to show them.