IOC Report
Server.exe

loading gifFilesProcessesRegistryMemdumps321010010Label

Files

File Path
Type
Category
Malicious
Download
Server.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\18f92744a712890ce1a5852179df81aaWindows Update.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\18f92744a712890ce1a5852179df81aaWindows Update.exe:Zone.Identifier
ASCII text, with CRLF line terminators
modified
malicious
C:\Users\user\AppData\Roaming\app
Unicode text, UTF-8 (with BOM) text, with no line terminators
dropped
\Device\ConDrv
ASCII text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Server.exe
"C:\Users\user\Desktop\Server.exe"
malicious
C:\Windows\SysWOW64\netsh.exe
netsh firewall add allowedprogram "C:\Users\user\Desktop\Server.exe" "Server.exe" ENABLE
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Environment
SEE_MASK_NOZONECHECKS
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
Download
F02000
unkown
page readonly
malicious
1597000
heap
page read and write
4680000
heap
page read and write
77A000
heap
page read and write
734000
heap
page read and write
1D5C000
stack
page read and write
76F000
heap
page read and write
7A9000
heap
page read and write
1D60000
heap
page read and write
1C70000
trusted library allocation
page execute and read and write
1530000
heap
page execute and read and write
78D000
heap
page read and write
16AE000
stack
page read and write
609D000
stack
page read and write
775000
heap
page read and write
741000
heap
page read and write
46E8000
trusted library allocation
page read and write
36CE000
trusted library allocation
page read and write
779000
heap
page read and write
795000
heap
page read and write
7A9000
heap
page read and write
5F5E000
stack
page read and write
1B60000
heap
page read and write
7C0000
heap
page read and write
77A000
heap
page read and write
7C0000
heap
page read and write
4BBF000
stack
page read and write
65E0000
trusted library allocation
page read and write
7A0000
heap
page read and write
1FB000
stack
page read and write
4D4B000
heap
page read and write
7A9000
heap
page read and write
78F000
heap
page read and write
142D000
stack
page read and write
7CE000
heap
page read and write
76D000
heap
page read and write
7AD000
heap
page read and write
14EC000
trusted library allocation
page execute and read and write
7CE000
heap
page read and write
776000
heap
page read and write
7CF000
heap
page read and write
815000
heap
page read and write
14E0000
trusted library allocation
page read and write
77A000
heap
page read and write
615E000
stack
page read and write
150C000
trusted library allocation
page execute and read and write
4CBF000
stack
page read and write
629D000
stack
page read and write
77A000
heap
page read and write
731000
heap
page read and write
46C1000
trusted library allocation
page read and write
60DD000
stack
page read and write
775000
heap
page read and write
4D48000
heap
page read and write
7810000
heap
page read and write
1510000
trusted library allocation
page read and write
778000
heap
page read and write
7CE000
heap
page read and write
812000
heap
page read and write
79D000
heap
page read and write
720000
heap
page read and write
172D000
stack
page read and write
FAA000
stack
page read and write
7CE000
heap
page read and write
768000
heap
page read and write
68E000
unkown
page read and write
1517000
trusted library allocation
page execute and read and write
78F000
heap
page read and write
767000
heap
page read and write
4D47000
heap
page read and write
1430000
heap
page read and write
611B000
stack
page read and write
741000
heap
page read and write
649E000
stack
page read and write
4D49000
heap
page read and write
4570000
heap
page read and write
13E0000
heap
page read and write
78D000
heap
page read and write
4D3D000
heap
page read and write
790000
heap
page read and write
1CC0000
heap
page read and write
1B50000
trusted library allocation
page read and write
4D4C000
heap
page read and write
755000
heap
page read and write
8910000
heap
page read and write
150A000
trusted library allocation
page execute and read and write
81A000
heap
page read and write
773000
heap
page read and write
72A000
heap
page read and write
15F2000
heap
page read and write
36C1000
trusted library allocation
page read and write
776000
heap
page read and write
81E000
heap
page read and write
186E000
stack
page read and write
76B000
heap
page read and write
79D000
heap
page read and write
14FA000
trusted library allocation
page execute and read and write
14D2000
trusted library allocation
page execute and read and write
58FC000
stack
page read and write
B0C2000
trusted library allocation
page read and write
776000
heap
page read and write
2AF6000
heap
page read and write
1300000
heap
page read and write
818000
heap
page read and write
79F000
heap
page read and write
4D3D000
heap
page read and write
64DE000
stack
page read and write
7AC000
heap
page read and write
1500000
trusted library allocation
page read and write
B066000
trusted library allocation
page read and write
5AFE000
unkown
page read and write
81E000
heap
page read and write
1502000
trusted library allocation
page execute and read and write
79D000
heap
page read and write
778000
heap
page read and write
4D32000
heap
page read and write
162E000
heap
page read and write
796000
heap
page read and write
1610000
heap
page read and write
1570000
heap
page read and write
4D3D000
heap
page read and write
7A2000
heap
page read and write
79E000
heap
page read and write
14C0000
trusted library allocation
page read and write
690000
heap
page read and write
AD61000
trusted library allocation
page read and write
1485000
heap
page read and write
76DE000
stack
page read and write
4F3000
stack
page read and write
8974000
heap
page read and write
940000
heap
page read and write
12F6000
stack
page read and write
7A5000
heap
page read and write
4EE000
stack
page read and write
811000
heap
page read and write
7AD000
heap
page read and write
4D3D000
heap
page read and write
1480000
heap
page read and write
1760000
heap
page read and write
815000
heap
page read and write
79D000
heap
page read and write
2A8E000
stack
page read and write
792000
heap
page read and write
4D3D000
heap
page read and write
791000
heap
page read and write
741000
heap
page read and write
1750000
trusted library allocation
page read and write
773000
heap
page read and write
2AF0000
heap
page read and write
B154000
trusted library allocation
page read and write
8B70000
heap
page read and write
1512000
trusted library allocation
page read and write
F00000
unkown
page readonly
778000
heap
page read and write
81B000
heap
page read and write
76C000
heap
page read and write
797000
heap
page read and write
645000
heap
page read and write
1578000
heap
page read and write
4D31000
heap
page read and write
796000
heap
page read and write
7AB000
heap
page read and write
77B000
heap
page read and write
7AD000
heap
page read and write
1613000
heap
page read and write
14EA000
trusted library allocation
page execute and read and write
7C0000
heap
page read and write
7AF000
heap
page read and write
4D3D000
heap
page read and write
AE27000
trusted library allocation
page read and write
7CE000
heap
page read and write
7D0000
heap
page read and write
7A2000
heap
page read and write
6A0000
heap
page read and write
14DA000
trusted library allocation
page execute and read and write
7A5000
heap
page read and write
79A000
heap
page read and write
58BB000
stack
page read and write
796000
heap
page read and write
14F7000
trusted library allocation
page execute and read and write
758000
heap
page read and write
157E000
heap
page read and write
7AC000
heap
page read and write
4D49000
heap
page read and write
7A6000
heap
page read and write
1C6F000
stack
page read and write
7AC000
heap
page read and write
5E5D000
stack
page read and write
62A0000
heap
page read and write
65F0000
unclassified section
page read and write
91F000
unkown
page read and write
4D10000
heap
page read and write
7AB000
heap
page read and write
4D38000
heap
page read and write
4D11000
heap
page read and write
78D8000
heap
page read and write
779000
heap
page read and write
14E2000
trusted library allocation
page execute and read and write
8B60000
heap
page read and write
65DE000
stack
page read and write
7A9000
heap
page read and write
151B000
trusted library allocation
page execute and read and write
1450000
heap
page read and write
18AE000
stack
page read and write
1540000
heap
page read and write
7CF000
heap
page read and write
4FE000
stack
page read and write
76B000
heap
page read and write
814000
heap
page read and write
560000
heap
page read and write
456E000
stack
page read and write
4D3D000
heap
page read and write
1B3C000
stack
page read and write
625D000
stack
page read and write
7AB000
heap
page read and write
767000
heap
page read and write
778000
heap
page read and write
640000
heap
page read and write
4FB000
stack
page read and write
43DE000
stack
page read and write
813000
heap
page read and write
773000
heap
page read and write
4D4A000
heap
page read and write
5F9C000
stack
page read and write
59FD000
stack
page read and write
7894000
heap
page read and write
BDBD000
trusted library allocation
page read and write
1730000
trusted library allocation
page execute and read and write
4420000
heap
page read and write
779000
heap
page read and write
4D30000
heap
page read and write
1440000
heap
page read and write
7A0000
heap
page read and write
7A6000
heap
page read and write
B0A4000
trusted library allocation
page read and write
15EE000
heap
page read and write
7A1000
heap
page read and write
8BA7000
heap
page read and write
819000
heap
page read and write
4D3F000
heap
page read and write
7A9000
heap
page read and write
4D3F000
heap
page read and write
6FE000
stack
page read and write
79D000
heap
page read and write
785B000
heap
page read and write
81E000
heap
page read and write
57BD000
stack
page read and write
7C0000
heap
page read and write
There are 238 hidden memdumps, click here to show them.