{"ver": "100019", "gtag": "top147", "servs": ["65.152.201.203:443", "185.56.175.122:443", "46.99.175.217:443", "179.189.229.254:443", "46.99.175.149:443", "181.129.167.82:443", "216.166.148.187:443", "46.99.188.223:443", "128.201.76.252:443", "62.99.79.77:443", "60.51.47.65:443", "24.162.214.166:443", "45.36.99.184:443", "97.83.40.67:443", "184.74.99.214:443", "103.105.254.17:443", "62.99.76.213:443", "82.159.149.52:443"], "autorun": ["pwgrabb", "pwgrabc"], "ecc_key": "RUNTMzAAAABbfmkJRvwyw7iFkX40hL2HwsUeOSZZZo0FRRWGkY6J1+gf3YKq13Ee4sY3Jb9/0myCr0MwzNK1K2l5yuY87nW29Q/yjMJG0ISDj0HNBC3G+ZGta6Oi9QkjCwnNGbw2hQ4="}
Source: 00000000.00000002.374239555.0000000000B31000.00000040.00000001.sdmp | Malware Configuration Extractor: Trickbot {"ver": "100019", "gtag": "top147", "servs": ["65.152.201.203:443", "185.56.175.122:443", "46.99.175.217:443", "179.189.229.254:443", "46.99.175.149:443", "181.129.167.82:443", "216.166.148.187:443", "46.99.188.223:443", "128.201.76.252:443", "62.99.79.77:443", "60.51.47.65:443", "24.162.214.166:443", "45.36.99.184:443", "97.83.40.67:443", "184.74.99.214:443", "103.105.254.17:443", "62.99.76.213:443", "82.159.149.52:443"], "autorun": ["pwgrabb", "pwgrabc"], "ecc_key": "RUNTMzAAAABbfmkJRvwyw7iFkX40hL2HwsUeOSZZZo0FRRWGkY6J1+gf3YKq13Ee4sY3Jb9/0myCr0MwzNK1K2l5yuY87nW29Q/yjMJG0ISDj0HNBC3G+ZGta6Oi9QkjCwnNGbw2hQ4="} |
Source: C:\Windows\System32\wermgr.exe | Code function: 4x nop then dec eax |
Source: C:\Windows\System32\wermgr.exe | Code function: 4x nop then dec eax |
Source: C:\Windows\System32\wermgr.exe | Code function: 4x nop then inc esp |
Source: C:\Windows\System32\wermgr.exe | Code function: 4x nop then dec eax |
Source: C:\Windows\System32\wermgr.exe | Code function: 4x nop then mov ebx, edx |
Source: C:\Windows\System32\wermgr.exe | Code function: 4x nop then dec ecx |
Source: C:\Windows\System32\wermgr.exe | Code function: 4x nop then dec eax |
Source: C:\Windows\System32\wermgr.exe | Code function: 4x nop then cmp dword ptr [eax], ecx |
Source: C:\Windows\System32\wermgr.exe | Code function: 4x nop then dec eax |
Source: C:\Windows\System32\wermgr.exe | Code function: 4x nop then inc ebp |
Source: C:\Windows\System32\wermgr.exe | Code function: 4x nop then movzx ecx, byte ptr [ebp-07h] |
Source: C:\Windows\System32\wermgr.exe | Code function: 4x nop then dec eax |
Source: C:\Windows\System32\wermgr.exe | Code function: 4x nop then mov byte ptr [esp+ecx+70h], cl |
Source: C:\Windows\System32\wermgr.exe | Code function: 4x nop then dec eax |
Source: C:\Windows\System32\wermgr.exe | Code function: 4x nop then inc esp |
Source: C:\Windows\System32\wermgr.exe | Code function: 4x nop then dec eax |
Source: C:\Windows\System32\wermgr.exe | Code function: 4x nop then dec eax |
Source: C:\Windows\System32\wermgr.exe | Code function: 4x nop then inc esp |
Source: C:\Windows\System32\wermgr.exe | Code function: 4x nop then dec eax |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: 0_2_001A911C |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: 0_2_0019C201 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: 0_2_001A82BD |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: 0_2_001A941B |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: 0_2_0019C5D3 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: 0_2_001A16DE |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: 0_2_001A880E |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: 0_2_0018C950 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: 0_2_0019C9BB |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: 0_2_0019B9CE |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: 0_2_001ABBF1 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: 0_2_00195C19 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: 0_2_001A4D22 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: 0_2_001A7D6E |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: 0_2_001A9E7F |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: 0_2_0019BE63 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: 0_2_001A8EA1 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: 0_2_00B33168 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18C2F30 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18CC750 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18D4260 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18E4CF0 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18C1030 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18DE47D |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18D73A0 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18C3BB0 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18E33D0 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18DE3F0 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18D17F0 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18D740C |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18C4730 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18C7340 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18E5F60 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18D7760 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18D1EA0 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18E52C0 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18D5AC0 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18D7EE0 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18CF700 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18E4B10 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18D9A80 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18CFE8E |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18D51A0 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18E45D0 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18D35D0 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18C79D0 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18D0A00 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18DB920 |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18DED70 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: 0_2_00190093 pushad ; ret |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: 0_2_0018D0DF push ecx; ret |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: 0_2_00194425 push ecx; ret |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: 0_2_0019CEE1 push 510019C7h; retf |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: 0_2_00B50390 push dword ptr [edx+14h]; ret |
Source: C:\Windows\System32\wermgr.exe | Code function: 1_2_00000239A18DDF22 push esp; iretd |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: __getptd,_LcidFromHexString,GetLocaleInfoA,_TestDefaultLanguage, |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: EnumSystemLocalesA, |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: _strlen,_strlen,_GetPrimaryLen,EnumSystemLocalesA, |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: _strlen,_GetPrimaryLen,EnumSystemLocalesA, |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: __getptd,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_strlen,EnumSystemLocalesA,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoA,_strcpy_s,__invoke_watson,GetLocaleInfoA,GetLocaleInfoA,__itow_s, |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,InterlockedDecrement,InterlockedDecrement,InterlockedDecrement,_free,_free, |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,_malloc,GetLocaleInfoW,WideCharToMultiByte,__freea, |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: ___crtGetLocaleInfoA,GetLastError,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__invoke_watson,GetLocaleInfoW,GetLocaleInfoW,__calloc_crt,GetLocaleInfoW,_free,GetLocaleInfoW, |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat, |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: GetLocaleInfoA, |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_mon,_free,_free,_free,InterlockedDecrement,InterlockedDecrement,_free,_free, |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: GetLocaleInfoA,GetLocaleInfoA,_LocaleUpdate::_LocaleUpdate,___ascii_strnicmp,__tolower_l,__tolower_l, |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo, |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,GetCPInfo,___crtGetStringTypeA,___crtLCMapStringA,___crtLCMapStringA,_memmove,_memmove,_memmove,InterlockedDecrement,_free,_free,_free,_free,_free,_free,_free,_free,_free,InterlockedDecrement, |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: __getptd,_LcidFromHexString,GetLocaleInfoA, |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: GetLocaleInfoW,_GetPrimaryLen,_strlen, |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe | Code function: __getptd,_LcidFromHexString,GetLocaleInfoA,GetLocaleInfoA,GetLocaleInfoA,_strlen,GetLocaleInfoA,_strlen,_TestDefaultLanguage, |