IOC Report
WhaleInstall.exe

loading gif

Files

File Path
Type
Category
Malicious
WhaleInstall.exe
PE32+ executable (console) x86-64, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T9RRWRNL\guardservice[1].exe
PE32 executable (GUI) Intel 80386, for MS Windows
modified
malicious
C:\Users\user\Desktop\record_hit.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
\Device\ConDrv
ASCII text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\record_hit.exe
"C:\Users\user\Desktop\record_hit.exe"
malicious
C:\Users\user\Desktop\WhaleInstall.exe
"C:\Users\user\Desktop\WhaleInstall.exe"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
https://www.kenesrakishevinfo.com
unknown
malicious
https://www.kenesrakishevinfo.com/
unknown
malicious
https://www.kenesrakishevinfo.comReferer:
unknown
malicious
https://www.kenesrakishevinfo.com/api/census/RecordHit
198.185.159.144
malicious
https://www.kenesrakishevinfo.com/f
unknown
malicious
https://www.kenesrakishevinfo.com/l
unknown
malicious
https://www.kenesrakishevinfo.com/api/census/RecordHitsuccess://record_hit.exerunas(X
unknown
malicious
http://127.0.0.1:8888/test
unknown
http://www.eyuyan.com)DVarFileInfo$
unknown
http://127.0.0.1:8888/testtestMozilla/5.0
unknown
https://file.znhds.com.cn/pd/update/Update.exeD:
unknown
https://sgz-1302338321.cos.ap-guangzhou.myqcloud.com/store_app/guardservice.exe
159.75.57.69
https://sgz-1302338321.cos.ap-guangzhou.myqcloud.com/
unknown
https://sgz-1302338321.cos.ap-guangzhou.myqcloud.com/k
unknown
https://file.znhds.com.cn/pd/update/Update.exe
unknown
https://sgz-1302338321.cos.ap-guangzhou.myqcloud.com/store_app/guardservice.exe1
unknown
https://sgz-1302338321.cos.ap-guangzhou.myqcloud.com/store_app/guardservice.exe0
unknown
http://whale.naver.com0
unknown
There are 8 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
ext-sq.squarespace.com
198.185.159.144
gz.file.myqcloud.com
159.75.57.69
www.kenesrakishevinfo.com
unknown
sgz-1302338321.cos.ap-guangzhou.myqcloud.com
unknown

IPs

IP
Domain
Country
Malicious
198.185.159.144
ext-sq.squarespace.com
United States
159.75.57.69
gz.file.myqcloud.com
China

Memdumps

Base Address
Regiontype
Protect
Malicious
2AA289C8000
heap
page read and write
7FF772C04000
unkown
page readonly
42A000
unkown
page read and write
BCFE3F7000
stack
page read and write
2AA289C0000
heap
page read and write
2AA289B0000
remote allocation
page read and write
680000
heap
page read and write
2AA26D16000
heap
page read and write
BCFEDFB000
stack
page read and write
7FF772A61000
unkown
page execute read
2AA28C50000
heap
page read and write
7FF772B6E000
unkown
page write copy
42F000
unkown
page write copy
570000
heap
page read and write
2AA26CCD000
heap
page read and write
2AA26C97000
heap
page read and write
400000
unkown
page readonly
7FF772B6F000
unkown
page write copy
2AA26C00000
heap
page read and write
7FF772B6B000
unkown
page read and write
68A000
heap
page read and write
2AA26C9B000
heap
page read and write
2AA26E55000
heap
page read and write
433000
unkown
page write copy
BCFF1FD000
stack
page read and write
9D000
stack
page read and write
BCFF3FF000
stack
page read and write
2AA26C55000
heap
page read and write
BCFEBFB000
stack
page read and write
7FF772B35000
unkown
page write copy
BCFE9FF000
stack
page read and write
2AA26C81000
heap
page read and write
7FF772A60000
unkown
page readonly
2AA26CF2000
heap
page read and write
42F000
unkown
page write copy
433000
unkown
page write copy
BCFEFFF000
stack
page read and write
540000
heap
page read and write
2AA26E50000
heap
page read and write
400000
unkown
page readonly
7FF772C04000
unkown
page readonly
7FF772B39000
unkown
page readonly
2AA26CCB000
heap
page read and write
2AA26CEA000
heap
page read and write
7FF772B37000
unkown
page write copy
2AA26CEA000
heap
page read and write
2AA289C1000
heap
page read and write
460000
heap
page read and write
2AA26CCD000
heap
page read and write
2AA26CCD000
heap
page read and write
2AA289D5000
heap
page read and write
401000
unkown
page execute read
7FF772B39000
unkown
page readonly
2AA26C08000
heap
page read and write
19D000
stack
page read and write
42B000
unkown
page readonly
401000
unkown
page execute read
7FF772B72000
unkown
page readonly
7FF772A61000
unkown
page execute read
2AA289DC000
heap
page read and write
2AA26BC0000
heap
page read and write
2AA26CA3000
heap
page read and write
2AA289B0000
remote allocation
page read and write
2AA289B0000
remote allocation
page read and write
7FF772B6E000
unkown
page read and write
2AA26BA0000
heap
page read and write
42A000
unkown
page readonly
2AA26CCB000
heap
page read and write
7FF772A60000
unkown
page readonly
444000
unkown
page readonly
7FF772B35000
unkown
page read and write
7FF772B72000
unkown
page readonly
68E000
heap
page read and write
2AA26CF5000
heap
page read and write
444000
unkown
page readonly
2AA26AC0000
heap
page read and write
2AA26CCB000
heap
page read and write
2AA26C8C000
heap
page read and write
There are 68 hidden memdumps, click here to show them.