IOC Report
C9zGTJBy3T.exe

loading gif

Files

File Path
Type
Category
Malicious
C9zGTJBy3T.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\autorun.inf
Microsoft Windows Autorun file
dropped
malicious
C:\google.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\google.exe:Zone.Identifier
ASCII text, with CRLF line terminators
dropped
malicious
\Device\ConDrv
ASCII text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\C9zGTJBy3T.exe
"C:\Users\user\Desktop\C9zGTJBy3T.exe"
malicious
C:\Windows\SysWOW64\netsh.exe
netsh firewall add allowedprogram "C:\Users\user\Desktop\C9zGTJBy3T.exe" "C9zGTJBy3T.exe" ENABLE
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
https://dl.dropbox.com/s/p84aaz28t0hepul/Pass.exe?dl=0
unknown

Domains

Name
IP
Malicious
0.tcp.eu.ngrok.io
3.125.209.94
malicious

IPs

IP
Domain
Country
Malicious
3.125.223.134
unknown
United States
malicious
3.125.209.94
0.tcp.eu.ngrok.io
United States
malicious
18.192.31.165
unknown
United States
malicious
3.125.102.39
unknown
United States
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER
di

Memdumps

Base Address
Regiontype
Protect
Malicious
C72000
unkown
page readonly
malicious
3060000
heap
page read and write
331B000
heap
page read and write
32A9000
heap
page read and write
329E000
heap
page read and write
125A000
trusted library allocation
page execute and read and write
326C000
heap
page read and write
331E000
heap
page read and write
32F6000
heap
page read and write
13CF000
heap
page read and write
535E000
stack
page read and write
3293000
heap
page read and write
32A9000
heap
page read and write
32C4000
heap
page read and write
32A5000
heap
page read and write
1262000
trusted library allocation
page execute and read and write
32AB000
heap
page read and write
55FB000
heap
page read and write
1240000
trusted library allocation
page read and write
3292000
heap
page read and write
560B000
heap
page read and write
5609000
heap
page read and write
32A9000
heap
page read and write
1427000
heap
page read and write
1257000
trusted library allocation
page execute and read and write
3255000
heap
page read and write
10F6000
stack
page read and write
565D000
stack
page read and write
17DF000
stack
page read and write
5BA0000
heap
page read and write
3313000
heap
page read and write
330F000
heap
page read and write
56A0000
trusted library allocation
page execute and read and write
2F5B000
stack
page read and write
1820000
heap
page execute and read and write
3311000
heap
page read and write
C7C000
unkown
page readonly
32A5000
heap
page read and write
3313000
heap
page read and write
32A4000
heap
page read and write
32AC000
heap
page read and write
1270000
trusted library allocation
page read and write
1290000
heap
page read and write
3268000
heap
page read and write
3010000
heap
page read and write
5609000
heap
page read and write
1400000
heap
page read and write
326F000
heap
page read and write
3297000
heap
page read and write
55FC000
heap
page read and write
32A4000
heap
page read and write
3210000
heap
page read and write
5BB0000
heap
page read and write
326B000
heap
page read and write
15A0000
trusted library allocation
page execute and read and write
1272000
trusted library allocation
page read and write
2F4E000
stack
page read and write
32EF000
heap
page read and write
3268000
heap
page read and write
3269000
heap
page read and write
55F3000
heap
page read and write
32AC000
heap
page read and write
35C4000
trusted library allocation
page read and write
55F9000
heap
page read and write
3278000
heap
page read and write
35B1000
trusted library allocation
page read and write
2FB0000
heap
page read and write
55F6000
heap
page read and write
3570000
heap
page read and write
4541000
trusted library allocation
page read and write
329F000
heap
page read and write
341E000
unkown
page read and write
1295000
heap
page read and write
3310000
heap
page read and write
126A000
trusted library allocation
page execute and read and write
32CF000
heap
page read and write
32A9000
heap
page read and write
330F000
heap
page read and write
133C000
stack
page read and write
1390000
heap
page read and write
32AB000
heap
page read and write
32A9000
heap
page read and write
3276000
heap
page read and write
329F000
heap
page read and write
19DE000
stack
page read and write
2F5E000
stack
page read and write
1220000
trusted library allocation
page read and write
127B000
trusted library allocation
page execute and read and write
16DE000
stack
page read and write
1838000
trusted library allocation
page read and write
328F000
heap
page read and write
D80000
heap
page read and write
32AC000
heap
page read and write
55FC000
heap
page read and write
7FAC0000
trusted library allocation
page execute and read and write
327B000
heap
page read and write
55D0000
heap
page read and write
1436000
heap
page read and write
32AE000
heap
page read and write
55FD000
heap
page read and write
1370000
trusted library allocation
page execute and read and write
3297000
heap
page read and write
561C000
stack
page read and write
1277000
trusted library allocation
page execute and read and write
3000000
heap
page read and write
3318000
heap
page read and write
123A000
trusted library allocation
page execute and read and write
55FD000
heap
page read and write
32AD000
heap
page read and write
3240000
heap
page read and write
326F000
heap
page read and write
1250000
trusted library allocation
page read and write
32D2000
heap
page read and write
328F000
heap
page read and write
326E000
heap
page read and write
32AE000
heap
page read and write
1A30000
unclassified section
page read and write
3256000
heap
page read and write
3290000
heap
page read and write
32A9000
heap
page read and write
545F000
stack
page read and write
32AB000
heap
page read and write
32CF000
heap
page read and write
32D0000
heap
page read and write
55BE000
stack
page read and write
560C000
heap
page read and write
3560000
heap
page read and write
317E000
stack
page read and write
3318000
heap
page read and write
32D0000
heap
page read and write
32A7000
heap
page read and write
32A9000
heap
page read and write
DCE000
stack
page read and write
1490000
heap
page read and write
32A0000
heap
page read and write
327B000
heap
page read and write
32A9000
heap
page read and write
560A000
heap
page read and write
56D3000
heap
page read and write
327C000
heap
page read and write
3271000
heap
page read and write
5608000
heap
page read and write
32AE000
heap
page read and write
32AD000
heap
page read and write
32A0000
heap
page read and write
1458000
heap
page read and write
32AE000
heap
page read and write
326F000
heap
page read and write
329C000
heap
page read and write
35E1000
trusted library allocation
page read and write
3259000
heap
page read and write
1442000
heap
page read and write
3598000
trusted library allocation
page read and write
3294000
heap
page read and write
15D0000
heap
page read and write
D70000
heap
page read and write
3065000
heap
page read and write
15B0000
trusted library allocation
page read and write
1232000
trusted library allocation
page execute and read and write
329E000
heap
page read and write
18D6000
heap
page read and write
12E0000
heap
page read and write
32A6000
heap
page read and write
331E000
heap
page read and write
5460000
heap
page read and write
329F000
heap
page read and write
32AB000
heap
page read and write
329A000
heap
page read and write
3292000
heap
page read and write
3299000
heap
page read and write
3271000
heap
page read and write
3272000
heap
page read and write
3294000
heap
page read and write
326D000
heap
page read and write
1360000
trusted library allocation
page read and write
32CF000
heap
page read and write
351E000
stack
page read and write
3576000
heap
page read and write
32A1000
heap
page read and write
55DA000
stack
page read and write
330F000
heap
page read and write
3270000
heap
page read and write
3290000
heap
page read and write
55F3000
heap
page read and write
1380000
trusted library allocation
page read and write
3268000
heap
page read and write
2FFE000
unkown
page read and write
124A000
trusted library allocation
page execute and read and write
3220000
heap
page read and write
329E000
heap
page read and write
3296000
heap
page read and write
5C70000
heap
page read and write
3268000
heap
page read and write
358E000
trusted library allocation
page read and write
3290000
heap
page read and write
1A50000
heap
page read and write
18D0000
heap
page read and write
12DE000
stack
page read and write
D0A000
stack
page read and write
3259000
heap
page read and write
32F6000
heap
page read and write
56D0000
heap
page read and write
327C000
heap
page read and write
32F6000
heap
page read and write
3293000
heap
page read and write
32C4000
heap
page read and write
57CF000
stack
page read and write
32CF000
heap
page read and write
32AE000
heap
page read and write
327B000
heap
page read and write
3235000
heap
page read and write
326C000
heap
page read and write
329F000
heap
page read and write
35C7000
trusted library allocation
page read and write
331A000
heap
page read and write
327D000
heap
page read and write
3268000
heap
page read and write
C70000
unkown
page readonly
32A7000
heap
page read and write
1242000
trusted library allocation
page execute and read and write
328F000
heap
page read and write
35DA000
trusted library allocation
page read and write
35BD000
trusted library allocation
page read and write
139E000
heap
page read and write
329F000
heap
page read and write
1424000
heap
page read and write
32A9000
heap
page read and write
327B000
heap
page read and write
329E000
heap
page read and write
357E000
trusted library allocation
page read and write
32C4000
heap
page read and write
14A0000
heap
page read and write
5608000
heap
page read and write
3541000
trusted library allocation
page read and write
2F54000
stack
page read and write
2E5B000
stack
page read and write
32A0000
heap
page read and write
4D50000
heap
page read and write
32F1000
heap
page read and write
32C4000
heap
page read and write
32CF000
heap
page read and write
3292000
heap
page read and write
3311000
heap
page read and write
3231000
heap
page read and write
32AB000
heap
page read and write
3315000
heap
page read and write
32A9000
heap
page read and write
13D3000
heap
page read and write
139A000
heap
page read and write
32B0000
heap
page read and write
181C000
stack
page read and write
32AE000
heap
page read and write
3240000
heap
page read and write
1225000
trusted library allocation
page read and write
55FF000
heap
page read and write
There are 245 hidden memdumps, click here to show them.