Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
C9zGTJBy3T.exe
|
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
initial sample
|
||
C:\autorun.inf
|
Microsoft Windows Autorun file
|
dropped
|
||
C:\google.exe
|
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\google.exe:Zone.Identifier
|
ASCII text, with CRLF line terminators
|
dropped
|
||
\Device\ConDrv
|
ASCII text, with CRLF line terminators
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\C9zGTJBy3T.exe
|
"C:\Users\user\Desktop\C9zGTJBy3T.exe"
|
||
C:\Windows\SysWOW64\netsh.exe
|
netsh firewall add allowedprogram "C:\Users\user\Desktop\C9zGTJBy3T.exe" "C9zGTJBy3T.exe" ENABLE
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://dl.dropbox.com/s/p84aaz28t0hepul/Pass.exe?dl=0
|
unknown
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
0.tcp.eu.ngrok.io
|
3.125.209.94
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
3.125.223.134
|
unknown
|
United States
|
||
3.125.209.94
|
0.tcp.eu.ngrok.io
|
United States
|
||
18.192.31.165
|
unknown
|
United States
|
||
3.125.102.39
|
unknown
|
United States
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER
|
di
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
C72000
|
unkown
|
page readonly
|
||
3060000
|
heap
|
page read and write
|
||
331B000
|
heap
|
page read and write
|
||
32A9000
|
heap
|
page read and write
|
||
329E000
|
heap
|
page read and write
|
||
125A000
|
trusted library allocation
|
page execute and read and write
|
||
326C000
|
heap
|
page read and write
|
||
331E000
|
heap
|
page read and write
|
||
32F6000
|
heap
|
page read and write
|
||
13CF000
|
heap
|
page read and write
|
||
535E000
|
stack
|
page read and write
|
||
3293000
|
heap
|
page read and write
|
||
32A9000
|
heap
|
page read and write
|
||
32C4000
|
heap
|
page read and write
|
||
32A5000
|
heap
|
page read and write
|
||
1262000
|
trusted library allocation
|
page execute and read and write
|
||
32AB000
|
heap
|
page read and write
|
||
55FB000
|
heap
|
page read and write
|
||
1240000
|
trusted library allocation
|
page read and write
|
||
3292000
|
heap
|
page read and write
|
||
560B000
|
heap
|
page read and write
|
||
5609000
|
heap
|
page read and write
|
||
32A9000
|
heap
|
page read and write
|
||
1427000
|
heap
|
page read and write
|
||
1257000
|
trusted library allocation
|
page execute and read and write
|
||
3255000
|
heap
|
page read and write
|
||
10F6000
|
stack
|
page read and write
|
||
565D000
|
stack
|
page read and write
|
||
17DF000
|
stack
|
page read and write
|
||
5BA0000
|
heap
|
page read and write
|
||
3313000
|
heap
|
page read and write
|
||
330F000
|
heap
|
page read and write
|
||
56A0000
|
trusted library allocation
|
page execute and read and write
|
||
2F5B000
|
stack
|
page read and write
|
||
1820000
|
heap
|
page execute and read and write
|
||
3311000
|
heap
|
page read and write
|
||
C7C000
|
unkown
|
page readonly
|
||
32A5000
|
heap
|
page read and write
|
||
3313000
|
heap
|
page read and write
|
||
32A4000
|
heap
|
page read and write
|
||
32AC000
|
heap
|
page read and write
|
||
1270000
|
trusted library allocation
|
page read and write
|
||
1290000
|
heap
|
page read and write
|
||
3268000
|
heap
|
page read and write
|
||
3010000
|
heap
|
page read and write
|
||
5609000
|
heap
|
page read and write
|
||
1400000
|
heap
|
page read and write
|
||
326F000
|
heap
|
page read and write
|
||
3297000
|
heap
|
page read and write
|
||
55FC000
|
heap
|
page read and write
|
||
32A4000
|
heap
|
page read and write
|
||
3210000
|
heap
|
page read and write
|
||
5BB0000
|
heap
|
page read and write
|
||
326B000
|
heap
|
page read and write
|
||
15A0000
|
trusted library allocation
|
page execute and read and write
|
||
1272000
|
trusted library allocation
|
page read and write
|
||
2F4E000
|
stack
|
page read and write
|
||
32EF000
|
heap
|
page read and write
|
||
3268000
|
heap
|
page read and write
|
||
3269000
|
heap
|
page read and write
|
||
55F3000
|
heap
|
page read and write
|
||
32AC000
|
heap
|
page read and write
|
||
35C4000
|
trusted library allocation
|
page read and write
|
||
55F9000
|
heap
|
page read and write
|
||
3278000
|
heap
|
page read and write
|
||
35B1000
|
trusted library allocation
|
page read and write
|
||
2FB0000
|
heap
|
page read and write
|
||
55F6000
|
heap
|
page read and write
|
||
3570000
|
heap
|
page read and write
|
||
4541000
|
trusted library allocation
|
page read and write
|
||
329F000
|
heap
|
page read and write
|
||
341E000
|
unkown
|
page read and write
|
||
1295000
|
heap
|
page read and write
|
||
3310000
|
heap
|
page read and write
|
||
126A000
|
trusted library allocation
|
page execute and read and write
|
||
32CF000
|
heap
|
page read and write
|
||
32A9000
|
heap
|
page read and write
|
||
330F000
|
heap
|
page read and write
|
||
133C000
|
stack
|
page read and write
|
||
1390000
|
heap
|
page read and write
|
||
32AB000
|
heap
|
page read and write
|
||
32A9000
|
heap
|
page read and write
|
||
3276000
|
heap
|
page read and write
|
||
329F000
|
heap
|
page read and write
|
||
19DE000
|
stack
|
page read and write
|
||
2F5E000
|
stack
|
page read and write
|
||
1220000
|
trusted library allocation
|
page read and write
|
||
127B000
|
trusted library allocation
|
page execute and read and write
|
||
16DE000
|
stack
|
page read and write
|
||
1838000
|
trusted library allocation
|
page read and write
|
||
328F000
|
heap
|
page read and write
|
||
D80000
|
heap
|
page read and write
|
||
32AC000
|
heap
|
page read and write
|
||
55FC000
|
heap
|
page read and write
|
||
7FAC0000
|
trusted library allocation
|
page execute and read and write
|
||
327B000
|
heap
|
page read and write
|
||
55D0000
|
heap
|
page read and write
|
||
1436000
|
heap
|
page read and write
|
||
32AE000
|
heap
|
page read and write
|
||
55FD000
|
heap
|
page read and write
|
||
1370000
|
trusted library allocation
|
page execute and read and write
|
||
3297000
|
heap
|
page read and write
|
||
561C000
|
stack
|
page read and write
|
||
1277000
|
trusted library allocation
|
page execute and read and write
|
||
3000000
|
heap
|
page read and write
|
||
3318000
|
heap
|
page read and write
|
||
123A000
|
trusted library allocation
|
page execute and read and write
|
||
55FD000
|
heap
|
page read and write
|
||
32AD000
|
heap
|
page read and write
|
||
3240000
|
heap
|
page read and write
|
||
326F000
|
heap
|
page read and write
|
||
1250000
|
trusted library allocation
|
page read and write
|
||
32D2000
|
heap
|
page read and write
|
||
328F000
|
heap
|
page read and write
|
||
326E000
|
heap
|
page read and write
|
||
32AE000
|
heap
|
page read and write
|
||
1A30000
|
unclassified section
|
page read and write
|
||
3256000
|
heap
|
page read and write
|
||
3290000
|
heap
|
page read and write
|
||
32A9000
|
heap
|
page read and write
|
||
545F000
|
stack
|
page read and write
|
||
32AB000
|
heap
|
page read and write
|
||
32CF000
|
heap
|
page read and write
|
||
32D0000
|
heap
|
page read and write
|
||
55BE000
|
stack
|
page read and write
|
||
560C000
|
heap
|
page read and write
|
||
3560000
|
heap
|
page read and write
|
||
317E000
|
stack
|
page read and write
|
||
3318000
|
heap
|
page read and write
|
||
32D0000
|
heap
|
page read and write
|
||
32A7000
|
heap
|
page read and write
|
||
32A9000
|
heap
|
page read and write
|
||
DCE000
|
stack
|
page read and write
|
||
1490000
|
heap
|
page read and write
|
||
32A0000
|
heap
|
page read and write
|
||
327B000
|
heap
|
page read and write
|
||
32A9000
|
heap
|
page read and write
|
||
560A000
|
heap
|
page read and write
|
||
56D3000
|
heap
|
page read and write
|
||
327C000
|
heap
|
page read and write
|
||
3271000
|
heap
|
page read and write
|
||
5608000
|
heap
|
page read and write
|
||
32AE000
|
heap
|
page read and write
|
||
32AD000
|
heap
|
page read and write
|
||
32A0000
|
heap
|
page read and write
|
||
1458000
|
heap
|
page read and write
|
||
32AE000
|
heap
|
page read and write
|
||
326F000
|
heap
|
page read and write
|
||
329C000
|
heap
|
page read and write
|
||
35E1000
|
trusted library allocation
|
page read and write
|
||
3259000
|
heap
|
page read and write
|
||
1442000
|
heap
|
page read and write
|
||
3598000
|
trusted library allocation
|
page read and write
|
||
3294000
|
heap
|
page read and write
|
||
15D0000
|
heap
|
page read and write
|
||
D70000
|
heap
|
page read and write
|
||
3065000
|
heap
|
page read and write
|
||
15B0000
|
trusted library allocation
|
page read and write
|
||
1232000
|
trusted library allocation
|
page execute and read and write
|
||
329E000
|
heap
|
page read and write
|
||
18D6000
|
heap
|
page read and write
|
||
12E0000
|
heap
|
page read and write
|
||
32A6000
|
heap
|
page read and write
|
||
331E000
|
heap
|
page read and write
|
||
5460000
|
heap
|
page read and write
|
||
329F000
|
heap
|
page read and write
|
||
32AB000
|
heap
|
page read and write
|
||
329A000
|
heap
|
page read and write
|
||
3292000
|
heap
|
page read and write
|
||
3299000
|
heap
|
page read and write
|
||
3271000
|
heap
|
page read and write
|
||
3272000
|
heap
|
page read and write
|
||
3294000
|
heap
|
page read and write
|
||
326D000
|
heap
|
page read and write
|
||
1360000
|
trusted library allocation
|
page read and write
|
||
32CF000
|
heap
|
page read and write
|
||
351E000
|
stack
|
page read and write
|
||
3576000
|
heap
|
page read and write
|
||
32A1000
|
heap
|
page read and write
|
||
55DA000
|
stack
|
page read and write
|
||
330F000
|
heap
|
page read and write
|
||
3270000
|
heap
|
page read and write
|
||
3290000
|
heap
|
page read and write
|
||
55F3000
|
heap
|
page read and write
|
||
1380000
|
trusted library allocation
|
page read and write
|
||
3268000
|
heap
|
page read and write
|
||
2FFE000
|
unkown
|
page read and write
|
||
124A000
|
trusted library allocation
|
page execute and read and write
|
||
3220000
|
heap
|
page read and write
|
||
329E000
|
heap
|
page read and write
|
||
3296000
|
heap
|
page read and write
|
||
5C70000
|
heap
|
page read and write
|
||
3268000
|
heap
|
page read and write
|
||
358E000
|
trusted library allocation
|
page read and write
|
||
3290000
|
heap
|
page read and write
|
||
1A50000
|
heap
|
page read and write
|
||
18D0000
|
heap
|
page read and write
|
||
12DE000
|
stack
|
page read and write
|
||
D0A000
|
stack
|
page read and write
|
||
3259000
|
heap
|
page read and write
|
||
32F6000
|
heap
|
page read and write
|
||
56D0000
|
heap
|
page read and write
|
||
327C000
|
heap
|
page read and write
|
||
32F6000
|
heap
|
page read and write
|
||
3293000
|
heap
|
page read and write
|
||
32C4000
|
heap
|
page read and write
|
||
57CF000
|
stack
|
page read and write
|
||
32CF000
|
heap
|
page read and write
|
||
32AE000
|
heap
|
page read and write
|
||
327B000
|
heap
|
page read and write
|
||
3235000
|
heap
|
page read and write
|
||
326C000
|
heap
|
page read and write
|
||
329F000
|
heap
|
page read and write
|
||
35C7000
|
trusted library allocation
|
page read and write
|
||
331A000
|
heap
|
page read and write
|
||
327D000
|
heap
|
page read and write
|
||
3268000
|
heap
|
page read and write
|
||
C70000
|
unkown
|
page readonly
|
||
32A7000
|
heap
|
page read and write
|
||
1242000
|
trusted library allocation
|
page execute and read and write
|
||
328F000
|
heap
|
page read and write
|
||
35DA000
|
trusted library allocation
|
page read and write
|
||
35BD000
|
trusted library allocation
|
page read and write
|
||
139E000
|
heap
|
page read and write
|
||
329F000
|
heap
|
page read and write
|
||
1424000
|
heap
|
page read and write
|
||
32A9000
|
heap
|
page read and write
|
||
327B000
|
heap
|
page read and write
|
||
329E000
|
heap
|
page read and write
|
||
357E000
|
trusted library allocation
|
page read and write
|
||
32C4000
|
heap
|
page read and write
|
||
14A0000
|
heap
|
page read and write
|
||
5608000
|
heap
|
page read and write
|
||
3541000
|
trusted library allocation
|
page read and write
|
||
2F54000
|
stack
|
page read and write
|
||
2E5B000
|
stack
|
page read and write
|
||
32A0000
|
heap
|
page read and write
|
||
4D50000
|
heap
|
page read and write
|
||
32F1000
|
heap
|
page read and write
|
||
32C4000
|
heap
|
page read and write
|
||
32CF000
|
heap
|
page read and write
|
||
3292000
|
heap
|
page read and write
|
||
3311000
|
heap
|
page read and write
|
||
3231000
|
heap
|
page read and write
|
||
32AB000
|
heap
|
page read and write
|
||
3315000
|
heap
|
page read and write
|
||
32A9000
|
heap
|
page read and write
|
||
13D3000
|
heap
|
page read and write
|
||
139A000
|
heap
|
page read and write
|
||
32B0000
|
heap
|
page read and write
|
||
181C000
|
stack
|
page read and write
|
||
32AE000
|
heap
|
page read and write
|
||
3240000
|
heap
|
page read and write
|
||
1225000
|
trusted library allocation
|
page read and write
|
||
55FF000
|
heap
|
page read and write
|
There are 245 hidden memdumps, click here to show them.