Source: 0.2.Request for Tender Quotation.exe.43b9860.3.raw.unpack |
Malware Configuration Extractor: RedLine {"C2 url": ["198.12.90.244:49780"], "Bot Id": "success", "Authorization Header": "c74790bd166600f1f665c8ce201776eb"} |
Source: Request for Tender Quotation.exe |
Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Source: |
Binary string: C:\Windows\System.ServiceModel.pdbpdbdel.pdb source: Request for Tender Quotation.exe, 0000000A.00000002.3424586120.0000000001866000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\dll\System.ServiceModel.pdb source: Request for Tender Quotation.exe, 0000000A.00000002.3424586120.0000000001866000.00000004.00000020.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3422939745.00000000014E8000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\System.ServiceModel.pdb source: Request for Tender Quotation.exe, 0000000A.00000002.3424586120.00000000018CB000.00000004.00000020.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3422939745.0000000001594000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\dll\System.ServiceModel.pdb0 source: Request for Tender Quotation.exe, 0000000A.00000002.3424586120.0000000001866000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: C:\Windows\System.ServiceModel.pdbpdbdel.pdb source: BtsoqoHwldFQNw.exe, 0000000F.00000002.3422939745.00000000014E8000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: System.ServiceModel.pdb source: Request for Tender Quotation.exe, 0000000A.00000002.3424586120.0000000001901000.00000004.00000020.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3422939745.0000000001586000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.pdb source: Request for Tender Quotation.exe, 0000000A.00000002.3424586120.0000000001866000.00000004.00000020.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3422939745.00000000014E8000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\System.ServiceModel.pdbY source: BtsoqoHwldFQNw.exe, 0000000F.00000002.3422939745.0000000001594000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\symbols\dll\System.ServiceModel.pdb source: Request for Tender Quotation.exe, 0000000A.00000002.3424586120.0000000001866000.00000004.00000020.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3422939745.00000000014E8000.00000004.00000020.00020000.00000000.sdmp |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.12.90.244 |
Source: Request for Tender Quotation.exe, 0000000A.00000002.3426922416.00000000034F1000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.0000000003291000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/soap/actor/next |
Source: Request for Tender Quotation.exe, 0000000A.00000002.3426922416.00000000034F1000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.0000000003291000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/ |
Source: Request for Tender Quotation.exe, 0000000A.00000002.3426922416.00000000034F1000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.0000000003291000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing |
Source: Request for Tender Quotation.exe, 0000000A.00000002.3426922416.00000000034F1000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.0000000003291000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/fault |
Source: Request for Tender Quotation.exe, 0000000A.00000002.3426922416.00000000034F1000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.0000000003291000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous |
Source: Request for Tender Quotation.exe, 0000000A.00000002.3426922416.00000000034F1000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.0000000003291000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/AckRequested |
Source: Request for Tender Quotation.exe, 0000000A.00000002.3426922416.00000000034F1000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.0000000003291000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/CreateSequence |
Source: Request for Tender Quotation.exe, 0000000A.00000002.3426922416.00000000034F1000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.0000000003291000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/CreateSequenceResponse |
Source: Request for Tender Quotation.exe, 0000000A.00000002.3426922416.00000000034F1000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.0000000003291000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/LastMessage |
Source: Request for Tender Quotation.exe, 0000000A.00000002.3426922416.00000000034F1000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.0000000003291000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/SequenceAcknowledgement |
Source: Request for Tender Quotation.exe, 0000000A.00000002.3426922416.00000000034F1000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.0000000003291000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/TerminateSequence |
Source: Request for Tender Quotation.exe, 0000000A.00000002.3426922416.00000000034F1000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.0000000003291000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rmX |
Source: Request for Tender Quotation.exe, 0000000A.00000002.3426922416.00000000034F1000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.0000000003291000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/dns |
Source: Request for Tender Quotation.exe, 00000000.00000002.2210989615.0000000003324000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000B.00000002.2291032391.0000000003054000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: Request for Tender Quotation.exe, 0000000A.00000002.3426922416.00000000034F1000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.0000000003291000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/right/possessproperty |
Source: Request for Tender Quotation.exe, 0000000A.00000002.3426922416.00000000034F1000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.0000000003291000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/ |
Source: BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.0000000003291000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.000000000357C000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.000000000352E000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.00000000034DF000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.0000000003668000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.000000000361A000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.00000000035CB000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Ent |
Source: BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.0000000003843000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.00000000035CB000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/ |
Source: Request for Tender Quotation.exe, 0000000A.00000002.3426922416.0000000003653000.00000004.00000800.00020000.00000000.sdmp, Request for Tender Quotation.exe, 0000000A.00000002.3426922416.00000000037DC000.00000004.00000800.00020000.00000000.sdmp, Request for Tender Quotation.exe, 0000000A.00000002.3426922416.000000000387A000.00000004.00000800.00020000.00000000.sdmp, Request for Tender Quotation.exe, 0000000A.00000002.3426922416.00000000035FE000.00000004.00000800.00020000.00000000.sdmp, Request for Tender Quotation.exe, 0000000A.00000002.3426922416.000000000373F000.00000004.00000800.00020000.00000000.sdmp, Request for Tender Quotation.exe, 0000000A.00000002.3426922416.000000000378E000.00000004.00000800.00020000.00000000.sdmp, Request for Tender Quotation.exe, 0000000A.00000002.3426922416.00000000039B5000.00000004.00000800.00020000.00000000.sdmp, Request for Tender Quotation.exe, 0000000A.00000002.3426922416.00000000034F1000.00000004.00000800.00020000.00000000.sdmp, Request for Tender Quotation.exe, 0000000A.00000002.3426922416.00000000036F0000.00000004.00000800.00020000.00000000.sdmp, Request for Tender Quotation.exe, 0000000A.00000002.3426922416.0000000003917000.00000004.00000800.00020000.00000000.sdmp, Request for Tender Quotation.exe, 0000000A.00000002.3426922416.00000000036A2000.00000004.00000800.00020000.00000000.sdmp, Request for Tender Quotation.exe, 0000000A.00000002.3426922416.000000000382B000.00000004.00000800.00020000.00000000.sdmp, Request for Tender Quotation.exe, 0000000A.00000002.3426922416.00000000038C9000.00000004.00000800.00020000.00000000.sdmp, Request for Tender Quotation.exe, 0000000A.00000002.3426922416.0000000003966000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.000000000339E000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.0000000003706000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.0000000003755000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.00000000033F3000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.0000000003490000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.0000000003442000.00000004.00000800.00020000.00000000.sdmp, BtsoqoHwldFQNw.exe, 0000000F.00000002.3425316831.00000000036B7000.00000004.00000800.00020000.0 |