IOC Report
a7HdB2dU5P.exe

loading gif

Files

File Path
Type
Category
Malicious
a7HdB2dU5P.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\a7HdB2dU5P.exe.log
CSV text
modified
malicious
\Device\ConDrv
ASCII text, with CRLF, LF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\a7HdB2dU5P.exe
"C:\Users\user\Desktop\a7HdB2dU5P.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
https://drawzhotdog.shop/api
104.21.58.182
malicious
lootebarrkeyn.shop
malicious
https://performenj.shop/vo
unknown
malicious
https://gutterydhowi.shop/api
104.21.4.136
malicious
reinforcenh.shop
malicious
stogeneratmns.shop
malicious
https://offensivedzvju.shop/
unknown
malicious
https://performenj.shop/apiG
unknown
malicious
https://reinforcenh.shop/api
104.21.77.130
malicious
ghostreedmnu.shop
malicious
https://reinforcenh.shop/
unknown
malicious
https://reinforcenh.shop/api2
unknown
malicious
https://drawzhotdog.shop/
unknown
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
https://performenj.shop/
unknown
malicious
https://vozmeatillu.shop/Y
unknown
malicious
https://vozmeatillu.shop/api
188.114.96.3
malicious
https://stogeneratmns.shop/api
188.114.96.3
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
https://ghostreedmnu.shop/api
188.114.97.3
malicious
fragnantbui.shop
malicious
gutterydhowi.shop
malicious
https://offensivedzvju.shop/api
188.114.96.3
malicious
https://stogeneratmns.shop/apiD
unknown
malicious
https://fragnantbui.shop/api
188.114.97.3
malicious
offensivedzvju.shop
malicious
drawzhotdog.shop
malicious
https://performenj.shop/G
unknown
malicious
https://performenj.shop/api
172.67.189.2
malicious
vozmeatillu.shop
malicious
https://steamcommunity.com/profiles/76561199724331900/badges
unknown
malicious
https://player.vimeo.com
unknown
https://community.akamai.steamstatic.com/
unknown
https://www.gstatic.cn/recaptcha/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
https://recaptcha.net/recaptcha/;
unknown
https://www.youtube.com
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=nSnUuYf7g6U1&a
unknown
https://www.google.com
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://steamcommunity.com/K
unknown
https://s.ytimg.com;
unknown
https://login.steampowered.com/
unknown
https://store.steampowered.com/legal/
unknown
https://steam.tv/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=WnGP
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://store.steampowered.com/
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
https://www.youtube.com/
unknown
http://127.0.0.1:27060
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=PzKBszTg
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://help.steampowered.com/
unknown
https://api.steampowered.com/
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://steamcommunity.com/
unknown
https://store.steampowered.com/;
unknown
https://steamcommunity.com/x
unknown
There are 57 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
fragnantbui.shop
188.114.97.3
malicious
performenj.shop
172.67.189.2
malicious
gutterydhowi.shop
104.21.4.136
malicious
offensivedzvju.shop
188.114.96.3
malicious
stogeneratmns.shop
188.114.96.3
malicious
reinforcenh.shop
104.21.77.130
malicious
drawzhotdog.shop
104.21.58.182
malicious
ghostreedmnu.shop
188.114.97.3
malicious
vozmeatillu.shop
188.114.96.3
malicious
lootebarrkeyn.shop
unknown
malicious
steamcommunity.com
104.102.49.254
There are 1 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.21.77.130
reinforcenh.shop
United States
malicious
104.21.4.136
gutterydhowi.shop
United States
malicious
172.67.189.2
performenj.shop
United States
malicious
188.114.97.3
fragnantbui.shop
European Union
malicious
188.114.96.3
offensivedzvju.shop
European Union
malicious
104.21.58.182
drawzhotdog.shop
United States
malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
355F000
stack
page read and write
D63000
heap
page read and write
B10000
heap
page read and write
C3B000
trusted library allocation
page execute and read and write
130E000
heap
page read and write
A30000
heap
page read and write
CA0000
heap
page read and write
CF0000
trusted library allocation
page read and write
C03000
trusted library allocation
page execute and read and write
C37000
trusted library allocation
page execute and read and write
6CC000
stack
page read and write
F1F000
stack
page read and write
D4D000
heap
page read and write
1276000
heap
page read and write
2E2F000
stack
page read and write
345E000
stack
page read and write
C10000
trusted library allocation
page read and write
D28000
heap
page read and write
D00000
heap
page execute and read and write
C16000
trusted library allocation
page read and write
D55000
heap
page read and write
5D0000
unkown
page readonly
2E6D000
stack
page read and write
C80000
heap
page read and write
1265000
heap
page read and write
38C1000
trusted library allocation
page read and write
38C5000
trusted library allocation
page read and write
28BE000
stack
page read and write
BBE000
stack
page read and write
B75000
heap
page read and write
400000
remote allocation
page execute and read and write
1050000
heap
page read and write
101F000
stack
page read and write
11B0000
heap
page read and write
128D000
heap
page read and write
28C1000
trusted library allocation
page execute and read and write
499E000
stack
page read and write
DEC000
stack
page read and write
C14000
trusted library allocation
page read and write
D2E000
heap
page read and write
7C8000
stack
page read and write
126D000
heap
page read and write
B5E000
stack
page read and write
12ED000
heap
page read and write
369E000
stack
page read and write
28C3000
trusted library allocation
page read and write
D20000
heap
page read and write
1145000
heap
page read and write
D48000
heap
page read and write
12E4000
heap
page read and write
5D2000
unkown
page readonly
2BEF000
stack
page read and write
BE0000
trusted library allocation
page read and write
2CEE000
stack
page read and write
CEE000
stack
page read and write
1240000
heap
page read and write
1140000
heap
page read and write
62E000
unkown
page readonly
C2A000
trusted library allocation
page execute and read and write
359E000
stack
page read and write
4A9E000
stack
page read and write
33FD000
stack
page read and write
14D0000
heap
page read and write
2D2E000
stack
page read and write
124A000
heap
page read and write
C04000
trusted library allocation
page read and write
11AE000
stack
page read and write
1300000
heap
page read and write
C60000
trusted library allocation
page execute and read and write
32FE000
stack
page read and write
460000
remote allocation
page execute and read and write
BF0000
heap
page read and write
B70000
heap
page read and write
1130000
heap
page read and write
2F6D000
stack
page read and write
120E000
stack
page read and write
CEC000
stack
page read and write
12A1000
heap
page read and write
C70000
heap
page read and write
There are 69 hidden memdumps, click here to show them.