IOC Report
w4oDGAPUMH.exe

loading gif

Files

File Path
Type
Category
Malicious
w4oDGAPUMH.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\w4oDGAPUMH.exe.log
ASCII text, with CRLF line terminators
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\w4oDGAPUMH.exe
"C:\Users\user\Desktop\w4oDGAPUMH.exe"
malicious

URLs

Name
IP
Malicious
217.119.129.17:1912
malicious
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Text
unknown
http://schemas.xmlsoap.org/ws/2005/02/sc/sct
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/sc/dk
unknown
http://tempuri.org/Entity/Id23ResponseD
unknown
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#HexBinary
unknown
http://tempuri.org/Entity/Id12Response
unknown
http://tempuri.org/
unknown
http://tempuri.org/Entity/Id2Response
unknown
http://schemas.xmlsoap.org/ws/2005/02/sc/dk/p_sha1
unknown
http://tempuri.org/Entity/Id21Response
unknown
http://schemas.xmlsoap.org/2005/02/trust/spnego#GSS_Wrap
unknown
http://tempuri.org/Entity/Id9
unknown
http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLID
unknown
http://tempuri.org/Entity/Id8
unknown
http://tempuri.org/Entity/Id5
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Prepare
unknown
http://tempuri.org/Entity/Id4
unknown
http://tempuri.org/Entity/Id7
unknown
http://tempuri.org/Entity/Id6
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust#BinarySecret
unknown
http://tempuri.org/Entity/Id19Response
unknown
http://docs.oasis-open.org/wss/oasis-wss-rel-token-profile-1.0.pdf#license
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/Issue
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Aborted
unknown
http://schemas.xmlsoap.org/ws/2005/02/rm/TerminateSequence
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/fault
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat
unknown
http://docs.oasis-open.org/wss/oasis-wss-soap-message-security-1.1#EncryptedKey
unknown
http://tempuri.org/Entity/Id15Response
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/SCT/Renew
unknown
http://schemas.xmlsoap.org/ws/2004/10/wscoor/Register
unknown
http://tempuri.org/Entity/Id6Response
unknown
http://schemas.xmlsoap.org/ws/2004/04/trust/SymmetricKey
unknown
https://api.ip.sb/ip
unknown
http://schemas.xmlsoap.org/ws/2004/04/sc
unknown
http://tempuri.org/Entity/Id1ResponseD
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Volatile2PC
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/SCT/Cancel
unknown
http://tempuri.org/Entity/Id9Response
unknown
http://tempuri.org/Entity/Id20
unknown
http://tempuri.org/Entity/Id21
unknown
http://tempuri.org/Entity/Id22
unknown
http://docs.oasis-open.org/wss/oasis-wss-kerberos-token-profile-1.1#Kerberosv5APREQSHA1
unknown
http://tempuri.org/Entity/Id23
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/CK/PSHA1
unknown
http://tempuri.org/Entity/Id24
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/RSTR/Issue
unknown
http://tempuri.org/Entity/Id24Response
unknown
http://tempuri.org/Entity/Id1Response
unknown
http://schemas.xmlsoap.org/ws/2005/02/rm/AckRequested
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/ReadOnly
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Replay
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/tlsnego
unknown
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Base64Binary
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Durable2PC
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/SymmetricKey
unknown
http://schemas.xmlsoap.org/ws/2004/08/addressing
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RST/Issue
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Completion
unknown
http://schemas.xmlsoap.org/ws/2004/04/trust
unknown
http://tempuri.org/Entity/Id10
unknown
http://tempuri.org/Entity/Id11
unknown
http://tempuri.org/Entity/Id12
unknown
http://tempuri.org/Entity/Id16Response
unknown
http://schemas.xmlsoap.org/ws/2004/10/wscoor/CreateCoordinationContextResponse
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RST/SCT/Cancel
unknown
http://tempuri.org/Entity/Id13
unknown
http://tempuri.org/Entity/Id14
unknown
http://tempuri.org/Entity/Id15
unknown
http://tempuri.org/Entity/Id16
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/Nonce
unknown
http://tempuri.org/Entity/Id17
unknown
http://tempuri.org/Entity/Id18
unknown
http://tempuri.org/Entity/Id5Response
unknown
http://tempuri.org/Entity/Id19
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/dns
unknown
http://tempuri.org/Entity/Id10Response
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/Renew
unknown
http://tempuri.org/Entity/Id8Response
unknown
http://schemas.xmlsoap.org/ws/2004/04/trust/PublicKey
unknown
http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLV2.0
unknown
http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.0#SAMLAssertionID
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/RST/SCT
unknown
http://schemas.xmlsoap.org/ws/2006/02/addressingidentity
unknown
http://schemas.xmlsoap.org/soap/envelope/
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/PublicKey
unknown
http://docs.oasis-open.org/wss/oasis-wss-soap-message-security-1.1#EncryptedKeySHA1
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Rollback
unknown
http://tempuri.org/Entity/Id3ResponseD
unknown
http://tempuri.org/Entity/Id23Response
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/RSTR/SCT
unknown
http://tempuri.org/D
unknown
http://schemas.xmlsoap.org/ws/2004/06/addressingex
unknown
http://schemas.xmlsoap.org/ws/2004/10/wscoor
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/Nonce
unknown
http://schemas.xmlsoap.org/ws/2005/02/rm/CreateSequenceResponse
unknown
http://schemas.xmlsoap.org/ws/2004/08/addressing/fault
unknown
There are 90 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
217.119.129.17
unknown
unknown
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFiles0000
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFilesHash

Memdumps

Base Address
Regiontype
Protect
Malicious
2DE4000
trusted library allocation
page read and write
malicious
A52000
unkown
page readonly
malicious
7831000
trusted library allocation
page read and write
71CF000
trusted library allocation
page read and write
1062000
trusted library allocation
page read and write
15AB000
heap
page read and write
105D000
trusted library allocation
page execute and read and write
70D2000
heap
page read and write
5261000
trusted library allocation
page read and write
734E000
stack
page read and write
1580000
trusted library allocation
page read and write
3D5F000
trusted library allocation
page read and write
104D000
trusted library allocation
page execute and read and write
5530000
heap
page execute and read and write
5F85000
heap
page read and write
5240000
trusted library allocation
page read and write
57E0000
trusted library allocation
page read and write
32AB000
trusted library allocation
page read and write
A82000
unkown
page readonly
336B000
trusted library allocation
page read and write
3144000
trusted library allocation
page read and write
1066000
trusted library allocation
page execute and read and write
3D51000
trusted library allocation
page read and write
40D5000
trusted library allocation
page read and write
5244000
trusted library allocation
page read and write
2FB1000
trusted library allocation
page read and write
6FB4000
heap
page read and write
57C0000
trusted library allocation
page execute and read and write
32B2000
trusted library allocation
page read and write
40C3000
trusted library allocation
page read and write
7300000
trusted library allocation
page read and write
5691000
trusted library allocation
page read and write
5F12000
heap
page read and write
6FED000
heap
page read and write
1220000
heap
page read and write
406A000
trusted library allocation
page read and write
2E8F000
trusted library allocation
page read and write
405D000
trusted library allocation
page read and write
6C8C000
stack
page read and write
92C6000
heap
page read and write
3315000
trusted library allocation
page read and write
3D7A000
trusted library allocation
page read and write
7065000
heap
page read and write
626E000
stack
page read and write
10C6000
heap
page read and write
3014000
trusted library allocation
page read and write
63B0000
trusted library allocation
page execute and read and write
6E40000
trusted library allocation
page execute and read and write
7FB0000
heap
page read and write
5F8C000
heap
page read and write
71F2000
trusted library allocation
page read and write
B19000
stack
page read and write
40DB000
trusted library allocation
page read and write
4096000
trusted library allocation
page read and write
B90000
heap
page read and write
11E0000
heap
page read and write
334C000
trusted library allocation
page read and write
6CEE000
stack
page read and write
3070000
trusted library allocation
page read and write
3385000
trusted library allocation
page read and write
72C0000
trusted library allocation
page read and write
3148000
trusted library allocation
page read and write
62AE000
stack
page read and write
6FF8000
heap
page read and write
616E000
stack
page read and write
EF7000
stack
page read and write
32C4000
trusted library allocation
page read and write
54D8000
trusted library allocation
page read and write
5F6A000
heap
page read and write
327D000
trusted library allocation
page read and write
3378000
trusted library allocation
page read and write
2E8B000
trusted library allocation
page read and write
56A2000
trusted library allocation
page read and write
3DCF000
trusted library allocation
page read and write
6FE5000
heap
page read and write
1060000
trusted library allocation
page read and write
72B0000
trusted library allocation
page read and write
6E00000
trusted library allocation
page read and write
726D000
stack
page read and write
146B000
stack
page read and write
52B0000
trusted library allocation
page read and write
142E000
stack
page read and write
72F0000
trusted library allocation
page execute and read and write
56B1000
trusted library allocation
page read and write
56C5000
trusted library allocation
page read and write
72E0000
trusted library allocation
page execute and read and write
5F92000
heap
page read and write
6FCE000
heap
page read and write
3D8B000
trusted library allocation
page read and write
3355000
trusted library allocation
page read and write
304D000
trusted library allocation
page read and write
5730000
trusted library allocation
page read and write
3D71000
trusted library allocation
page read and write
5760000
trusted library allocation
page read and write
524B000
trusted library allocation
page read and write
7FEB000
heap
page read and write
7044000
heap
page read and write
157E000
stack
page read and write
315F000
trusted library allocation
page read and write
8EAE000
stack
page read and write
15A7000
heap
page read and write
568B000
trusted library allocation
page read and write
1090000
heap
page read and write
5F4D000
heap
page read and write
5310000
heap
page read and write
1050000
trusted library allocation
page read and write
33C5000
trusted library allocation
page read and write
31F0000
trusted library allocation
page read and write
4089000
trusted library allocation
page read and write
5FEB000
heap
page read and write
3025000
trusted library allocation
page read and write
40A6000
trusted library allocation
page read and write
1190000
trusted library allocation
page read and write
307B000
trusted library allocation
page read and write
40B6000
trusted library allocation
page read and write
407E000
trusted library allocation
page read and write
3040000
trusted library allocation
page read and write
768E000
stack
page read and write
7025000
heap
page read and write
30FD000
trusted library allocation
page read and write
1210000
trusted library allocation
page execute and read and write
322C000
trusted library allocation
page read and write
1043000
trusted library allocation
page execute and read and write
335F000
trusted library allocation
page read and write
6E53000
trusted library allocation
page read and write
1030000
trusted library allocation
page read and write
71DA000
trusted library allocation
page read and write
2F49000
trusted library allocation
page read and write
5F14000
heap
page read and write
40CC000
trusted library allocation
page read and write
40EF000
trusted library allocation
page read and write
4077000
trusted library allocation
page read and write
52A5000
trusted library allocation
page read and write
7370000
heap
page read and write
52D0000
trusted library allocation
page read and write
3205000
trusted library allocation
page read and write
5280000
trusted library allocation
page read and write
2FDD000
trusted library allocation
page read and write
6A1C000
stack
page read and write
5F02000
heap
page read and write
3389000
trusted library allocation
page read and write
1044000
trusted library allocation
page read and write
5EFF000
heap
page read and write
5330000
trusted library allocation
page execute and read and write
5700000
trusted library allocation
page execute and read and write
7200000
trusted library allocation
page read and write
3154000
trusted library allocation
page read and write
32E5000
trusted library allocation
page read and write
7360000
trusted library allocation
page read and write
5FB0000
heap
page read and write
4D58000
trusted library allocation
page read and write
2F51000
trusted library allocation
page read and write
1020000
heap
page read and write
6C90000
trusted library allocation
page read and write
56D0000
trusted library allocation
page read and write
71C8000
trusted library allocation
page read and write
106A000
trusted library allocation
page execute and read and write
701A000
heap
page read and write
321C000
trusted library allocation
page read and write
57D0000
trusted library allocation
page read and write
71B2000
trusted library allocation
page read and write
31FD000
trusted library allocation
page read and write
1593000
heap
page read and write
56CB000
trusted library allocation
page read and write
71F5000
trusted library allocation
page read and write
56C0000
trusted library allocation
page read and write
5EE0000
trusted library allocation
page execute and read and write
31D6000
trusted library allocation
page read and write
5230000
trusted library allocation
page read and write
5F53000
heap
page read and write
40B0000
trusted library allocation
page read and write
3210000
trusted library allocation
page read and write
71D5000
trusted library allocation
page read and write
71B9000
trusted library allocation
page read and write
40BD000
trusted library allocation
page read and write
7840000
heap
page read and write
5750000
trusted library allocation
page read and write
5EF2000
heap
page read and write
2F4D000
trusted library allocation
page read and write
410F000
trusted library allocation
page read and write
54F0000
trusted library allocation
page read and write
B80000
heap
page read and write
780E000
stack
page read and write
310B000
trusted library allocation
page read and write
6E50000
trusted library allocation
page read and write
11DE000
stack
page read and write
76CE000
stack
page read and write
3FAF000
trusted library allocation
page read and write
56F0000
trusted library allocation
page read and write
2E7E000
trusted library allocation
page read and write
54DA000
trusted library allocation
page read and write
31CE000
trusted library allocation
page read and write
A50000
unkown
page readonly
5320000
trusted library allocation
page read and write
1040000
trusted library allocation
page read and write
3125000
trusted library allocation
page read and write
40D2000
trusted library allocation
page read and write
3054000
trusted library allocation
page read and write
56E0000
trusted library allocation
page read and write
54D5000
trusted library allocation
page read and write
602E000
stack
page read and write
10D3000
heap
page read and write
71B0000
trusted library allocation
page read and write
5290000
trusted library allocation
page read and write
5FE3000
heap
page read and write
6B3C000
stack
page read and write
5521000
trusted library allocation
page read and write
5740000
trusted library allocation
page read and write
3217000
trusted library allocation
page read and write
788B000
stack
page read and write
31C5000
trusted library allocation
page read and write
6B8E000
stack
page read and write
71E4000
trusted library allocation
page read and write
71F0000
trusted library allocation
page read and write
92B0000
heap
page read and write
5ED0000
trusted library allocation
page read and write
305F000
trusted library allocation
page read and write
3027000
trusted library allocation
page read and write
5322000
trusted library allocation
page read and write
40D0000
trusted library allocation
page read and write
71DF000
trusted library allocation
page read and write
7054000
heap
page read and write
326E000
trusted library allocation
page read and write
5F74000
heap
page read and write
2E7B000
trusted library allocation
page read and write
72AE000
stack
page read and write
5FA2000
heap
page read and write
79CE000
stack
page read and write
3137000
trusted library allocation
page read and write
107B000
trusted library allocation
page execute and read and write
7011000
heap
page read and write
7082000
heap
page read and write
3237000
trusted library allocation
page read and write
2E78000
trusted library allocation
page read and write
1072000
trusted library allocation
page read and write
420F000
trusted library allocation
page read and write
30EE000
trusted library allocation
page read and write
335D000
trusted library allocation
page read and write
30B5000
trusted library allocation
page read and write
109E000
heap
page read and write
770E000
stack
page read and write
100E000
stack
page read and write
5EB0000
trusted library allocation
page execute and read and write
71CA000
trusted library allocation
page read and write
40C7000
trusted library allocation
page read and write
7FDC0000
trusted library allocation
page execute and read and write
32CF000
trusted library allocation
page read and write
6E07000
trusted library allocation
page read and write
301D000
trusted library allocation
page read and write
56BA000
trusted library allocation
page read and write
1590000
heap
page read and write
6A30000
trusted library allocation
page execute and read and write
30F6000
trusted library allocation
page read and write
529E000
trusted library allocation
page read and write
3087000
trusted library allocation
page read and write
72D0000
trusted library allocation
page read and write
57B0000
trusted library allocation
page execute and read and write
567F000
stack
page read and write
52A0000
trusted library allocation
page read and write
1075000
trusted library allocation
page execute and read and write
3033000
trusted library allocation
page read and write
15A0000
heap
page read and write
557E000
stack
page read and write
5F79000
heap
page read and write
32BD000
trusted library allocation
page read and write
5F2E000
heap
page read and write
306B000
trusted library allocation
page read and write
312C000
trusted library allocation
page read and write
71E0000
trusted library allocation
page read and write
6FC0000
heap
page read and write
6DED000
stack
page read and write
1025000
heap
page read and write
4EEC000
stack
page read and write
30EC000
trusted library allocation
page read and write
2D51000
trusted library allocation
page read and write
31E3000
trusted library allocation
page read and write
54D0000
trusted library allocation
page read and write
2E88000
trusted library allocation
page read and write
7072000
heap
page read and write
32CA000
trusted library allocation
page read and write
1077000
trusted library allocation
page execute and read and write
132F000
stack
page read and write
313E000
trusted library allocation
page read and write
56AE000
trusted library allocation
page read and write
5FB5000
heap
page read and write
700B000
heap
page read and write
5266000
trusted library allocation
page read and write
612F000
stack
page read and write
526D000
trusted library allocation
page read and write
56CE000
trusted library allocation
page read and write
798D000
stack
page read and write
525E000
trusted library allocation
page read and write
5500000
heap
page read and write
409B000
trusted library allocation
page read and write
6EB0000
heap
page read and write
3D93000
trusted library allocation
page read and write
5696000
trusted library allocation
page read and write
5510000
trusted library allocation
page read and write
113B000
heap
page read and write
5680000
trusted library allocation
page read and write
3118000
trusted library allocation
page read and write
318D000
trusted library allocation
page read and write
71B5000
trusted library allocation
page read and write
5FD0000
heap
page read and write
6FB0000
heap
page read and write
32DA000
trusted library allocation
page read and write
11F0000
heap
page read and write
6E56000
trusted library allocation
page read and write
2E6F000
trusted library allocation
page read and write
63AE000
stack
page read and write
5EC0000
trusted library allocation
page read and write
30FF000
trusted library allocation
page read and write
1470000
heap
page execute and read and write
BDE000
stack
page read and write
5EF0000
heap
page read and write
5272000
trusted library allocation
page read and write
764E000
stack
page read and write
3066000
trusted library allocation
page read and write
1070000
trusted library allocation
page read and write
3221000
trusted library allocation
page read and write
There are 310 hidden memdumps, click here to show them.