Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
SecuriteInfo.com.Win32.Evo-gen.3521.549.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T9RRWRNL\json[1].json
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Roaming\Key\logs.dat
|
data
|
dropped
|
||
C:\Users\user\Pictures\TermianlConsole\TerminalIll.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.3521.549.exe
|
"C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.3521.549.exe"
|
||
C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.3521.549.exe
|
"C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.3521.549.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
hotsdefender.webredirect.org
|
|||
http://geoplugin.net/json.gp
|
178.237.33.50
|
||
http://geoplugin.net/json.gp%
|
unknown
|
||
http://geoplugin.net/json.gp/C
|
unknown
|
||
http://geoplugin.net/json.gpP
|
unknown
|
||
http://geoplugin.net/json.gpSystem32
|
unknown
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
hotsdefender.webredirect.org
|
5.34.182.173
|
||
geoplugin.net
|
178.237.33.50
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
5.34.182.173
|
hotsdefender.webredirect.org
|
Ukraine
|
||
178.237.33.50
|
geoplugin.net
|
Netherlands
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
|
AdvancedUpdater
|
||
HKEY_CURRENT_USER\SOFTWARE\Ag0s70JwbdycP5ikGBT/VhjSeXFA==-S28M8P
|
exepath
|
||
HKEY_CURRENT_USER\SOFTWARE\Ag0s70JwbdycP5ikGBT/VhjSeXFA==-S28M8P
|
licence
|
||
HKEY_CURRENT_USER\SOFTWARE\Ag0s70JwbdycP5ikGBT/VhjSeXFA==-S28M8P
|
time
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
46A0000
|
remote allocation
|
page execute and read and write
|
||
51C000
|
unkown
|
page execute and read and write
|
||
49A7000
|
heap
|
page read and write
|
||
6300000
|
direct allocation
|
page execute and read and write
|
||
515000
|
unkown
|
page write copy
|
||
401000
|
unkown
|
page execute read
|
||
4A2C000
|
heap
|
page read and write
|
||
664C000
|
stack
|
page read and write
|
||
616000
|
unkown
|
page readonly
|
||
401000
|
unkown
|
page execute read
|
||
519000
|
unkown
|
page write copy
|
||
9C000
|
stack
|
page read and write
|
||
621000
|
unkown
|
page execute and read and write
|
||
476C000
|
stack
|
page read and write
|
||
4870000
|
heap
|
page read and write
|
||
51A000
|
unkown
|
page readonly
|
||
686000
|
unkown
|
page readonly
|
||
4A2F000
|
stack
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
60A000
|
unkown
|
page readonly
|
||
4A26000
|
heap
|
page read and write
|
||
48D0000
|
heap
|
page read and write
|
||
60A000
|
unkown
|
page execute and write copy
|
||
4D6F000
|
stack
|
page read and write
|
||
4780000
|
heap
|
page read and write
|
||
61E000
|
unkown
|
page readonly
|
||
4A05000
|
heap
|
page read and write
|
||
60A000
|
unkown
|
page readonly
|
||
66C3000
|
direct allocation
|
page read and write
|
||
4A26000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
62F0000
|
heap
|
page read and write
|
||
64F0000
|
direct allocation
|
page read and write
|
||
5D8000
|
unkown
|
page readonly
|
||
5D8000
|
unkown
|
page readonly
|
||
4A2C000
|
heap
|
page read and write
|
||
5E7000
|
unkown
|
page readonly
|
||
51A000
|
unkown
|
page readonly
|
||
627000
|
unkown
|
page readonly
|
||
4E2000
|
unkown
|
page readonly
|
||
486C000
|
stack
|
page read and write
|
||
60A000
|
unkown
|
page readonly
|
||
49E8000
|
heap
|
page read and write
|
||
4A26000
|
heap
|
page read and write
|
||
659000
|
unkown
|
page readonly
|
||
4B2F000
|
stack
|
page read and write
|
||
616000
|
unkown
|
page readonly
|
||
5E7000
|
unkown
|
page readonly
|
||
619000
|
unkown
|
page execute and read and write
|
||
61E000
|
unkown
|
page execute and write copy
|
||
4980000
|
heap
|
page read and write
|
||
47CE000
|
stack
|
page read and write
|
||
59B000
|
unkown
|
page readonly
|
||
74EF000
|
stack
|
page read and write
|
||
4A15000
|
heap
|
page read and write
|
||
198000
|
stack
|
page read and write
|
||
48E0000
|
heap
|
page read and write
|
||
627000
|
unkown
|
page readonly
|
||
62B000
|
unkown
|
page execute and read and write
|
||
5D5000
|
unkown
|
page readonly
|
||
5E7000
|
unkown
|
page readonly
|
||
6378000
|
direct allocation
|
page execute and read and write
|
||
48CE000
|
stack
|
page read and write
|
||
65D000
|
unkown
|
page execute and read and write
|
||
49F6000
|
heap
|
page read and write
|
||
4E2000
|
unkown
|
page readonly
|
||
4E2000
|
unkown
|
page readonly
|
||
627000
|
unkown
|
page execute and write copy
|
||
73EE000
|
stack
|
page read and write
|
||
6A2E000
|
stack
|
page read and write
|
||
481E000
|
stack
|
page read and write
|
||
59B000
|
unkown
|
page readonly
|
||
4A1C000
|
heap
|
page read and write
|
||
497E000
|
stack
|
page read and write
|
||
660F000
|
stack
|
page read and write
|
||
4714000
|
remote allocation
|
page execute and read and write
|
||
4837000
|
heap
|
page read and write
|
||
59B000
|
unkown
|
page readonly
|
||
401000
|
unkown
|
page execute read
|
||
4A1C000
|
heap
|
page read and write
|
||
5D5000
|
unkown
|
page readonly
|
||
5E7000
|
unkown
|
page readonly
|
||
46A0000
|
heap
|
page read and write
|
||
49A0000
|
heap
|
page read and write
|
||
5D8000
|
unkown
|
page readonly
|
||
4880000
|
heap
|
page readonly
|
||
4A16000
|
heap
|
page read and write
|
||
48E5000
|
heap
|
page read and write
|
||
519000
|
unkown
|
page readonly
|
||
4B70000
|
heap
|
page read and write
|
||
674F000
|
stack
|
page read and write
|
||
68CE000
|
stack
|
page read and write
|
||
66C0000
|
direct allocation
|
page read and write
|
||
66F6000
|
direct allocation
|
page read and write
|
||
64E0000
|
heap
|
page read and write
|
||
6709000
|
direct allocation
|
page read and write
|
||
59B000
|
unkown
|
page readonly
|
||
5D8000
|
unkown
|
page readonly
|
||
66D2000
|
direct allocation
|
page read and write
|
||
4A2C000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
659000
|
unkown
|
page execute and write copy
|
||
4A05000
|
heap
|
page read and write
|
||
515000
|
unkown
|
page write copy
|
||
515000
|
unkown
|
page read and write
|
||
6686000
|
direct allocation
|
page read and write
|
||
4A1C000
|
heap
|
page read and write
|
||
678C000
|
stack
|
page read and write
|
||
6745000
|
direct allocation
|
page read and write
|
||
688F000
|
stack
|
page read and write
|
||
60E000
|
unkown
|
page execute and read and write
|
||
616000
|
unkown
|
page execute and write copy
|
||
69D0000
|
heap
|
page read and write
|
||
4E2000
|
unkown
|
page readonly
|
||
49E8000
|
heap
|
page read and write
|
||
4718000
|
remote allocation
|
page execute and read and write
|
||
47D0000
|
heap
|
page read and write
|
||
6B2F000
|
stack
|
page read and write
|
||
66DC000
|
direct allocation
|
page read and write
|
||
4830000
|
heap
|
page read and write
|
||
659000
|
unkown
|
page readonly
|
||
49D9000
|
heap
|
page read and write
|
||
61E000
|
unkown
|
page readonly
|
||
69CF000
|
stack
|
page read and write
|
||
5D5000
|
unkown
|
page readonly
|
||
607000
|
unkown
|
page execute and write copy
|
||
49F6000
|
heap
|
page read and write
|
||
519000
|
unkown
|
page write copy
|
||
516000
|
unkown
|
page write copy
|
||
515000
|
unkown
|
page write copy
|
||
401000
|
unkown
|
page execute read
|
||
5D5000
|
unkown
|
page readonly
|
||
51A000
|
unkown
|
page readonly
|
||
627000
|
unkown
|
page readonly
|
||
659000
|
unkown
|
page readonly
|
||
616000
|
unkown
|
page readonly
|
||
400000
|
unkown
|
page readonly
|
||
61E000
|
unkown
|
page readonly
|
||
519000
|
unkown
|
page write copy
|
There are 129 hidden memdumps, click here to show them.