IOC Report
SecuriteInfo.com.Trojan.MulDrop28.21322.11416.10977.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.Trojan.MulDrop28.21322.11416.10977.exe
"C:\Users\user\Desktop\SecuriteInfo.com.Trojan.MulDrop28.21322.11416.10977.exe"
malicious

URLs

Name
IP
Malicious
119.91.152.151
malicious
http://114.132.64.209:9652/mstsc.exe
114.132.64.209
http://114.132.64.209/
unknown
http://114.132.64.209:9652/mstsc.exeTx
unknown
http://114.132.64.209:9652/mstsc.exeC:
unknown

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.210.172
fp2e7a.wpc.phicdn.net
192.229.221.95

IPs

IP
Domain
Country
Malicious
119.91.152.151
unknown
China
malicious
114.132.64.209
unknown
China

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Rsymwe miusskwq
ConnectGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Rsymwe miusskwq
MarkTime
HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum
Version

Memdumps

Base Address
Regiontype
Protect
Malicious
992000
unkown
page read and write
malicious
10015000
direct allocation
page readonly
malicious
300E000
stack
page read and write
1208000
heap
page read and write
349E000
direct allocation
page read and write
10000000
direct allocation
page read and write
426E000
stack
page read and write
9E0000
unkown
page read and write
3DDF000
stack
page read and write
40DC000
stack
page read and write
351B000
stack
page read and write
FC0000
heap
page read and write
3781000
heap
page read and write
92A000
unkown
page readonly
308C000
stack
page read and write
3780000
heap
page read and write
11BE000
heap
page read and write
FC6000
heap
page read and write
411E000
stack
page read and write
9E7000
unkown
page readonly
6D0000
unkown
page readonly
376F000
stack
page read and write
92A000
unkown
page readonly
2CA0000
heap
page read and write
3FDF000
stack
page read and write
117A000
heap
page read and write
11E1000
heap
page read and write
2EC0000
heap
page read and write
F90000
heap
page read and write
2D20000
heap
page read and write
3EDE000
stack
page read and write
10001000
direct allocation
page execute read
1214000
heap
page read and write
2CE0000
heap
page read and write
9D8000
unkown
page write copy
421E000
stack
page read and write
6D1000
unkown
page execute read
9E7000
unkown
page readonly
1170000
heap
page read and write
11B1000
heap
page read and write
3094000
heap
page read and write
3090000
heap
page read and write
376D000
stack
page read and write
117E000
heap
page read and write
1150000
heap
page read and write
2CE3000
heap
page read and write
6D0000
unkown
page readonly
1160000
heap
page read and write
2CC0000
heap
page read and write
F80000
heap
page read and write
30A0000
direct allocation
page read and write
992000
unkown
page write copy
1001B000
direct allocation
page read and write
2D27000
heap
page read and write
F39000
stack
page read and write
FC7000
heap
page read and write
3620000
heap
page read and write
366C000
stack
page read and write
10020000
direct allocation
page readonly
361B000
stack
page read and write
436F000
stack
page read and write
E3B000
stack
page read and write
2E9E000
stack
page read and write
9D8000
unkown
page read and write
11F5000
heap
page read and write
3097000
heap
page read and write
304E000
stack
page read and write
6D1000
unkown
page execute read
3880000
trusted library allocation
page read and write
10021000
direct allocation
page read and write
There are 60 hidden memdumps, click here to show them.