IOC Report
gZzI6gTYn4.exe

loading gif

Files

File Path
Type
Category
Malicious
gZzI6gTYn4.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\gZzI6gTYn4.exe.log
CSV text
modified
malicious
\Device\ConDrv
ASCII text, with CRLF, LF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\gZzI6gTYn4.exe
"C:\Users\user\Desktop\gZzI6gTYn4.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
https://drawzhotdog.shop/api
172.67.162.108
malicious
lootebarrkeyn.shop
malicious
https://gutterydhowi.shop/api
104.21.4.136
malicious
reinforcenh.shop
malicious
stogeneratmns.shop
malicious
https://reinforcenh.shop/api
104.21.77.130
malicious
ghostreedmnu.shop
malicious
https://ballotnwu.site/api
172.67.128.144
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
https://vozmeatillu.shop/api
188.114.96.3
malicious
https://stogeneratmns.shop/api
188.114.96.3
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
https://ghostreedmnu.shop/api
188.114.96.3
malicious
fragnantbui.shop
malicious
gutterydhowi.shop
malicious
https://offensivedzvju.shop/api
188.114.97.3
malicious
https://fragnantbui.shop/api
188.114.96.3
malicious
offensivedzvju.shop
malicious
drawzhotdog.shop
malicious
vozmeatillu.shop
malicious
https://ballotnwu.site/apiX
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://reinforcenh.shop/apij
unknown
https://reinforcenh.shop/apio
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_respons
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapte
unknown
https://ballotnwu.site/P
unknown
https://ghostreedmnu.shop/apiD
unknown
https://vozmeatillu.shop/0
unknown
https://vozmeatillu.shop/1
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.c
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://reinforcenh.shop/
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://steamcommunity.com/cr
unknown
https://store.steampowered.com/legal/
unknown
https://community.akamai.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=e
unknown
https://ballotnwu.site/
unknown
https://community.akamai.steamstatic.com/pI
unknown
https://ghostreedmnu.shop/
unknown
https://community.akamai.steamstatic.com/public/javascript/modalContent.~
unknown
https://offensivedzvju.shop/api2
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
https://offensivedzvju.shop/)
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
https://stogeneratmns.shop/
unknown
https://ballotnwu.site:443/apiprofiles/76561199724331900
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/javascript/promo/stickers.js?v=upl9NJ5D2xk0
unknown
https://community.akamai.steamstatic.com/publi
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://vozmeatillu.shop/apis
unknown
https://steamcommunity.com/
unknown
https://community.akamai.
unknown
There are 52 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
fragnantbui.shop
188.114.96.3
malicious
gutterydhowi.shop
104.21.4.136
malicious
offensivedzvju.shop
188.114.97.3
malicious
stogeneratmns.shop
188.114.96.3
malicious
reinforcenh.shop
104.21.77.130
malicious
drawzhotdog.shop
172.67.162.108
malicious
ghostreedmnu.shop
188.114.96.3
malicious
vozmeatillu.shop
188.114.96.3
malicious
ballotnwu.site
172.67.128.144
malicious
lootebarrkeyn.shop
unknown
malicious
steamcommunity.com
104.102.49.254
There are 1 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.21.77.130
reinforcenh.shop
United States
malicious
104.21.4.136
gutterydhowi.shop
United States
malicious
188.114.97.3
offensivedzvju.shop
European Union
malicious
172.67.162.108
drawzhotdog.shop
United States
malicious
172.67.128.144
ballotnwu.site
United States
malicious
188.114.96.3
fragnantbui.shop
European Union
malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
3935000
trusted library allocation
page read and write
malicious
400000
remote allocation
page execute and read and write
malicious
113A000
heap
page read and write
11D8000
heap
page read and write
9DC000
heap
page read and write
2780000
heap
page read and write
34DE000
stack
page read and write
BF0000
trusted library allocation
page read and write
915000
heap
page read and write
4C0000
unkown
page readonly
1240000
heap
page read and write
1155000
heap
page read and write
1230000
heap
page read and write
DCC000
stack
page read and write
C03000
trusted library allocation
page execute and read and write
910000
heap
page read and write
2F1E000
stack
page read and write
117D000
heap
page read and write
E47000
trusted library allocation
page execute and read and write
98E000
stack
page read and write
EF0000
trusted library allocation
page execute and read and write
9F2000
heap
page read and write
12E5000
heap
page read and write
1130000
heap
page read and write
EAE000
stack
page read and write
4A2E000
stack
page read and write
9E5000
heap
page read and write
2D9D000
stack
page read and write
BC0000
heap
page read and write
F00000
trusted library allocation
page read and write
2C5F000
stack
page read and write
E4B000
trusted library allocation
page execute and read and write
2931000
trusted library allocation
page execute and read and write
930000
heap
page read and write
2920000
heap
page execute and read and write
9D7000
heap
page read and write
11ED000
heap
page read and write
12E0000
heap
page read and write
363F000
stack
page read and write
11EB000
heap
page read and write
1260000
heap
page read and write
1190000
heap
page read and write
10FC000
stack
page read and write
460000
remote allocation
page execute and read and write
C14000
trusted library allocation
page read and write
115D000
heap
page read and write
9B8000
heap
page read and write
12C0000
heap
page read and write
C20000
heap
page read and write
EED000
stack
page read and write
1162000
heap
page read and write
940000
heap
page read and write
2A94000
trusted library allocation
page read and write
288F000
stack
page read and write
C10000
trusted library allocation
page read and write
9BE000
heap
page read and write
C16000
trusted library allocation
page read and write
E2E000
stack
page read and write
2DDD000
stack
page read and write
2933000
trusted library allocation
page read and write
12BE000
stack
page read and write
E3A000
trusted library allocation
page execute and read and write
BBE000
stack
page read and write
4C2000
unkown
page readonly
8F8000
stack
page read and write
33DD000
stack
page read and write
3931000
trusted library allocation
page read and write
F10000
heap
page read and write
2C9E000
stack
page read and write
C04000
trusted library allocation
page read and write
2EDD000
stack
page read and write
D2F000
stack
page read and write
353E000
stack
page read and write
5BC000
stack
page read and write
1166000
heap
page read and write
51E000
unkown
page readonly
9B0000
heap
page read and write
301F000
stack
page read and write
There are 68 hidden memdumps, click here to show them.