IOC Report
kewyIO69TI.exe

loading gif

Files

File Path
Type
Category
Malicious
kewyIO69TI.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\kewyIO69TI.exe.log
CSV text
modified
malicious
\Device\ConDrv
ASCII text, with CRLF, LF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\kewyIO69TI.exe
"C:\Users\user\Desktop\kewyIO69TI.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
https://drawzhotdog.shop/api
104.21.58.182
malicious
lootebarrkeyn.shop
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
https://gutterydhowi.shop/api
104.21.4.136
malicious
https://vozmeatillu.shop/api
188.114.97.3
malicious
https://stogeneratmns.shop/api
188.114.96.3
malicious
stogeneratmns.shop
malicious
reinforcenh.shop
malicious
https://ghostreedmnu.shop/api
188.114.96.3
malicious
fragnantbui.shop
malicious
gutterydhowi.shop
malicious
https://offensivedzvju.shop/api
188.114.96.3
malicious
https://fragnantbui.shop/api
188.114.97.3
malicious
https://steamcommunity.com/profiles/76561199724331900$vF
unknown
malicious
offensivedzvju.shop
malicious
https://reinforcenh.shop/api
104.21.77.130
malicious
drawzhotdog.shop
malicious
ghostreedmnu.shop
malicious
https://ballotnwu.site/api
104.21.2.13
malicious
vozmeatillu.shop
malicious
https://ballotnwu.site:443/api
unknown
https://stogeneratmns.shop/
unknown
https://reinforcenh.shop/api0
unknown
https://reinforcenh.shop/apicL
unknown
https://offensivedzvju.shop/
unknown
https://ballotnwu.site/apiz
unknown
https://reinforcenh.shop/
unknown
https://ballotnwu.site/b
unknown
https://steamcommunity.com/~
unknown
https://drawzhotdog.shop/
unknown
https://fragnantbui.shop/
unknown
https://ballotnwu.site/
unknown
There are 22 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
fragnantbui.shop
188.114.97.3
malicious
gutterydhowi.shop
104.21.4.136
malicious
offensivedzvju.shop
188.114.96.3
malicious
stogeneratmns.shop
188.114.96.3
malicious
reinforcenh.shop
104.21.77.130
malicious
drawzhotdog.shop
104.21.58.182
malicious
ghostreedmnu.shop
188.114.96.3
malicious
vozmeatillu.shop
188.114.97.3
malicious
ballotnwu.site
104.21.2.13
malicious
lootebarrkeyn.shop
unknown
malicious
steamcommunity.com
104.102.49.254
There are 1 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.21.77.130
reinforcenh.shop
United States
malicious
104.21.4.136
gutterydhowi.shop
United States
malicious
188.114.97.3
fragnantbui.shop
European Union
malicious
188.114.96.3
offensivedzvju.shop
European Union
malicious
104.21.2.13
ballotnwu.site
United States
malicious
104.21.58.182
drawzhotdog.shop
United States
malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
400000
remote allocation
page execute and read and write
malicious
3CF5000
trusted library allocation
page read and write
malicious
E49000
heap
page read and write
11A3000
trusted library allocation
page execute and read and write
1210000
trusted library allocation
page read and write
2A2D000
stack
page read and write
9BC000
stack
page read and write
E63000
heap
page read and write
DF2000
heap
page read and write
11D7000
trusted library allocation
page execute and read and write
2C2D000
stack
page read and write
D20000
heap
page read and write
1190000
trusted library allocation
page read and write
9C0000
heap
page read and write
DC6000
heap
page read and write
322F000
stack
page read and write
9B0000
heap
page read and write
E4E000
heap
page read and write
106E000
stack
page read and write
2CF1000
trusted library allocation
page execute and read and write
E67000
heap
page read and write
2B2F000
stack
page read and write
852000
unkown
page readonly
E40000
heap
page read and write
11B4000
trusted library allocation
page read and write
CFC000
stack
page read and write
30CD000
stack
page read and write
11D0000
trusted library allocation
page read and write
DFA000
heap
page read and write
1220000
heap
page read and write
2CF3000
trusted library allocation
page read and write
11CA000
trusted library allocation
page execute and read and write
E5F000
heap
page read and write
103F000
stack
page read and write
E4D000
heap
page read and write
117F000
stack
page read and write
11F0000
trusted library allocation
page read and write
2B0F000
stack
page read and write
11B0000
trusted library allocation
page read and write
11B6000
trusted library allocation
page read and write
DAA000
heap
page read and write
E7B000
heap
page read and write
E0E000
stack
page read and write
DA0000
heap
page read and write
11A4000
trusted library allocation
page read and write
107E000
stack
page read and write
850000
unkown
page readonly
E75000
heap
page read and write
4DEE000
stack
page read and write
D30000
heap
page read and write
102E000
stack
page read and write
9F0000
heap
page read and write
D9E000
stack
page read and write
312E000
stack
page read and write
11DB000
trusted library allocation
page execute and read and write
CF8000
stack
page read and write
E6C000
heap
page read and write
8AE000
unkown
page readonly
E82000
heap
page read and write
9D0000
heap
page read and write
DD8000
heap
page read and write
2CE0000
heap
page execute and read and write
9F5000
heap
page read and write
11C0000
trusted library allocation
page read and write
EA9000
heap
page read and write
2BFD000
stack
page read and write
E10000
heap
page read and write
2FCD000
stack
page read and write
FED000
stack
page read and write
1200000
trusted library allocation
page execute and read and write
2A0E000
stack
page read and write
EB0000
heap
page read and write
EB5000
heap
page read and write
E55000
heap
page read and write
94C000
stack
page read and write
460000
remote allocation
page execute and read and write
E4A000
heap
page read and write
2B10000
heap
page read and write
1080000
heap
page read and write
3CF1000
trusted library allocation
page read and write
DEE000
heap
page read and write
F90000
heap
page read and write
292F000
stack
page read and write
There are 73 hidden memdumps, click here to show them.