IOC Report
d3r1KVj317.exe

loading gif

Files

File Path
Type
Category
Malicious
d3r1KVj317.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\Desktop\Config.ini
ISO-8859 text, with CRLF line terminators
dropped
C:\Users\user\Desktop\SkinH_EL.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, UPX compressed
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\d3r1KVj317.exe
"C:\Users\user\Desktop\d3r1KVj317.exe"
malicious

URLs

Name
IP
Malicious
http://112.74.185.5/3R%E6%8A%80%E6%9C%AF.exe
unknown
http://www.eyuyan.com)DVarFileInfo$
unknown
http://api.ttshitu.com/predict
unknown
http://api.ttshitu.com/predictto16unfunction
unknown

IPs

IP
Domain
Country
Malicious
112.74.185.5
unknown
China

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Multimedia\DrawDib
1280x1024x32(BGR 0)

Memdumps

Base Address
Regiontype
Protect
Malicious
401000
unkown
page execute read
897000
unkown
page write copy
92C000
unkown
page readonly
2725000
heap
page read and write
2D5E000
stack
page read and write
8A3000
unkown
page write copy
CD2000
heap
page read and write
6AE000
unkown
page readonly
A37000
heap
page read and write
CA3000
heap
page read and write
4680000
trusted library allocation
page read and write
2620000
heap
page read and write
BF0000
heap
page read and write
90F000
unkown
page readonly
287B000
heap
page read and write
8B0000
unkown
page write copy
50BF000
stack
page read and write
2A60000
trusted library allocation
page read and write
C5D000
heap
page read and write
400000
unkown
page readonly
2B9F000
stack
page read and write
4300000
heap
page read and write
1002C000
unkown
page execute and read and write
BD0000
heap
page read and write
6AE000
unkown
page readonly
8B0000
unkown
page read and write
78B000
unkown
page readonly
CC0000
heap
page read and write
287F000
heap
page read and write
C55000
heap
page read and write
10001000
unkown
page execute and read and write
8AC000
unkown
page read and write
400000
unkown
page readonly
C5D000
heap
page read and write
296C000
heap
page read and write
2A60000
trusted library allocation
page read and write
2854000
heap
page read and write
A35000
heap
page read and write
1003A000
unkown
page execute and write copy
ACE000
stack
page read and write
8A7000
unkown
page write copy
2670000
heap
page read and write
76D000
unkown
page readonly
430D000
heap
page read and write
C61000
heap
page read and write
A20000
heap
page read and write
2A60000
trusted library allocation
page read and write
CD6000
heap
page read and write
940000
heap
page read and write
893000
unkown
page write copy
C60000
heap
page read and write
C68000
heap
page read and write
2A60000
trusted library allocation
page read and write
1003C000
unkown
page read and write
2850000
heap
page read and write
BFA000
heap
page read and write
91D000
unkown
page readonly
286E000
heap
page read and write
92000
stack
page read and write
2A60000
trusted library allocation
page read and write
2A9C000
stack
page read and write
907000
unkown
page read and write
CCE000
heap
page read and write
2860000
heap
page read and write
895000
unkown
page read and write
4FBE000
stack
page read and write
78B000
unkown
page readonly
4F7F000
stack
page read and write
8A6000
unkown
page read and write
2961000
heap
page read and write
19B000
stack
page read and write
2A60000
trusted library allocation
page read and write
C9C000
heap
page read and write
2A60000
trusted library allocation
page read and write
8A2000
unkown
page read and write
10030000
unkown
page execute and read and write
C60000
heap
page read and write
BE0000
heap
page read and write
893000
unkown
page write copy
2A60000
trusted library allocation
page read and write
401000
unkown
page execute read
BFE000
heap
page read and write
A30000
heap
page read and write
90F000
unkown
page readonly
C60000
heap
page read and write
C61000
heap
page read and write
90D000
unkown
page read and write
2A60000
trusted library allocation
page read and write
2720000
heap
page read and write
C50000
heap
page read and write
2700000
heap
page read and write
10000000
unkown
page readonly
91D000
unkown
page readonly
DEF000
stack
page read and write
76D000
unkown
page readonly
8BD000
unkown
page read and write
2960000
heap
page read and write
10038000
unkown
page execute and read and write
92C000
unkown
page readonly
There are 89 hidden memdumps, click here to show them.