Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
d3r1KVj317.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\Users\user\Desktop\Config.ini
|
ISO-8859 text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\Desktop\SkinH_EL.dll
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, UPX compressed
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\d3r1KVj317.exe
|
"C:\Users\user\Desktop\d3r1KVj317.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://112.74.185.5/3R%E6%8A%80%E6%9C%AF.exe
|
unknown
|
||
http://www.eyuyan.com)DVarFileInfo$
|
unknown
|
||
http://api.ttshitu.com/predict
|
unknown
|
||
http://api.ttshitu.com/predictto16unfunction
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
112.74.185.5
|
unknown
|
China
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Multimedia\DrawDib
|
1280x1024x32(BGR 0)
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
401000
|
unkown
|
page execute read
|
||
897000
|
unkown
|
page write copy
|
||
92C000
|
unkown
|
page readonly
|
||
2725000
|
heap
|
page read and write
|
||
2D5E000
|
stack
|
page read and write
|
||
8A3000
|
unkown
|
page write copy
|
||
CD2000
|
heap
|
page read and write
|
||
6AE000
|
unkown
|
page readonly
|
||
A37000
|
heap
|
page read and write
|
||
CA3000
|
heap
|
page read and write
|
||
4680000
|
trusted library allocation
|
page read and write
|
||
2620000
|
heap
|
page read and write
|
||
BF0000
|
heap
|
page read and write
|
||
90F000
|
unkown
|
page readonly
|
||
287B000
|
heap
|
page read and write
|
||
8B0000
|
unkown
|
page write copy
|
||
50BF000
|
stack
|
page read and write
|
||
2A60000
|
trusted library allocation
|
page read and write
|
||
C5D000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
2B9F000
|
stack
|
page read and write
|
||
4300000
|
heap
|
page read and write
|
||
1002C000
|
unkown
|
page execute and read and write
|
||
BD0000
|
heap
|
page read and write
|
||
6AE000
|
unkown
|
page readonly
|
||
8B0000
|
unkown
|
page read and write
|
||
78B000
|
unkown
|
page readonly
|
||
CC0000
|
heap
|
page read and write
|
||
287F000
|
heap
|
page read and write
|
||
C55000
|
heap
|
page read and write
|
||
10001000
|
unkown
|
page execute and read and write
|
||
8AC000
|
unkown
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
C5D000
|
heap
|
page read and write
|
||
296C000
|
heap
|
page read and write
|
||
2A60000
|
trusted library allocation
|
page read and write
|
||
2854000
|
heap
|
page read and write
|
||
A35000
|
heap
|
page read and write
|
||
1003A000
|
unkown
|
page execute and write copy
|
||
ACE000
|
stack
|
page read and write
|
||
8A7000
|
unkown
|
page write copy
|
||
2670000
|
heap
|
page read and write
|
||
76D000
|
unkown
|
page readonly
|
||
430D000
|
heap
|
page read and write
|
||
C61000
|
heap
|
page read and write
|
||
A20000
|
heap
|
page read and write
|
||
2A60000
|
trusted library allocation
|
page read and write
|
||
CD6000
|
heap
|
page read and write
|
||
940000
|
heap
|
page read and write
|
||
893000
|
unkown
|
page write copy
|
||
C60000
|
heap
|
page read and write
|
||
C68000
|
heap
|
page read and write
|
||
2A60000
|
trusted library allocation
|
page read and write
|
||
1003C000
|
unkown
|
page read and write
|
||
2850000
|
heap
|
page read and write
|
||
BFA000
|
heap
|
page read and write
|
||
91D000
|
unkown
|
page readonly
|
||
286E000
|
heap
|
page read and write
|
||
92000
|
stack
|
page read and write
|
||
2A60000
|
trusted library allocation
|
page read and write
|
||
2A9C000
|
stack
|
page read and write
|
||
907000
|
unkown
|
page read and write
|
||
CCE000
|
heap
|
page read and write
|
||
2860000
|
heap
|
page read and write
|
||
895000
|
unkown
|
page read and write
|
||
4FBE000
|
stack
|
page read and write
|
||
78B000
|
unkown
|
page readonly
|
||
4F7F000
|
stack
|
page read and write
|
||
8A6000
|
unkown
|
page read and write
|
||
2961000
|
heap
|
page read and write
|
||
19B000
|
stack
|
page read and write
|
||
2A60000
|
trusted library allocation
|
page read and write
|
||
C9C000
|
heap
|
page read and write
|
||
2A60000
|
trusted library allocation
|
page read and write
|
||
8A2000
|
unkown
|
page read and write
|
||
10030000
|
unkown
|
page execute and read and write
|
||
C60000
|
heap
|
page read and write
|
||
BE0000
|
heap
|
page read and write
|
||
893000
|
unkown
|
page write copy
|
||
2A60000
|
trusted library allocation
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
BFE000
|
heap
|
page read and write
|
||
A30000
|
heap
|
page read and write
|
||
90F000
|
unkown
|
page readonly
|
||
C60000
|
heap
|
page read and write
|
||
C61000
|
heap
|
page read and write
|
||
90D000
|
unkown
|
page read and write
|
||
2A60000
|
trusted library allocation
|
page read and write
|
||
2720000
|
heap
|
page read and write
|
||
C50000
|
heap
|
page read and write
|
||
2700000
|
heap
|
page read and write
|
||
10000000
|
unkown
|
page readonly
|
||
91D000
|
unkown
|
page readonly
|
||
DEF000
|
stack
|
page read and write
|
||
76D000
|
unkown
|
page readonly
|
||
8BD000
|
unkown
|
page read and write
|
||
2960000
|
heap
|
page read and write
|
||
10038000
|
unkown
|
page execute and read and write
|
||
92C000
|
unkown
|
page readonly
|
There are 89 hidden memdumps, click here to show them.