IOC Report
kYpONUhAR5.exe

loading gif

Files

File Path
Type
Category
Malicious
kYpONUhAR5.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\kYpONUhAR5.exe.log
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\Public\Desktop\Google Chrome.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:41 2023, mtime=Thu Oct 5 05:47:19 2023, atime=Wed Sep 27 08:36:54 2023, length=3242272, window=hide
dropped
C:\Users\user\AppData\Local\Temp\Tmp382E.tmp
data
dropped
C:\Users\user\AppData\Local\Temp\Tmp383F.tmp
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-2246122658-3693405117-2476756634-1003\76b53b3ec448f7ccdda2063b15d2bfc3_9e146be9-c76a-4720-bcdb-53011b87bd06
data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\kYpONUhAR5.exe
"C:\Users\user\Desktop\kYpONUhAR5.exe"
malicious

URLs

Name
IP
Malicious
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Text
unknown
http://schemas.xmlsoap.org/ws/2005/02/sc/sct
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/sc/dk
unknown
http://tempuri.org/Entity/Id14ResponseD
unknown
http://tempuri.org/Entity/Id23ResponseD
unknown
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#HexBinary
unknown
http://tempuri.org/Entity/Id12Response
unknown
http://tempuri.org/
unknown
http://tempuri.org/Entity/Id2Response
unknown
http://schemas.xmlsoap.org/ws/2005/02/sc/dk/p_sha1
unknown
http://tempuri.org/Entity/Id21Response
unknown
http://schemas.xmlsoap.org/2005/02/trust/spnego#GSS_Wrap
unknown
http://tempuri.org/Entity/Id9
unknown
http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLID
unknown
http://tempuri.org/Entity/Id8
unknown
http://tempuri.org/Entity/Id6ResponseD
unknown
http://tempuri.org/Entity/Id5
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Prepare
unknown
http://tempuri.org/Entity/Id4
unknown
http://tempuri.org/Entity/Id7
unknown
http://tempuri.org/Entity/Id6
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust#BinarySecret
unknown
http://tempuri.org/Entity/Id19Response
unknown
http://docs.oasis-open.org/wss/oasis-wss-rel-token-profile-1.0.pdf#license
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/Issue
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Aborted
unknown
http://schemas.xmlsoap.org/ws/2005/02/rm/TerminateSequence
unknown
http://tempuri.org/Entity/Id13ResponseD
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/fault
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat
unknown
http://docs.oasis-open.org/wss/oasis-wss-soap-message-security-1.1#EncryptedKey
unknown
http://tempuri.org/Entity/Id15Response
unknown
http://tempuri.org/Entity/Id5ResponseD
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/SCT/Renew
unknown
http://schemas.xmlsoap.org/ws/2004/08/addressing/faultp9
unknown
http://schemas.xmlsoap.org/ws/2004/10/wscoor/Register
unknown
http://tempuri.org/Entity/Id6Response
unknown
http://schemas.xmlsoap.org/ws/2004/04/trust/SymmetricKey
unknown
https://api.ip.sb/ip
unknown
http://schemas.xmlsoap.org/ws/2004/04/sc
unknown
http://tempuri.org/Entity/Id1ResponseD
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Volatile2PC
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/SCT/Cancel
unknown
http://tempuri.org/Entity/Id9Response
unknown
http://tempuri.org/Entity/Id20
unknown
http://tempuri.org/Entity/Id21
unknown
http://tempuri.org/Entity/Id22
unknown
http://docs.oasis-open.org/wss/oasis-wss-kerberos-token-profile-1.1#Kerberosv5APREQSHA1
unknown
http://tempuri.org/Entity/Id23
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/CK/PSHA1
unknown
http://tempuri.org/Entity/Id24
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/RSTR/Issue
unknown
http://tempuri.org/Entity/Id24Response
unknown
http://tempuri.org/Entity/Id1Response
unknown
http://schemas.xmlsoap.org/ws/2005/02/rm/AckRequested
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/ReadOnly
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Replay
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/tlsnego
unknown
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Base64Binary
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Durable2PC
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/SymmetricKey
unknown
http://tempuri.org/Entity/Id21ResponseD
unknown
http://schemas.xmlsoap.org/ws/2004/08/addressing
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RST/Issue
unknown
http://schemas.xmlsoap.org/ws/2004/10/wsat/Completion
unknown
http://schemas.xmlsoap.org/ws/2004/04/trust
unknown
http://tempuri.org/Entity/Id10
unknown
http://tempuri.org/Entity/Id11
unknown
http://tempuri.org/Entity/Id10ResponseD
unknown
http://tempuri.org/Entity/Id12
unknown
http://tempuri.org/Entity/Id16Response
unknown
http://schemas.xmlsoap.org/ws/2004/10/wscoor/CreateCoordinationContextResponse
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/RST/SCT/Cancel
unknown
http://tempuri.org/Entity/Id13
unknown
http://tempuri.org/Entity/Id14
unknown
http://tempuri.org/Entity/Id15
unknown
http://tempuri.org/Entity/Id16
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/Nonce
unknown
http://tempuri.org/Entity/Id17
unknown
http://tempuri.org/Entity/Id18
unknown
http://tempuri.org/Entity/Id5Response
unknown
http://tempuri.org/Entity/Id19
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/dns
unknown
http://tempuri.org/Entity/Id15ResponseD
unknown
http://tempuri.org/Entity/Id10Response
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/Renew
unknown
http://tempuri.org/Entity/Id11ResponseD
unknown
http://tempuri.org/Entity/Id8Response
unknown
http://schemas.xmlsoap.org/ws/2004/04/trust/PublicKey
unknown
http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLV2.0
unknown
http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.0#SAMLAssertionID
unknown
http://schemas.xmlsoap.org/ws/2004/04/security/trust/RST/SCT
unknown
http://schemas.xmlsoap.org/ws/2006/02/addressingidentity
unknown
http://tempuri.org/Entity/Id17ResponseD
unknown
http://schemas.xmlsoap.org/soap/envelope/
unknown
http://tempuri.org/Entity/Id8ResponseD
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust/PublicKey
unknown
http://docs.oasis-open.org/wss/oasis-wss-soap-message-security-1.1#EncryptedKeySHA1
unknown
http://schemas.xmlsoap.org/ws/2005/02/trust
unknown
There are 90 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
185.215.113.67
unknown
Portugal
malicious

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F1A578C4CB5DE79A370893983FD4DA8B67B2B064
Blob
malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFiles0000
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFilesHash

Memdumps

Base Address
Regiontype
Protect
Malicious
E32000
unkown
page readonly
malicious
724C000
stack
page read and write
6EFB000
heap
page read and write
3269000
trusted library allocation
page read and write
17E0000
heap
page execute and read and write
6EC0000
heap
page read and write
7190000
trusted library allocation
page read and write
69B0000
trusted library allocation
page read and write
6EF8000
heap
page read and write
802E000
stack
page read and write
6F32000
trusted library allocation
page read and write
649E000
stack
page read and write
1886000
heap
page read and write
7520000
trusted library allocation
page read and write
6B5D000
stack
page read and write
36DB000
trusted library allocation
page read and write
71E0000
trusted library allocation
page execute and read and write
358F000
trusted library allocation
page read and write
1850000
heap
page read and write
7EDA000
trusted library allocation
page read and write
3316000
trusted library allocation
page read and write
F80000
heap
page read and write
5695000
trusted library allocation
page read and write
E76000
unkown
page readonly
7ED5000
trusted library allocation
page read and write
31D8000
trusted library allocation
page read and write
1840000
trusted library allocation
page read and write
312F000
stack
page read and write
1450000
trusted library allocation
page read and write
188B000
heap
page read and write
6DE9000
trusted library allocation
page read and write
5690000
trusted library allocation
page read and write
8645000
trusted library allocation
page read and write
14A1000
heap
page read and write
7D6A000
heap
page read and write
6CCE000
stack
page read and write
56D0000
trusted library allocation
page read and write
5650000
trusted library allocation
page read and write
14A5000
heap
page read and write
7CE9000
heap
page read and write
337F000
trusted library allocation
page read and write
32D5000
trusted library allocation
page read and write
6DD0000
trusted library allocation
page read and write
74E3000
trusted library allocation
page read and write
E30000
unkown
page readonly
42B0000
trusted library allocation
page read and write
7EF4000
trusted library allocation
page read and write
641E000
stack
page read and write
520B000
stack
page read and write
6231000
heap
page read and write
6A50000
heap
page read and write
6FE0000
trusted library allocation
page read and write
85CF000
stack
page read and write
32F4000
trusted library allocation
page read and write
69A8000
trusted library allocation
page read and write
6F3E000
trusted library allocation
page read and write
869E000
stack
page read and write
685F000
stack
page read and write
530C000
stack
page read and write
7D27000
heap
page read and write
69C0000
trusted library allocation
page read and write
5AEF000
stack
page read and write
837E000
stack
page read and write
7CA0000
heap
page read and write
167D000
trusted library allocation
page execute and read and write
6DD5000
trusted library allocation
page read and write
7EB0000
trusted library allocation
page read and write
8E9E000
stack
page read and write
6DE5000
trusted library allocation
page read and write
6A60000
trusted library allocation
page execute and read and write
1692000
trusted library allocation
page read and write
7D3E000
heap
page read and write
5676000
trusted library allocation
page read and write
7EB9000
trusted library allocation
page read and write
748C000
stack
page read and write
833E000
stack
page read and write
1494000
heap
page read and write
330A000
trusted library allocation
page read and write
32FD000
trusted library allocation
page read and write
5671000
trusted library allocation
page read and write
86F0000
trusted library allocation
page read and write
7EDF000
trusted library allocation
page read and write
8380000
trusted library allocation
page execute and read and write
4273000
trusted library allocation
page read and write
5682000
trusted library allocation
page read and write
5C6E000
stack
page read and write
689E000
stack
page read and write
1660000
trusted library allocation
page read and write
565B000
trusted library allocation
page read and write
59D0000
heap
page read and write
4131000
trusted library allocation
page read and write
645E000
stack
page read and write
7EF0000
trusted library allocation
page read and write
7D7E000
heap
page read and write
7010000
trusted library allocation
page execute and read and write
71D0000
trusted library allocation
page read and write
16B6000
heap
page read and write
7000000
trusted library allocation
page execute and read and write
7CDE000
heap
page read and write
5710000
heap
page read and write
74CE000
stack
page read and write
17D0000
trusted library allocation
page execute and read and write
1870000
trusted library allocation
page read and write
1670000
trusted library allocation
page read and write
6F0C000
heap
page read and write
6F10000
trusted library allocation
page read and write
85E0000
trusted library allocation
page read and write
7D4C000
heap
page read and write
1664000
trusted library allocation
page read and write
699E000
stack
page read and write
FB0000
heap
page read and write
84CE000
stack
page read and write
6FF0000
trusted library allocation
page read and write
863C000
stack
page read and write
6EDE000
heap
page read and write
335C000
trusted library allocation
page read and write
7ECF000
trusted library allocation
page read and write
6F70000
trusted library allocation
page read and write
5654000
trusted library allocation
page read and write
187E000
trusted library allocation
page read and write
FB5000
heap
page read and write
7F2F0000
trusted library allocation
page execute and read and write
F1A000
stack
page read and write
7EB2000
trusted library allocation
page read and write
83A0000
heap
page read and write
36E2000
trusted library allocation
page read and write
8D9E000
stack
page read and write
6FB0000
trusted library allocation
page read and write
7FE0000
trusted library allocation
page read and write
7FD0000
trusted library allocation
page read and write
7F10000
trusted library allocation
page execute and read and write
1690000
trusted library allocation
page read and write
7CD2000
heap
page read and write
1880000
heap
page read and write
5B2E000
stack
page read and write
6DDA000
trusted library allocation
page read and write
7FCE000
stack
page read and write
7CC5000
heap
page read and write
7F20000
trusted library allocation
page read and write
182E000
stack
page read and write
6F26000
trusted library allocation
page read and write
7CC2000
heap
page read and write
7CA8000
heap
page read and write
1686000
trusted library allocation
page execute and read and write
6F06000
heap
page read and write
567D000
trusted library allocation
page read and write
734C000
stack
page read and write
56A0000
trusted library allocation
page read and write
59B0000
heap
page read and write
71A0000
trusted library allocation
page read and write
6E9F000
heap
page read and write
16B0000
heap
page read and write
3300000
trusted library allocation
page read and write
7EA9000
trusted library allocation
page read and write
6EFD000
heap
page read and write
7CD5000
heap
page read and write
738E000
stack
page read and write
1663000
trusted library allocation
page execute and read and write
1830000
trusted library allocation
page read and write
6F90000
trusted library allocation
page read and write
12F7000
stack
page read and write
592E000
stack
page read and write
6C5E000
stack
page read and write
3303000
trusted library allocation
page read and write
7EE0000
trusted library allocation
page execute and read and write
7D38000
heap
page read and write
35A1000
trusted library allocation
page read and write
17BE000
stack
page read and write
6F50000
trusted library allocation
page read and write
168A000
trusted library allocation
page execute and read and write
36CE000
trusted library allocation
page read and write
1540000
heap
page read and write
E62000
unkown
page readonly
1860000
trusted library allocation
page read and write
F90000
heap
page read and write
1460000
heap
page read and write
6FA0000
trusted library allocation
page read and write
36ED000
trusted library allocation
page read and write
7060000
trusted library allocation
page execute and read and write
71C0000
trusted library allocation
page read and write
1680000
trusted library allocation
page read and write
140D000
stack
page read and write
74E0000
trusted library allocation
page read and write
3595000
trusted library allocation
page read and write
7F00000
trusted library allocation
page read and write
6EEE000
heap
page read and write
36F4000
trusted library allocation
page read and write
165E000
stack
page read and write
6F1B000
trusted library allocation
page read and write
33D7000
trusted library allocation
page read and write
6F41000
trusted library allocation
page read and write
7C4D000
stack
page read and write
6DE0000
trusted library allocation
page read and write
6A70000
trusted library allocation
page execute and read and write
7EB5000
trusted library allocation
page read and write
1682000
trusted library allocation
page read and write
5720000
trusted library allocation
page read and write
FFE000
stack
page read and write
6E66000
heap
page read and write
7EC8000
trusted library allocation
page read and write
71B0000
trusted library allocation
page read and write
359D000
trusted library allocation
page read and write
6E52000
heap
page read and write
3591000
trusted library allocation
page read and write
675F000
stack
page read and write
166D000
trusted library allocation
page execute and read and write
8640000
trusted library allocation
page read and write
6F80000
trusted library allocation
page read and write
17C0000
trusted library allocation
page read and write
7523000
trusted library allocation
page read and write
7CB6000
heap
page read and write
32F1000
trusted library allocation
page read and write
624A000
heap
page read and write
31DC000
trusted library allocation
page read and write
1695000
trusted library allocation
page execute and read and write
8720000
heap
page read and write
59E0000
heap
page execute and read and write
6EEB000
heap
page read and write
566E000
trusted library allocation
page read and write
413F000
trusted library allocation
page read and write
6245000
heap
page read and write
9D9F000
stack
page read and write
3131000
trusted library allocation
page read and write
5138000
trusted library allocation
page read and write
6F6B000
trusted library allocation
page read and write
169B000
trusted library allocation
page execute and read and write
146E000
heap
page read and write
7EA0000
trusted library allocation
page read and write
7D2A000
heap
page read and write
3597000
trusted library allocation
page read and write
6F21000
trusted library allocation
page read and write
1410000
heap
page read and write
1697000
trusted library allocation
page execute and read and write
85D0000
trusted library allocation
page execute and read and write
7D5A000
heap
page read and write
32E6000
trusted library allocation
page read and write
8390000
heap
page read and write
8650000
trusted library allocation
page read and write
7526000
trusted library allocation
page read and write
36FE000
trusted library allocation
page read and write
806E000
stack
page read and write
370A000
trusted library allocation
page read and write
6E24000
heap
page read and write
154F000
heap
page read and write
56B3000
heap
page read and write
5722000
trusted library allocation
page read and write
32DD000
trusted library allocation
page read and write
6F60000
trusted library allocation
page read and write
7070000
trusted library allocation
page execute and read and write
7ECA000
trusted library allocation
page read and write
5C2E000
stack
page read and write
7200000
trusted library allocation
page execute and read and write
3715000
trusted library allocation
page read and write
E67000
unkown
page readonly
6DCE000
stack
page read and write
7F8D000
stack
page read and write
4152000
trusted library allocation
page read and write
1520000
heap
page read and write
6F6E000
trusted library allocation
page read and write
6F65000
trusted library allocation
page read and write
7CAF000
heap
page read and write
359B000
trusted library allocation
page read and write
32D9000
trusted library allocation
page read and write
69A0000
trusted library allocation
page read and write
56B0000
heap
page read and write
5730000
trusted library allocation
page execute and read and write
86DE000
stack
page read and write
36FA000
trusted library allocation
page read and write
56DE000
trusted library allocation
page read and write
7D06000
heap
page read and write
6DE7000
trusted library allocation
page read and write
There are 261 hidden memdumps, click here to show them.