IOC Report
SecuriteInfo.com.Win32.MalwareX-gen.16263.14680.dll

loading gif

Files

File Path
Type
Category
Malicious
SecuriteInfo.com.Win32.MalwareX-gen.16263.14680.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Windows\Prairie Wind.bmp.bak
ASCII text, with no line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Windows\System32\loaddll32.exe
loaddll32.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.16263.14680.dll"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd.exe /C rundll32.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.16263.14680.dll",#1
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.16263.14680.dll",#1

URLs

Name
IP
Malicious
http://ds1.mentality-us.com/ld/HiQueen/v1/down.bmp
unknown
http://ds1.mentality-us.com/ld/HiQueen/v1/index.
unknown
http://ds1.mentality-us.com/ld/HiQueen/v1/index.jpg
unknown
http://ds1.mentality-us.com/ld/HiQueen/v1/getnews.php?s=
unknown
http://ds1.mentality-us.com/ld/HiQueen/v1/index.jpgficmanager.nety
unknown
http://ds1.mentality-us.com/ld/HiQueen/v1/index.jpgrX
unknown
http://ds1.mentality-us.com/ld/HiQueen/v1/news.jpg
unknown
http://www.rsac.org/ratingsv01.html
unknown

Domains

Name
IP
Malicious
ds1.mentality-us.com
unknown
time.windows.com
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
2DD0000
heap
page read and write
2D88000
heap
page read and write
2CAE000
stack
page read and write
476C000
stack
page read and write
2C6D000
stack
page read and write
2AB0000
heap
page read and write
58E000
stack
page read and write
6444000
heap
page read and write
2F87000
heap
page read and write
22FE000
stack
page read and write
2D8B000
heap
page read and write
2DD0000
heap
page read and write
6430000
heap
page read and write
1EC000
stack
page read and write
2E50000
direct allocation
page read and write
287F000
stack
page read and write
2B50000
heap
page read and write
2170000
heap
page read and write
2DA3000
heap
page read and write
2D10000
heap
page read and write
2D50000
heap
page read and write
638B000
stack
page read and write
2F8C000
heap
page read and write
7E9000
stack
page read and write
2A7C000
stack
page read and write
2B3E000
stack
page read and write
2B56000
heap
page read and write
540000
heap
page read and write
63CD000
stack
page read and write
5C0000
heap
page read and write
9C000
stack
page read and write
47EE000
stack
page read and write
243C000
stack
page read and write
482F000
stack
page read and write
657E000
stack
page read and write
5EF000
heap
page read and write
2D5A000
heap
page read and write
6420000
heap
page read and write
2D8E000
heap
page read and write
4860000
heap
page read and write
545000
heap
page read and write
2F80000
heap
page read and write
2DA3000
heap
page read and write
210C000
stack
page read and write
47AC000
stack
page read and write
2D8E000
heap
page read and write
7BE000
stack
page read and write
5D7000
heap
page read and write
8FF000
stack
page read and write
2CEF000
stack
page read and write
2D8E000
heap
page read and write
5CB000
heap
page read and write
2330000
heap
page read and write
2D79000
heap
page read and write
22BE000
stack
page read and write
430000
heap
page read and write
2AC0000
heap
page read and write
4960000
heap
page read and write
7FE000
stack
page read and write
2180000
direct allocation
page read and write
48FD000
stack
page read and write
5CF000
heap
page read and write
2D91000
heap
page read and write
2ABF000
stack
page read and write
65BF000
stack
page read and write
297F000
stack
page read and write
2D78000
heap
page read and write
29BE000
stack
page read and write
634D000
stack
page read and write
6690000
trusted library allocation
page read and write
48BE000
stack
page read and write
510000
heap
page read and write
640E000
stack
page read and write
2D84000
heap
page read and write
20B0000
heap
page read and write
6440000
heap
page read and write
There are 66 hidden memdumps, click here to show them.