IOC Report
2qsdqACnX3.exe

loading gif

Files

File Path
Type
Category
Malicious
2qsdqACnX3.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Temp\5990015.bat
ASCII text, with CRLF, CR line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\2qsdqACnX3.exe
"C:\Users\user\Desktop\2qsdqACnX3.exe"
malicious
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\5990015.bat" "C:\Users\user\Desktop\2qsdqACnX3.exe" "
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
http://gunnylaumienphi2017.com/
malicious
http://https://ftp://operawand.dat_Software
unknown
https://ac.ecosia.org/autocomplete?q=
unknown
https://duckduckgo.com/chrome_newtab
unknown
https://duckduckgo.com/ac/?q=
unknown
https://www.google.com/images/branding/product/ico/googleg_lodp.ico
unknown
ftp://http://https://ftp.fireFTPsites.datSeaMonkey
unknown
https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
unknown
https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
unknown
https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
unknown
https://www.ecosia.org/newtab/
unknown
https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
unknown
http://gunnylaumienphi2017.com/YUIPWDFILE0YUIPKDFILE0YUICRYPTED0YUI1.0
unknown
There are 3 hidden URLs, click here to show them.

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\WinRAR
HWID

Memdumps

Base Address
Regiontype
Protect
Malicious
411000
unkown
page read and write
malicious
411000
unkown
page write copy
malicious
4F0000
heap
page read and write
74E000
heap
page read and write
25C0000
trusted library allocation
page read and write
74F000
heap
page read and write
401000
unkown
page execute read
753000
heap
page read and write
74E000
heap
page read and write
754000
heap
page read and write
74C000
heap
page read and write
753000
heap
page read and write
2F4C000
stack
page read and write
2B3F000
stack
page read and write
28FE000
stack
page read and write
505000
heap
page read and write
54E000
stack
page read and write
AE7000
heap
page read and write
9B000
stack
page read and write
1F0000
heap
page read and write
8EF000
stack
page read and write
19B000
stack
page read and write
74E000
heap
page read and write
74E000
heap
page read and write
6F0000
heap
page read and write
6B0000
heap
page read and write
711000
heap
page read and write
2DBF000
stack
page read and write
2B7E000
stack
page read and write
2A3E000
stack
page read and write
2CBE000
stack
page read and write
25C0000
trusted library allocation
page read and write
400000
unkown
page readonly
26BD000
stack
page read and write
2270000
heap
page read and write
27BF000
stack
page read and write
304C000
stack
page read and write
401000
unkown
page execute read
400000
unkown
page readonly
6FA000
heap
page read and write
29FF000
stack
page read and write
500000
heap
page read and write
21BC000
stack
page read and write
AE0000
heap
page read and write
760000
heap
page read and write
68E000
stack
page read and write
64E000
stack
page read and write
2C7F000
stack
page read and write
28BF000
stack
page read and write
6FE000
heap
page read and write
223E000
stack
page read and write
3050000
heap
page read and write
766000
heap
page read and write
759000
heap
page read and write
21FE000
stack
page read and write
There are 45 hidden memdumps, click here to show them.