IOC Report
Passport.vbs

loading gif

Files

File Path
Type
Category
Malicious
Passport.vbs
ASCII text, with CRLF line terminators
initial sample
malicious
C:\Users\user\AppData\Local\Temp\Passport.vbs
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\pesuti.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Tue Oct 1 08:00:57 2024, mtime=Tue Oct 1 08:00:57 2024, atime=Tue Oct 1 08:00:56 2024, length=5114, window=hide
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\53IVYM2Y\country[1].htm
ASCII text
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\org[1].htm
ASCII text
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T9RRWRNL\country[1].htm
ASCII text
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T9RRWRNL\org[1].htm
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\Passport.vbs:Zone.Identifier
ASCII text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Windows\System32\wscript.exe
C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\Passport.vbs"
malicious
C:\Windows\System32\wscript.exe
"C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Local\Temp\Passport.vbs"
malicious

URLs

Name
IP
Malicious
http://185.244.29.74:456/document
185.244.29.74
malicious
https://ipinfo.io/org
34.117.59.81
malicious
https://ipinfo.io/country
34.117.59.81
malicious
https://ipinfo.io/
unknown
malicious
http://185.244.29.74:456/documentB
unknown
http://185.244.29.74:456/documentG
unknown
https://ipinfo.io/countryz%
unknown
https://ipinfo.io/country6%
unknown
http://185.244.29.74:456/documentage:
unknown
https://ipinfo.io/countryS
unknown
http://185.244.29.74:456/documentT
unknown
https://ipinfo.io/countryY:
unknown
http://185.244.29.74:456/documentnE
unknown
http://185.244.29.74/j
unknown
http://185.244.29.74:456/documentX
unknown
http://185.244.29.74:456/documentJ
unknown
http://185.244.29.74:456/document32
unknown
http://185.244.29.74:456/document&
unknown
https://ipinfo.io/countryq
unknown
http://185.244.29.74/d1
unknown
http://185.244.29.74:456/document_
unknown
http://185.244.29.74:456/documentr
unknown
http://185.244.29.74:456/documentq
unknown
http://185.244.29.74:456/documentgE
unknown
https://ipinfo.io/countryW
unknown
https://ipinfo.io/org_
unknown
http://185.244.29.74/
unknown
https://ipinfo.io/country_
unknown
There are 18 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
ipinfo.io
34.117.59.81
malicious

IPs

IP
Domain
Country
Malicious
34.117.59.81
ipinfo.io
United States
malicious
185.244.29.74
unknown
Netherlands
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
282CCF86000
heap
page read and write
282CCF38000
heap
page read and write
1F2457A0000
heap
page read and write
1F245790000
heap
page read and write
282CAD40000
heap
page read and write
A4F76FE000
stack
page read and write
FEB1FB000
stack
page read and write
282CD040000
heap
page read and write
282CCFBD000
heap
page read and write
1F243560000
heap
page read and write
1F2434E0000
heap
page read and write
282CAD48000
heap
page read and write
A4F77FD000
stack
page read and write
1F2435CE000
heap
page read and write
1F2438FB000
heap
page read and write
282CD630000
heap
page read and write
282CC870000
heap
page read and write
282CAFD5000
heap
page read and write
282CCBC0000
heap
page read and write
1F245373000
heap
page read and write
1F24573B000
heap
page read and write
282CAFDA000
heap
page read and write
282CACC0000
heap
page read and write
282CAFDB000
heap
page read and write
1F2455E0000
heap
page read and write
282CACD0000
heap
page read and write
1F24365D000
heap
page read and write
1F24364C000
heap
page read and write
1F245371000
heap
page read and write
1F2434D0000
heap
page read and write
282CCBCA000
heap
page read and write
FEA715000
stack
page read and write
1F24573D000
heap
page read and write
282CD290000
heap
page read and write
282CCF88000
heap
page read and write
1F2456DE000
heap
page read and write
1F2456B2000
heap
page read and write
1F245940000
heap
page read and write
1F245702000
heap
page read and write
FEADFF000
stack
page read and write
1F245570000
heap
page read and write
A4F71FE000
stack
page read and write
1F245000000
heap
page read and write
282CCBCA000
heap
page read and write
282CCFA3000
heap
page read and write
A4F6B45000
stack
page read and write
1F245675000
heap
page read and write
282CCBC1000
heap
page read and write
1F245630000
remote allocation
page read and write
1F24575D000
heap
page read and write
282CD0C0000
remote allocation
page read and write
1F2456BC000
heap
page read and write
1F24537A000
heap
page read and write
282CAFD0000
heap
page read and write
282CD2E0000
heap
page read and write
1F245950000
trusted library allocation
page read and write
FEB2FF000
stack
page read and write
FEACFD000
stack
page read and write
282CCF03000
heap
page read and write
282CCED0000
heap
page read and write
282CCFB1000
heap
page read and write
282CCEDD000
heap
page read and write
282CAE3E000
heap
page read and write
282CD0C0000
remote allocation
page read and write
282CD000000
heap
page read and write
1F2456AE000
heap
page read and write
282CCF30000
heap
page read and write
282CD150000
heap
page read and write
282CCBCA000
heap
page read and write
282CCBC3000
heap
page read and write
282CACF0000
heap
page read and write
1F243568000
heap
page read and write
282CCEDB000
heap
page read and write
282CD045000
heap
page read and write
282CCBD2000
heap
page read and write
FEAAFD000
stack
page read and write
1F245670000
heap
page read and write
1F2435B7000
heap
page read and write
1F245382000
heap
page read and write
1F2438F0000
heap
page read and write
282CCF46000
heap
page read and write
1F245630000
remote allocation
page read and write
1F24364E000
heap
page read and write
1F245630000
remote allocation
page read and write
282CAE15000
heap
page read and write
282CD0C0000
remote allocation
page read and write
1F24575F000
heap
page read and write
1F2438FA000
heap
page read and write
1F24537A000
heap
page read and write
282CAD94000
heap
page read and write
282CCBC6000
heap
page read and write
A4F6EFC000
stack
page read and write
A4F70FD000
stack
page read and write
1F245696000
heap
page read and write
1F245371000
heap
page read and write
1F243500000
heap
page read and write
282CD480000
heap
page read and write
282CD640000
trusted library allocation
page read and write
1F245376000
heap
page read and write
282CADAD000
heap
page read and write
1F2438F5000
heap
page read and write
1F245714000
heap
page read and write
1F2455D0000
heap
page read and write
1F24537A000
heap
page read and write
There are 94 hidden memdumps, click here to show them.