Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
Passport.vbs
|
ASCII text, with CRLF line terminators
|
initial sample
|
||
C:\Users\user\AppData\Local\Temp\Passport.vbs
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\pesuti.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive,
ctime=Tue Oct 1 08:00:57 2024, mtime=Tue Oct 1 08:00:57 2024, atime=Tue Oct 1 08:00:56 2024, length=5114, window=hide
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\53IVYM2Y\country[1].htm
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\org[1].htm
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T9RRWRNL\country[1].htm
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T9RRWRNL\org[1].htm
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\Passport.vbs:Zone.Identifier
|
ASCII text, with CRLF line terminators
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Windows\System32\wscript.exe
|
C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\Passport.vbs"
|
||
C:\Windows\System32\wscript.exe
|
"C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Local\Temp\Passport.vbs"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://185.244.29.74:456/document
|
185.244.29.74
|
||
https://ipinfo.io/org
|
34.117.59.81
|
||
https://ipinfo.io/country
|
34.117.59.81
|
||
https://ipinfo.io/
|
unknown
|
||
http://185.244.29.74:456/documentB
|
unknown
|
||
http://185.244.29.74:456/documentG
|
unknown
|
||
https://ipinfo.io/countryz%
|
unknown
|
||
https://ipinfo.io/country6%
|
unknown
|
||
http://185.244.29.74:456/documentage:
|
unknown
|
||
https://ipinfo.io/countryS
|
unknown
|
||
http://185.244.29.74:456/documentT
|
unknown
|
||
https://ipinfo.io/countryY:
|
unknown
|
||
http://185.244.29.74:456/documentnE
|
unknown
|
||
http://185.244.29.74/j
|
unknown
|
||
http://185.244.29.74:456/documentX
|
unknown
|
||
http://185.244.29.74:456/documentJ
|
unknown
|
||
http://185.244.29.74:456/document32
|
unknown
|
||
http://185.244.29.74:456/document&
|
unknown
|
||
https://ipinfo.io/countryq
|
unknown
|
||
http://185.244.29.74/d1
|
unknown
|
||
http://185.244.29.74:456/document_
|
unknown
|
||
http://185.244.29.74:456/documentr
|
unknown
|
||
http://185.244.29.74:456/documentq
|
unknown
|
||
http://185.244.29.74:456/documentgE
|
unknown
|
||
https://ipinfo.io/countryW
|
unknown
|
||
https://ipinfo.io/org_
|
unknown
|
||
http://185.244.29.74/
|
unknown
|
||
https://ipinfo.io/country_
|
unknown
|
There are 18 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
ipinfo.io
|
34.117.59.81
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
34.117.59.81
|
ipinfo.io
|
United States
|
||
185.244.29.74
|
unknown
|
Netherlands
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
282CCF86000
|
heap
|
page read and write
|
||
282CCF38000
|
heap
|
page read and write
|
||
1F2457A0000
|
heap
|
page read and write
|
||
1F245790000
|
heap
|
page read and write
|
||
282CAD40000
|
heap
|
page read and write
|
||
A4F76FE000
|
stack
|
page read and write
|
||
FEB1FB000
|
stack
|
page read and write
|
||
282CD040000
|
heap
|
page read and write
|
||
282CCFBD000
|
heap
|
page read and write
|
||
1F243560000
|
heap
|
page read and write
|
||
1F2434E0000
|
heap
|
page read and write
|
||
282CAD48000
|
heap
|
page read and write
|
||
A4F77FD000
|
stack
|
page read and write
|
||
1F2435CE000
|
heap
|
page read and write
|
||
1F2438FB000
|
heap
|
page read and write
|
||
282CD630000
|
heap
|
page read and write
|
||
282CC870000
|
heap
|
page read and write
|
||
282CAFD5000
|
heap
|
page read and write
|
||
282CCBC0000
|
heap
|
page read and write
|
||
1F245373000
|
heap
|
page read and write
|
||
1F24573B000
|
heap
|
page read and write
|
||
282CAFDA000
|
heap
|
page read and write
|
||
282CACC0000
|
heap
|
page read and write
|
||
282CAFDB000
|
heap
|
page read and write
|
||
1F2455E0000
|
heap
|
page read and write
|
||
282CACD0000
|
heap
|
page read and write
|
||
1F24365D000
|
heap
|
page read and write
|
||
1F24364C000
|
heap
|
page read and write
|
||
1F245371000
|
heap
|
page read and write
|
||
1F2434D0000
|
heap
|
page read and write
|
||
282CCBCA000
|
heap
|
page read and write
|
||
FEA715000
|
stack
|
page read and write
|
||
1F24573D000
|
heap
|
page read and write
|
||
282CD290000
|
heap
|
page read and write
|
||
282CCF88000
|
heap
|
page read and write
|
||
1F2456DE000
|
heap
|
page read and write
|
||
1F2456B2000
|
heap
|
page read and write
|
||
1F245940000
|
heap
|
page read and write
|
||
1F245702000
|
heap
|
page read and write
|
||
FEADFF000
|
stack
|
page read and write
|
||
1F245570000
|
heap
|
page read and write
|
||
A4F71FE000
|
stack
|
page read and write
|
||
1F245000000
|
heap
|
page read and write
|
||
282CCBCA000
|
heap
|
page read and write
|
||
282CCFA3000
|
heap
|
page read and write
|
||
A4F6B45000
|
stack
|
page read and write
|
||
1F245675000
|
heap
|
page read and write
|
||
282CCBC1000
|
heap
|
page read and write
|
||
1F245630000
|
remote allocation
|
page read and write
|
||
1F24575D000
|
heap
|
page read and write
|
||
282CD0C0000
|
remote allocation
|
page read and write
|
||
1F2456BC000
|
heap
|
page read and write
|
||
1F24537A000
|
heap
|
page read and write
|
||
282CAFD0000
|
heap
|
page read and write
|
||
282CD2E0000
|
heap
|
page read and write
|
||
1F245950000
|
trusted library allocation
|
page read and write
|
||
FEB2FF000
|
stack
|
page read and write
|
||
FEACFD000
|
stack
|
page read and write
|
||
282CCF03000
|
heap
|
page read and write
|
||
282CCED0000
|
heap
|
page read and write
|
||
282CCFB1000
|
heap
|
page read and write
|
||
282CCEDD000
|
heap
|
page read and write
|
||
282CAE3E000
|
heap
|
page read and write
|
||
282CD0C0000
|
remote allocation
|
page read and write
|
||
282CD000000
|
heap
|
page read and write
|
||
1F2456AE000
|
heap
|
page read and write
|
||
282CCF30000
|
heap
|
page read and write
|
||
282CD150000
|
heap
|
page read and write
|
||
282CCBCA000
|
heap
|
page read and write
|
||
282CCBC3000
|
heap
|
page read and write
|
||
282CACF0000
|
heap
|
page read and write
|
||
1F243568000
|
heap
|
page read and write
|
||
282CCEDB000
|
heap
|
page read and write
|
||
282CD045000
|
heap
|
page read and write
|
||
282CCBD2000
|
heap
|
page read and write
|
||
FEAAFD000
|
stack
|
page read and write
|
||
1F245670000
|
heap
|
page read and write
|
||
1F2435B7000
|
heap
|
page read and write
|
||
1F245382000
|
heap
|
page read and write
|
||
1F2438F0000
|
heap
|
page read and write
|
||
282CCF46000
|
heap
|
page read and write
|
||
1F245630000
|
remote allocation
|
page read and write
|
||
1F24364E000
|
heap
|
page read and write
|
||
1F245630000
|
remote allocation
|
page read and write
|
||
282CAE15000
|
heap
|
page read and write
|
||
282CD0C0000
|
remote allocation
|
page read and write
|
||
1F24575F000
|
heap
|
page read and write
|
||
1F2438FA000
|
heap
|
page read and write
|
||
1F24537A000
|
heap
|
page read and write
|
||
282CAD94000
|
heap
|
page read and write
|
||
282CCBC6000
|
heap
|
page read and write
|
||
A4F6EFC000
|
stack
|
page read and write
|
||
A4F70FD000
|
stack
|
page read and write
|
||
1F245696000
|
heap
|
page read and write
|
||
1F245371000
|
heap
|
page read and write
|
||
1F243500000
|
heap
|
page read and write
|
||
282CD480000
|
heap
|
page read and write
|
||
282CD640000
|
trusted library allocation
|
page read and write
|
||
1F245376000
|
heap
|
page read and write
|
||
282CADAD000
|
heap
|
page read and write
|
||
1F2438F5000
|
heap
|
page read and write
|
||
1F245714000
|
heap
|
page read and write
|
||
1F2455D0000
|
heap
|
page read and write
|
||
1F24537A000
|
heap
|
page read and write
|
There are 94 hidden memdumps, click here to show them.