IOC Report
origin.bin.exe

loading gif

Files

File Path
Type
Category
Malicious
origin.bin.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_origin.bin.exe_7d6a97761f20f53c7dc4c45612edad3adb8344b_fcb3c975_4933da78-9d97-4b66-b347-40729795de4e\Report.wer
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
malicious
C:\ProgramData\Microsoft\Windows\WER\Temp\WER83F6.tmp.dmp
Mini DuMP crash report, 15 streams, Tue Oct 1 15:03:05 2024, 0x1205a4 type
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WER87B0.tmp.WERInternalMetadata.xml
XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WER87D0.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\Windows\appcompat\Programs\Amcache.hve
MS Windows registry file, NT/2000 or above
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\origin.bin.exe
"C:\Users\user\Desktop\origin.bin.exe"
malicious
C:\Windows\SysWOW64\WerFault.exe
C:\Windows\SysWOW64\WerFault.exe -u -p 7308 -s 2340

URLs

Name
IP
Malicious
https://savory.com.bd/comments/feed/
unknown
https://savory.com.bd/wp-content/plugins/elementor/assets/css/frontend.min.css?ver=3.24.4
unknown
https://savory.com.bd/wp-content/plugins/simple-job-board/sjb-block/dist/blocks.style.build.css
unknown
https://savory.com.bd/wp-includes/css/dist/preferences/style.min.css?ver=6.6.2
unknown
http://www.fontbureau.com/designers
unknown
https://savory.com.bd/wp-content/themes/thegem-elementor/css/thegem-widgets.css?ver=6.6.2
unknown
http://ogp.me/ns/fb#
unknown
https://savory.com.bd/
unknown
http://www.sajatypeworks.com
unknown
http://www.founder.com.cn/cn/cThe
unknown
https://savory.com.bd/wp-content/themes/thegem-elementor/css/thegem-grid.css?ver=6.6.2
unknown
http://savory.com.bd/sav/Ztvfo.pngd
unknown
https://savory.com.bd/wp-includes/css/dist/block-library/style.min.css?ver=6.6.2
unknown
http://savory.com.bd/sav/Ztvfo.png
65.181.111.142
https://savory.com.bd/wp-content/plugins/simple-job-board/includes/css/font-awesome.min.css?ver=5.15
unknown
http://www.galapagosdesign.com/DPlease
unknown
https://savory.com.bd/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
unknown
https://savory.com.bd/xmlrpc.php
unknown
http://www.urwpp.deDPlease
unknown
https://savory.com.bd/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=9.3.3
unknown
http://www.zhongyicts.com.cn
unknown
https://savory.com.bd/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=9.3.3
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
https://savory.com.bd/wp-content/plugins/easy-login-woocommerce/xoo-form-fields-fw/lib/fontawesome5/
unknown
https://savory.com.bd/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.svg#WooCommerce
unknown
http://savory.com.bd/wp-content/uploads/2022/04/Loginiage5.jpg);
unknown
https://savory.com.bd/wp-content/plugins/jetwoo-widgets-for-elementor/assets/css/jet-woo-widgets.css
unknown
https://savory.com.bd/wp-content/plugins/thegem-elements-elementor/inc/gdpr/assets/css/public.css?ve
unknown
http://savory.com.bdd
unknown
https://savory.com.bd/wp-content/plugins/zilla-likes/scripts/zilla-likes.js?ver=6.6.2
unknown
https://savory.com.bd/wp-content/themes/thegem-elementor/css/thegem-woocommerce-minicart.css?ver=6.6
unknown
https://savory.com.bd/wp-includes/css/dist/block-editor/style.min.css?ver=6.6.2
unknown
https://savory.com.bd/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.eot?#iefix
unknown
https://savory.com.bd/wp-content/plugins/easy-login-woocommerce/xoo-form-fields-fw/assets/css/xoo-af
unknown
https://savory.com.bd/wp-content/themes/thegem-elementor/css/thegem-new-css.css?ver=6.6.2
unknown
https://savory.com.bd/wp-content/themes/thegem-elementor/style.css?ver=6.6.2
unknown
https://schema.org
unknown
https://savory.com.bd/wp-content/plugins/simple-job-board/public/css/jquery-ui.css?ver=1.12.1
unknown
http://gmpg.org/xfn/11
unknown
http://www.carterandcone.coml
unknown
http://www.fontbureau.com/designers/frere-user.html
unknown
https://savory.com.bd/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?
unknown
https://savory.com.bd/wp-includes/css/dist/editor/style.min.css?ver=6.6.2
unknown
http://ogp.me/ns#
unknown
https://savory.com.bd/?s=
unknown
https://savory.com.bd/wp-content/plugins/easy-login-woocommerce/assets/css/xoo-el-style.css?ver=2.7.
unknown
https://savory.com.bd/wp-json/
unknown
https://savory.com.bd/wp-content/plugins/LayerSlider/assets/static/layerslider/css/layerslider.css?v
unknown
http://www.fontbureau.com/designersG
unknown
http://savory.com.bd
unknown
https://savory.com.bd/sav/Ztvfo.png
65.181.111.142
https://savory.com.bd/wp-content/themes/thegem-elementor/css/custom-3qA74UHG.css?ver=6.6.2
unknown
https://savory.com.bd/wp-content/themes/thegem-elementor/css/thegem-preloader.css?ver=6.6.2
unknown
http://www.fontbureau.com/designers/?
unknown
http://www.founder.com.cn/cn/bThe
unknown
https://savory.com.bd/xmlrpc.php?rsd
unknown
https://yoast.com/wordpress/plugins/seo/
unknown
http://www.fontbureau.com/designers?
unknown
https://savory.com.bd
unknown
http://savory.com.bd8
unknown
http://www.tiro.com
unknown
https://savory.com.bd/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.ttf
unknown
http://www.goodfont.co.kr
unknown
https://savory.com.bd/feed/
unknown
https://savory.com.bd/wp-content/plugins/simple-job-board/public/css/simple-job-board-public.css?ver
unknown
https://savory.com.bd/wp-content/themes/thegem-elementor/css/thegem-perevazka-css.css?ver=6.6.2
unknown
https://savory.com.bd/wp-includes/css/dist/components/style.min.css?ver=6.6.2
unknown
https://layerslider.kreaturamedia.com
unknown
http://www.typography.netD
unknown
http://www.galapagosdesign.com/staff/dennis.htm
unknown
https://savory.com.bd/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=5.9.8
unknown
https://savory.com.bd/wp-content/plugins/essential-addons-for-elementor-lite/assets/front-end/css/vi
unknown
https://savory.com.bd/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
unknown
https://savory.com.bd/wp-content/themes/thegem-elementor/wishlist.css?ver=3.38.0
unknown
http://www.fonts.com
unknown
http://www.sandoll.co.kr
unknown
https://savory.com.bd/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.eot
unknown
https://savory.com.bd/#website
unknown
http://www.sakkal.com
unknown
http://www.apache.org/licenses/LICENSE-2.0
unknown
http://www.fontbureau.com
unknown
https://savory.com.bd/wp-content/themes/thegem-elementor/css/thegem-reset.css?ver=6.6.2
unknown
https://savory.com.bd/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-
unknown
https://savory.com.bd/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.woff
unknown
https://api.w.org/
unknown
http://upx.sf.net
unknown
http://www.microsoft.
unknown
https://savory.com.bd/wp-content/plugins/easy-login-woocommerce/xoo-form-fields-fw/assets/js/xoo-aff
unknown
https://savory.com.bd/wp-content/themes/thegem-elementor/js/fancyBox/jquery.fancybox.min.css?ver=6.6
unknown
http://www.fontbureau.com/designers/cabarga.htmlN
unknown
http://www.founder.com.cn/cn
unknown
http://www.jiyu-kobo.co.jp/
unknown
https://savory.com.bd/wp-includes/css/dist/patterns/style.min.css?ver=6.6.2
unknown
http://www.fontbureau.com/designers8
unknown
https://savory.com.bd/wp-content/themes/thegem-elementor/css/thegem-header.css?ver=6.6.2
unknown
https://savory.com.bd/wp-content/themes/thegem-elementor/js/html5.js?ver=3.7.3
unknown
https://savory.com.bd/wp-includes/css/dist/reusable-blocks/style.min.css?ver=6.6.2
unknown
https://savory.com.bd/wp-content/plugins/easy-login-woocommerce/assets/css/xoo-el-fonts.css?ver=2.7.
unknown
There are 88 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
savory.com.bd
65.181.111.142

IPs

IP
Domain
Country
Malicious
65.181.111.142
savory.com.bd
United States

Registry

Path
Value
Malicious
\REGISTRY\A\{b649a690-ee35-3823-1df7-b9610a578d9b}\Root\InventoryApplicationFile\origin.bin.exe|ff9df0e60f44383e
ProgramId
malicious
\REGISTRY\A\{b649a690-ee35-3823-1df7-b9610a578d9b}\Root\InventoryApplicationFile\origin.bin.exe|ff9df0e60f44383e
FileId
malicious
\REGISTRY\A\{b649a690-ee35-3823-1df7-b9610a578d9b}\Root\InventoryApplicationFile\origin.bin.exe|ff9df0e60f44383e
LowerCaseLongPath
malicious
\REGISTRY\A\{b649a690-ee35-3823-1df7-b9610a578d9b}\Root\InventoryApplicationFile\origin.bin.exe|ff9df0e60f44383e
LongPathHash
malicious
\REGISTRY\A\{b649a690-ee35-3823-1df7-b9610a578d9b}\Root\InventoryApplicationFile\origin.bin.exe|ff9df0e60f44383e
Name
malicious
\REGISTRY\A\{b649a690-ee35-3823-1df7-b9610a578d9b}\Root\InventoryApplicationFile\origin.bin.exe|ff9df0e60f44383e
OriginalFileName
malicious
\REGISTRY\A\{b649a690-ee35-3823-1df7-b9610a578d9b}\Root\InventoryApplicationFile\origin.bin.exe|ff9df0e60f44383e
Publisher
malicious
\REGISTRY\A\{b649a690-ee35-3823-1df7-b9610a578d9b}\Root\InventoryApplicationFile\origin.bin.exe|ff9df0e60f44383e
Version
malicious
\REGISTRY\A\{b649a690-ee35-3823-1df7-b9610a578d9b}\Root\InventoryApplicationFile\origin.bin.exe|ff9df0e60f44383e
BinFileVersion
malicious
\REGISTRY\A\{b649a690-ee35-3823-1df7-b9610a578d9b}\Root\InventoryApplicationFile\origin.bin.exe|ff9df0e60f44383e
BinaryType
malicious
\REGISTRY\A\{b649a690-ee35-3823-1df7-b9610a578d9b}\Root\InventoryApplicationFile\origin.bin.exe|ff9df0e60f44383e
ProductName
malicious
\REGISTRY\A\{b649a690-ee35-3823-1df7-b9610a578d9b}\Root\InventoryApplicationFile\origin.bin.exe|ff9df0e60f44383e
ProductVersion
malicious
\REGISTRY\A\{b649a690-ee35-3823-1df7-b9610a578d9b}\Root\InventoryApplicationFile\origin.bin.exe|ff9df0e60f44383e
LinkDate
malicious
\REGISTRY\A\{b649a690-ee35-3823-1df7-b9610a578d9b}\Root\InventoryApplicationFile\origin.bin.exe|ff9df0e60f44383e
BinProductVersion
malicious
\REGISTRY\A\{b649a690-ee35-3823-1df7-b9610a578d9b}\Root\InventoryApplicationFile\origin.bin.exe|ff9df0e60f44383e
AppxPackageFullName
malicious
\REGISTRY\A\{b649a690-ee35-3823-1df7-b9610a578d9b}\Root\InventoryApplicationFile\origin.bin.exe|ff9df0e60f44383e
AppxPackageRelativeId
malicious
\REGISTRY\A\{b649a690-ee35-3823-1df7-b9610a578d9b}\Root\InventoryApplicationFile\origin.bin.exe|ff9df0e60f44383e
Size
malicious
\REGISTRY\A\{b649a690-ee35-3823-1df7-b9610a578d9b}\Root\InventoryApplicationFile\origin.bin.exe|ff9df0e60f44383e
Language
malicious
\REGISTRY\A\{b649a690-ee35-3823-1df7-b9610a578d9b}\Root\InventoryApplicationFile\origin.bin.exe|ff9df0e60f44383e
Usn
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\origin_RASAPI32
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\origin_RASAPI32
EnableAutoFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\origin_RASAPI32
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\origin_RASAPI32
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\origin_RASAPI32
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\origin_RASAPI32
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\origin_RASAPI32
FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\origin_RASMANCS
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\origin_RASMANCS
EnableAutoFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\origin_RASMANCS
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\origin_RASMANCS
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\origin_RASMANCS
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\origin_RASMANCS
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\origin_RASMANCS
FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\IdentityCRL\ClockData
ClockTimeSeconds
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\IdentityCRL\ClockData
TickCount
There are 26 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
3EE9000
trusted library allocation
page read and write
2D20000
trusted library allocation
page read and write
5490000
heap
page read and write
756E000
stack
page read and write
7F4E000
stack
page read and write
2F46000
trusted library allocation
page read and write
140E000
stack
page read and write
1374000
trusted library allocation
page read and write
13C0000
trusted library allocation
page read and write
138D000
trusted library allocation
page execute and read and write
5420000
heap
page read and write
5700000
heap
page read and write
766E000
stack
page read and write
2E20000
trusted library allocation
page read and write
5440000
heap
page read and write
1392000
trusted library allocation
page read and write
2FF2000
trusted library allocation
page read and write
59EE000
stack
page read and write
2EB2000
trusted library allocation
page read and write
2F3E000
trusted library allocation
page read and write
574A000
heap
page read and write
FA3000
heap
page read and write
1373000
trusted library allocation
page execute and read and write
1460000
trusted library allocation
page read and write
7433000
heap
page read and write
2F71000
trusted library allocation
page read and write
1380000
trusted library allocation
page read and write
4FDE000
stack
page read and write
2D46000
trusted library allocation
page read and write
53F0000
trusted library allocation
page read and write
2E35000
trusted library allocation
page read and write
6FD2000
trusted library allocation
page read and write
5495000
heap
page read and write
2D41000
trusted library allocation
page read and write
1250000
trusted library allocation
page read and write
742F000
stack
page read and write
F40000
heap
page read and write
7CCE000
stack
page read and write
2ED0000
heap
page execute and read and write
748C000
heap
page read and write
1260000
heap
page read and write
2D70000
heap
page read and write
7499000
heap
page read and write
EF7000
stack
page read and write
1396000
trusted library allocation
page execute and read and write
7D0E000
stack
page read and write
F60000
heap
page read and write
548B000
stack
page read and write
5430000
heap
page read and write
B80000
heap
page read and write
7E0E000
stack
page read and write
6FB0000
trusted library allocation
page read and write
808E000
stack
page read and write
54D0000
heap
page read and write
5443000
heap
page read and write
1450000
trusted library allocation
page execute and read and write
F96000
heap
page read and write
2FF0000
trusted library allocation
page read and write
1470000
heap
page read and write
F3E000
stack
page read and write
BF0000
heap
page read and write
2D3E000
trusted library allocation
page read and write
2F97000
trusted library allocation
page read and write
FF6000
heap
page read and write
136F000
stack
page read and write
139A000
trusted library allocation
page execute and read and write
144E000
stack
page read and write
7BCF000
stack
page read and write
56EE000
stack
page read and write
F89000
heap
page read and write
2FF5000
trusted library allocation
page read and write
5410000
trusted library section
page readonly
842F000
stack
page read and write
2D4D000
trusted library allocation
page read and write
587E000
heap
page read and write
76AE000
stack
page read and write
2EC0000
trusted library allocation
page execute and read and write
772E000
stack
page read and write
820E000
stack
page read and write
2D60000
trusted library allocation
page read and write
5740000
heap
page read and write
782F000
stack
page read and write
F6E000
heap
page read and write
2F62000
trusted library allocation
page read and write
54E1000
trusted library allocation
page read and write
7F8E000
stack
page read and write
A80000
unkown
page readonly
2E30000
trusted library allocation
page read and write
2EE1000
trusted library allocation
page read and write
13A0000
trusted library allocation
page read and write
122F000
stack
page read and write
13AB000
trusted library allocation
page execute and read and write
7E4E000
stack
page read and write
1383000
trusted library allocation
page read and write
7437000
heap
page read and write
1034000
heap
page read and write
13A2000
trusted library allocation
page read and write
B19000
stack
page read and write
F68000
heap
page read and write
1370000
trusted library allocation
page read and write
13A7000
trusted library allocation
page execute and read and write
137D000
trusted library allocation
page execute and read and write
B90000
heap
page read and write
2D2B000
trusted library allocation
page read and write
2E40000
trusted library allocation
page read and write
76EE000
stack
page read and write
2D52000
trusted library allocation
page read and write
2F4C000
trusted library allocation
page read and write
2E60000
trusted library allocation
page read and write
3EE1000
trusted library allocation
page read and write
2EB0000
trusted library allocation
page read and write
54B0000
trusted library allocation
page execute and read and write
2F41000
trusted library allocation
page read and write
1477000
heap
page read and write
2E2F000
trusted library allocation
page read and write
1390000
trusted library allocation
page read and write
2EA0000
heap
page read and write
A82000
unkown
page readonly
73ED000
stack
page read and write
80CE000
stack
page read and write
BF5000
heap
page read and write
7430000
heap
page read and write
81CE000
stack
page read and write
59AD000
stack
page read and write
2F4F000
trusted library allocation
page read and write
2F86000
trusted library allocation
page read and write
2F5C000
trusted library allocation
page read and write
54F0000
heap
page execute and read and write
830E000
stack
page read and write
BDE000
stack
page read and write
56F0000
heap
page read and write
5870000
heap
page read and write
786E000
stack
page read and write
2F93000
trusted library allocation
page read and write
2D1E000
stack
page read and write
There are 125 hidden memdumps, click here to show them.