IOC Report
calc.exe

loading gif

Files

File Path
Type
Category
Malicious
calc.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\Desktop\JzM4PpnOtP.jse
data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\calc.exe
"C:\Users\user\Desktop\calc.exe"
malicious
C:\Windows\SysWOW64\wscript.exe
"C:\Windows\System32\wscript.exe" JzM4PpnOtP.jse
malicious
C:\Windows\SysWOW64\net.exe
"C:\Windows\System32\net.exe" user LocalAdministrator /add
malicious
C:\Windows\SysWOW64\net.exe
"C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add
malicious
C:\Users\user\Desktop\calc.exe
"C:\Users\user\Desktop\calc.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\net1.exe
C:\Windows\system32\net1 user LocalAdministrator /add
C:\Windows\SysWOW64\net1.exe
C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Script\Settings\Telemetry\calc.exe
JScriptSetScriptStateStarted
malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Script\Settings
JITDebug
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Script\Settings\Telemetry\wscript.exe
JScriptSetScriptStateStarted

Memdumps

Base Address
Regiontype
Protect
Malicious
29DD000
heap
page read and write
935000
heap
page read and write
591000
heap
page read and write
29A0000
heap
page read and write
593000
heap
page read and write
585000
heap
page read and write
29BE000
heap
page read and write
2510000
heap
page read and write
12D000
stack
page read and write
2256000
heap
page read and write
B3E000
stack
page read and write
2C1F000
stack
page read and write
7D0000
heap
page read and write
26A7000
heap
page read and write
4F5000
heap
page read and write
29C2000
heap
page read and write
47E000
unkown
page read and write
4CE000
heap
page read and write
2530000
heap
page read and write
29A2000
heap
page read and write
225A000
heap
page read and write
4F5000
heap
page read and write
680000
heap
page read and write
580000
heap
page read and write
459000
unkown
page readonly
B40000
heap
page read and write
A60000
heap
page read and write
2984000
heap
page read and write
2999000
heap
page read and write
1F0000
heap
page read and write
86E000
stack
page read and write
58E000
heap
page read and write
585000
heap
page read and write
620000
heap
page read and write
7F9000
heap
page read and write
AE0000
heap
page read and write
58A000
heap
page read and write
547000
heap
page read and write
5A0000
heap
page read and write
297F000
stack
page read and write
21AE000
stack
page read and write
213E000
stack
page read and write
401000
unkown
page execute read
2950000
heap
page read and write
B4C000
heap
page read and write
50C0000
heap
page read and write
4FE000
stack
page read and write
2989000
heap
page read and write
2E35000
heap
page read and write
51E000
heap
page read and write
297C000
heap
page read and write
4BD000
stack
page read and write
CF8000
heap
page read and write
586000
heap
page read and write
685000
heap
page read and write
4D2E000
stack
page read and write
26A6000
heap
page read and write
29AD000
heap
page read and write
93F000
stack
page read and write
547000
heap
page read and write
BB0000
heap
page read and write
29A4000
heap
page read and write
9A0000
heap
page read and write
465000
unkown
page write copy
59A000
heap
page read and write
29A2000
heap
page read and write
18C000
stack
page read and write
76B000
stack
page read and write
670000
heap
page read and write
299E000
heap
page read and write
18C000
stack
page read and write
B46000
heap
page read and write
5A3000
heap
page read and write
5AE000
stack
page read and write
26B9000
heap
page read and write
30AE000
stack
page read and write
2980000
heap
page read and write
5BF000
heap
page read and write
5BF000
heap
page read and write
B1E000
stack
page read and write
29B6000
heap
page read and write
4D8000
heap
page read and write
CD0000
heap
page read and write
2230000
heap
page read and write
99E000
stack
page read and write
29B7000
heap
page read and write
26A7000
heap
page read and write
4750000
heap
page read and write
1E0000
heap
page read and write
53D000
stack
page read and write
7CF000
stack
page read and write
4CA000
heap
page read and write
26BA000
heap
page read and write
29AA000
heap
page read and write
518000
heap
page read and write
5BF000
heap
page read and write
482000
unkown
page readonly
29DD000
heap
page read and write
5EE000
stack
page read and write
2958000
heap
page read and write
29C9000
heap
page read and write
299F000
heap
page read and write
540000
heap
page read and write
AD0000
heap
page read and write
7F5000
heap
page read and write
56F000
stack
page read and write
2F6E000
stack
page read and write
FD000
stack
page read and write
56A000
heap
page read and write
5A7000
heap
page read and write
7DD000
stack
page read and write
7AF000
stack
page read and write
BE0000
heap
page read and write
47E000
unkown
page read and write
543000
heap
page read and write
29C1000
heap
page read and write
26A9000
heap
page read and write
1F0000
heap
page read and write
2DEF000
stack
page read and write
299A000
heap
page read and write
2998000
heap
page read and write
4FAE000
stack
page read and write
68F000
stack
page read and write
297D000
heap
page read and write
299D000
heap
page read and write
558000
heap
page read and write
50AE000
stack
page read and write
81E000
stack
page read and write
94F000
stack
page read and write
71D000
stack
page read and write
477000
unkown
page read and write
5B9000
heap
page read and write
56A000
heap
page read and write
29A5000
heap
page read and write
54AC000
stack
page read and write
1F0000
heap
page read and write
5F0000
heap
page read and write
459000
unkown
page readonly
83E000
stack
page read and write
17F000
stack
page read and write
2250000
heap
page read and write
400000
unkown
page readonly
299A000
heap
page read and write
81E000
stack
page read and write
4D8000
heap
page read and write
4A0000
heap
page read and write
400000
unkown
page readonly
29A6000
heap
page read and write
473E000
stack
page read and write
2D1F000
stack
page read and write
2150000
heap
page read and write
482000
unkown
page readonly
2224000
heap
page read and write
29A6000
heap
page read and write
2978000
heap
page read and write
2E60000
heap
page read and write
29AF000
heap
page read and write
29CA000
heap
page read and write
950000
heap
page read and write
26A4000
heap
page read and write
306F000
stack
page read and write
29B9000
heap
page read and write
6A0000
heap
page read and write
4BAF000
stack
page read and write
5A8000
heap
page read and write
2999000
heap
page read and write
5A0000
heap
page read and write
5A5000
heap
page read and write
57F000
heap
page read and write
4DF000
heap
page read and write
CF0000
heap
page read and write
29A8000
heap
page read and write
2987000
heap
page read and write
4A0000
heap
page read and write
2534000
heap
page read and write
29C3000
heap
page read and write
2E6C000
heap
page read and write
459000
unkown
page readonly
4D8000
heap
page read and write
CD5000
heap
page read and write
625000
heap
page read and write
630000
heap
page read and write
2CEE000
stack
page read and write
BEC000
heap
page read and write
5A3000
heap
page read and write
559000
heap
page read and write
401000
unkown
page execute read
4E0000
heap
page read and write
2987000
heap
page read and write
190000
heap
page read and write
5B7000
heap
page read and write
6A8000
heap
page read and write
5A4000
heap
page read and write
7E0000
heap
page read and write
2998000
heap
page read and write
29B2000
heap
page read and write
2989000
heap
page read and write
354C000
stack
page read and write
490000
heap
page read and write
4E2F000
stack
page read and write
1F5000
heap
page read and write
29BB000
heap
page read and write
26A9000
heap
page read and write
870000
heap
page read and write
540000
heap
page read and write
477000
unkown
page read and write
D05000
heap
page read and write
4F6E000
stack
page read and write
465000
unkown
page read and write
B4A000
heap
page read and write
401000
unkown
page execute read
825000
heap
page read and write
29DD000
heap
page read and write
79E000
stack
page read and write
400000
unkown
page readonly
299D000
heap
page read and write
1E0000
heap
page read and write
BAF000
stack
page read and write
29B5000
heap
page read and write
17D000
stack
page read and write
29AC000
heap
page read and write
4CEF000
stack
page read and write
2F2F000
stack
page read and write
A00000
heap
page read and write
26B8000
heap
page read and write
6CE000
stack
page read and write
585000
heap
page read and write
248E000
stack
page read and write
26B8000
heap
page read and write
482000
unkown
page readonly
4B0000
heap
page read and write
17F000
stack
page read and write
482000
unkown
page readonly
1DE000
stack
page read and write
289F000
stack
page read and write
A5F000
stack
page read and write
269E000
stack
page read and write
4D2000
heap
page read and write
29AA000
heap
page read and write
401000
unkown
page execute read
588000
heap
page read and write
BFE000
stack
page read and write
930000
heap
page read and write
4C7000
heap
page read and write
66B000
stack
page read and write
26A0000
heap
page read and write
225C000
heap
page read and write
4D9000
heap
page read and write
5A0000
heap
page read and write
4CE000
heap
page read and write
2E30000
heap
page read and write
59D000
heap
page read and write
5CE000
stack
page read and write
26A9000
heap
page read and write
2220000
heap
page read and write
7F0000
heap
page read and write
4E2000
heap
page read and write
4A8000
heap
page read and write
5A1000
heap
page read and write
4760000
heap
page read and write
58B000
heap
page read and write
4D2000
heap
page read and write
400000
unkown
page readonly
2989000
heap
page read and write
60E000
stack
page read and write
299D000
heap
page read and write
344C000
stack
page read and write
4BEE000
stack
page read and write
9A000
stack
page read and write
50E000
stack
page read and write
50C2000
heap
page read and write
2E2E000
stack
page read and write
55AC000
stack
page read and write
95E000
stack
page read and write
A2F000
stack
page read and write
9A000
stack
page read and write
510000
heap
page read and write
5550000
trusted library allocation
page read and write
29DD000
heap
page read and write
29B7000
heap
page read and write
ACE000
stack
page read and write
AD000
stack
page read and write
31AF000
stack
page read and write
638000
heap
page read and write
91F000
stack
page read and write
586000
heap
page read and write
5A7000
heap
page read and write
29C9000
heap
page read and write
AD8000
heap
page read and write
29A5000
heap
page read and write
29BC000
heap
page read and write
2986000
heap
page read and write
56A000
heap
page read and write
29A9000
heap
page read and write
585000
heap
page read and write
2E30000
heap
page read and write
B90000
heap
page read and write
C80000
heap
page read and write
B20000
heap
page read and write
820000
heap
page read and write
510000
heap
page read and write
29B4000
heap
page read and write
21F0000
heap
page read and write
4D2000
heap
page read and write
459000
unkown
page readonly
594000
heap
page read and write
C7F000
stack
page read and write
596000
heap
page read and write
58A000
heap
page read and write
5A5000
heap
page read and write
4E6E000
stack
page read and write
465000
unkown
page read and write
5BF000
heap
page read and write
465000
unkown
page write copy
There are 304 hidden memdumps, click here to show them.