IOC Report
-pdf.bat.exe

loading gif

Files

File Path
Type
Category
Malicious
-pdf.bat.exe
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
initial sample
malicious
C:\Users\user\AppData\Local\Anvilled\Baadehavnes.Ugo
data
dropped
C:\Users\user\AppData\Local\Anvilled\Martyrizations.Sim
data
dropped
C:\Users\user\AppData\Local\Anvilled\Opsamlingsbeholdere119.bes
data
dropped
C:\Users\user\AppData\Local\Anvilled\ammunitionsfabrikken.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Anvilled\teleph.all
data
dropped
C:\Users\user\AppData\Local\Temp\nsbF5BA.tmp
data
dropped
C:\Users\user\AppData\Local\Temp\nsk89.tmp\System.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
modified

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\-pdf.bat.exe
"C:\Users\user\Desktop\-pdf.bat.exe"
malicious

URLs

Name
IP
Malicious
http://nsis.sf.net/NSIS_ErrorError
unknown

Domains

Name
IP
Malicious
s-part-0017.t-0009.fb-t-msedge.net
13.107.253.45

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\factorised\afrohaar
bytteret
HKEY_CURRENT_USER\atomforsgsstation\hydramnios
spenderingerne

Memdumps

Base Address
Regiontype
Protect
Malicious
54C5000
direct allocation
page execute and read and write
malicious
19A000
stack
page read and write
864000
heap
page read and write
427000
unkown
page read and write
6A0000
heap
page read and write
408000
unkown
page readonly
40A000
unkown
page read and write
70440000
unkown
page readonly
4990000
heap
page read and write
287E000
heap
page read and write
5EC5000
direct allocation
page execute and read and write
48E000
unkown
page readonly
2788000
heap
page read and write
49A0000
trusted library allocation
page read and write
70446000
unkown
page readonly
450000
unkown
page readonly
42E000
unkown
page read and write
8EB000
heap
page read and write
400000
unkown
page readonly
7B0000
heap
page read and write
44E000
unkown
page readonly
890000
heap
page read and write
610000
heap
page read and write
401000
unkown
page execute read
879000
heap
page read and write
7AF000
stack
page read and write
8DE000
heap
page read and write
8FF000
heap
page read and write
8E2000
heap
page read and write
8CF000
heap
page read and write
870000
heap
page read and write
51DC000
stack
page read and write
4B0000
heap
page read and write
6A5000
heap
page read and write
2770000
heap
page read and write
860000
heap
page read and write
52DE000
stack
page read and write
434000
unkown
page read and write
490000
unkown
page readonly
897000
heap
page read and write
2778000
heap
page read and write
490000
unkown
page readonly
70444000
unkown
page readonly
42C000
unkown
page read and write
98000
stack
page read and write
875000
heap
page read and write
408000
unkown
page readonly
52E0000
direct allocation
page execute and read and write
8D3000
heap
page read and write
400000
unkown
page readonly
44E000
unkown
page readonly
70441000
unkown
page execute read
36B0000
trusted library allocation
page read and write
31A0000
heap
page read and write
8DF000
heap
page read and write
5CE000
stack
page read and write
401000
unkown
page execute read
40A000
unkown
page write copy
8DF000
heap
page read and write
48E000
unkown
page readonly
450000
unkown
page readonly
There are 51 hidden memdumps, click here to show them.