Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
-pdf.bat.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
|
initial sample
|
||
C:\Users\user\AppData\Local\Anvilled\Baadehavnes.Ugo
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Anvilled\Martyrizations.Sim
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Anvilled\Opsamlingsbeholdere119.bes
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Anvilled\ammunitionsfabrikken.txt
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Anvilled\teleph.all
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\nsbF5BA.tmp
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\nsk89.tmp\System.dll
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
modified
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\-pdf.bat.exe
|
"C:\Users\user\Desktop\-pdf.bat.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://nsis.sf.net/NSIS_ErrorError
|
unknown
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
s-part-0017.t-0009.fb-t-msedge.net
|
13.107.253.45
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\factorised\afrohaar
|
bytteret
|
||
HKEY_CURRENT_USER\atomforsgsstation\hydramnios
|
spenderingerne
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
54C5000
|
direct allocation
|
page execute and read and write
|
||
19A000
|
stack
|
page read and write
|
||
864000
|
heap
|
page read and write
|
||
427000
|
unkown
|
page read and write
|
||
6A0000
|
heap
|
page read and write
|
||
408000
|
unkown
|
page readonly
|
||
40A000
|
unkown
|
page read and write
|
||
70440000
|
unkown
|
page readonly
|
||
4990000
|
heap
|
page read and write
|
||
287E000
|
heap
|
page read and write
|
||
5EC5000
|
direct allocation
|
page execute and read and write
|
||
48E000
|
unkown
|
page readonly
|
||
2788000
|
heap
|
page read and write
|
||
49A0000
|
trusted library allocation
|
page read and write
|
||
70446000
|
unkown
|
page readonly
|
||
450000
|
unkown
|
page readonly
|
||
42E000
|
unkown
|
page read and write
|
||
8EB000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
7B0000
|
heap
|
page read and write
|
||
44E000
|
unkown
|
page readonly
|
||
890000
|
heap
|
page read and write
|
||
610000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
879000
|
heap
|
page read and write
|
||
7AF000
|
stack
|
page read and write
|
||
8DE000
|
heap
|
page read and write
|
||
8FF000
|
heap
|
page read and write
|
||
8E2000
|
heap
|
page read and write
|
||
8CF000
|
heap
|
page read and write
|
||
870000
|
heap
|
page read and write
|
||
51DC000
|
stack
|
page read and write
|
||
4B0000
|
heap
|
page read and write
|
||
6A5000
|
heap
|
page read and write
|
||
2770000
|
heap
|
page read and write
|
||
860000
|
heap
|
page read and write
|
||
52DE000
|
stack
|
page read and write
|
||
434000
|
unkown
|
page read and write
|
||
490000
|
unkown
|
page readonly
|
||
897000
|
heap
|
page read and write
|
||
2778000
|
heap
|
page read and write
|
||
490000
|
unkown
|
page readonly
|
||
70444000
|
unkown
|
page readonly
|
||
42C000
|
unkown
|
page read and write
|
||
98000
|
stack
|
page read and write
|
||
875000
|
heap
|
page read and write
|
||
408000
|
unkown
|
page readonly
|
||
52E0000
|
direct allocation
|
page execute and read and write
|
||
8D3000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
44E000
|
unkown
|
page readonly
|
||
70441000
|
unkown
|
page execute read
|
||
36B0000
|
trusted library allocation
|
page read and write
|
||
31A0000
|
heap
|
page read and write
|
||
8DF000
|
heap
|
page read and write
|
||
5CE000
|
stack
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
40A000
|
unkown
|
page write copy
|
||
8DF000
|
heap
|
page read and write
|
||
48E000
|
unkown
|
page readonly
|
||
450000
|
unkown
|
page readonly
|
There are 51 hidden memdumps, click here to show them.