IOC Report
IMG_3322101870451.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\IMG_3322101870451.exe
"C:\Users\user\Desktop\IMG_3322101870451.exe"
malicious

URLs

Name
IP
Malicious
http://185.167.61.13
unknown
http://185.167.61.13/aa/Ubeyvibl.vdfP
unknown
http://crl.thawte.com/ThawteTimestampingCA.crl0
unknown
http://185.167.61.13D
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
http://ocsp.thawte.com0
unknown
http://185.167.61.13/aa/Ubeyvibl.vdf
185.167.61.13

IPs

IP
Domain
Country
Malicious
185.167.61.13
unknown
Turkey

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASAPI32
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASAPI32
EnableAutoFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASAPI32
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASAPI32
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASAPI32
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASAPI32
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASAPI32
FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASMANCS
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASMANCS
EnableAutoFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASMANCS
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASMANCS
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASMANCS
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASMANCS
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\IMG_3322101870451_RASMANCS
FileDirectory
There are 5 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
33F2000
trusted library allocation
page read and write
1350000
heap
page read and write
31C0000
trusted library allocation
page read and write
17FE000
stack
page read and write
42C1000
trusted library allocation
page read and write
344C000
trusted library allocation
page read and write
338A000
trusted library allocation
page read and write
33C6000
trusted library allocation
page read and write
1519000
heap
page read and write
1453000
trusted library allocation
page execute and read and write
3456000
trusted library allocation
page read and write
587D000
stack
page read and write
53BE000
stack
page read and write
5730000
heap
page execute and read and write
6D10000
heap
page read and write
12FB000
stack
page read and write
3366000
trusted library allocation
page read and write
14A5000
heap
page read and write
3392000
trusted library allocation
page read and write
1377000
heap
page read and write
6460000
heap
page read and write
1454000
trusted library allocation
page read and write
147E000
heap
page read and write
3439000
trusted library allocation
page read and write
333E000
trusted library allocation
page read and write
32B7000
heap
page read and write
31BE000
stack
page read and write
1770000
trusted library allocation
page read and write
3319000
trusted library allocation
page read and write
6D00000
heap
page read and write
1470000
heap
page read and write
13A0000
heap
page read and write
6BFD000
stack
page read and write
13ED000
stack
page read and write
5D4D000
stack
page read and write
6463000
heap
page read and write
646B000
heap
page read and write
5CCE000
stack
page read and write
1800000
trusted library allocation
page execute and read and write
6471000
heap
page read and write
3379000
trusted library allocation
page read and write
337E000
trusted library allocation
page read and write
F20000
unkown
page readonly
5B8D000
stack
page read and write
5720000
heap
page read and write
5E4C000
stack
page read and write
6010000
trusted library section
page read and write
577D000
stack
page read and write
58BE000
stack
page read and write
3358000
trusted library allocation
page read and write
1757000
trusted library allocation
page execute and read and write
338C000
trusted library allocation
page read and write
1810000
heap
page read and write
1740000
trusted library allocation
page read and write
6473000
heap
page read and write
FEC000
stack
page read and write
3396000
trusted library allocation
page read and write
609E000
stack
page read and write
605D000
stack
page read and write
5F0E000
stack
page read and write
174A000
trusted library allocation
page execute and read and write
17BE000
stack
page read and write
147A000
heap
page read and write
5C88000
stack
page read and write
1746000
trusted library allocation
page execute and read and write
67DD000
stack
page read and write
335F000
trusted library allocation
page read and write
32C1000
trusted library allocation
page read and write
31E0000
trusted library allocation
page read and write
1750000
trusted library allocation
page read and write
145D000
trusted library allocation
page execute and read and write
33FA000
trusted library allocation
page read and write
59BE000
stack
page read and write
1817000
heap
page read and write
32C6000
trusted library allocation
page read and write
3448000
trusted library allocation
page read and write
3450000
trusted library allocation
page read and write
6CFC000
stack
page read and write
151E000
heap
page read and write
F22000
unkown
page readonly
3390000
trusted library allocation
page read and write
5D0E000
stack
page read and write
1440000
trusted library allocation
page read and write
600F000
stack
page read and write
173D000
stack
page read and write
66DD000
stack
page read and write
621D000
stack
page read and write
631E000
stack
page read and write
142D000
stack
page read and write
1460000
trusted library allocation
page read and write
5700000
trusted library allocation
page read and write
1370000
heap
page read and write
31F0000
heap
page execute and read and write
338E000
trusted library allocation
page read and write
175B000
trusted library allocation
page execute and read and write
14B2000
heap
page read and write
1360000
heap
page read and write
6465000
heap
page read and write
191D000
stack
page read and write
1450000
trusted library allocation
page read and write
32B0000
heap
page read and write
33BE000
trusted library allocation
page read and write
There are 92 hidden memdumps, click here to show them.