IOC Report
JpQFDOA7Uk.exe

loading gif

Files

File Path
Type
Category
Malicious
JpQFDOA7Uk.exe
PE32 executable (console) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\.ms-ad\CyberVolk_ReadMe.txt
ASCII text
dropped
malicious
C:\Users\user\3D Objects\CyberVolk_ReadMe.txt
ASCII text
dropped
malicious
C:\Users\user\Contacts\CyberVolk_ReadMe.txt
ASCII text
dropped
malicious
C:\Users\user\Desktop\BJZFPPWAPT\CyberVolk_ReadMe.txt
ASCII text
dropped
malicious
C:\Users\user\Desktop\EIVQSAOTAQ\CyberVolk_ReadMe.txt
ASCII text
dropped
malicious
C:\Users\user\Desktop\EWZCVGNOWT\CyberVolk_ReadMe.txt
ASCII text
dropped
malicious
C:\Users\user\Desktop\GRXZDKKVDB\CyberVolk_ReadMe.txt
ASCII text
dropped
malicious
C:\Users\user\Desktop\JpQFDOA7Uk.exe.CyberVolk
data
dropped
malicious
C:\Users\user\Downloads\CyberVolk_ReadMe.txt
ASCII text
dropped
malicious
C:\Users\user\Favorites\CyberVolk_ReadMe.txt
ASCII text
dropped
malicious
C:\Users\user\Favorites\Links\CyberVolk_ReadMe.txt
ASCII text
dropped
malicious
C:\Users\CyberVolk_ReadMe.txt
ASCII text
modified
C:\Users\Public\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\Public\Documents\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\Public\Documents\desktop.ini.CyberVolk
data
dropped
C:\Users\Public\Downloads\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\Public\Downloads\desktop.ini.CyberVolk
data
dropped
C:\Users\Public\Music\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\Public\Music\desktop.ini.CyberVolk
data
dropped
C:\Users\Public\Pictures\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\Public\Pictures\desktop.ini.CyberVolk
data
dropped
C:\Users\Public\Videos\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\Public\Videos\desktop.ini.CyberVolk
data
dropped
C:\Users\Public\desktop.ini.CyberVolk
data
dropped
C:\Users\user\.curlrc.CyberVolk
data
dropped
C:\Users\user\3D Objects\desktop.ini.CyberVolk
data
dropped
C:\Users\user\AppData\Local\Temp\tmp.bmp
PC bitmap, Windows 3.x format, 1920 x 1080 x 24, image size 6220800, cbSize 6220854, bits offset 54
dropped
C:\Users\user\AppData\Roaming\time.dat
ASCII text, with no line terminators
dropped
C:\Users\user\Contacts\desktop.ini.CyberVolk
data
dropped
C:\Users\user\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Desktop\BJZFPPWAPT.docx.CyberVolk
data
dropped
C:\Users\user\Desktop\BJZFPPWAPT.xlsx.CyberVolk
data
dropped
C:\Users\user\Desktop\BJZFPPWAPT\BJZFPPWAPT.docx.CyberVolk
data
dropped
C:\Users\user\Desktop\BJZFPPWAPT\DUUDTUBZFW.xlsx.CyberVolk
data
dropped
C:\Users\user\Desktop\BJZFPPWAPT\EWZCVGNOWT.jpg.CyberVolk
data
dropped
C:\Users\user\Desktop\BJZFPPWAPT\JDDHMPCDUJ.mp3.CyberVolk
data
dropped
C:\Users\user\Desktop\BJZFPPWAPT\KLIZUSIQEN.png.CyberVolk
data
dropped
C:\Users\user\Desktop\BJZFPPWAPT\ZGGKNSUKOP.pdf.CyberVolk
data
dropped
C:\Users\user\Desktop\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Desktop\DUUDTUBZFW.jpg.CyberVolk
data
dropped
C:\Users\user\Desktop\DUUDTUBZFW.xlsx.CyberVolk
data
dropped
C:\Users\user\Desktop\EOWRVPQCCS.png.CyberVolk
data
dropped
C:\Users\user\Desktop\EWZCVGNOWT.jpg.CyberVolk
data
dropped
C:\Users\user\Desktop\Excel.lnk.CyberVolk
data
dropped
C:\Users\user\Desktop\GIGIYTFFYT.pdf.CyberVolk
data
dropped
C:\Users\user\Desktop\GLTYDMDUST.mp3.CyberVolk
data
dropped
C:\Users\user\Desktop\GRXZDKKVDB.docx.CyberVolk
data
dropped
C:\Users\user\Desktop\GRXZDKKVDB\BJZFPPWAPT.xlsx.CyberVolk
data
dropped
C:\Users\user\Desktop\GRXZDKKVDB\DUUDTUBZFW.jpg.CyberVolk
data
dropped
C:\Users\user\Desktop\GRXZDKKVDB\EOWRVPQCCS.png.CyberVolk
data
dropped
C:\Users\user\Desktop\GRXZDKKVDB\GRXZDKKVDB.docx.CyberVolk
data
dropped
C:\Users\user\Desktop\GRXZDKKVDB\PALRGUCVEH.pdf.CyberVolk
data
dropped
C:\Users\user\Desktop\GRXZDKKVDB\ZGGKNSUKOP.mp3.CyberVolk
data
dropped
C:\Users\user\Desktop\JDDHMPCDUJ.jpg.CyberVolk
data
dropped
C:\Users\user\Desktop\JDDHMPCDUJ.mp3.CyberVolk
data
dropped
C:\Users\user\Desktop\KLIZUSIQEN.png.CyberVolk
data
dropped
C:\Users\user\Desktop\LIJDSFKJZG\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Desktop\NWCXBPIUYI\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Desktop\NYMMPCEIMA\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Desktop\PALRGUCVEH.docx.CyberVolk
data
dropped
C:\Users\user\Desktop\PALRGUCVEH.pdf.CyberVolk
data
dropped
C:\Users\user\Desktop\PALRGUCVEH\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Desktop\PALRGUCVEH\GIGIYTFFYT.pdf.CyberVolk
data
dropped
C:\Users\user\Desktop\PALRGUCVEH\GLTYDMDUST.mp3.CyberVolk
data
dropped
C:\Users\user\Desktop\PALRGUCVEH\JDDHMPCDUJ.jpg.CyberVolk
data
dropped
C:\Users\user\Desktop\PALRGUCVEH\PALRGUCVEH.docx.CyberVolk
data
dropped
C:\Users\user\Desktop\PALRGUCVEH\ZGGKNSUKOP.xlsx.CyberVolk
data
dropped
C:\Users\user\Desktop\PALRGUCVEH\ZIPXYXWIOY.png.CyberVolk
data
dropped
C:\Users\user\Desktop\VWDFPKGDUF\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Desktop\ZGGKNSUKOP.mp3.CyberVolk
data
dropped
C:\Users\user\Desktop\ZGGKNSUKOP.pdf.CyberVolk
data
dropped
C:\Users\user\Desktop\ZGGKNSUKOP.xlsx.CyberVolk
data
dropped
C:\Users\user\Desktop\ZIPXYXWIOY.png.CyberVolk
data
dropped
C:\Users\user\Desktop\desktop.ini.CyberVolk
data
dropped
C:\Users\user\Documents\BJZFPPWAPT.docx.CyberVolk
data
dropped
C:\Users\user\Documents\BJZFPPWAPT.xlsx.CyberVolk
data
dropped
C:\Users\user\Documents\BJZFPPWAPT\BJZFPPWAPT.docx.CyberVolk
data
dropped
C:\Users\user\Documents\BJZFPPWAPT\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Documents\BJZFPPWAPT\DUUDTUBZFW.xlsx.CyberVolk
data
dropped
C:\Users\user\Documents\BJZFPPWAPT\EWZCVGNOWT.jpg.CyberVolk
data
dropped
C:\Users\user\Documents\BJZFPPWAPT\JDDHMPCDUJ.mp3.CyberVolk
data
dropped
C:\Users\user\Documents\BJZFPPWAPT\KLIZUSIQEN.png.CyberVolk
data
dropped
C:\Users\user\Documents\BJZFPPWAPT\ZGGKNSUKOP.pdf.CyberVolk
data
dropped
C:\Users\user\Documents\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Documents\DUUDTUBZFW.jpg.CyberVolk
data
dropped
C:\Users\user\Documents\DUUDTUBZFW.xlsx.CyberVolk
data
dropped
C:\Users\user\Documents\EIVQSAOTAQ\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Documents\EOWRVPQCCS.png.CyberVolk
data
dropped
C:\Users\user\Documents\EWZCVGNOWT.jpg.CyberVolk
data
dropped
C:\Users\user\Documents\EWZCVGNOWT\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Documents\GIGIYTFFYT.pdf.CyberVolk
data
dropped
C:\Users\user\Documents\GLTYDMDUST.mp3.CyberVolk
data
dropped
C:\Users\user\Documents\GRXZDKKVDB.docx.CyberVolk
data
dropped
C:\Users\user\Documents\GRXZDKKVDB\BJZFPPWAPT.xlsx.CyberVolk
data
dropped
C:\Users\user\Documents\GRXZDKKVDB\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Documents\GRXZDKKVDB\DUUDTUBZFW.jpg.CyberVolk
data
dropped
C:\Users\user\Documents\GRXZDKKVDB\EOWRVPQCCS.png.CyberVolk
data
dropped
C:\Users\user\Documents\GRXZDKKVDB\GRXZDKKVDB.docx.CyberVolk
data
dropped
C:\Users\user\Documents\GRXZDKKVDB\PALRGUCVEH.pdf.CyberVolk
data
dropped
C:\Users\user\Documents\GRXZDKKVDB\ZGGKNSUKOP.mp3.CyberVolk
data
dropped
C:\Users\user\Documents\JDDHMPCDUJ.jpg.CyberVolk
data
dropped
C:\Users\user\Documents\JDDHMPCDUJ.mp3.CyberVolk
data
dropped
C:\Users\user\Documents\KLIZUSIQEN.png.CyberVolk
data
dropped
C:\Users\user\Documents\LIJDSFKJZG\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Documents\NWCXBPIUYI\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Documents\NYMMPCEIMA\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Documents\PALRGUCVEH.docx.CyberVolk
data
dropped
C:\Users\user\Documents\PALRGUCVEH.pdf.CyberVolk
data
dropped
C:\Users\user\Documents\PALRGUCVEH\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Documents\PALRGUCVEH\GIGIYTFFYT.pdf.CyberVolk
data
dropped
C:\Users\user\Documents\PALRGUCVEH\GLTYDMDUST.mp3.CyberVolk
data
dropped
C:\Users\user\Documents\PALRGUCVEH\JDDHMPCDUJ.jpg.CyberVolk
data
dropped
C:\Users\user\Documents\PALRGUCVEH\PALRGUCVEH.docx.CyberVolk
data
dropped
C:\Users\user\Documents\PALRGUCVEH\ZGGKNSUKOP.xlsx.CyberVolk
data
dropped
C:\Users\user\Documents\PALRGUCVEH\ZIPXYXWIOY.png.CyberVolk
data
dropped
C:\Users\user\Documents\VWDFPKGDUF\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Documents\ZGGKNSUKOP.mp3.CyberVolk
data
dropped
C:\Users\user\Documents\ZGGKNSUKOP.pdf.CyberVolk
data
dropped
C:\Users\user\Documents\ZGGKNSUKOP.xlsx.CyberVolk
data
dropped
C:\Users\user\Documents\ZIPXYXWIOY.png.CyberVolk
data
dropped
C:\Users\user\Documents\desktop.ini.CyberVolk
data
dropped
C:\Users\user\Downloads\BJZFPPWAPT.docx.CyberVolk
data
dropped
C:\Users\user\Downloads\BJZFPPWAPT.xlsx.CyberVolk
data
dropped
C:\Users\user\Downloads\DUUDTUBZFW.jpg.CyberVolk
data
dropped
C:\Users\user\Downloads\DUUDTUBZFW.xlsx.CyberVolk
data
dropped
C:\Users\user\Downloads\EOWRVPQCCS.png.CyberVolk
data
dropped
C:\Users\user\Downloads\EWZCVGNOWT.jpg.CyberVolk
data
dropped
C:\Users\user\Downloads\GIGIYTFFYT.pdf.CyberVolk
data
dropped
C:\Users\user\Downloads\GLTYDMDUST.mp3.CyberVolk
data
dropped
C:\Users\user\Downloads\GRXZDKKVDB.docx.CyberVolk
data
dropped
C:\Users\user\Downloads\JDDHMPCDUJ.jpg.CyberVolk
data
dropped
C:\Users\user\Downloads\JDDHMPCDUJ.mp3.CyberVolk
data
dropped
C:\Users\user\Downloads\KLIZUSIQEN.png.CyberVolk
data
dropped
C:\Users\user\Downloads\PALRGUCVEH.docx.CyberVolk
data
dropped
C:\Users\user\Downloads\PALRGUCVEH.pdf.CyberVolk
data
dropped
C:\Users\user\Downloads\ZGGKNSUKOP.mp3.CyberVolk
data
dropped
C:\Users\user\Downloads\ZGGKNSUKOP.pdf.CyberVolk
data
dropped
C:\Users\user\Downloads\ZGGKNSUKOP.xlsx.CyberVolk
data
dropped
C:\Users\user\Downloads\ZIPXYXWIOY.png.CyberVolk
data
dropped
C:\Users\user\Downloads\desktop.ini.CyberVolk
data
dropped
C:\Users\user\Favorites\Amazon.url.CyberVolk
data
dropped
C:\Users\user\Favorites\Bing.url.CyberVolk
data
dropped
C:\Users\user\Favorites\Facebook.url.CyberVolk
data
dropped
C:\Users\user\Favorites\Google.url.CyberVolk
data
dropped
C:\Users\user\Favorites\Links\desktop.ini.CyberVolk
data
dropped
C:\Users\user\Favorites\Live.url.CyberVolk
data
dropped
C:\Users\user\Favorites\NYTimes.url.CyberVolk
data
dropped
C:\Users\user\Favorites\Reddit.url.CyberVolk
data
dropped
C:\Users\user\Favorites\Twitter.url.CyberVolk
data
dropped
C:\Users\user\Favorites\Wikipedia.url.CyberVolk
data
dropped
C:\Users\user\Favorites\Youtube.url.CyberVolk
data
dropped
C:\Users\user\Favorites\desktop.ini.CyberVolk
data
dropped
C:\Users\user\Links\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Links\Desktop.lnk.CyberVolk
data
dropped
C:\Users\user\Links\Downloads.lnk.CyberVolk
data
dropped
C:\Users\user\Links\desktop.ini.CyberVolk
data
dropped
C:\Users\user\Music\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Music\desktop.ini.CyberVolk
data
dropped
C:\Users\user\NTUSER.DAT{53b39e88-18c4-11ea-a811-000d3aa4692b}.TM.blf.CyberVolk
data
dropped
C:\Users\user\NTUSER.DAT{53b39e88-18c4-11ea-a811-000d3aa4692b}.TMContainer00000000000000000001.regtrans-ms.CyberVolk
data
dropped
C:\Users\user\NTUSER.DAT{53b39e88-18c4-11ea-a811-000d3aa4692b}.TMContainer00000000000000000002.regtrans-ms.CyberVolk
data
dropped
C:\Users\user\OneDrive\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\OneDrive\desktop.ini.CyberVolk
data
dropped
C:\Users\user\Pictures\Camera Roll\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Pictures\Camera Roll\desktop.ini.CyberVolk
data
dropped
C:\Users\user\Pictures\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Pictures\Saved Pictures\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Pictures\Saved Pictures\desktop.ini.CyberVolk
data
dropped
C:\Users\user\Pictures\desktop.ini.CyberVolk
data
dropped
C:\Users\user\Recent\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Saved Games\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Saved Games\desktop.ini.CyberVolk
data
dropped
C:\Users\user\Searches\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Searches\Everywhere.search-ms.CyberVolk
data
dropped
C:\Users\user\Searches\Indexed Locations.search-ms.CyberVolk
data
dropped
C:\Users\user\Searches\desktop.ini.CyberVolk
data
dropped
C:\Users\user\Searches\winrt--{S-1-5-21-2246122658-3693405117-2476756634-1003}-.searchconnector-ms.CyberVolk
data
dropped
C:\Users\user\Videos\CyberVolk_ReadMe.txt
ASCII text
dropped
C:\Users\user\Videos\desktop.ini.CyberVolk
data
dropped
C:\Users\user\_curlrc.CyberVolk
data
dropped
C:\Users\user\ntuser.ini.CyberVolk
data
dropped
C:\Users\desktop.ini.CyberVolk
data
dropped
\Device\ConDrv
ASCII text, with CRLF line terminators
dropped
There are 174 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\JpQFDOA7Uk.exe
"C:\Users\user\Desktop\JpQFDOA7Uk.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
https://t.me/cubervolk
unknown
malicious

Domains

Name
IP
Malicious
241.42.69.40.in-addr.arpa
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
ED7000
heap
page read and write
EDE000
heap
page read and write
EDA000
heap
page read and write
ED0000
heap
page read and write
EDE000
heap
page read and write
EDF000
heap
page read and write
EDE000
heap
page read and write
ED9000
heap
page read and write
EE0000
heap
page read and write
EDE000
heap
page read and write
EDE000
heap
page read and write
ED6000
heap
page read and write
F00000
heap
page read and write
CA0000
heap
page read and write
42B000
unkown
page read and write
3440000
trusted library allocation
page read and write
2FF5000
heap
page read and write
2FF0000
heap
page read and write
DFF000
stack
page read and write
2F04000
heap
page read and write
ED8000
heap
page read and write
EE0000
heap
page read and write
EDA000
heap
page read and write
343C000
stack
page read and write
ED6000
heap
page read and write
EFE000
heap
page read and write
EDE000
heap
page read and write
423000
unkown
page readonly
ED9000
heap
page read and write
EDA000
heap
page read and write
ED8000
heap
page read and write
EDE000
heap
page read and write
EE9000
heap
page read and write
ED8000
heap
page read and write
431000
unkown
page readonly
EDA000
heap
page read and write
EDE000
heap
page read and write
400000
unkown
page readonly
ED5000
heap
page read and write
EDE000
heap
page read and write
EDE000
heap
page read and write
2FD0000
heap
page read and write
19D000
stack
page read and write
3435000
stack
page read and write
ED9000
heap
page read and write
EE0000
heap
page read and write
401000
unkown
page execute read
E8A000
heap
page read and write
2F00000
heap
page read and write
EDF000
heap
page read and write
ED9000
heap
page read and write
1F0000
heap
page read and write
EDE000
heap
page read and write
ED6000
heap
page read and write
9B000
stack
page read and write
EDE000
heap
page read and write
ED6000
heap
page read and write
ED9000
heap
page read and write
EDE000
heap
page read and write
EA2000
heap
page read and write
ED8000
heap
page read and write
E80000
heap
page read and write
ED6000
heap
page read and write
400000
unkown
page readonly
431000
unkown
page readonly
EDE000
heap
page read and write
EDA000
heap
page read and write
EDE000
heap
page read and write
ED9000
heap
page read and write
EDF000
heap
page read and write
EDE000
heap
page read and write
2F4E000
stack
page read and write
F59000
heap
page read and write
EDE000
heap
page read and write
EDA000
heap
page read and write
CFE000
stack
page read and write
EEA000
heap
page read and write
EEA000
heap
page read and write
ED7000
heap
page read and write
2A9F000
stack
page read and write
42B000
unkown
page write copy
EDE000
heap
page read and write
401000
unkown
page execute read
EDA000
heap
page read and write
ED8000
heap
page read and write
EF7000
heap
page read and write
EDE000
heap
page read and write
EDE000
heap
page read and write
EE9000
heap
page read and write
EDA000
heap
page read and write
ED8000
heap
page read and write
ED8000
heap
page read and write
EDE000
heap
page read and write
EDE000
heap
page read and write
ED8000
heap
page read and write
ED8000
heap
page read and write
ED6000
heap
page read and write
EDA000
heap
page read and write
ED7000
heap
page read and write
ED9000
heap
page read and write
EDE000
heap
page read and write
ECE000
heap
page read and write
EE0000
heap
page read and write
ED9000
heap
page read and write
295C000
stack
page read and write
EDE000
heap
page read and write
CB0000
heap
page read and write
F62000
heap
page read and write
EDE000
heap
page read and write
E8E000
heap
page read and write
ED6000
heap
page read and write
EDE000
heap
page read and write
ED7000
heap
page read and write
ED7000
heap
page read and write
ED6000
heap
page read and write
EDE000
heap
page read and write
ED6000
heap
page read and write
ED6000
heap
page read and write
EDF000
heap
page read and write
2FF9000
heap
page read and write
EDE000
heap
page read and write
EE0000
heap
page read and write
343E000
stack
page read and write
EDA000
heap
page read and write
EDA000
heap
page read and write
ED7000
heap
page read and write
EEA000
heap
page read and write
EA9000
heap
page read and write
431000
unkown
page readonly
423000
unkown
page readonly
ED7000
heap
page read and write
285A000
stack
page read and write
2EF0000
heap
page read and write
EE0000
heap
page read and write
ED6000
heap
page read and write
ED8000
heap
page read and write
EDE000
heap
page read and write
EDA000
heap
page read and write
EDE000
heap
page read and write
ED8000
heap
page read and write
299C000
stack
page read and write
EDE000
heap
page read and write
There are 132 hidden memdumps, click here to show them.