IOC Report
startswinstall.exe

loading gif

Files

File Path
Type
Category
Malicious
startswinstall.exe
PE32 executable (console) Intel 80386, for MS Windows
initial sample
\Device\ConDrv
ASCII text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\startswinstall.exe
"C:\Users\user\Desktop\startswinstall.exe" -install
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Users\user\Desktop\startswinstall.exe
"C:\Users\user\Desktop\startswinstall.exe" /install
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Users\user\Desktop\startswinstall.exe
"C:\Users\user\Desktop\startswinstall.exe" /load
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

Domains

Name
IP
Malicious
198.187.3.20.in-addr.arpa
unknown

Registry

Path
Value
Malicious
HKEY_CURRENT_USER_Classes\Local Settings\MuiCache\1e\417C44EB
@%SystemRoot%\System32\ndfapi.dll,-40001

Memdumps

Base Address
Regiontype
Protect
Malicious
9BD000
heap
page read and write
A9E000
stack
page read and write
5950000
heap
page read and write
8D0000
heap
page read and write
889000
heap
page read and write
241000
unkown
page execute read
3AE000
unkown
page readonly
900000
heap
page read and write
91B000
heap
page read and write
B6C000
heap
page read and write
98D000
heap
page read and write
930000
heap
page read and write
A10000
heap
page read and write
B5E000
heap
page read and write
B6C000
heap
page read and write
88A000
heap
page read and write
318E000
stack
page read and write
913000
heap
page read and write
B69000
heap
page read and write
B22000
heap
page read and write
A10000
heap
page read and write
304E000
stack
page read and write
A02000
heap
page read and write
8B0000
heap
page read and write
8BE000
heap
page read and write
B1A000
heap
page read and write
998000
heap
page read and write
A1E000
heap
page read and write
2640000
heap
page read and write
898000
heap
page read and write
24F6000
heap
page read and write
2523000
heap
page read and write
8CD000
heap
page read and write
A02000
heap
page read and write
8E0000
heap
page read and write
8D5000
heap
page read and write
B15000
heap
page read and write
241000
unkown
page execute read
B10000
heap
page read and write
A13000
heap
page read and write
5960000
trusted library allocation
page read and write
5BD000
stack
page read and write
960000
heap
page read and write
3FF000
unkown
page write copy
820000
heap
page read and write
B6C000
heap
page read and write
9A4000
heap
page read and write
241000
unkown
page execute read
A17000
heap
page read and write
B41000
heap
page read and write
970000
heap
page read and write
B1E000
heap
page read and write
3FF000
unkown
page write copy
B66000
heap
page read and write
87D000
heap
page read and write
1B0000
heap
page read and write
B18000
heap
page read and write
9B3000
heap
page read and write
908000
heap
page read and write
90B000
heap
page read and write
ACA000
heap
page read and write
9F0000
heap
page read and write
B41000
heap
page read and write
A0A000
heap
page read and write
90B000
heap
page read and write
317E000
stack
page read and write
241000
unkown
page execute read
A02000
heap
page read and write
9E5000
heap
page read and write
407000
unkown
page readonly
A10000
heap
page read and write
B61000
heap
page read and write
B22000
heap
page read and write
A10000
heap
page read and write
B6C000
heap
page read and write
2E4C000
stack
page read and write
2600000
heap
page read and write
2D45000
stack
page read and write
8B0000
heap
page read and write
8BC000
heap
page read and write
240000
unkown
page readonly
87F000
heap
page read and write
960000
heap
page read and write
896000
heap
page read and write
220000
heap
page read and write
9E3000
heap
page read and write
A1E000
heap
page read and write
860000
heap
page read and write
9F2000
heap
page read and write
8BF000
heap
page read and write
A02000
heap
page read and write
A02000
heap
page read and write
3FD000
unkown
page write copy
91A000
heap
page read and write
983000
heap
page read and write
90C000
heap
page read and write
B3F000
heap
page read and write
AF1000
heap
page read and write
4BB000
stack
page read and write
AAE000
stack
page read and write
8BC000
heap
page read and write
ACE000
heap
page read and write
2FC0000
heap
page read and write
B61000
heap
page read and write
B10000
heap
page read and write
903000
heap
page read and write
8E6000
heap
page read and write
3AE000
unkown
page readonly
AE7000
heap
page read and write
A10000
heap
page read and write
A07000
heap
page read and write
308E000
stack
page read and write
407000
unkown
page readonly
9E2000
heap
page read and write
3FD000
unkown
page read and write
404000
unkown
page read and write
241000
unkown
page execute read
B10000
heap
page read and write
2665000
stack
page read and write
B69000
heap
page read and write
327F000
stack
page read and write
898000
heap
page read and write
8DF000
heap
page read and write
A30000
heap
page read and write
402000
unkown
page read and write
B2D000
heap
page read and write
9D0000
heap
page read and write
B1F000
heap
page read and write
867000
heap
page read and write
B69000
heap
page read and write
A1E000
heap
page read and write
24F0000
heap
page read and write
8BC000
heap
page read and write
9F2000
heap
page read and write
AF4000
heap
page read and write
B61000
heap
page read and write
3AE000
unkown
page readonly
1FE000
stack
page read and write
CBE000
stack
page read and write
AEA000
heap
page read and write
89F000
heap
page read and write
260B000
heap
page read and write
1BB000
stack
page read and write
B69000
heap
page read and write
9B3000
heap
page read and write
2673000
heap
page read and write
3FD000
unkown
page read and write
995000
heap
page read and write
83D000
stack
page read and write
90B000
heap
page read and write
9E5000
heap
page read and write
8BC000
heap
page read and write
87D000
heap
page read and write
2FEE000
stack
page read and write
240000
unkown
page readonly
A10000
heap
page read and write
B7C000
heap
page read and write
90B000
heap
page read and write
896000
heap
page read and write
900000
heap
page read and write
2570000
heap
page read and write
A1C000
heap
page read and write
990000
heap
page read and write
A0C000
heap
page read and write
25CD000
stack
page read and write
A0A000
heap
page read and write
5C20000
heap
page read and write
241000
unkown
page execute read
9B0000
heap
page read and write
C6E000
stack
page read and write
B69000
heap
page read and write
9B3000
heap
page read and write
90B000
heap
page read and write
BAE000
stack
page read and write
9C1000
heap
page read and write
B69000
heap
page read and write
9CD000
heap
page read and write
98E000
stack
page read and write
9C5000
heap
page read and write
52C000
stack
page read and write
A1E000
heap
page read and write
B40000
heap
page read and write
407000
unkown
page readonly
9CD000
heap
page read and write
87E000
stack
page read and write
A06000
heap
page read and write
A0A000
heap
page read and write
A0A000
heap
page read and write
9A5000
heap
page read and write
23D6000
heap
page read and write
404000
unkown
page read and write
9E5000
heap
page read and write
A10000
heap
page read and write
8BA000
heap
page read and write
2520000
heap
page read and write
240000
unkown
page readonly
B18000
heap
page read and write
A30000
heap
page read and write
8CA000
heap
page read and write
240000
unkown
page readonly
2606000
heap
page read and write
200000
heap
page read and write
89B000
heap
page read and write
2EAE000
stack
page read and write
94E000
stack
page read and write
9E7000
heap
page read and write
301E000
stack
page read and write
230000
heap
page read and write
9BF000
heap
page read and write
8E4000
heap
page read and write
89F000
heap
page read and write
407000
unkown
page readonly
9BF000
heap
page read and write
3FD000
unkown
page read and write
B2A000
heap
page read and write
B61000
heap
page read and write
2610000
heap
page read and write
A1E000
heap
page read and write
24FB000
heap
page read and write
B69000
heap
page read and write
2E50000
heap
page read and write
23D0000
heap
page read and write
9E9000
heap
page read and write
98D000
heap
page read and write
896000
heap
page read and write
B2E000
heap
page read and write
AC0000
heap
page read and write
3AE000
unkown
page readonly
240000
unkown
page readonly
930000
heap
page read and write
980000
heap
page read and write
A0A000
heap
page read and write
2670000
heap
page read and write
898000
heap
page read and write
B89000
heap
page read and write
A0A000
heap
page read and write
B6C000
heap
page read and write
89F000
heap
page read and write
8BC000
heap
page read and write
977000
heap
page read and write
14B000
stack
page read and write
9C2000
heap
page read and write
A0A000
heap
page read and write
8E1000
heap
page read and write
B1B000
heap
page read and write
33FE000
stack
page read and write
402000
unkown
page read and write
407000
unkown
page readonly
3AE000
unkown
page readonly
240000
unkown
page readonly
A02000
heap
page read and write
B7B000
heap
page read and write
5C30000
trusted library allocation
page read and write
9D1000
heap
page read and write
32FE000
stack
page read and write
B6E000
stack
page read and write
3FF000
unkown
page write copy
A1A000
heap
page read and write
A1E000
heap
page read and write
B18000
heap
page read and write
407000
unkown
page readonly
9BF000
heap
page read and write
A0A000
heap
page read and write
B61000
heap
page read and write
402000
unkown
page read and write
5EA0000
trusted library allocation
page read and write
8B0000
heap
page read and write
9C0000
heap
page read and write
AE7000
heap
page read and write
90B000
heap
page read and write
A0A000
heap
page read and write
B6C000
heap
page read and write
23DB000
heap
page read and write
9A0000
heap
page read and write
2FAE000
stack
page read and write
998000
heap
page read and write
52C000
stack
page read and write
9FF000
heap
page read and write
30EF000
stack
page read and write
83E000
stack
page read and write
B6C000
heap
page read and write
8CE000
heap
page read and write
404000
unkown
page read and write
3FD000
unkown
page write copy
2FBB000
stack
page read and write
8E2000
heap
page read and write
B6D000
heap
page read and write
89B000
heap
page read and write
B61000
heap
page read and write
B89000
heap
page read and write
90B000
heap
page read and write
8C2000
heap
page read and write
3AE000
unkown
page readonly
A10000
heap
page read and write
311E000
stack
page read and write
89B000
heap
page read and write
8E4000
heap
page read and write
A02000
heap
page read and write
9E5000
heap
page read and write
9F2000
heap
page read and write
995000
heap
page read and write
3FD000
unkown
page write copy
990000
heap
page read and write
There are 293 hidden memdumps, click here to show them.