IOC Report
P3KxDOMmD3.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\P3KxDOMmD3.exe
"C:\Users\user\Desktop\P3KxDOMmD3.exe"
malicious

URLs

Name
IP
Malicious
http://89.197.154.116:7810/cm
89.197.154.116
malicious
89.197.154.116
malicious
http://89.197.154.116:7810/cmZ
unknown
http://89.197.154.116:7810/cmuj
unknown
http://89.197.154.116:7810/cmV
unknown
http://89.197.154.116:7810/cmX
unknown
http://89.197.154.116:7810/cmN
unknown
http://89.197.154.116:7810/cmP
unknown
http://89.197.154.116:7810/cmk.3v
unknown
http://89.197.154.116:7810/cmD
unknown
http://89.197.154.116:7810/cm54.116:7810/cm
unknown
http://89.197.154.116:7810/cmy
unknown
http://89.197.154.116:7810/cm.d
unknown
http://89.197.154.116:7810/cmu
unknown
http://89.197.154.116:7810/cmx
unknown
http://89.197.154.116:7810/cmq
unknown
http://89.197.154.116:7810/cmr
unknown
http://89.197.154.116:7810/cmxu
unknown
http://89.197.154.116:7810/cmp
unknown
http://89.197.154.116:7810/cm54.116:7810/cmay
unknown
http://89.197.154.116:7810/cmj
unknown
http://89.197.154.116:7810/cmh
unknown
http://89.197.154.116:7810/cmVA
unknown
http://127.0.0.1:%u/
unknown
http://89.197.154.116:7810/cmc
unknown
http://89.197.154.116:7810/cmk.py
unknown
There are 16 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
89.197.154.116
unknown
United Kingdom
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
660000
direct allocation
page execute and read and write
malicious
1A0000
direct allocation
page execute read
malicious
798000
heap
page read and write
76F000
heap
page read and write
76F000
heap
page read and write
78C000
heap
page read and write
76F000
heap
page read and write
76F000
heap
page read and write
78D000
heap
page read and write
79F000
heap
page read and write
BC0000
heap
page read and write
9FF000
stack
page read and write
76F000
heap
page read and write
76F000
heap
page read and write
454000
unkown
page write copy
BC5000
heap
page read and write
793000
heap
page read and write
76F000
heap
page read and write
401000
unkown
page execute read
450000
unkown
page readonly
76F000
heap
page read and write
405000
unkown
page write copy
79F000
heap
page read and write
6AE000
direct allocation
page execute and read and write
76F000
heap
page read and write
6B3000
direct allocation
page execute and read and write
76F000
heap
page read and write
700000
heap
page read and write
33BF000
stack
page read and write
76F000
heap
page read and write
78E000
heap
page read and write
180000
heap
page read and write
76F000
heap
page read and write
793000
heap
page read and write
404000
unkown
page read and write
76F000
heap
page read and write
450000
unkown
page readonly
76F000
heap
page read and write
76F000
heap
page read and write
A00000
heap
page read and write
76B000
heap
page read and write
6AB000
direct allocation
page execute and read and write
80000
heap
page read and write
76F000
heap
page read and write
35BD000
stack
page read and write
401000
unkown
page execute read
771000
heap
page read and write
76F000
heap
page read and write
793000
heap
page read and write
741000
heap
page read and write
454000
unkown
page read and write
76F000
heap
page read and write
2DBF000
stack
page read and write
771000
heap
page read and write
76F000
heap
page read and write
79F000
heap
page read and write
76F000
heap
page read and write
70C000
heap
page read and write
FCD000
stack
page read and write
76F000
heap
page read and write
DCA000
stack
page read and write
76D000
heap
page read and write
76F000
heap
page read and write
65D000
stack
page read and write
400000
unkown
page readonly
74C000
heap
page read and write
37BC000
stack
page read and write
6A8000
direct allocation
page execute and read and write
78F000
heap
page read and write
44F000
unkown
page read and write
404000
unkown
page write copy
79F000
heap
page read and write
6B1000
direct allocation
page execute and read and write
706000
heap
page read and write
79F000
heap
page read and write
793000
heap
page read and write
76F000
heap
page read and write
76F000
heap
page read and write
771000
heap
page read and write
76F000
heap
page read and write
76F000
heap
page read and write
160000
heap
page read and write
400000
unkown
page readonly
There are 73 hidden memdumps, click here to show them.