IOC Report
vNenBbeRFZ.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\vNenBbeRFZ.exe
"C:\Users\user\Desktop\vNenBbeRFZ.exe"
malicious

URLs

Name
IP
Malicious
47.239.242.141
malicious
http://47.239.242.141/BQPy
malicious
http://47.239.242.141:9999/ga.js
47.239.242.141
malicious
http://47.239.242.141:9999/BQPy
47.239.242.141
malicious
http://47.239.242.141:9999/ga.jskX
unknown
http://47.239.242.141:9999/ga.jslu
unknown
http://47.239.242.141:9999/BQPyHPe)
unknown
http://47.239.242.141:9999/ga.jsl
unknown
http://47.239.242.141:9999/ga.jsl#
unknown
http://47.239.242.141:9999/BQPy%
unknown
http://47.239.242.141:9999/BQPygP
unknown
http://47.239.242.141:9999/ga.jslGX
unknown
http://47.239.242.141:9999/ga.jslqX
unknown
http://127.0.0.1:%u/
unknown
http://47.239.242.141:9999/ga.jsSX
unknown
http://47.239.242.141:9999/ga.jsot
unknown
http://47.239.242.141:9999/ga.jsW
unknown
There are 7 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
47.239.242.141
unknown
United States
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
3970000
direct allocation
page execute and read and write
malicious
110000
direct allocation
page execute read
malicious
3D70000
direct allocation
page execute and read and write
malicious
349B000
stack
page read and write
719000
heap
page read and write
71E000
heap
page read and write
1FC000
stack
page read and write
A20000
heap
page read and write
A0F000
stack
page read and write
325F000
stack
page read and write
3F20000
heap
page read and write
34DE000
stack
page read and write
75C000
heap
page read and write
130000
heap
page read and write
AFE000
stack
page read and write
401000
unkown
page execute read
F7D000
stack
page read and write
100000
heap
page read and write
372E000
stack
page read and write
403000
unkown
page write copy
401000
unkown
page execute read
60E000
stack
page read and write
400000
unkown
page readonly
785000
heap
page read and write
3DAD000
direct allocation
page execute and read and write
400000
unkown
page readonly
3EE0000
direct allocation
page execute read
3EE1000
direct allocation
page execute and read and write
3DA4000
direct allocation
page execute and read and write
77E000
heap
page read and write
36DE000
stack
page read and write
F0000
heap
page read and write
403000
unkown
page read and write
3F30000
heap
page read and write
329E000
stack
page read and write
305F000
stack
page read and write
406000
unkown
page write copy
3ED0000
heap
page read and write
404000
unkown
page readonly
B70000
heap
page read and write
3F34000
heap
page read and write
3DAF000
direct allocation
page execute and read and write
B5E000
stack
page read and write
135000
heap
page read and write
406000
unkown
page read and write
9D000
stack
page read and write
404000
unkown
page readonly
775000
heap
page read and write
392E000
stack
page read and write
3F38000
heap
page read and write
710000
heap
page read and write
17E000
stack
page read and write
39A4000
direct allocation
page execute and read and write
3F32000
heap
page read and write
3DA6000
direct allocation
page execute and read and write
There are 45 hidden memdumps, click here to show them.