IOC Report
USBRecoveryCreator.exe

loading gif

Files

File Path
Type
Category
Malicious
USBRecoveryCreator.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\0ba7d819-f360-4626-b4fb-4b6a653ac16c.tmp
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\246e527c-8108-42ea-be7a-ff7f7c6b46e4.tmp
JSON data
modified
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\3f2621aa-bb61-4f6d-9263-164c8242a7de.tmp
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\5301e1b9-15c2-49f0-95dd-104cd89f2234.tmp
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\6fd7a13f-0753-4d03-b0e5-eb9627615cf1.tmp
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\BrowserMetrics-spare.pma (copy)
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\BrowserMetrics-spare.pma.tmp
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Crashpad\settings.dat
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Crashpad\throttle_store.dat
ASCII text
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\027a0f36-1d5f-43db-80d9-0c51c5940405.tmp
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\38a36b08-5554-42c3-af0c-8cf1267052d7.tmp
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\39f80b5e-f713-4e1b-86f3-4ccef2e12912.tmp
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\42d11d95-a355-4f26-a41f-510a537d3e4c.tmp
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Cache\Cache_Data\data_0
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Cache\Cache_Data\data_1
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Cache\Cache_Data\data_2
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Cache\Cache_Data\data_3
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Cache\Cache_Data\f_000001
Unicode text, UTF-8 text, with very long lines (49130), with no line terminators
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Cache\Cache_Data\f_000002
ASCII text, with very long lines (3396)
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Cache\Cache_Data\f_000003
ASCII text, with very long lines (5945)
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Cache\Cache_Data\f_000004
Unicode text, UTF-8 text, with very long lines (51681), with no line terminators
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Cache\Cache_Data\f_000005
ASCII text, with very long lines (22564), with no line terminators
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Cache\Cache_Data\f_000006
C source, Unicode text, UTF-8 text, with very long lines (28643), with no line terminators
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Cache\Cache_Data\f_000007
Unicode text, UTF-8 text, with very long lines (25453), with no line terminators
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Cache\Cache_Data\f_000008
HTML document, ASCII text, with very long lines (32769)
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Cache\Cache_Data\f_000009
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Cache\Cache_Data\f_00000a
ASCII text, with very long lines (724)
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Cache\Cache_Data\f_00000b
ASCII text, with very long lines (65536), with no line terminators
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Cache\Cache_Data\index
FoxPro FPT, blocks size 768, next free block index 3284796353, field type 0
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Code Cache\js\012edbef7abcf9c9_0
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Code Cache\js\01627f27fb7071ca_0
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Code Cache\js\1493379f364199af_0
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Code Cache\js\5639aaefef9788b1_0
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Code Cache\js\56ff516abbc097e3_0
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Code Cache\js\57587f1582d66016_0
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Code Cache\js\5e6b352005ba6b9c_0
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Code Cache\js\735bf054f08dabfd_0
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Code Cache\js\90b10fdbbf5e582a_0
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Code Cache\js\af91641539dc4e3a_0
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Code Cache\js\c43927c4ca8e9a6d_0
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Code Cache\js\d988bfbda8695bb4_0
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Code Cache\js\index-dir\temp-index
x86 executable not stripped
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Code Cache\js\index-dir\the-real-index (copy)
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Code Cache\js\index-dir\the-real-index~RF4d0d28.TMP (copy)
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Code Cache\wasm\index
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Code Cache\wasm\index-dir\temp-index
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Code Cache\wasm\index-dir\the-real-index (copy)
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\DawnCache\data_1
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\DawnCache\index
FoxPro FPT, blocks size 768, next free block index 3284796353, field type 0
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\GPUCache\data_0
dBase III DBT, next free block index 3238316739, block length 1024
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\GPUCache\data_1
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\GPUCache\data_2
dBase III DBT, next free block index 3238316739, block length 1024
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\GPUCache\index
FoxPro FPT, blocks size 768, next free block index 3284796353, field type 0
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Network\56a46b80-df69-4b5d-9cb8-3182e24c6565.tmp
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Network\65442db1-2f61-4545-a6d0-61bd377815a9.tmp
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Network\7a58ac41-47c3-4414-b6ee-90555ae92473.tmp
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Network\Network Persistent State (copy)
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Network\Network Persistent State~RF4d1333.TMP (copy)
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Network\Network Persistent State~RF4d812f.TMP (copy)
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Network\SCT Auditing Pending Reports (copy)
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Network\SCT Auditing Pending Reports~RF4c638a.TMP (copy)
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Network\Sdch Dictionaries (copy)
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Network\d0f21931-ace5-4cde-9bcf-4e0b07f57c1b.tmp
JSON data
modified
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Network\e8b728ca-a013-4d5a-b2df-97ac4ad0c62d.tmp
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Preferences (copy)
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Preferences~RF4cbb30.TMP (copy)
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Preferences~RF4cee17.TMP (copy)
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Preferences~RF4d75c5.TMP (copy)
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\PreferredApps
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\README
ASCII text, with no line terminators
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Secure Preferences (copy)
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Site Characteristics Database\000001.dbtmp
ASCII text
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Site Characteristics Database\CURRENT (copy)
ASCII text
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\Sync Data\LevelDB\MANIFEST-000001
OpenPGP Secret Key
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Default\b9ef0d62-b181-4573-a293-e03534377839.tmp
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\GrShaderCache\index
FoxPro FPT, blocks size 768, next free block index 3284796353, field type 0
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\GraphiteDawnCache\data_0
FoxPro FPT, blocks size 512, next free block index 3284796609, field type 0
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\GraphiteDawnCache\index
FoxPro FPT, blocks size 768, next free block index 3284796353, field type 0
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Last Version
ASCII text, with no line terminators
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Local State (copy)
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Local State~RF4c6213.TMP (copy)
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Local State~RF4c6261.TMP (copy)
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Local State~RF4c8952.TMP (copy)
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Local State~RF4ceec3.TMP (copy)
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Local State~RF4d75c5.TMP (copy)
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\ShaderCache\data_3
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\ShaderCache\index
FoxPro FPT, blocks size 768, next free block index 3284796353, field type 0
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\SmartScreen\RemoteData\customSettings
ASCII text, with no line terminators
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\SmartScreen\RemoteData\customSettings_F95BA787499AB4FA9EFFF472CE383A14
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\SmartScreen\RemoteData\customSynchronousLookupUris
ASCII text, with no line terminators
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\SmartScreen\RemoteData\customSynchronousLookupUris_0
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\SmartScreen\RemoteData\edgeSettings
ASCII text, with no line terminators
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\SmartScreen\RemoteData\edgeSettings_2.0-0
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\SmartScreen\RemoteData\synchronousLookupUris
ASCII text, with no line terminators
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\SmartScreen\RemoteData\topTraffic
ASCII text, with no line terminators
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\SmartScreen\RemoteData\topTraffic_170540185939602997400506234197983529371
data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\Variations
JSON data
dropped
malicious
C:\Users\user\Desktop\USBRecoveryCreator.exe.WebView2\EBWebView\d0eb52f5-0d88-4b3a-8151-07a3b526ecd4.tmp
JSON data
dropped
malicious
C:\ProgramData\Lenovo\USBRecoveryCreator\Patch.zip
Zip archive data, at least v2.0 to extract, compression method=store
modified
C:\ProgramData\Lenovo\USBRecoveryCreator\SanitizerOptions.json
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\ProgramData\Lenovo\USBRecoveryCreator\ThirdPartyNotices.txt
Unicode text, UTF-8 text, with very long lines (755), with CRLF line terminators
dropped
C:\ProgramData\Lenovo\USBRecoveryCreator\USBComponent.dll
PE32 executable (DLL) (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
C:\ProgramData\Lenovo\USBRecoveryCreator\msvcp140.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\ProgramData\Lenovo\USBRecoveryCreator\vcruntime140.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\5a2a7058cf8d1e56c20e6b19a7c48eb2386d141b.tbres
data
dropped
C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\e8ddd4cbd9c0504aace6ef7a13fa20d04fd52408.tbres
data
dropped
C:\Users\user\AppData\Local\Temp\.net\USBRecoveryCreator\1bdc\D3DCompiler_47_cor3.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\.net\USBRecoveryCreator\1bdc\Lenovo.CertificateValidation.Native.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\.net\USBRecoveryCreator\1bdc\PenImc_cor3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\.net\USBRecoveryCreator\1bdc\PresentationNative_cor3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\.net\USBRecoveryCreator\1bdc\WebView2Loader.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\.net\USBRecoveryCreator\1bdc\runtimes\win-arm64\native\WebView2Loader.dll
PE32+ executable (DLL) (console) Aarch64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\.net\USBRecoveryCreator\1bdc\runtimes\win-x64\native\WebView2Loader.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\.net\USBRecoveryCreator\1bdc\vcruntime140_cor3.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\.net\USBRecoveryCreator\1bdc\wpfgfx_cor3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
There are 106 hidden files, click here to show them.

Domains

Name
IP
Malicious
chrome.cloudflare-dns.com
162.159.61.3
dds.lenovo.com
13.215.130.214
www.google.com
142.250.186.68
passport.lenovo.com
unknown

IPs

IP
Domain
Country
Malicious
142.250.186.68
www.google.com
United States
1.1.1.1
unknown
Australia
142.250.176.196
unknown
United States
142.250.65.174
unknown
United States
216.58.206.72
unknown
United States
13.107.21.239
unknown
United States
104.102.20.239
unknown
United States
13.107.42.16
unknown
United States
142.250.80.67
unknown
United States
162.159.61.3
chrome.cloudflare-dns.com
United States
142.250.65.227
unknown
United States
13.215.130.214
dds.lenovo.com
United States
23.201.163.250
unknown
United States
172.64.41.3
unknown
United States
142.250.186.99
unknown
United States
There are 5 hidden IPs, click here to show them.