Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
Photoshop_x64_en-us.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
|
initial sample
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\LICENSE.txt
|
Unicode text, UTF-8 text, with very long lines (514), with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\host\fxr\8.0.8\hostfxr.dll
|
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\Microsoft.CSharp.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\Microsoft.DiaSymReader.Native.amd64.dll
|
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\Microsoft.VisualBasic.Core.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\Microsoft.Win32.Registry.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Collections.Concurrent.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Collections.Immutable.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Collections.NonGeneric.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Collections.Specialized.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Collections.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.ComponentModel.Annotations.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.ComponentModel.TypeConverter.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Console.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Data.Common.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Diagnostics.DiagnosticSource.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Diagnostics.Process.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Diagnostics.TraceSource.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Drawing.Primitives.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Formats.Asn1.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Formats.Tar.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.IO.Compression.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.IO.FileSystem.AccessControl.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.IO.Pipes.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Linq.Expressions.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Linq.Parallel.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Linq.Queryable.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Linq.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Memory.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Net.Http.Json.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Net.Http.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Net.HttpListener.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Net.Mail.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Net.NameResolution.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Net.NetworkInformation.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Net.Ping.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Net.Primitives.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Net.Quic.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Net.Requests.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Net.Security.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Net.Sockets.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Net.WebClient.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Net.WebSockets.Client.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Net.WebSockets.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Private.Uri.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Private.Xml.Linq.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Private.Xml.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Reflection.Emit.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Reflection.Metadata.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Runtime.InteropServices.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Runtime.Numerics.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Runtime.Serialization.Formatters.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Security.AccessControl.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Security.Claims.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Security.Cryptography.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Security.Principal.Windows.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Text.Encoding.CodePages.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Text.Encodings.Web.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Text.Json.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Text.RegularExpressions.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Threading.Channels.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Threading.Tasks.Dataflow.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Threading.Tasks.Parallel.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\System.Transactions.Local.dll
|
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\clretwrc.dll
|
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\clrgc.dll
|
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\clrjit.dll
|
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\coreclr.dll
|
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\hostpolicy.dll
|
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\mscordaccore.dll
|
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\mscordaccore_amd64_amd64_8.0.824.36612.dll
|
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\mscordbi.dll
|
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\mscorrc.dll
|
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Release_1.7.5.2\shared\Microsoft.NETCore.App\8.0.8\msquic.dll
|
PE32+ executable (DLL) (console) x86-64, for MS Windows
|
dropped
|
There are 65 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\Photoshop_x64_en-us.exe
|
"C:\Users\user\Desktop\Photoshop_x64_en-us.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://github.com/mono/linker/issues/1731
|
unknown
|
||
https://github.com/mono/linker/issues/1981
|
unknown
|
||
https://github.com/mono/linker/pull/2125.
|
unknown
|
||
http://nsis.sf.net/NSIS_Error
|
unknown
|
||
https://aka.ms/dotnet-warnings/
|
unknown
|
||
https://github.com/mono/linker/issues/1416.
|
unknown
|
||
https://github.com/mono/linker/issues/1906.
|
unknown
|
||
https://aka.ms/serializationformat-binary-obsolete
|
unknown
|
||
https://aka.ms/binaryformatter
|
unknown
|
||
https://github.com/dotnet/linker/issues/2715.
|
unknown
|
||
http://nsis.sf.net/NSIS_ErrorError
|
unknown
|
||
https://github.com/mono/linker/issues/1187
|
unknown
|
||
https://github.com/dotnet/runtime
|
unknown
|
||
https://github.com/mono/linker/issues/378
|
unknown
|
There are 4 hidden URLs, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
435000
|
unkown
|
page read and write
|
||
408000
|
unkown
|
page readonly
|
||
22E4000
|
heap
|
page read and write
|
||
40A000
|
unkown
|
page read and write
|
||
4000000
|
trusted library allocation
|
page read and write
|
||
22C0000
|
heap
|
page read and write
|
||
19A000
|
stack
|
page read and write
|
||
520000
|
heap
|
page read and write
|
||
450000
|
heap
|
page read and write
|
||
20DE000
|
stack
|
page read and write
|
||
272F000
|
stack
|
page read and write
|
||
22D0000
|
heap
|
page read and write
|
||
408000
|
unkown
|
page readonly
|
||
56F000
|
heap
|
page read and write
|
||
59A000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
224E000
|
stack
|
page read and write
|
||
1E0000
|
heap
|
page read and write
|
||
4E0000
|
heap
|
page read and write
|
||
528000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
43B000
|
unkown
|
page readonly
|
||
57E000
|
heap
|
page read and write
|
||
210A000
|
heap
|
page read and write
|
||
40A000
|
unkown
|
page write copy
|
||
22E0000
|
heap
|
page read and write
|
||
557000
|
heap
|
page read and write
|
||
2100000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
401000
|
unkown
|
page execute read
|
||
2105000
|
heap
|
page read and write
|
||
57E000
|
heap
|
page read and write
|
||
96000
|
stack
|
page read and write
|
||
220F000
|
stack
|
page read and write
|
||
42C000
|
unkown
|
page read and write
|
||
592000
|
heap
|
page read and write
|
||
43B000
|
unkown
|
page readonly
|
||
59A000
|
heap
|
page read and write
|
There are 28 hidden memdumps, click here to show them.