IOC Report
Nulzuen.exe

loading gif

Files

File Path
Type
Category
Malicious
Nulzuen.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Roaming\Zwrgmbkirk.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Roaming\Zwrgmbkirk.exe:Zone.Identifier
ASCII text, with CRLF line terminators
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Nulzuen.exe
"C:\Users\user\Desktop\Nulzuen.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe"
malicious
C:\Windows\SysWOW64\WerFault.exe
C:\Windows\SysWOW64\WerFault.exe -u -p 7828 -s 1156

URLs

Name
IP
Malicious
https://github.com/mgravell/protobuf-net
unknown
https://github.com/mgravell/protobuf-neti
unknown
https://stackoverflow.com/q/14436606/23354
unknown
https://github.com/mgravell/protobuf-netJ
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
https://stackoverflow.com/q/11564914/23354;
unknown
https://stackoverflow.com/q/2152978/23354
unknown

Domains

Name
IP
Malicious
s-part-0015.t-0009.t-msedge.net
13.107.246.43

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Zwrgmbkirk

Memdumps

Base Address
Regiontype
Protect
Malicious
2901000
trusted library allocation
page read and write
malicious
5950000
trusted library section
page read and write
malicious
2F1F000
trusted library allocation
page read and write
31AB000
trusted library allocation
page read and write
2BE9000
trusted library allocation
page read and write
2DC7000
trusted library allocation
page read and write
2D3E000
trusted library allocation
page read and write
C81000
heap
page read and write
2E1E000
trusted library allocation
page read and write
2AFA000
trusted library allocation
page read and write
2D5D000
trusted library allocation
page read and write
3E0000
unkown
page readonly
2F1D000
trusted library allocation
page read and write
3120000
trusted library section
page read and write
2F5A000
trusted library allocation
page read and write
31C6000
trusted library allocation
page read and write
2EF5000
trusted library allocation
page read and write
2DA8000
trusted library allocation
page read and write
2C48000
trusted library allocation
page read and write
2FA2000
trusted library allocation
page read and write
2C55000
trusted library allocation
page read and write
15C8000
heap
page read and write
2F17000
trusted library allocation
page read and write
2B0A000
trusted library allocation
page read and write
5B60000
heap
page read and write
2C0D000
trusted library allocation
page read and write
2F32000
trusted library allocation
page read and write
2C8F000
trusted library allocation
page read and write
2F53000
trusted library allocation
page read and write
2F68000
trusted library allocation
page read and write
2E3B000
trusted library allocation
page read and write
2BBA000
trusted library allocation
page read and write
31A9000
trusted library allocation
page read and write
2FBF000
trusted library allocation
page read and write
2FCA000
trusted library allocation
page read and write
2E09000
trusted library allocation
page read and write
2F6C000
trusted library allocation
page read and write
2BA9000
trusted library allocation
page read and write
2B63000
trusted library allocation
page read and write
3E90000
trusted library allocation
page read and write
57CE000
stack
page read and write
5840000
trusted library allocation
page read and write
2DB2000
trusted library allocation
page read and write
2C59000
trusted library allocation
page read and write
2B2D000
trusted library allocation
page read and write
2D74000
trusted library allocation
page read and write
2D66000
trusted library allocation
page read and write
2E1C000
trusted library allocation
page read and write
2B58000
trusted library allocation
page read and write
2B50000
trusted library allocation
page read and write
2D4A000
trusted library allocation
page read and write
E5B000
trusted library allocation
page execute and read and write
2D7C000
trusted library allocation
page read and write
5650000
heap
page read and write
2B10000
trusted library allocation
page read and write
2F49000
trusted library allocation
page read and write
2EF7000
trusted library allocation
page read and write
13E0000
heap
page read and write
2BEB000
trusted library allocation
page read and write
2C57000
trusted library allocation
page read and write
2F4B000
trusted library allocation
page read and write
2C3C000
trusted library allocation
page read and write
BCE000
stack
page read and write
5B34000
heap
page read and write
2880000
trusted library allocation
page read and write
2BC6000
trusted library allocation
page read and write
2C5D000
trusted library allocation
page read and write
2F6E000
trusted library allocation
page read and write
5A30000
trusted library allocation
page execute and read and write
2AF7000
trusted library allocation
page read and write
2DCF000
trusted library allocation
page read and write
2C11000
trusted library allocation
page read and write
2A2F000
trusted library allocation
page read and write
3E2000
unkown
page readonly
2D48000
trusted library allocation
page read and write
2C44000
trusted library allocation
page read and write
2C42000
trusted library allocation
page read and write
1320000
heap
page read and write
58F0000
trusted library section
page read and write
2770000
trusted library allocation
page execute and read and write
2B3F000
trusted library allocation
page read and write
568F000
stack
page read and write
E52000
trusted library allocation
page read and write
3150000
remote allocation
page read and write
5AB0000
trusted library allocation
page read and write
2CC4000
trusted library allocation
page read and write
2BCE000
trusted library allocation
page read and write
2C0B000
trusted library allocation
page read and write
2FC1000
trusted library allocation
page read and write
5A2E000
trusted library allocation
page read and write
606E000
stack
page read and write
E57000
trusted library allocation
page execute and read and write
17C0000
heap
page read and write
2CC8000
trusted library allocation
page read and write
2D02000
trusted library allocation
page read and write
2C5F000
trusted library allocation
page read and write
2D80000
trusted library allocation
page read and write
13B4000
trusted library allocation
page read and write
486000
remote allocation
page execute and read and write
2CFC000
trusted library allocation
page read and write
5830000
trusted library allocation
page execute and read and write
2B8E000
trusted library allocation
page read and write
58E9000
trusted library allocation
page read and write
2CB6000
trusted library allocation
page read and write
15A0000
trusted library allocation
page execute and read and write
2DCD000
trusted library allocation
page read and write
2AF3000
trusted library allocation
page read and write
2BA7000
trusted library allocation
page read and write
2B08000
trusted library allocation
page read and write
2CDF000
trusted library allocation
page read and write
2C1D000
trusted library allocation
page read and write
59CE000
stack
page read and write
2C7C000
trusted library allocation
page read and write
32B6000
trusted library allocation
page read and write
13A0000
trusted library allocation
page read and write
2CE7000
trusted library allocation
page read and write
2B42000
trusted library allocation
page read and write
2B2B000
trusted library allocation
page read and write
2B21000
trusted library allocation
page read and write
2C64000
trusted library allocation
page read and write
2FA8000
trusted library allocation
page read and write
17EF000
trusted library allocation
page read and write
2BED000
trusted library allocation
page read and write
58C0000
trusted library allocation
page execute and read and write
57D0000
trusted library section
page read and write
587E000
trusted library allocation
page read and write
2C08000
trusted library allocation
page read and write
320B000
trusted library allocation
page read and write
2BE7000
trusted library allocation
page read and write
2F2A000
trusted library allocation
page read and write
D24000
heap
page read and write
2CE5000
trusted library allocation
page read and write
C68000
heap
page read and write
2FAE000
trusted library allocation
page read and write
2B90000
trusted library allocation
page read and write
2C70000
trusted library allocation
page read and write
2F3B000
trusted library allocation
page read and write
2FAA000
trusted library allocation
page read and write
56B2000
heap
page read and write
2F38000
trusted library allocation
page read and write
2C91000
trusted library allocation
page read and write
2EF9000
trusted library allocation
page read and write
2CFE000
trusted library allocation
page read and write
2DCB000
trusted library allocation
page read and write
276F000
stack
page read and write
5DA0000
heap
page read and write
17FC000
trusted library allocation
page read and write
2C72000
trusted library allocation
page read and write
2E33000
trusted library allocation
page read and write
2BC8000
trusted library allocation
page read and write
2DE4000
trusted library allocation
page read and write
3925000
trusted library allocation
page read and write
558E000
stack
page read and write
2BFE000
trusted library allocation
page read and write
E46000
trusted library allocation
page execute and read and write
2D8F000
trusted library allocation
page read and write
28C0000
trusted library allocation
page read and write
2D40000
trusted library allocation
page read and write
2CCE000
trusted library allocation
page read and write
2BE3000
trusted library allocation
page read and write
1644000
heap
page read and write
2FBD000
trusted library allocation
page read and write
530D000
stack
page read and write
14F0000
trusted library allocation
page read and write
30DE000
stack
page read and write
13D7000
trusted library allocation
page execute and read and write
286C000
stack
page read and write
2CA7000
trusted library allocation
page read and write
402000
remote allocation
page execute and read and write
3171000
trusted library allocation
page read and write
2DEA000
trusted library allocation
page read and write
56AA000
heap
page read and write
2C04000
trusted library allocation
page read and write
E9C000
stack
page read and write
2E39000
trusted library allocation
page read and write
2D78000
trusted library allocation
page read and write
2C46000
trusted library allocation
page read and write
2C32000
trusted library allocation
page read and write
2CFA000
trusted library allocation
page read and write
2D76000
trusted library allocation
page read and write
2D04000
trusted library allocation
page read and write
2B56000
trusted library allocation
page read and write
5690000
heap
page read and write
2F64000
trusted library allocation
page read and write
162E000
heap
page read and write
14F7000
trusted library allocation
page execute and read and write
15EE000
heap
page read and write
2C3A000
trusted library allocation
page read and write
540E000
stack
page read and write
8F7000
stack
page read and write
517F000
stack
page read and write
2780000
heap
page read and write
E4A000
trusted library allocation
page execute and read and write
2C93000
trusted library allocation
page read and write
5870000
trusted library allocation
page read and write
CB4000
heap
page read and write
2CE3000
trusted library allocation
page read and write
507E000
stack
page read and write
A5E000
stack
page read and write
EC0000
heap
page read and write
C4A000
heap
page read and write
13BD000
trusted library allocation
page execute and read and write
2798000
trusted library allocation
page read and write
2CCC000
trusted library allocation
page read and write
28B0000
heap
page execute and read and write
2788000
heap
page read and write
3AD7000
trusted library allocation
page read and write
E40000
trusted library allocation
page read and write
2D89000
trusted library allocation
page read and write
2BD4000
trusted library allocation
page read and write
530E000
stack
page read and write
554F000
stack
page read and write
2DAE000
trusted library allocation
page read and write
58A0000
trusted library allocation
page execute and read and write
2FC3000
trusted library allocation
page read and write
2B2F000
trusted library allocation
page read and write
C14000
trusted library allocation
page read and write
31BF000
trusted library allocation
page read and write
4DEE000
stack
page read and write
2F51000
trusted library allocation
page read and write
A80000
heap
page read and write
C30000
heap
page read and write
2C21000
trusted library allocation
page read and write
C4E000
heap
page read and write
4EEF000
stack
page read and write
C13000
trusted library allocation
page execute and read and write
2DB0000
trusted library allocation
page read and write
2B6D000
trusted library allocation
page read and write
2B8C000
trusted library allocation
page read and write
2B93000
trusted library allocation
page read and write
2C97000
trusted library allocation
page read and write
2CE9000
trusted library allocation
page read and write
2B80000
trusted library allocation
page read and write
2CAD000
trusted library allocation
page read and write
445C000
trusted library allocation
page read and write
2D5F000
trusted library allocation
page read and write
2B79000
trusted library allocation
page read and write
2B23000
trusted library allocation
page read and write
2CA9000
trusted library allocation
page read and write
58EB000
trusted library allocation
page read and write
2AF1000
trusted library allocation
page read and write
C20000
trusted library allocation
page read and write
5F6E000
stack
page read and write
544E000
stack
page read and write
2D91000
trusted library allocation
page read and write
2D99000
trusted library allocation
page read and write
4171000
trusted library allocation
page read and write
5CA0000
trusted library allocation
page execute and read and write
2DB5000
trusted library allocation
page read and write
15FA000
heap
page read and write
C40000
heap
page read and write
2C8D000
trusted library allocation
page read and write
2BDB000
trusted library allocation
page read and write
2B86000
trusted library allocation
page read and write
2B54000
trusted library allocation
page read and write
2C3E000
trusted library allocation
page read and write
28E9000
trusted library allocation
page read and write
13C0000
trusted library allocation
page read and write
5880000
trusted library allocation
page read and write
2CEC000
trusted library allocation
page read and write
56C8000
heap
page read and write
155E000
stack
page read and write
2D46000
trusted library allocation
page read and write
2DAC000
trusted library allocation
page read and write
13D0000
trusted library allocation
page read and write
28A0000
heap
page read and write
2BD2000
trusted library allocation
page read and write
2F66000
trusted library allocation
page read and write
5A30000
trusted library allocation
page read and write
2B27000
trusted library allocation
page read and write
5CB000
stack
page read and write
2B0C000
trusted library allocation
page read and write
5890000
trusted library allocation
page read and write
5910000
trusted library allocation
page execute and read and write
2B82000
trusted library allocation
page read and write
2FD8000
trusted library allocation
page read and write
2B99000
trusted library allocation
page read and write
5860000
trusted library allocation
page read and write
2B29000
trusted library allocation
page read and write
2BE5000
trusted library allocation
page read and write
2D5B000
trusted library allocation
page read and write
2B75000
trusted library allocation
page read and write
13DA000
trusted library allocation
page execute and read and write
2BB7000
trusted library allocation
page read and write
2FA6000
trusted library allocation
page read and write
57E0000
heap
page execute and read and write
2DA6000
trusted library allocation
page read and write
1830000
heap
page read and write
15B0000
heap
page read and write
6070000
heap
page read and write
2F56000
trusted library allocation
page read and write
58F0000
trusted library allocation
page read and write
2B8A000
trusted library allocation
page read and write
2F36000
trusted library allocation
page read and write
15C0000
heap
page read and write
930000
heap
page read and write
2E07000
trusted library allocation
page read and write
5940000
trusted library allocation
page execute and read and write
2DBD000
trusted library allocation
page read and write
2FAC000
trusted library allocation
page read and write
3901000
trusted library allocation
page read and write
2B73000
trusted library allocation
page read and write
5820000
trusted library allocation
page read and write
2BD0000
trusted library allocation
page read and write
15B6000
heap
page read and write
58EE000
stack
page read and write
5A55000
trusted library allocation
page read and write
E70000
trusted library allocation
page read and write
B8E000
stack
page read and write
2E01000
trusted library allocation
page read and write
2BF1000
trusted library allocation
page read and write
2DD4000
trusted library allocation
page read and write
2F71000
trusted library allocation
page read and write
2E37000
trusted library allocation
page read and write
14FB000
trusted library allocation
page execute and read and write
EBE000
stack
page read and write
2F7D000
trusted library allocation
page read and write
532000
unkown
page readonly
2DEF000
trusted library allocation
page read and write
2B5C000
trusted library allocation
page read and write
2DE2000
trusted library allocation
page read and write
1200000
heap
page read and write
394F000
trusted library allocation
page read and write
394C000
trusted library allocation
page read and write
2D38000
trusted library allocation
page read and write
5920000
trusted library allocation
page read and write
2E22000
trusted library allocation
page read and write
1810000
heap
page read and write
C00000
trusted library allocation
page read and write
2D00000
trusted library allocation
page read and write
2B12000
trusted library allocation
page read and write
2B95000
trusted library allocation
page read and write
2F81000
trusted library allocation
page read and write
2F4D000
trusted library allocation
page read and write
28F0000
heap
page execute and read and write
2D7A000
trusted library allocation
page read and write
2C61000
trusted library allocation
page read and write
2AEF000
trusted library allocation
page read and write
2E05000
trusted library allocation
page read and write
2D6A000
trusted library allocation
page read and write
2D42000
trusted library allocation
page read and write
2C95000
trusted library allocation
page read and write
42E8000
trusted library allocation
page read and write
2C7A000
trusted library allocation
page read and write
2870000
trusted library allocation
page read and write
2BFA000
trusted library allocation
page read and write
57C0000
trusted library allocation
page execute and read and write
2CAF000
trusted library allocation
page read and write
2F1B000
trusted library allocation
page read and write
2DFB000
trusted library allocation
page read and write
5B20000
trusted library allocation
page read and write
2C19000
trusted library allocation
page read and write
2E18000
trusted library allocation
page read and write
BD0000
heap
page read and write
2B25000
trusted library allocation
page read and write
C1D000
trusted library allocation
page execute and read and write
5B30000
heap
page read and write
A10000
heap
page read and write
2EFC000
trusted library allocation
page read and write
5930000
trusted library allocation
page execute and read and write
2B5A000
trusted library allocation
page read and write
5A60000
trusted library section
page read and write
2B0E000
trusted library allocation
page read and write
400000
remote allocation
page execute and read and write
2AF5000
trusted library allocation
page read and write
2AED000
trusted library allocation
page read and write
2E1A000
trusted library allocation
page read and write
2B52000
trusted library allocation
page read and write
2F19000
trusted library allocation
page read and write
C75000
heap
page read and write
2BA1000
trusted library allocation
page read and write
7FD40000
trusted library allocation
page execute and read and write
2D59000
trusted library allocation
page read and write
49FE000
stack
page read and write
2F30000
trusted library allocation
page read and write
2D44000
trusted library allocation
page read and write
2D3C000
trusted library allocation
page read and write
2DD1000
trusted library allocation
page read and write
2C74000
trusted library allocation
page read and write
2CB1000
trusted library allocation
page read and write
2CD2000
trusted library allocation
page read and write
2DFD000
trusted library allocation
page read and write
A85000
heap
page read and write
2CCA000
trusted library allocation
page read and write
13C4000
trusted library allocation
page read and write
2BA3000
trusted library allocation
page read and write
3A02000
trusted library allocation
page read and write
2BD6000
trusted library allocation
page read and write
28D0000
trusted library allocation
page read and write
2F34000
trusted library allocation
page read and write
2D97000
trusted library allocation
page read and write
2B71000
trusted library allocation
page read and write
2CAB000
trusted library allocation
page read and write
2DAA000
trusted library allocation
page read and write
2E31000
trusted library allocation
page read and write
E42000
trusted library allocation
page read and write
2BCA000
trusted library allocation
page read and write
2CC6000
trusted library allocation
page read and write
2B14000
trusted library allocation
page read and write
2D93000
trusted library allocation
page read and write
2ADB000
trusted library allocation
page read and write
13C8000
trusted library allocation
page read and write
2BCC000
trusted library allocation
page read and write
2C1B000
trusted library allocation
page read and write
2EF3000
trusted library allocation
page read and write
3160000
heap
page execute and read and write
2FA4000
trusted library allocation
page read and write
5A34000
trusted library allocation
page read and write
13B3000
trusted library allocation
page execute and read and write
28E0000
trusted library allocation
page read and write
2CD0000
trusted library allocation
page read and write
17E0000
trusted library allocation
page read and write
D18000
heap
page read and write
2BA5000
trusted library allocation
page read and write
2C1F000
trusted library allocation
page read and write
1370000
heap
page read and write
2E20000
trusted library allocation
page read and write
1510000
trusted library allocation
page read and write
2E35000
trusted library allocation
page read and write
16A7000
heap
page read and write
4EF0000
trusted library section
page read and write
C10000
trusted library allocation
page read and write
159D000
stack
page read and write
2D13000
trusted library allocation
page read and write
2B02000
trusted library allocation
page read and write
2C76000
trusted library allocation
page read and write
1608000
heap
page read and write
2F58000
trusted library allocation
page read and write
2FA0000
trusted library allocation
page read and write
17F0000
trusted library allocation
page read and write
2EC9000
trusted library allocation
page read and write
2CE1000
trusted library allocation
page read and write
5180000
trusted library section
page read and write
2C02000
trusted library allocation
page read and write
2D95000
trusted library allocation
page read and write
2C83000
trusted library allocation
page read and write
311E000
stack
page read and write
58E0000
trusted library allocation
page read and write
2DFF000
trusted library allocation
page read and write
2C85000
trusted library allocation
page read and write
C2D000
trusted library allocation
page execute and read and write
F98000
stack
page read and write
2C06000
trusted library allocation
page read and write
2B6F000
trusted library allocation
page read and write
2BF8000
trusted library allocation
page read and write
16AA000
heap
page read and write
2DC9000
trusted library allocation
page read and write
2F6A000
trusted library allocation
page read and write
2F2E000
trusted library allocation
page read and write
2D07000
trusted library allocation
page read and write
2C40000
trusted library allocation
page read and write
E3F000
stack
page read and write
2DEC000
trusted library allocation
page read and write
588E000
trusted library allocation
page read and write
2CB3000
trusted library allocation
page read and write
2B6B000
trusted library allocation
page read and write
There are 446 hidden memdumps, click here to show them.