IOC Report
Verus.exe

loading gif

Files

File Path
Type
Category
Malicious
Verus.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_Verus.exe_60c2564910af18faa22197385ca3547fdd3431b_6e980beb_4fc4714e-6a46-4c80-b28f-3fd7bfcdd490\Report.wer
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
malicious
C:\ProgramData\Microsoft\Windows\WER\Temp\WER10AC.tmp.dmp
Mini DuMP crash report, 15 streams, Mon Oct 14 07:41:29 2024, 0x1205a4 type
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WER11A7.tmp.WERInternalMetadata.xml
XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\WER\Temp\WER11E6.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\Windows\appcompat\Programs\Amcache.hve
MS Windows registry file, NT/2000 or above
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Verus.exe
"C:\Users\user\Desktop\Verus.exe"
malicious
C:\Windows\SysWOW64\WerFault.exe
C:\Windows\SysWOW64\WerFault.exe -u -p 7416 -s 1812

URLs

Name
IP
Malicious
enlargkiw.sbs
malicious
allocatinow.sbs
malicious
drawwyobstacw.sbs
malicious
mathcucom.sbs
malicious
https://enginenek.buzz/api
188.114.97.3
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
https://vennurviot.sbs/api
172.67.140.193
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
ehticsprocw.sbs
malicious
condifendteu.sbs
malicious
https://drawwyobstacw.sbs/api
188.114.97.3
malicious
enginenek.buzz
malicious
https://resinedyw.sbs/api
172.67.205.156
malicious
https://mathcucom.sbs/api
188.114.96.3
malicious
resinedyw.sbs
malicious
vennurviot.sbs
malicious
https://www.cloudflare.com/learning/access-management/phishing-attack/
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://store.steampowered.com/;Persistent-AuthWWW-AuthenticateVarysteamCountry=US%7Cd7fb65801182a5f
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://sergei-esenin.com/
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&amp
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://allocatinow.sbs/s
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=hgPi
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4Ok
unknown
https://community.akamai.steamsta
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
http://www.entrust.net/rpa03
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://community.akam
unknown
https://store.steampowered.com/points/shop/
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://www.cloudflare.com/5xx-error-landing
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
http://crl.micK)
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=2Ih2WOq7ErXY&a
unknown
https://mathcucom.sbs/
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
unknown
http://crl.entrust.net/2048ca.crl0
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://store.steampowered.com/;
unknown
https://www.entrust.net/rpa0
unknown
https://store.steampowered.com/about/
unknown
https://steamcommunity.com/my/wishlist/
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
http://ocsp.entrust.net03
unknown
http://ocsp.entrust.net02
unknown
https://help.steampowered.com/en/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://allocatinow.sbs/api
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://community.akamai.steamstatic.com/public/javascript/promo/stickers.js?v=upl9NJ5D2xkP&l=en
unknown
http://www.FeyTools.com
unknown
https://steamcommunity.com/discussions/
unknown
https://store.steampowered.com/stats/
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://resinedyw.sbs/
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://vennurviot.sbs/apis
unknown
https://ehticsprocw.sbs/.
unknown
https://community.akamai.steamstatic.com/public/javascript/webui/clientcom.js?v=jGtzAgjYROne&l=e
unknown
https://sergei-esenin.com:443/apita
unknown
http://crl.entrust.net/ts1ca.crl0
unknown
https://steamcommunity.com/workshop/
unknown
https://store.steampowered.com/legal/
unknown
https://community.akamai.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=e
unknown
https://allocatinow.sbs/a
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_resp
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
https://sergei-esenin.com/api/Tew
unknown
https://drawwyobstacw.sbs/api7j
unknown
http://aia.entrust.net/ts1-chain256.cer01
unknown
http://upx.sf.net
unknown
https://community.akamai.steamstatic.coD
unknown
https://drawwyobstacw.sbs/api/
unknown
https://store.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://community.akamai.steamstatic.com/public/javascript/profile.js?v=f3v/
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
https://vennurviot.sbs/q
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
condifendteu.sbs
172.67.141.136
malicious
steamcommunity.com
104.102.49.254
malicious
vennurviot.sbs
172.67.140.193
malicious
drawwyobstacw.sbs
188.114.97.3
malicious
mathcucom.sbs
188.114.96.3
malicious
enginenek.buzz
188.114.97.3
malicious
sergei-esenin.com
104.21.53.8
malicious
ehticsprocw.sbs
172.67.173.224
malicious
resinedyw.sbs
172.67.205.156
malicious
enlargkiw.sbs
172.67.152.13
malicious
allocatinow.sbs
unknown
malicious
There are 1 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.21.53.8
sergei-esenin.com
United States
malicious
188.114.97.3
drawwyobstacw.sbs
European Union
malicious
172.67.173.224
ehticsprocw.sbs
United States
malicious
188.114.96.3
mathcucom.sbs
European Union
malicious
172.67.152.13
enlargkiw.sbs
United States
malicious
172.67.141.136
condifendteu.sbs
United States
malicious
104.102.49.254
steamcommunity.com
United States
malicious
172.67.205.156
resinedyw.sbs
United States
malicious
172.67.140.193
vennurviot.sbs
United States
malicious

Registry

Path
Value
Malicious
\REGISTRY\A\{2904f97a-4ba9-48b2-3f6f-3e1c5f33c4a0}\Root\InventoryApplicationFile\verus.exe|f8e64dde0c02617d
ProgramId
\REGISTRY\A\{2904f97a-4ba9-48b2-3f6f-3e1c5f33c4a0}\Root\InventoryApplicationFile\verus.exe|f8e64dde0c02617d
FileId
\REGISTRY\A\{2904f97a-4ba9-48b2-3f6f-3e1c5f33c4a0}\Root\InventoryApplicationFile\verus.exe|f8e64dde0c02617d
LowerCaseLongPath
\REGISTRY\A\{2904f97a-4ba9-48b2-3f6f-3e1c5f33c4a0}\Root\InventoryApplicationFile\verus.exe|f8e64dde0c02617d
LongPathHash
\REGISTRY\A\{2904f97a-4ba9-48b2-3f6f-3e1c5f33c4a0}\Root\InventoryApplicationFile\verus.exe|f8e64dde0c02617d
Name
\REGISTRY\A\{2904f97a-4ba9-48b2-3f6f-3e1c5f33c4a0}\Root\InventoryApplicationFile\verus.exe|f8e64dde0c02617d
OriginalFileName
\REGISTRY\A\{2904f97a-4ba9-48b2-3f6f-3e1c5f33c4a0}\Root\InventoryApplicationFile\verus.exe|f8e64dde0c02617d
Publisher
\REGISTRY\A\{2904f97a-4ba9-48b2-3f6f-3e1c5f33c4a0}\Root\InventoryApplicationFile\verus.exe|f8e64dde0c02617d
Version
\REGISTRY\A\{2904f97a-4ba9-48b2-3f6f-3e1c5f33c4a0}\Root\InventoryApplicationFile\verus.exe|f8e64dde0c02617d
BinFileVersion
\REGISTRY\A\{2904f97a-4ba9-48b2-3f6f-3e1c5f33c4a0}\Root\InventoryApplicationFile\verus.exe|f8e64dde0c02617d
BinaryType
\REGISTRY\A\{2904f97a-4ba9-48b2-3f6f-3e1c5f33c4a0}\Root\InventoryApplicationFile\verus.exe|f8e64dde0c02617d
ProductName
\REGISTRY\A\{2904f97a-4ba9-48b2-3f6f-3e1c5f33c4a0}\Root\InventoryApplicationFile\verus.exe|f8e64dde0c02617d
ProductVersion
\REGISTRY\A\{2904f97a-4ba9-48b2-3f6f-3e1c5f33c4a0}\Root\InventoryApplicationFile\verus.exe|f8e64dde0c02617d
LinkDate
\REGISTRY\A\{2904f97a-4ba9-48b2-3f6f-3e1c5f33c4a0}\Root\InventoryApplicationFile\verus.exe|f8e64dde0c02617d
BinProductVersion
\REGISTRY\A\{2904f97a-4ba9-48b2-3f6f-3e1c5f33c4a0}\Root\InventoryApplicationFile\verus.exe|f8e64dde0c02617d
AppxPackageFullName
\REGISTRY\A\{2904f97a-4ba9-48b2-3f6f-3e1c5f33c4a0}\Root\InventoryApplicationFile\verus.exe|f8e64dde0c02617d
AppxPackageRelativeId
\REGISTRY\A\{2904f97a-4ba9-48b2-3f6f-3e1c5f33c4a0}\Root\InventoryApplicationFile\verus.exe|f8e64dde0c02617d
Size
\REGISTRY\A\{2904f97a-4ba9-48b2-3f6f-3e1c5f33c4a0}\Root\InventoryApplicationFile\verus.exe|f8e64dde0c02617d
Language
\REGISTRY\A\{2904f97a-4ba9-48b2-3f6f-3e1c5f33c4a0}\Root\InventoryApplicationFile\verus.exe|f8e64dde0c02617d
Usn
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\IdentityCRL\ClockData
ClockTimeSeconds
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\IdentityCRL\ClockData
TickCount
There are 11 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
B50000
direct allocation
page execute and read and write
malicious
1F4000
heap
page read and write
284D000
stack
page read and write
25DC000
unclassified section
page readonly
740000
heap
page read and write
400000
unkown
page readonly
803000
heap
page read and write
3470000
trusted library allocation
page read and write
B4F000
stack
page read and write
1F4000
heap
page read and write
1F4000
heap
page read and write
770000
heap
page read and write
BB0000
trusted library allocation
page read and write
74A000
heap
page read and write
1F4000
heap
page read and write
C76000
heap
page read and write
1F4000
heap
page read and write
3680000
heap
page read and write
35AE000
stack
page read and write
401000
unkown
page execute read
2600000
heap
page read and write
70E000
stack
page read and write
C30000
heap
page read and write
9C000
stack
page read and write
2421000
heap
page read and write
2960000
heap
page read and write
4C4000
unkown
page readonly
7A2000
heap
page read and write
2AE2000
trusted library allocation
page read and write
3452000
trusted library allocation
page read and write
1F4000
heap
page read and write
796000
heap
page read and write
2AEE000
stack
page read and write
4F1000
unkown
page write copy
347E000
trusted library allocation
page read and write
401000
unkown
page execute read
2581000
unclassified section
page execute read
31FE000
stack
page read and write
2975000
trusted library allocation
page read and write
334E000
stack
page read and write
7A2000
heap
page read and write
6C0000
heap
page read and write
7F9000
heap
page read and write
4EB000
unkown
page write copy
823000
heap
page read and write
400000
unkown
page readonly
798000
heap
page read and write
7F2000
heap
page read and write
2421000
heap
page read and write
7FA000
heap
page read and write
25CB000
unclassified section
page write copy
2AAD000
stack
page read and write
804000
heap
page read and write
77E000
heap
page read and write
74E000
heap
page read and write
7F9000
heap
page read and write
1F4000
heap
page read and write
35B0000
trusted library allocation
page read and write
7B8000
heap
page read and write
1F4000
heap
page read and write
3458000
trusted library allocation
page read and write
7A2000
heap
page read and write
2421000
heap
page read and write
1F4000
heap
page read and write
7FB000
heap
page read and write
BEE000
stack
page read and write
30BE000
stack
page read and write
19D000
stack
page read and write
77E000
heap
page read and write
2BEF000
stack
page read and write
2520000
direct allocation
page read and write
25C8000
unclassified section
page readonly
25D1000
unclassified section
page read and write
4EB000
unkown
page write copy
2D2F000
stack
page read and write
4F0000
unkown
page read and write
270F000
stack
page read and write
53D000
unkown
page readonly
C70000
heap
page read and write
2420000
heap
page read and write
7F4000
heap
page read and write
A4E000
stack
page read and write
830000
heap
page read and write
82F000
heap
page read and write
1F4000
heap
page read and write
1F4000
heap
page read and write
C2C000
stack
page read and write
31BF000
stack
page read and write
798000
heap
page read and write
576000
unkown
page readonly
833000
heap
page read and write
294D000
stack
page read and write
6B0000
heap
page read and write
805000
heap
page read and write
803000
heap
page read and write
25F0000
remote allocation
page read and write
280B000
stack
page read and write
378F000
stack
page read and write
4C4000
unkown
page readonly
813000
heap
page read and write
7E1000
heap
page read and write
25F0000
remote allocation
page read and write
5BA000
unkown
page readonly
796000
heap
page read and write
2C2E000
stack
page read and write
53D000
unkown
page readonly
1F0000
heap
page read and write
2421000
heap
page read and write
32FE000
stack
page read and write
345E000
trusted library allocation
page read and write
1F4000
heap
page read and write
3450000
trusted library allocation
page read and write
576000
unkown
page readonly
344E000
stack
page read and write
29AE000
stack
page read and write
5BA000
unkown
page readonly
25F0000
remote allocation
page read and write
808000
heap
page read and write
77A000
heap
page read and write
2421000
heap
page read and write
7F6000
heap
page read and write
A0F000
stack
page read and write
53C000
unkown
page read and write
2421000
heap
page read and write
7A2000
heap
page read and write
2421000
heap
page read and write
There are 116 hidden memdumps, click here to show them.