IOC Report
http://74.248.123.196/d/msdownload/update/software/defu/2024/10/updateplatform.amd64fre_d3f6f8300855e56b8ed00da6dac55a3c4cbf8c20.exe?cacheHostOrigin=au.download.windowsupdate.com

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\Desktop\cmdline.out
ASCII text, with CRLF line terminators
modified

Processes

Path
Cmdline
Malicious
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "http://74.248.123.196/d/msdownload/update/software/defu/2024/10/updateplatform.amd64fre_d3f6f8300855e56b8ed00da6dac55a3c4cbf8c20.exe?cacheHostOrigin=au.download.windowsupdate.com" > cmdline.out 2>&1
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\wget.exe
wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "http://74.248.123.196/d/msdownload/update/software/defu/2024/10/updateplatform.amd64fre_d3f6f8300855e56b8ed00da6dac55a3c4cbf8c20.exe?cacheHostOrigin=au.download.windowsupdate.com"

URLs

Name
IP
Malicious
http://74.248.123.196/d/msdownload/update/software/defu/2024/10/updateplatform.amd64fre_d3f6f8300855e56b8ed00da6dac55a3c4cbf8c20.exe?cacheHostOrigin=au.download.windowsupdate.com
http://74.24
unknown
http://74.248.123.196/d/msdownload/update/software/defu/2024/10/updateplatform.
unknown
http://74.248.123.196/d/msdownload/update/software/defu/2024/10/updateplatform.amd64fre_d3f6f8300855
unknown

IPs

IP
Domain
Country
Malicious
74.248.123.196
unknown
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
D4E000
stack
page read and write
A0E000
stack
page read and write
10F0000
heap
page read and write
D0F000
stack
page read and write
9C000
stack
page read and write
1100000
heap
page read and write
9CD000
stack
page read and write
100000
heap
page read and write
A17000
heap
page read and write
1F0000
heap
page read and write
1E0000
heap
page read and write
1F6000
heap
page read and write
1130000
heap
page read and write
1135000
heap
page read and write
F4F000
stack
page read and write
A10000
heap
page read and write
There are 6 hidden memdumps, click here to show them.