Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
z39UartAssist.exe
|
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed
|
initial sample
|
||
C:\Users\user\AppData\Roaming\Cmsoft\uartassist.sys
|
ASCII text, with CRLF line terminators
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\z39UartAssist.exe
|
"C:\Users\user\Desktop\z39UartAssist.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://www.cmsoft.cn/assistcenter/
|
unknown
|
||
http://www.cmsoft.cn/assistcenter/uartassist_upgrade/?ver=50014&ident=SYWVSLRYMZWXKN5D&stamp=01729767727
|
114.55.6.143
|
||
http://www.cmsoft.cnhttp://www.cmsoft.cn/assistcenter/http://www.scomm.cn/assistcenter/http://free.c
|
unknown
|
||
http://free.scomm.cn/assistcenter/
|
unknown
|
||
http://free.cmsoft.cn/download/cmsoft/assistant/uartassist5.0.14.zip
|
unknown
|
||
http://www.cmsoft.cn/assistcenter/uartassist_upgrade/?ver=50014&ident=SYWVSLRYMZWXKN5D&stamp=0172976
|
unknown
|
||
http://crl.gdca.com.cn/crl/GDCA_TrustAUTH_R5_ROOT.crl0
|
unknown
|
||
http://ocsp2.gdca.com.cn/ocsp0
|
unknown
|
||
http://www.gdca.com.cn/cert/GDCA_TrustAUTH_R5_ROOT.der0)
|
unknown
|
||
http://crl.gdca.com.cn/crl/GDCA_TrustAUTH_R4_Generic_CA.crl0
|
unknown
|
||
http://free.cmsoft.cn/tools/ntp/?handler=%d
|
unknown
|
||
http://www.cmsoft.cn/assistcenter/images/assist_dll3.raw
|
unknown
|
||
http://www.gdca.com.cn/cps/cps0L
|
unknown
|
||
http://free.cmsoft.cn/assistcenter/help/UartAssist
|
unknown
|
||
http://www.cmsoft.cn
|
unknown
|
||
http://free.cmsoft.cn/tools/ntp/?handler=%dtimestamp
|
unknown
|
||
http://www.gdca.com.cn/cps/cps0F
|
unknown
|
||
http://www.cmsoft.cn/assistcenter/uartassist_upgrade/
|
unknown
|
||
http://free.cmsoft.cn/assistcenter/
|
unknown
|
||
http://www.scomm.cn/assistcenter/
|
unknown
|
There are 10 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
www.cmsoft.cn
|
114.55.6.143
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
114.55.6.143
|
www.cmsoft.cn
|
China
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
C1B000
|
heap
|
page read and write
|
||
775000
|
heap
|
page read and write
|
||
2E2C000
|
stack
|
page read and write
|
||
2442000
|
direct allocation
|
page read and write
|
||
2453000
|
direct allocation
|
page read and write
|
||
5DF000
|
unkown
|
page execute and read and write
|
||
8BA000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
2DEF000
|
stack
|
page read and write
|
||
46EF000
|
stack
|
page read and write
|
||
8B7000
|
heap
|
page read and write
|
||
88F000
|
heap
|
page read and write
|
||
5E7000
|
unkown
|
page execute and read and write
|
||
8B3000
|
heap
|
page read and write
|
||
770000
|
heap
|
page read and write
|
||
8A0000
|
heap
|
page read and write
|
||
A4F000
|
stack
|
page read and write
|
||
7F0000
|
heap
|
page read and write
|
||
95000
|
stack
|
page read and write
|
||
401000
|
unkown
|
page execute and read and write
|
||
2620000
|
heap
|
page read and write
|
||
639000
|
unkown
|
page write copy
|
||
19B000
|
stack
|
page read and write
|
||
420C000
|
direct allocation
|
page read and write
|
||
481F000
|
stack
|
page read and write
|
||
4D20000
|
trusted library allocation
|
page read and write
|
||
41F0000
|
direct allocation
|
page read and write
|
||
C15000
|
heap
|
page read and write
|
||
8AE000
|
heap
|
page read and write
|
||
885000
|
heap
|
page read and write
|
||
25E0000
|
heap
|
page read and write
|
||
895000
|
heap
|
page read and write
|
||
2481000
|
direct allocation
|
page read and write
|
||
26C3000
|
heap
|
page read and write
|
||
634000
|
unkown
|
page execute and read and write
|
||
8B0000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
85E000
|
heap
|
page read and write
|
||
C10000
|
heap
|
page read and write
|
||
2EDE000
|
stack
|
page read and write
|
||
800000
|
direct allocation
|
page execute and read and write
|
||
420C000
|
direct allocation
|
page read and write
|
||
88F000
|
heap
|
page read and write
|
||
88C000
|
heap
|
page read and write
|
||
892000
|
heap
|
page read and write
|
||
894000
|
heap
|
page read and write
|
||
4820000
|
heap
|
page read and write
|
||
8E3000
|
heap
|
page read and write
|
||
248E000
|
direct allocation
|
page read and write
|
||
59F000
|
unkown
|
page execute and write copy
|
||
859000
|
heap
|
page read and write
|
||
5F5000
|
unkown
|
page execute and read and write
|
||
248C000
|
direct allocation
|
page read and write
|
||
850000
|
heap
|
page read and write
|
||
89E000
|
heap
|
page read and write
|
||
75E000
|
stack
|
page read and write
|
||
8BF000
|
heap
|
page read and write
|
||
4D1F000
|
stack
|
page read and write
|
||
63F000
|
unkown
|
page read and write
|
||
609000
|
unkown
|
page execute and read and write
|
||
45EE000
|
stack
|
page read and write
|
||
2CEE000
|
stack
|
page read and write
|
||
23C0000
|
direct allocation
|
page read and write
|
||
1F0000
|
heap
|
page read and write
|
||
25B0000
|
heap
|
page read and write
|
||
26C0000
|
heap
|
page read and write
|
||
5EB000
|
unkown
|
page execute and read and write
|
||
710000
|
heap
|
page read and write
|
||
4370000
|
trusted library allocation
|
page read and write
|
There are 59 hidden memdumps, click here to show them.