IOC Report
z39UartAssist.exe

loading gif

Files

File Path
Type
Category
Malicious
z39UartAssist.exe
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed
initial sample
C:\Users\user\AppData\Roaming\Cmsoft\uartassist.sys
ASCII text, with CRLF line terminators
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\z39UartAssist.exe
"C:\Users\user\Desktop\z39UartAssist.exe"
malicious

URLs

Name
IP
Malicious
http://www.cmsoft.cn/assistcenter/
unknown
http://www.cmsoft.cn/assistcenter/uartassist_upgrade/?ver=50014&ident=SYWVSLRYMZWXKN5D&stamp=01729767727
114.55.6.143
http://www.cmsoft.cnhttp://www.cmsoft.cn/assistcenter/http://www.scomm.cn/assistcenter/http://free.c
unknown
http://free.scomm.cn/assistcenter/
unknown
http://free.cmsoft.cn/download/cmsoft/assistant/uartassist5.0.14.zip
unknown
http://www.cmsoft.cn/assistcenter/uartassist_upgrade/?ver=50014&ident=SYWVSLRYMZWXKN5D&stamp=0172976
unknown
http://crl.gdca.com.cn/crl/GDCA_TrustAUTH_R5_ROOT.crl0
unknown
http://ocsp2.gdca.com.cn/ocsp0
unknown
http://www.gdca.com.cn/cert/GDCA_TrustAUTH_R5_ROOT.der0)
unknown
http://crl.gdca.com.cn/crl/GDCA_TrustAUTH_R4_Generic_CA.crl0
unknown
http://free.cmsoft.cn/tools/ntp/?handler=%d
unknown
http://www.cmsoft.cn/assistcenter/images/assist_dll3.raw
unknown
http://www.gdca.com.cn/cps/cps0L
unknown
http://free.cmsoft.cn/assistcenter/help/UartAssist
unknown
http://www.cmsoft.cn
unknown
http://free.cmsoft.cn/tools/ntp/?handler=%dtimestamp
unknown
http://www.gdca.com.cn/cps/cps0F
unknown
http://www.cmsoft.cn/assistcenter/uartassist_upgrade/
unknown
http://free.cmsoft.cn/assistcenter/
unknown
http://www.scomm.cn/assistcenter/
unknown
There are 10 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
www.cmsoft.cn
114.55.6.143

IPs

IP
Domain
Country
Malicious
114.55.6.143
www.cmsoft.cn
China

Memdumps

Base Address
Regiontype
Protect
Malicious
C1B000
heap
page read and write
775000
heap
page read and write
2E2C000
stack
page read and write
2442000
direct allocation
page read and write
2453000
direct allocation
page read and write
5DF000
unkown
page execute and read and write
8BA000
heap
page read and write
400000
unkown
page readonly
2DEF000
stack
page read and write
46EF000
stack
page read and write
8B7000
heap
page read and write
88F000
heap
page read and write
5E7000
unkown
page execute and read and write
8B3000
heap
page read and write
770000
heap
page read and write
8A0000
heap
page read and write
A4F000
stack
page read and write
7F0000
heap
page read and write
95000
stack
page read and write
401000
unkown
page execute and read and write
2620000
heap
page read and write
639000
unkown
page write copy
19B000
stack
page read and write
420C000
direct allocation
page read and write
481F000
stack
page read and write
4D20000
trusted library allocation
page read and write
41F0000
direct allocation
page read and write
C15000
heap
page read and write
8AE000
heap
page read and write
885000
heap
page read and write
25E0000
heap
page read and write
895000
heap
page read and write
2481000
direct allocation
page read and write
26C3000
heap
page read and write
634000
unkown
page execute and read and write
8B0000
heap
page read and write
400000
unkown
page readonly
85E000
heap
page read and write
C10000
heap
page read and write
2EDE000
stack
page read and write
800000
direct allocation
page execute and read and write
420C000
direct allocation
page read and write
88F000
heap
page read and write
88C000
heap
page read and write
892000
heap
page read and write
894000
heap
page read and write
4820000
heap
page read and write
8E3000
heap
page read and write
248E000
direct allocation
page read and write
59F000
unkown
page execute and write copy
859000
heap
page read and write
5F5000
unkown
page execute and read and write
248C000
direct allocation
page read and write
850000
heap
page read and write
89E000
heap
page read and write
75E000
stack
page read and write
8BF000
heap
page read and write
4D1F000
stack
page read and write
63F000
unkown
page read and write
609000
unkown
page execute and read and write
45EE000
stack
page read and write
2CEE000
stack
page read and write
23C0000
direct allocation
page read and write
1F0000
heap
page read and write
25B0000
heap
page read and write
26C0000
heap
page read and write
5EB000
unkown
page execute and read and write
710000
heap
page read and write
4370000
trusted library allocation
page read and write
There are 59 hidden memdumps, click here to show them.