IOC Report
WWAddToLocalAdmins.exe

loading gif

Files

File Path
Type
Category
Malicious
WWAddToLocalAdmins.exe
PE32 executable (console) Intel 80386, for MS Windows
initial sample
malicious
C:\Temp\60875D.vbs
ASCII text, with very long lines (2611), with no line terminators
dropped
\Device\Mup\849224*\MAILSLOT\NET\NETLOGON
data
dropped
\Device\Mup\SSO*\MAILSLOT\NET\NETLOGON
data
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\WWAddToLocalAdmins.exe
"C:\Users\user\Desktop\WWAddToLocalAdmins.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cscript.exe
"C:\Windows\system32\CScript.exe" //noLogo C:\Temp\60875D.vbs

Memdumps

Base Address
Regiontype
Protect
Malicious
31E6000
heap
page read and write
31CA000
heap
page read and write
51CF000
stack
page read and write
31BB000
heap
page read and write
31E2000
heap
page read and write
1FB0000
heap
page read and write
4FA000
heap
page read and write
31C1000
heap
page read and write
3170000
heap
page read and write
31DF000
heap
page read and write
420000
heap
page read and write
3190000
heap
page read and write
490000
heap
page read and write
414000
unkown
page readonly
31A5000
heap
page read and write
31CD000
heap
page read and write
521E000
stack
page read and write
400000
unkown
page readonly
348C000
heap
page read and write
31E1000
heap
page read and write
4D40000
heap
page read and write
31A7000
heap
page read and write
31D6000
heap
page read and write
2460000
heap
page read and write
19A000
stack
page read and write
531F000
stack
page read and write
46E000
stack
page read and write
31C0000
heap
page read and write
31E4000
heap
page read and write
30FE000
stack
page read and write
2D95000
heap
page read and write
3198000
heap
page read and write
A9B000
stack
page read and write
C10000
heap
page read and write
4FE000
heap
page read and write
31CE000
heap
page read and write
31E2000
heap
page read and write
211F000
stack
page read and write
9C000
stack
page read and write
5330000
heap
page read and write
40C000
unkown
page readonly
4F0000
heap
page read and write
2D90000
heap
page read and write
31E5000
heap
page read and write
417000
unkown
page read and write
401000
unkown
page execute read
31C9000
heap
page read and write
3480000
heap
page read and write
31DF000
heap
page read and write
31A7000
heap
page read and write
31DA000
heap
page read and write
40C000
unkown
page readonly
31B7000
heap
page read and write
31A4000
heap
page read and write
50CE000
stack
page read and write
414000
unkown
page readonly
401000
unkown
page execute read
2010000
heap
page read and write
2DDE000
stack
page read and write
31E2000
heap
page read and write
2016000
heap
page read and write
C5E000
stack
page read and write
31CE000
heap
page read and write
4DE000
stack
page read and write
1F0000
heap
page read and write
31BA000
heap
page read and write
411000
unkown
page read and write
31CE000
heap
page read and write
338E000
stack
page read and write
7BF000
stack
page read and write
31B6000
heap
page read and write
B99000
stack
page read and write
40F000
unkown
page write copy
400000
unkown
page readonly
40F000
unkown
page read and write
31D5000
heap
page read and write
19D000
stack
page read and write
2D60000
heap
page read and write
411000
unkown
page write copy
There are 69 hidden memdumps, click here to show them.