IOC Report
winexesvc.exe

loading gif

Files

File Path
Type
Category
Malicious
winexesvc.exe
PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
initial sample
malicious
C:\servicereg.log
ASCII text, with CRLF line terminators
modified
malicious
C:\servicestart.log
ASCII text, with CRLF line terminators
modified
C:\winexesvc.log
ASCII text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Windows\SysWOW64\cmd.exe
cmd /c sc create QkjJP binpath= "C:\Users\user\Desktop\winexesvc.exe" >> C:\servicereg.log 2>&1
malicious
C:\Windows\SysWOW64\sc.exe
sc create QkjJP binpath= "C:\Users\user\Desktop\winexesvc.exe"
malicious
C:\Windows\SysWOW64\cmd.exe
cmd /c sc start QkjJP >> C:\servicestart.log 2>&1
malicious
C:\Windows\SysWOW64\sc.exe
sc start QkjJP
malicious
C:\Users\user\Desktop\winexesvc.exe
C:\Users\user\Desktop\winexesvc.exe
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
15D000
stack
page read and write
210000
heap
page read and write
2F7000
heap
page read and write
22D000
stack
page read and write
210000
heap
page read and write
401000
unkown
page execute read
364000
heap
page read and write
58E000
stack
page read and write
20000
heap
page read and write
5D0000
heap
page read and write
410000
heap
page read and write
329000
heap
page read and write
400000
unkown
page readonly
20000
heap
page read and write
7DF000
stack
page read and write
20C000
stack
page read and write
10000
heap
page read and write
2B7000
heap
page read and write
DDE000
stack
page read and write
40B000
unkown
page read and write
217000
heap
page read and write
8C000
stack
page read and write
480000
heap
page read and write
9DF000
stack
page read and write
2EE000
heap
page read and write
20F000
stack
page read and write
406000
unkown
page readonly
2B0000
heap
page read and write
340000
heap
page read and write
500000
heap
page read and write
324000
heap
page read and write
347000
heap
page read and write
302000
heap
page read and write
45E000
stack
page read and write
4B6000
heap
page read and write
40F000
stack
page read and write
5D4000
heap
page read and write
406000
unkown
page readonly
400000
unkown
page readonly
10000
heap
page read and write
234000
heap
page read and write
10000
heap
page read and write
19E000
stack
page read and write
80000
heap
page read and write
40B000
unkown
page write copy
401000
unkown
page execute read
There are 36 hidden memdumps, click here to show them.