IOC Report
PO#83298373729383838392387373873PDF.exe

loading gif

Files

File Path
Type
Category
Malicious
PO#83298373729383838392387373873PDF.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Name.vbs
ASCII text, with no line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Name.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Roaming\Name.exe:Zone.Identifier
ASCII text, with CRLF line terminators
modified
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\PO#83298373729383838392387373873PDF.exe
"C:\Users\user\Desktop\PO#83298373729383838392387373873PDF.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe"
malicious
C:\Windows\SysWOW64\WerFault.exe
C:\Windows\SysWOW64\WerFault.exe -u -p 3160 -s 904

URLs

Name
IP
Malicious
nwamama.ydns.eu
malicious
https://github.com/mgravell/protobuf-net
unknown
https://github.com/mgravell/protobuf-neti
unknown
https://stackoverflow.com/q/14436606/23354
unknown
https://github.com/mgravell/protobuf-netJ
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
https://stackoverflow.com/q/11564914/23354;
unknown
https://stackoverflow.com/q/2152978/23354
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
2984000
trusted library allocation
page read and write
malicious
58A0000
trusted library section
page read and write
malicious
402000
remote allocation
page execute and read and write
malicious
2713000
trusted library allocation
page read and write
malicious
2886000
trusted library allocation
page read and write
2B7C000
trusted library allocation
page read and write
28D7000
trusted library allocation
page read and write
2B4A000
trusted library allocation
page read and write
2B48000
trusted library allocation
page read and write
9D9000
heap
page read and write
2831000
trusted library allocation
page read and write
2A47000
trusted library allocation
page read and write
28E0000
trusted library allocation
page read and write
2A0B000
trusted library allocation
page read and write
2D94000
trusted library allocation
page read and write
2948000
trusted library allocation
page read and write
DB7000
heap
page read and write
2C04000
trusted library allocation
page read and write
2D16000
trusted library allocation
page read and write
28BA000
trusted library allocation
page read and write
2B6C000
trusted library allocation
page read and write
55CE000
stack
page read and write
2BC4000
trusted library allocation
page read and write
29E1000
trusted library allocation
page read and write
2D50000
trusted library allocation
page read and write
2A2B000
trusted library allocation
page read and write
2D9C000
trusted library allocation
page read and write
2C69000
trusted library allocation
page read and write
D00000
heap
page read and write
2927000
trusted library allocation
page read and write
284E000
trusted library allocation
page read and write
2A76000
trusted library allocation
page read and write
C37000
trusted library allocation
page execute and read and write
2B99000
trusted library allocation
page read and write
2A11000
trusted library allocation
page read and write
2DB3000
trusted library allocation
page read and write
2C8C000
trusted library allocation
page read and write
2A72000
trusted library allocation
page read and write
29B8000
trusted library allocation
page read and write
2D9A000
trusted library allocation
page read and write
28C2000
trusted library allocation
page read and write
28C0000
trusted library allocation
page read and write
2A3A000
trusted library allocation
page read and write
3853000
trusted library allocation
page read and write
28DF000
trusted library allocation
page read and write
281F000
trusted library allocation
page read and write
D04000
trusted library allocation
page read and write
2AE3000
trusted library allocation
page read and write
29C0000
trusted library allocation
page read and write
2982000
trusted library allocation
page read and write
2ADB000
trusted library allocation
page read and write
28F0000
trusted library allocation
page read and write
F16000
trusted library allocation
page execute and read and write
2D35000
trusted library allocation
page read and write
2D9E000
trusted library allocation
page read and write
2BDD000
trusted library allocation
page read and write
29DB000
trusted library allocation
page read and write
29C2000
trusted library allocation
page read and write
5AE0000
trusted library allocation
page execute and read and write
2C71000
trusted library allocation
page read and write
2865000
trusted library allocation
page read and write
57AC000
heap
page read and write
2D2F000
trusted library allocation
page read and write
27CE000
trusted library allocation
page read and write
2B61000
trusted library allocation
page read and write
27DF000
trusted library allocation
page read and write
282F000
trusted library allocation
page read and write
6190000
trusted library allocation
page execute and read and write
5990000
trusted library section
page read and write
252000
unkown
page readonly
28D1000
trusted library allocation
page read and write
2D65000
trusted library allocation
page read and write
2BF8000
trusted library allocation
page read and write
5910000
trusted library allocation
page read and write
2B9B000
trusted library allocation
page read and write
2CBB000
trusted library allocation
page read and write
2B3E000
trusted library allocation
page read and write
2B7A000
trusted library allocation
page read and write
C22000
trusted library allocation
page read and write
2A78000
trusted library allocation
page read and write
2884000
trusted library allocation
page read and write
2D81000
trusted library allocation
page read and write
2BEE000
trusted library allocation
page read and write
2A13000
trusted library allocation
page read and write
C20000
trusted library allocation
page read and write
D10000
heap
page read and write
2B0F000
trusted library allocation
page read and write
2B42000
trusted library allocation
page read and write
27CC000
trusted library allocation
page read and write
286F000
trusted library allocation
page read and write
27EB000
trusted library allocation
page read and write
6CB000
stack
page read and write
2933000
trusted library allocation
page read and write
2CBF000
trusted library allocation
page read and write
28F6000
trusted library allocation
page read and write
9F9000
heap
page read and write
2C84000
trusted library allocation
page read and write
27C8000
trusted library allocation
page read and write
835000
heap
page read and write
F27000
trusted library allocation
page execute and read and write
283B000
trusted library allocation
page read and write
2790000
heap
page read and write
4FAE000
stack
page read and write
CEC000
stack
page read and write
2A40000
trusted library allocation
page read and write
288A000
trusted library allocation
page read and write
2835000
trusted library allocation
page read and write
287E000
trusted library allocation
page read and write
4AAE000
stack
page read and write
29C6000
trusted library allocation
page read and write
2B11000
trusted library allocation
page read and write
2950000
trusted library allocation
page read and write
5920000
trusted library allocation
page read and write
2D1A000
trusted library allocation
page read and write
29F2000
trusted library allocation
page read and write
A30000
heap
page read and write
289B000
trusted library allocation
page read and write
29AB000
trusted library allocation
page read and write
2888000
trusted library allocation
page read and write
29E8000
trusted library allocation
page read and write
2911000
trusted library allocation
page read and write
2AC4000
trusted library allocation
page read and write
27BC000
trusted library allocation
page read and write
2DAF000
trusted library allocation
page read and write
5670000
trusted library allocation
page read and write
280D000
trusted library allocation
page read and write
61D0000
trusted library allocation
page read and write
D3E000
heap
page read and write
2CD8000
trusted library allocation
page read and write
294A000
trusted library allocation
page read and write
3911000
trusted library allocation
page read and write
2A42000
trusted library allocation
page read and write
2CA3000
trusted library allocation
page read and write
57A4000
heap
page read and write
2A91000
trusted library allocation
page read and write
2D4C000
trusted library allocation
page read and write
D40000
heap
page read and write
47AE000
stack
page read and write
2D31000
trusted library allocation
page read and write
2A55000
trusted library allocation
page read and write
2B3A000
trusted library allocation
page read and write
28F2000
trusted library allocation
page read and write
28E5000
trusted library allocation
page read and write
D43000
heap
page read and write
4C00000
trusted library allocation
page read and write
C26000
trusted library allocation
page execute and read and write
2C82000
trusted library allocation
page read and write
2854000
trusted library allocation
page read and write
4FCE000
stack
page read and write
2BC2000
trusted library allocation
page read and write
2B76000
trusted library allocation
page read and write
2B8F000
trusted library allocation
page read and write
2963000
trusted library allocation
page read and write
26B1000
trusted library allocation
page read and write
5960000
trusted library allocation
page execute and read and write
28A7000
trusted library allocation
page read and write
2B40000
trusted library allocation
page read and write
2AE1000
trusted library allocation
page read and write
F1A000
trusted library allocation
page execute and read and write
2978000
trusted library allocation
page read and write
2A7B000
trusted library allocation
page read and write
40C000
remote allocation
page execute and read and write
27D1000
trusted library allocation
page read and write
294C000
trusted library allocation
page read and write
2B13000
trusted library allocation
page read and write
3881000
trusted library allocation
page read and write
2CF9000
trusted library allocation
page read and write
297A000
trusted library allocation
page read and write
5610000
trusted library allocation
page read and write
27E3000
trusted library allocation
page read and write
C1D000
trusted library allocation
page execute and read and write
292B000
trusted library allocation
page read and write
24F8000
trusted library allocation
page read and write
29E3000
trusted library allocation
page read and write
28DD000
trusted library allocation
page read and write
53CF000
stack
page read and write
2CA9000
trusted library allocation
page read and write
2D01000
trusted library allocation
page read and write
27C4000
trusted library allocation
page read and write
D81000
heap
page read and write
D98000
heap
page read and write
28D5000
trusted library allocation
page read and write
B65000
heap
page read and write
2CFF000
trusted library allocation
page read and write
5930000
trusted library allocation
page execute and read and write
2880000
trusted library allocation
page read and write
2CFD000
trusted library allocation
page read and write
A07000
heap
page read and write
2899000
trusted library allocation
page read and write
2A0D000
trusted library allocation
page read and write
2A5F000
trusted library allocation
page read and write
28A3000
trusted library allocation
page read and write
2C1D000
trusted library allocation
page read and write
25A0000
heap
page execute and read and write
CF4000
trusted library allocation
page read and write
2BEA000
trusted library allocation
page read and write
2C80000
trusted library allocation
page read and write
2817000
trusted library allocation
page read and write
2C8E000
trusted library allocation
page read and write
36B1000
trusted library allocation
page read and write
2A44000
trusted library allocation
page read and write
2BC6000
trusted library allocation
page read and write
2CFB000
trusted library allocation
page read and write
2C1F000
trusted library allocation
page read and write
C10000
trusted library allocation
page read and write
2CBD000
trusted library allocation
page read and write
2BE1000
trusted library allocation
page read and write
2AC2000
trusted library allocation
page read and write
2CC7000
trusted library allocation
page read and write
534E000
stack
page read and write
286D000
trusted library allocation
page read and write
2882000
trusted library allocation
page read and write
2CDA000
trusted library allocation
page read and write
55D5000
trusted library allocation
page read and write
297C000
trusted library allocation
page read and write
28DE000
stack
page read and write
3DC000
stack
page read and write
297E000
trusted library allocation
page read and write
2B15000
trusted library allocation
page read and write
296A000
trusted library allocation
page read and write
27FA000
trusted library allocation
page read and write
2BA0000
trusted library allocation
page read and write
2839000
trusted library allocation
page read and write
2A5B000
trusted library allocation
page read and write
2D54000
trusted library allocation
page read and write
4B9E000
stack
page read and write
2AF6000
trusted library allocation
page read and write
C2A000
trusted library allocation
page execute and read and write
2B44000
trusted library allocation
page read and write
5660000
trusted library allocation
page execute and read and write
5980000
trusted library allocation
page execute and read and write
4C10000
heap
page execute and read and write
2806000
trusted library allocation
page read and write
2AB4000
trusted library allocation
page read and write
FA0000
heap
page read and write
2965000
trusted library allocation
page read and write
29C4000
trusted library allocation
page read and write
2BE3000
trusted library allocation
page read and write
2895000
trusted library allocation
page read and write
2852000
trusted library allocation
page read and write
29FA000
trusted library allocation
page read and write
2BFA000
trusted library allocation
page read and write
2C19000
trusted library allocation
page read and write
2C86000
trusted library allocation
page read and write
2B93000
trusted library allocation
page read and write
27CA000
trusted library allocation
page read and write
2C44000
trusted library allocation
page read and write
2D52000
trusted library allocation
page read and write
55F0000
trusted library allocation
page read and write
2A2E000
trusted library allocation
page read and write
2ABC000
trusted library allocation
page read and write
2D86000
trusted library allocation
page read and write
4E70000
remote allocation
page read and write
97F000
stack
page read and write
2C54000
trusted library allocation
page read and write
2920000
trusted library allocation
page read and write
2DB5000
trusted library allocation
page read and write
2C26000
trusted library allocation
page read and write
2C5A000
trusted library allocation
page read and write
2D48000
trusted library allocation
page read and write
280F000
trusted library allocation
page read and write
2B17000
trusted library allocation
page read and write
2C6B000
trusted library allocation
page read and write
2B46000
trusted library allocation
page read and write
2BDF000
trusted library allocation
page read and write
4E1F000
stack
page read and write
28A5000
trusted library allocation
page read and write
2961000
trusted library allocation
page read and write
2CA5000
trusted library allocation
page read and write
2AFE000
trusted library allocation
page read and write
2B95000
trusted library allocation
page read and write
2AF4000
trusted library allocation
page read and write
27FC000
trusted library allocation
page read and write
2C02000
trusted library allocation
page read and write
2A96000
trusted library allocation
page read and write
2A89000
trusted library allocation
page read and write
2CDE000
trusted library allocation
page read and write
27FE000
trusted library allocation
page read and write
2D14000
trusted library allocation
page read and write
2BFE000
trusted library allocation
page read and write
535D000
trusted library allocation
page read and write
BCE000
stack
page read and write
2C75000
trusted library allocation
page read and write
2919000
trusted library allocation
page read and write
29F4000
trusted library allocation
page read and write
28DB000
trusted library allocation
page read and write
27EE000
trusted library allocation
page read and write
2C4E000
trusted library allocation
page read and write
28F8000
trusted library allocation
page read and write
2C1B000
trusted library allocation
page read and write
2CE1000
trusted library allocation
page read and write
4BDE000
stack
page read and write
2857000
trusted library allocation
page read and write
2A6C000
trusted library allocation
page read and write
2C91000
trusted library allocation
page read and write
28EE000
trusted library allocation
page read and write
5620000
trusted library allocation
page read and write
2D63000
trusted library allocation
page read and write
2CC3000
trusted library allocation
page read and write
C0D000
trusted library allocation
page execute and read and write
2AF2000
trusted library allocation
page read and write
284C000
trusted library allocation
page read and write
CAE000
stack
page read and write
D10000
heap
page read and write
4FEE000
stack
page read and write
2B68000
trusted library allocation
page read and write
2D1E000
trusted library allocation
page read and write
2A62000
trusted library allocation
page read and write
D30000
trusted library allocation
page read and write
29DF000
trusted library allocation
page read and write
2D18000
trusted library allocation
page read and write
7C7000
stack
page read and write
D18000
heap
page read and write
3705000
trusted library allocation
page read and write
2833000
trusted library allocation
page read and write
29A7000
trusted library allocation
page read and write
2C5C000
trusted library allocation
page read and write
2AF8000
trusted library allocation
page read and write
D4A000
heap
page read and write
281D000
trusted library allocation
page read and write
549E000
stack
page read and write
BC0000
heap
page read and write
2967000
trusted library allocation
page read and write
2B9D000
trusted library allocation
page read and write
F2B000
trusted library allocation
page execute and read and write
2C77000
trusted library allocation
page read and write
2D5F000
trusted library allocation
page read and write
C03000
trusted library allocation
page execute and read and write
2815000
trusted library allocation
page read and write
4F1E000
stack
page read and write
2D96000
trusted library allocation
page read and write
2C56000
trusted library allocation
page read and write
5740000
trusted library section
page read and write
2B5B000
trusted library allocation
page read and write
4E2E000
stack
page read and write
2590000
trusted library allocation
page read and write
29F6000
trusted library allocation
page read and write
2A8F000
trusted library allocation
page read and write
2B4C000
trusted library allocation
page read and write
2927000
trusted library allocation
page read and write
2ACB000
trusted library allocation
page read and write
502D000
stack
page read and write
281B000
trusted library allocation
page read and write
29FC000
trusted library allocation
page read and write
B60000
heap
page read and write
2C73000
trusted library allocation
page read and write
2C58000
trusted library allocation
page read and write
2B78000
trusted library allocation
page read and write
2900000
heap
page read and write
400000
remote allocation
page execute and read and write
2D1C000
trusted library allocation
page read and write
4B5E000
stack
page read and write
2929000
trusted library allocation
page read and write
535F000
trusted library allocation
page read and write
4E80000
heap
page read and write
27B0000
trusted library allocation
page read and write
A14000
heap
page read and write
286B000
trusted library allocation
page read and write
2C8A000
trusted library allocation
page read and write
D5B000
heap
page read and write
2BC0000
trusted library allocation
page read and write
57A8000
heap
page read and write
29F8000
trusted library allocation
page read and write
740000
heap
page read and write
2AC0000
trusted library allocation
page read and write
55E0000
trusted library allocation
page read and write
2B5D000
trusted library allocation
page read and write
559F000
stack
page read and write
2B91000
trusted library allocation
page read and write
2D21000
trusted library allocation
page read and write
C04000
trusted library allocation
page read and write
2946000
trusted library allocation
page read and write
2D2B000
trusted library allocation
page read and write
52C0000
heap
page execute and read and write
59E0000
heap
page read and write
5790000
trusted library allocation
page execute and read and write
2CC5000
trusted library allocation
page read and write
2B97000
trusted library allocation
page read and write
C3B000
trusted library allocation
page execute and read and write
2850000
trusted library allocation
page read and write
2BFC000
trusted library allocation
page read and write
87E000
stack
page read and write
2CC1000
trusted library allocation
page read and write
6F7000
stack
page read and write
2C13000
trusted library allocation
page read and write
BF0000
trusted library allocation
page read and write
2CF7000
trusted library allocation
page read and write
2A8D000
trusted library allocation
page read and write
539E000
stack
page read and write
5220000
trusted library section
page read and write
2CA7000
trusted library allocation
page read and write
2869000
trusted library allocation
page read and write
5900000
trusted library allocation
page read and write
9D0000
heap
page read and write
278D000
stack
page read and write
2C52000
trusted library allocation
page read and write
820000
heap
page read and write
2D4A000
trusted library allocation
page read and write
CE0000
trusted library allocation
page read and write
282D000
trusted library allocation
page read and write
D8E000
heap
page read and write
2837000
trusted library allocation
page read and write
2D39000
trusted library allocation
page read and write
4BF0000
trusted library allocation
page read and write
29A9000
trusted library allocation
page read and write
4B00000
trusted library allocation
page read and write
B50000
heap
page read and write
2C00000
trusted library allocation
page read and write
29E6000
trusted library allocation
page read and write
295D000
trusted library allocation
page read and write
29FE000
trusted library allocation
page read and write
2804000
trusted library allocation
page read and write
2AC8000
trusted library allocation
page read and write
C32000
trusted library allocation
page read and write
4E6E000
stack
page read and write
CF3000
trusted library allocation
page execute and read and write
27E7000
trusted library allocation
page read and write
2D27000
trusted library allocation
page read and write
2935000
trusted library allocation
page read and write
37C3000
trusted library allocation
page read and write
250000
unkown
page readonly
CF0000
trusted library allocation
page execute and read and write
2959000
trusted library allocation
page read and write
5950000
trusted library allocation
page execute and read and write
2BCC000
trusted library allocation
page read and write
2C50000
trusted library allocation
page read and write
2C2C000
trusted library allocation
page read and write
2BE5000
trusted library allocation
page read and write
DB0000
heap
page read and write
57C0000
heap
page read and write
2813000
trusted library allocation
page read and write
830000
heap
page read and write
F90000
trusted library allocation
page execute and read and write
51AF000
stack
page read and write
5607000
trusted library allocation
page read and write
2D3B000
trusted library allocation
page read and write
CFD000
trusted library allocation
page execute and read and write
2B0D000
trusted library allocation
page read and write
2D05000
trusted library allocation
page read and write
28D3000
trusted library allocation
page read and write
2D56000
trusted library allocation
page read and write
28F4000
trusted library allocation
page read and write
2DA0000
trusted library allocation
page read and write
A41000
heap
page read and write
2AD9000
trusted library allocation
page read and write
4E90000
heap
page read and write
54CF000
stack
page read and write
2931000
trusted library allocation
page read and write
29D7000
trusted library allocation
page read and write
2C88000
trusted library allocation
page read and write
2819000
trusted library allocation
page read and write
292D000
trusted library allocation
page read and write
2C11000
trusted library allocation
page read and write
29BC000
trusted library allocation
page read and write
2B7E000
trusted library allocation
page read and write
A3E000
heap
page read and write
27E9000
trusted library allocation
page read and write
2942000
trusted library allocation
page read and write
2A6E000
trusted library allocation
page read and write
2A3E000
trusted library allocation
page read and write
4D1E000
stack
page read and write
2A38000
trusted library allocation
page read and write
2BCA000
trusted library allocation
page read and write
2A5D000
trusted library allocation
page read and write
2867000
trusted library allocation
page read and write
28C5000
trusted library allocation
page read and write
2861000
trusted library allocation
page read and write
2C15000
trusted library allocation
page read and write
2AC6000
trusted library allocation
page read and write
2ABE000
trusted library allocation
page read and write
288C000
trusted library allocation
page read and write
2A93000
trusted library allocation
page read and write
2D37000
trusted library allocation
page read and write
2DB1000
trusted library allocation
page read and write
26AF000
stack
page read and write
29D9000
trusted library allocation
page read and write
2D03000
trusted library allocation
page read and write
292F000
trusted library allocation
page read and write
2A8B000
trusted library allocation
page read and write
2D33000
trusted library allocation
page read and write
5350000
trusted library allocation
page read and write
2CD6000
trusted library allocation
page read and write
29BE000
trusted library allocation
page read and write
2C9F000
trusted library allocation
page read and write
2C17000
trusted library allocation
page read and write
29AE000
trusted library allocation
page read and write
5680000
trusted library allocation
page read and write
2800000
trusted library allocation
page read and write
D00000
trusted library allocation
page read and write
2BCE000
trusted library allocation
page read and write
2CA1000
trusted library allocation
page read and write
2AE6000
trusted library allocation
page read and write
F8E000
stack
page read and write
2B82000
trusted library allocation
page read and write
9DE000
heap
page read and write
2BE7000
trusted library allocation
page read and write
2D4E000
trusted library allocation
page read and write
D58000
heap
page read and write
C60000
heap
page read and write
285D000
trusted library allocation
page read and write
29C9000
trusted library allocation
page read and write
27DD000
trusted library allocation
page read and write
2B1A000
trusted library allocation
page read and write
516E000
stack
page read and write
2A3C000
trusted library allocation
page read and write
2871000
trusted library allocation
page read and write
2A70000
trusted library allocation
page read and write
284A000
trusted library allocation
page read and write
2AFC000
trusted library allocation
page read and write
9BE000
stack
page read and write
2BF2000
trusted library allocation
page read and write
27C6000
trusted library allocation
page read and write
512A000
stack
page read and write
2957000
trusted library allocation
page read and write
2CAB000
trusted library allocation
page read and write
28B8000
trusted library allocation
page read and write
C00000
trusted library allocation
page read and write
2D83000
trusted library allocation
page read and write
28AA000
trusted library allocation
page read and write
2BC8000
trusted library allocation
page read and write
27D0000
heap
page execute and read and write
27E1000
trusted library allocation
page read and write
2B5F000
trusted library allocation
page read and write
There are 513 hidden memdumps, click here to show them.