IOC Report
ATF-Cleaner.exe

loading gifFilesProcessesURLsMemdumps20102Label

Files

File Path
Type
Category
Malicious
Download
ATF-Cleaner.exe
PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
initial sample
C:\Users\user\AppData\Local\Temp\~DF46DEC0923004EC71.TMP
Composite Document File V2 Document, Cannot read section info
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\ATF-Cleaner.exe
"C:\Users\user\Desktop\ATF-Cleaner.exe"

URLs

Name
IP
Malicious
https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&business=atribune%40atribune%2eorgu-
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
Download
2150000
trusted library allocation
page read and write
770000
heap
page read and write
337F000
stack
page read and write
2B50000
heap
page read and write
97000
stack
page read and write
7ED000
heap
page read and write
44D000
unkown
page execute and read and write
401000
unkown
page execute and read and write
4A9F000
stack
page read and write
7BA000
heap
page read and write
400000
unkown
page readonly
220E000
stack
page read and write
4B20000
trusted library allocation
page read and write
460000
heap
page read and write
44F000
unkown
page read and write
635000
heap
page read and write
2B40000
heap
page read and write
22C0000
trusted library allocation
page read and write
44F000
unkown
page write copy
7B0000
heap
page read and write
226E000
stack
page read and write
449000
unkown
page execute and read and write
22B0000
heap
page read and write
44E000
unkown
page execute and write copy
540000
heap
page read and write
2218000
heap
page read and write
22B9000
heap
page read and write
499E000
stack
page read and write
2B1E000
stack
page read and write
19B000
stack
page read and write
2C50000
trusted library section
page read and write
22B5000
heap
page read and write
2AD0000
heap
page read and write
790000
heap
page read and write
7CF000
heap
page read and write
630000
heap
page read and write
2B44000
heap
page read and write
2290000
trusted library allocation
page read and write
7BE000
heap
page read and write
2210000
heap
page read and write
444000
unkown
page execute and write copy
620000
heap
page read and write
400000
unkown
page readonly
2270000
heap
page read and write
5F0000
trusted library allocation
page execute read
327E000
stack
page read and write
323F000
stack
page read and write
815000
heap
page read and write
There are 38 hidden memdumps, click here to show them.