IOC Report
Start.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Start.exe
"C:\Users\user\Desktop\Start.exe"
malicious

URLs

Name
IP
Malicious
http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
unknown
http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0s
unknown
https://sectigo.com/CPS0
unknown
http://ocsp.sectigo.com0
unknown
http://crt.sectigo.com/SectigoRSACodeSigningCA.crt0#
unknown
http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
unknown
http://www.gimp.orgg
unknown
http://jimmac.musichall.cz
unknown
https://sectigo.com/CPS0D
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
11DA000
heap
page read and write
D3E000
unkown
page readonly
11C8000
heap
page read and write
11F1000
heap
page read and write
11CE000
heap
page read and write
119D000
heap
page read and write
1199000
heap
page read and write
11B1000
heap
page read and write
9A0000
unkown
page readonly
11A4000
heap
page read and write
CD5000
unkown
page read and write
11C7000
heap
page read and write
11F2000
heap
page read and write
5B0000
heap
page read and write
9A1000
unkown
page execute read
C05000
unkown
page readonly
11EF000
heap
page read and write
11AA000
heap
page read and write
1216000
heap
page read and write
CD6000
unkown
page write copy
1219000
heap
page read and write
11C0000
heap
page read and write
1199000
heap
page read and write
11CD000
heap
page read and write
CE6000
unkown
page read and write
11C0000
heap
page read and write
D1C000
unkown
page readonly
5F5000
heap
page read and write
11AD000
heap
page read and write
D0B000
unkown
page readonly
1219000
heap
page read and write
CDE000
unkown
page read and write
5C0000
heap
page read and write
5B40000
trusted library allocation
page read and write
11AD000
heap
page read and write
CD1000
unkown
page write copy
11A3000
heap
page read and write
1219000
heap
page read and write
1222000
heap
page read and write
123F000
heap
page read and write
2BCE000
stack
page read and write
121B000
heap
page read and write
9A1000
unkown
page execute read
5F0000
heap
page read and write
11DE000
heap
page read and write
441E000
stack
page read and write
97D000
stack
page read and write
1219000
heap
page read and write
8FC000
stack
page read and write
1140000
heap
page read and write
11CE000
heap
page read and write
D0B000
unkown
page readonly
451E000
stack
page read and write
11DA000
heap
page read and write
9A0000
unkown
page readonly
544000
stack
page read and write
11D2000
heap
page read and write
119F000
heap
page read and write
F85000
heap
page read and write
1170000
heap
page read and write
1100000
heap
page read and write
F80000
heap
page read and write
11BF000
heap
page read and write
D1C000
unkown
page readonly
5F9000
heap
page read and write
D3E000
unkown
page readonly
119A000
heap
page read and write
CCE000
unkown
page read and write
461F000
stack
page read and write
108E000
stack
page read and write
120E000
heap
page read and write
11C8000
heap
page read and write
11AD000
heap
page read and write
1178000
heap
page read and write
11A9000
heap
page read and write
1090000
heap
page read and write
11A1000
heap
page read and write
1219000
heap
page read and write
C05000
unkown
page readonly
11DD000
heap
page read and write
119D000
heap
page read and write
11AF000
heap
page read and write
F7E000
stack
page read and write
CCE000
unkown
page write copy
D09000
unkown
page read and write
1219000
heap
page read and write
1215000
heap
page read and write
2BF0000
heap
page read and write
2BF4000
heap
page read and write
93E000
stack
page read and write
117E000
heap
page read and write
There are 81 hidden memdumps, click here to show them.