IOC Report
conhost[1].exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\conhost[1].exe
"C:\Users\user\Desktop\conhost[1].exe"
C:\Windows\System32\cmd.exe
C:\Windows\system32\cmd.exe

Memdumps

Base Address
Regiontype
Protect
Malicious
AAE177C000
stack
page read and write
1C826686000
heap
page read and write
1C826594000
heap
page read and write
7FF7E088C000
unkown
page readonly
1C826602000
heap
page read and write
7FF7E07F0000
unkown
page readonly
1C826050000
heap
page read and write
1C8264C6000
heap
page read and write
7FF7E08C0000
unkown
page write copy
7FF7E08B6000
unkown
page readonly
1C828CF0000
heap
page read and write
1C8244F0000
heap
page read and write
7FF7E08B6000
unkown
page readonly
1C82659A000
heap
page read and write
1C82657A000
heap
page read and write
1C824470000
heap
page read and write
7FF7E08B5000
unkown
page read and write
AAE167E000
stack
page read and write
7FF7E07F1000
unkown
page execute read
AAE19FE000
unkown
page readonly
1C8246C0000
heap
page read and write
1C826053000
heap
page read and write
7FF7E08C1000
unkown
page readonly
1C826644000
heap
page read and write
1C824370000
heap
page read and write
1C8265A0000
heap
page read and write
AAE1AFE000
unkown
page readonly
7FF7E07F1000
unkown
page execute read
1C825F6D000
heap
page read and write
7FF7E088C000
unkown
page readonly
1C8245F0000
heap
page read and write
1C826464000
heap
page read and write
1C826510000
heap
page read and write
AAE17FE000
unkown
page readonly
1C8246C5000
heap
page read and write
1C826402000
heap
page read and write
1C8263A0000
heap
page read and write
1C8266CC000
heap
page read and write
1C82668B000
heap
page read and write
AAE1A7E000
stack
page read and write
7FF7E08B1000
unkown
page read and write
1C8246CB000
heap
page read and write
1C825E70000
heap
page read and write
1C825F67000
heap
page read and write
1C824450000
heap
page read and write
AAE18FE000
unkown
page readonly
1C826664000
heap
page read and write
1C8244F8000
heap
page read and write
1C825F5E000
heap
page read and write
AAE187B000
stack
page read and write
1C8266C8000
heap
page read and write
1C8284F0000
trusted library allocation
page read and write
AAE16FE000
unkown
page readonly
7FF7E07F0000
unkown
page readonly
AAE197E000
stack
page read and write
1C8266AE000
heap
page read and write
7FF7E08B1000
unkown
page write copy
There are 47 hidden memdumps, click here to show them.