IOC Report
SecuriteInfo.com.BScope.Trojan.Swrort.25034.19636.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Swrort.25034.19636.exe
"C:\Users\user\Desktop\SecuriteInfo.com.BScope.Trojan.Swrort.25034.19636.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

Memdumps

Base Address
Regiontype
Protect
Malicious
1090000
heap
page read and write
B50000
unkown
page readonly
140F000
stack
page read and write
B7A000
unkown
page read and write
BCE000
stack
page read and write
B3E000
stack
page read and write
B7F000
unkown
page readonly
1210000
heap
page read and write
A7D000
stack
page read and write
B63000
unkown
page execute read
B63000
unkown
page execute read
B7C000
unkown
page readonly
119F000
stack
page read and write
B8E000
unkown
page readonly
B50000
unkown
page readonly
B7A000
unkown
page write copy
B7B000
unkown
page readonly
121E000
heap
page read and write
B75000
unkown
page readonly
121A000
heap
page read and write
EFD000
stack
page read and write
B8E000
unkown
page readonly
B75000
unkown
page readonly
AE0000
heap
page read and write
B7F000
unkown
page readonly
AF0000
heap
page read and write
B61000
unkown
page execute read
B61000
unkown
page execute read
There are 18 hidden memdumps, click here to show them.