IOC Report
dotNetFx35setup.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\dotNetFx35setup.exe
"C:\Users\user\Desktop\dotNetFx35setup.exe"

Memdumps

Base Address
Regiontype
Protect
Malicious
1000000
unkown
page readonly
610000
heap
page read and write
101C000
unkown
page readonly
1002000
unkown
page execute read
1002000
unkown
page execute read
140000
heap
page read and write
560000
heap
page read and write
150000
heap
page read and write
61A000
heap
page read and write
1000000
unkown
page readonly
900000
heap
page read and write
9D000
stack
page read and write
DC000
stack
page read and write
101C000
unkown
page readonly
There are 4 hidden memdumps, click here to show them.