IOC Report
SecuriteInfo.com.Win32.TrojanX-gen.23930.29642.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.Win32.TrojanX-gen.23930.29642.exe
"C:\Users\user\Desktop\SecuriteInfo.com.Win32.TrojanX-gen.23930.29642.exe"
malicious

URLs

Name
IP
Malicious
http://195.123.217.199/aahs.php
unknown
http://195.123.217.199/aahs.php%temp%
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
5B0000
heap
page read and write
690000
heap
page read and write
FB0000
unkown
page readonly
8CE000
stack
page read and write
FC1000
unkown
page readonly
4FC000
stack
page read and write
540000
heap
page read and write
9CE000
stack
page read and write
530000
heap
page read and write
FCA000
unkown
page readonly
5AC000
direct allocation
page execute and read and write
F10000
heap
page read and write
5AB000
direct allocation
page readonly
FB0000
unkown
page readonly
FB1000
unkown
page execute read
69A000
heap
page read and write
58E000
stack
page read and write
5A0000
direct allocation
page readonly
FC8000
unkown
page read and write
69E000
heap
page read and write
FCA000
unkown
page readonly
1CC000
stack
page read and write
FC8000
unkown
page write copy
FC1000
unkown
page readonly
88E000
stack
page read and write
FB1000
unkown
page execute read
5A1000
direct allocation
page execute read
There are 17 hidden memdumps, click here to show them.