IOC Report
svchost(1).exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\svchost(1).exe
"C:\Users\user\Desktop\svchost(1).exe"

Memdumps

Base Address
Regiontype
Protect
Malicious
29CF000
stack
page read and write
4B0000
unkown
page readonly
253D000
stack
page read and write
24FD000
stack
page read and write
283F000
stack
page read and write
25F0000
heap
page read and write
4B0000
unkown
page readonly
4B1000
unkown
page execute read
25A0000
heap
page read and write
4BB000
unkown
page readonly
4BB000
unkown
page readonly
25EE000
stack
page read and write
4B8000
unkown
page readonly
4B1000
unkown
page execute read
29E0000
heap
page read and write
287E000
stack
page read and write
4B8000
unkown
page readonly
28B0000
heap
page read and write
29E7000
heap
page read and write
There are 9 hidden memdumps, click here to show them.