IOC Report
Nexthink_Collector_Installer_Silent.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Nexthink_Collector_Installer_Silent.exe
"C:\Users\user\Desktop\Nexthink_Collector_Installer_Silent.exe"

URLs

Name
IP
Malicious
http://wixtoolset.org
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
7FF7D75B0000
unkown
page readonly
233859CB000
heap
page read and write
7FF7DA7CF000
unkown
page readonly
7FF7D7561000
unkown
page execute read
7FF7D75CF000
unkown
page readonly
23385A43000
heap
page read and write
23385990000
heap
page read and write
23385A58000
heap
page read and write
7FF7D75CB000
unkown
page read and write
7FF7D7560000
unkown
page readonly
7FF7D93CF000
unkown
page readonly
23385A20000
heap
page read and write
7FF7D89CF000
unkown
page readonly
23385A28000
heap
page read and write
7FF7D75CB000
unkown
page write copy
23385A5E000
heap
page read and write
7FF7D89CF000
unkown
page readonly
233874F0000
heap
page read and write
7FF7D93CF000
unkown
page readonly
D86CAFE000
stack
page read and write
233898A0000
heap
page read and write
7FF7D9DCF000
unkown
page readonly
233874A0000
heap
page read and write
7FF7D7561000
unkown
page execute read
23385A47000
heap
page read and write
23385A00000
heap
page read and write
7FF7D7FCF000
unkown
page readonly
23385960000
heap
page read and write
7FF7DA7CF000
unkown
page readonly
D86C9FE000
stack
page read and write
7FF7D9DCF000
unkown
page readonly
7FF7DB85B000
unkown
page readonly
7FF7D75B0000
unkown
page readonly
23385970000
heap
page read and write
23385A63000
heap
page read and write
7FF7DB7B2000
unkown
page readonly
7FF7D75CF000
unkown
page readonly
7FF7DB1CF000
unkown
page readonly
7FF7DB863000
unkown
page readonly
7FF7DB7A3000
unkown
page readonly
233859C0000
heap
page read and write
23385A61000
heap
page read and write
7FF7D7560000
unkown
page readonly
23385A04000
heap
page read and write
7FF7D7FCF000
unkown
page readonly
D86C6FA000
stack
page read and write
233890A0000
trusted library allocation
page read and write
233859C5000
heap
page read and write
7FF7DB1CF000
unkown
page readonly
There are 39 hidden memdumps, click here to show them.