IOC Report
SecuriteInfo.com.Win32.TrojanX-gen.21226.23526.exe

loading gif

Files

File Path
Type
Category
Malicious
SecuriteInfo.com.Win32.TrojanX-gen.21226.23526.exe
PE32 executable (console) Intel 80386, for MS Windows
initial sample
malicious
\Device\ConDrv
ISO-8859 text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.Win32.TrojanX-gen.21226.23526.exe
"C:\Users\user\Desktop\SecuriteInfo.com.Win32.TrojanX-gen.21226.23526.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\cmd.exe /c color F2
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\cmd.exe /c taskkill /f /im Gift2.exe
C:\Windows\SysWOW64\taskkill.exe
taskkill /f /im Gift2.exe

Memdumps

Base Address
Regiontype
Protect
Malicious
2C5F000
stack
page read and write
10AB000
heap
page read and write
2EDF000
stack
page read and write
2F1E000
stack
page read and write
2B3000
unkown
page readonly
43F4000
heap
page read and write
FF0000
heap
page read and write
2B6000
unkown
page readonly
10AF000
heap
page read and write
10B0000
heap
page read and write
EB0000
heap
page read and write
939000
stack
page read and write
10BB000
heap
page read and write
10AC000
heap
page read and write
10AC000
heap
page read and write
10AB000
heap
page read and write
2B0000
unkown
page readonly
9B0000
heap
page read and write
FF9000
heap
page read and write
2B3000
unkown
page readonly
2C9E000
stack
page read and write
1080000
heap
page read and write
301F000
stack
page read and write
2B6000
unkown
page readonly
43F0000
heap
page read and write
CFC000
stack
page read and write
108A000
heap
page read and write
FC0000
heap
page read and write
2B1000
unkown
page execute read
9A0000
heap
page read and write
2D9F000
stack
page read and write
2B0000
unkown
page readonly
2DDE000
stack
page read and write
2B5E000
stack
page read and write
2B1000
unkown
page execute read
4740000
trusted library allocation
page read and write
FF5000
heap
page read and write
108E000
heap
page read and write
10A3000
heap
page read and write
EA0000
heap
page read and write
10A8000
heap
page read and write
There are 31 hidden memdumps, click here to show them.