IOC Report
WinUI.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\WinUI.exe
"C:\Users\user\Desktop\WinUI.exe"

URLs

Name
IP
Malicious
https://aka.ms/dotnet/app-launch-failed
unknown
https://aka.ms/dotnet-core-applaunch?You
unknown
https://aka.ms/dotnet/app-launch-failed&gui=trueShowing
unknown
https://aka.ms/dotnet-core-applaunch?
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
7FF62E5D1000
unkown
page execute read
2273D3C0000
heap
page read and write
A10157C000
stack
page read and write
7FF62E5EA000
unkown
page readonly
7FF62E5EA000
unkown
page readonly
2273D380000
heap
page read and write
7FF62E5F4000
unkown
page write copy
2273D3F0000
heap
page read and write
2273EDE0000
heap
page read and write
7FF62E5D0000
unkown
page readonly
A1016FE000
stack
page read and write
A10187F000
stack
page read and write
7FF62E5D1000
unkown
page execute read
2273D3FB000
heap
page read and write
7FF62E5F4000
unkown
page read and write
7FF62E5F6000
unkown
page readonly
7FF62E5D0000
unkown
page readonly
7FF62E5F6000
unkown
page readonly
2273D3F9000
heap
page read and write
2273D390000
heap
page read and write
There are 10 hidden memdumps, click here to show them.