IOC Report
AvastSvc.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\AvastSvc.exe
"C:\Users\user\Desktop\AvastSvc.exe"

URLs

Name
IP
Malicious
http://www.avast.com0/
unknown
http://www.avast.com0
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
BB0000
unkown
page readonly
BB2000
unkown
page readonly
BB0000
unkown
page readonly
112A000
heap
page read and write
112E000
heap
page read and write
BB1000
unkown
page execute read
1120000
heap
page read and write
B40000
heap
page read and write
B50000
heap
page read and write
1020000
heap
page read and write
BB2000
unkown
page readonly
EFD000
stack
page read and write
BB1000
unkown
page execute read
AED000
stack
page read and write
There are 4 hidden memdumps, click here to show them.