IOC Report
last_stage.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\last_stage.exe
"C:\Users\user\Desktop\last_stage.exe"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

Memdumps

Base Address
Regiontype
Protect
Malicious
255D000
stack
page read and write
4ED000
stack
page read and write
514000
unkown
page readonly
511000
unkown
page execute read
2D40000
heap
page read and write
516000
unkown
page readonly
2B5E000
stack
page read and write
2838000
heap
page read and write
25A0000
heap
page read and write
2ADF000
stack
page read and write
2830000
heap
page read and write
25F0000
heap
page read and write
2A5D000
stack
page read and write
2B1E000
stack
page read and write
2A9E000
stack
page read and write
510000
unkown
page readonly
514000
unkown
page readonly
510000
unkown
page readonly
516000
unkown
page readonly
25ED000
stack
page read and write
511000
unkown
page execute read
2940000
heap
page read and write
There are 12 hidden memdumps, click here to show them.