IOC Report
ArchivePlayer.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\ArchivePlayer.exe
"C:\Users\user\Desktop\ArchivePlayer.exe"
malicious

URLs

Name
IP
Malicious
http://%s:%d/cgi-bin/%smpeg4?USER=%s&PWD=%s&DIO_OUTPUT=0x%.2x%smpeg4?USER=%s&PWD=%s&CHANNEL=%d&DIO_O
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
C0F000
unkown
page readonly
2B9E000
stack
page read and write
EDF000
stack
page read and write
F9E000
heap
page read and write
100E000
heap
page read and write
B0E000
unkown
page write copy
2A80000
unkown
page read and write
F70000
heap
page read and write
401000
unkown
page execute read
FD4000
heap
page read and write
D6E000
stack
page read and write
1011000
heap
page read and write
C0E000
unkown
page write copy
98D000
unkown
page readonly
9F2000
unkown
page readonly
9EE000
unkown
page readonly
B0E000
unkown
page write copy
B15000
unkown
page write copy
2DEF000
stack
page read and write
2BF0000
heap
page read and write
D20000
heap
page read and write
FDE000
heap
page read and write
9FB000
unkown
page readonly
98000
stack
page read and write
2EEF000
stack
page read and write
FEB000
heap
page read and write
400000
unkown
page readonly
F90000
heap
page read and write
19A000
stack
page read and write
9FB000
unkown
page readonly
B13000
unkown
page read and write
1008000
heap
page read and write
9EE000
unkown
page readonly
98D000
unkown
page readonly
C0F000
unkown
page readonly
2BF5000
heap
page read and write
FDD000
heap
page read and write
C40000
heap
page read and write
FFE000
heap
page read and write
F9A000
heap
page read and write
FE8000
heap
page read and write
B3B000
unkown
page read and write
401000
unkown
page execute read
2A30000
heap
page read and write
2A50000
heap
page read and write
2A70000
unkown
page read and write
400000
unkown
page readonly
2A93000
heap
page read and write
DD0000
heap
page read and write
DD5000
heap
page read and write
2B5E000
stack
page read and write
9F2000
unkown
page readonly
C0E000
unkown
page write copy
C0D000
unkown
page read and write
B41000
unkown
page read and write
2A90000
heap
page read and write
401000
unkown
page execute read
There are 47 hidden memdumps, click here to show them.