IOC Report
Archivos.lnk

loading gif

Processes

Path
Cmdline
Malicious
C:\Windows\System32\wscript.exe
"C:\WINDOWS\system32\wscript.exe" Dark_Files\Cthulhu.vbs The_call 30000

Memdumps

Base Address
Regiontype
Protect
Malicious
1E09E820000
heap
page read and write
1E09CDD8000
heap
page read and write
7FFB226E5000
unkown
page readonly
7FFB226E0000
unkown
page read and write
7FFB226D6000
unkown
page readonly
1E09CE07000
heap
page read and write
7FFB226C1000
unkown
page execute read
1E09CDEC000
heap
page read and write
1E09CE07000
heap
page read and write
7FFB226C0000
unkown
page readonly
1E09CE0C000
heap
page read and write
1E0A0C00000
heap
page read and write
1E09CDF1000
heap
page read and write
1E09CE38000
heap
page read and write
1E09CDD0000
heap
page read and write
4C111FE000
stack
page read and write
4C110FD000
stack
page read and write
1E0A0400000
trusted library allocation
page read and write
1E09CE40000
heap
page read and write
4C113FF000
stack
page read and write
1E09CE23000
heap
page read and write
1E09CE12000
heap
page read and write
1E09CF8C000
heap
page read and write
1E09E824000
heap
page read and write
1E09CE40000
heap
page read and write
1E09CDB0000
heap
page read and write
1E09CE12000
heap
page read and write
1E09CF80000
heap
page read and write
1E09CE12000
heap
page read and write
1E0A02E0000
heap
page read and write
1E09CE07000
heap
page read and write
7FFB226E2000
unkown
page readonly
1E09CDFE000
heap
page read and write
1E09CE12000
heap
page read and write
1E09CE1C000
heap
page read and write
1E09CED0000
heap
page read and write
4C10DBA000
stack
page read and write
1E09CDFE000
heap
page read and write
1E09CCD0000
heap
page read and write
1E09CF85000
heap
page read and write
1E09CE18000
heap
page read and write
1E09CE0B000
heap
page read and write
1E09CDF1000
heap
page read and write
There are 33 hidden memdumps, click here to show them.