IOC Report
SecuriteInfo.com.Trojan.Win32.Zmem.13051.25997.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win32.Zmem.13051.25997.exe
"C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win32.Zmem.13051.25997.exe"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

Memdumps

Base Address
Regiontype
Protect
Malicious
ABF000
stack
page read and write
400000
unkown
page readonly
450000
unkown
page readonly
450000
unkown
page readonly
40C000
unkown
page read and write
408000
unkown
page readonly
40C000
unkown
page write copy
408000
unkown
page readonly
7C6000
heap
page read and write
40F000
unkown
page write copy
401000
unkown
page execute read
400000
unkown
page readonly
455000
unkown
page readonly
455000
unkown
page readonly
401000
unkown
page execute read
40F000
unkown
page write copy
7CC000
heap
page read and write
160000
heap
page read and write
80000
heap
page read and write
7C0000
heap
page read and write
65C000
stack
page read and write
There are 11 hidden memdumps, click here to show them.