IOC Report
rhc.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\rhc.exe
"C:\Users\user\Desktop\rhc.exe"
malicious
C:\Users\user\Desktop\rhc.exe
rhc.exe php.exe include.php
malicious
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
C:\Windows\System32\cmd.exe
"C:\Windows\system32\cmd.exe"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

Memdumps

Base Address
Regiontype
Protect
Malicious
641000
heap
page read and write
610000
heap
page read and write
648000
heap
page read and write
3B10000
heap
page read and write
1F0000
heap
page read and write
19C000
stack
page read and write
22EF000
stack
page read and write
646000
heap
page read and write
242F000
stack
page read and write
63D000
heap
page read and write
242B775E000
heap
page read and write
63B000
heap
page read and write
62E000
heap
page read and write
52E000
stack
page read and write
26C0000
heap
page read and write
242B7700000
heap
page read and write
4E0000
heap
page read and write
65F317E000
stack
page read and write
4E0000
heap
page read and write
653000
heap
page read and write
3EE0000
trusted library allocation
page read and write
248E000
stack
page read and write
63E000
heap
page read and write
2719000
heap
page read and write
870000
heap
page read and write
654000
heap
page read and write
258F000
stack
page read and write
61E000
heap
page read and write
636000
heap
page read and write
4F5000
heap
page read and write
72F000
stack
page read and write
242B7600000
heap
page read and write
633000
heap
page read and write
401000
unkown
page execute and write copy
4F0000
heap
page read and write
53E000
stack
page read and write
9BF000
stack
page read and write
242B7985000
heap
page read and write
61A000
heap
page read and write
64C000
heap
page read and write
242B76E0000
heap
page read and write
2710000
heap
page read and write
638000
heap
page read and write
242B92D0000
heap
page read and write
57E000
stack
page read and write
63E000
heap
page read and write
5BE000
stack
page read and write
80F000
stack
page read and write
64E000
heap
page read and write
3B14000
heap
page read and write
242B7980000
heap
page read and write
658000
heap
page read and write
8BE000
stack
page read and write
90F000
stack
page read and write
76E000
stack
page read and write
654000
heap
page read and write
2430000
heap
page read and write
401000
unkown
page execute and read and write
2715000
heap
page read and write
9C000
stack
page read and write
637000
heap
page read and write
400000
unkown
page readonly
65F30FE000
stack
page read and write
63A000
heap
page read and write
63A000
heap
page read and write
65F307C000
stack
page read and write
242B7750000
heap
page read and write
530000
heap
page read and write
631000
heap
page read and write
637000
heap
page read and write
62A000
heap
page read and write
232E000
stack
page read and write
63D000
heap
page read and write
63D000
heap
page read and write
26B0000
heap
page read and write
9A000
stack
page read and write
86F000
stack
page read and write
636000
heap
page read and write
641000
heap
page read and write
65F31FE000
stack
page read and write
A0E000
stack
page read and write
19D000
stack
page read and write
63E000
heap
page read and write
1F0000
heap
page read and write
632000
heap
page read and write
21EE000
stack
page read and write
242B7758000
heap
page read and write
637000
heap
page read and write
656000
heap
page read and write
538000
heap
page read and write
There are 80 hidden memdumps, click here to show them.