IOC Report
SecuriteInfo.com.Win64.Evo-gen.28415.5583.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.Win64.Evo-gen.28415.5583.exe
"C:\Users\user\Desktop\SecuriteInfo.com.Win64.Evo-gen.28415.5583.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
http://www.houseindustries.com/licenseBurbank
unknown
https://scripts.sil.org/OFLThis
unknown
http://www.houseindustries.comhttp://www.talleming.comHouse
unknown
http://www.houseindustries.com/licenseCopyright
unknown
https://scripts.sil.org/OFLhttps://www.katatrad.comhttps://cadsondemak.comKatatrad
unknown
https://github.com/ThomasJockin/lexend)Lexend
unknown
http://scripts.sil.org/OFLCopyright
unknown
http://scripts.sil.org/OFLProza
unknown
https://scripts.sil.org/OFLhttps://indiantypefoundry.comNinad
unknown
http://scripts.sil.org/OFLhttp://scripts.sil.org/OFL
unknown
http://scripts.sil.org/OFL
unknown
https://github.com/cadsondemak/kanit)
unknown
https://curl.haxx.se/docs/http-cookies.html
unknown
https://github.com/itfoundry/Poppins)&&&&o
unknown
http://www.houseindustries.com/license
unknown
There are 5 hidden URLs, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
575E4FC000
stack
page read and write
7FF6851DF000
unkown
page write copy
1B1DFD5C000
heap
page read and write
1B1DFCF0000
heap
page read and write
1B1DFD50000
heap
page read and write
7FF6851DF000
unkown
page write copy
7FF685131000
unkown
page execute read
1B1DFD56000
heap
page read and write
7FF685131000
unkown
page execute read
7FF6854B3000
unkown
page read and write
7FF6854BD000
unkown
page readonly
7FF6851BF000
unkown
page read and write
7FF6854B5000
unkown
page readonly
7FF6851C0000
unkown
page readonly
7FF685130000
unkown
page readonly
7FF6854B5000
unkown
page readonly
7FF6851BF000
unkown
page readonly
7FF685130000
unkown
page readonly
1B1DFD00000
heap
page read and write
575E6FE000
stack
page read and write
7FF6854BD000
unkown
page readonly
There are 11 hidden memdumps, click here to show them.