IOC Report
SecuriteInfo.com.W64.ABRisk.HGSF-5324.18792.11913.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.W64.ABRisk.HGSF-5324.18792.11913.exe
"C:\Users\user\Desktop\SecuriteInfo.com.W64.ABRisk.HGSF-5324.18792.11913.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

Memdumps

Base Address
Regiontype
Protect
Malicious
26056600000
heap
page read and write
80F09FE000
stack
page read and write
260567BC000
heap
page read and write
7FF6DCCDA000
unkown
page read and write
7FF6DD6DC000
unkown
page execute read
260566E0000
heap
page read and write
7FF6DC120000
unkown
page readonly
7FF6DDB90000
unkown
page readonly
260567B6000
heap
page read and write
7FF6DDB90000
unkown
page readonly
7FF6DD6DC000
unkown
page execute read
80F08FC000
stack
page read and write
7FF6DC120000
unkown
page readonly
260567B0000
heap
page read and write
7FF6DCCDC000
unkown
page execute read
7FF6DCCDC000
unkown
page execute read
7FF6DCCDA000
unkown
page write copy
There are 7 hidden memdumps, click here to show them.