IOC Report
self_updater.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\self_updater.exe
"C:\Users\user\Desktop\self_updater.exe"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

Memdumps

Base Address
Regiontype
Protect
Malicious
7FF76B1A0000
unkown
page readonly
7FF76B1E7000
unkown
page readonly
1FAAD280000
heap
page read and write
1FAAD420000
heap
page read and write
7FF76B1E7000
unkown
page readonly
7FF76B1A1000
unkown
page execute read
7FF76B1D6000
unkown
page readonly
2E58AFF000
stack
page read and write
7FF76B1A0000
unkown
page readonly
7FF76B1D6000
unkown
page readonly
1FAAD070000
heap
page read and write
1FAAD09C000
heap
page read and write
7FF76B1A1000
unkown
page execute read
2E588FC000
stack
page read and write
7FF76B1E6000
unkown
page write copy
7FF76B1E6000
unkown
page read and write
1FAAD099000
heap
page read and write
1FAAD090000
heap
page read and write
1FAAD096000
heap
page read and write
1FAAD260000
heap
page read and write
2E589FF000
stack
page read and write
There are 11 hidden memdumps, click here to show them.