IOC Report
ffprobe.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\ffprobe.exe
"C:\Users\user\Desktop\ffprobe.exe"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
http://x265.org
unknown
https://kode54.net/)
unknown
https://twitter.com/daniel_collin
unknown
https://github.com/nothings/stb/
unknown
https://github.com/iamgreaser/it2everything/
unknown
https://joaobapt.com/)
unknown
http://schismtracker.org/
unknown
http://standards.iso.org/ittf/PubliclyAvailableStandards/MPEG-DASH_schema_files/DASH-MPD.xsd
unknown
http://lame.sf.net64bits
unknown
http://www.oasis-open.org/committees/entity/release/1.0/catalog.dtd
unknown
https://bel.fi/alankila/modguide/interpolate.txt
unknown
http://www.oasis-open.org/committees/entity/release/1.0/catalog.dtd-//OASIS//DTD
unknown
https://www.3eality.com/
unknown
http://dashif.org/guidelines/last-segment-number
unknown
http://www.smpte-ra.org/schemas/2067-3/2013#standard-markersInvalid
unknown
http://www.smpte-ra.org/schemas/2067-3/2013#standard-markers
unknown
http://WWW-Authenticate:Proxy-Authenticate:Content-Encoding:gzip1.3.1Content-Length:
unknown
https://revenant1.net/)
unknown
http://lame.sf.net
unknown
http://relaxng.org/ns/structure/1.0datatypeLibrary:/#?includegrammardefinenamestartInternal
unknown
https://github.com/viiri/st2play
unknown
https://streams.videolan.org/upload/
unknown
https://coda.s3m.us/)
unknown
https://github.com/ryuhei-mori/tinyfft
unknown
http://www.videolan.org/x264.html
unknown
http://xaimus.com/)
unknown
http://dashif.org/guidelines/trickmode
unknown
http://www.brynosaurus.com/cachedir/
unknown
https://github.com/lieff/minimp3/
unknown
http://modplug-xmms.sourceforge.net/
unknown
http://relaxng.org/ns/structure/1.0
unknown
https://github.com/lclevy/unmo3
unknown
https://github.com/richgel999/miniz
unknown
http://www.gnu.org/licenses/
unknown
There are 24 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.210.172
fp2e7a.wpc.phicdn.net
192.229.211.108

Memdumps

Base Address
Regiontype
Protect
Malicious
1F23E1C0000
heap
page read and write
86F87FE000
stack
page read and write
7FF6A7EE1000
unkown
page execute read
1F23E318000
heap
page read and write
7FF6ACA03000
unkown
page write copy
7FF6AADFF000
unkown
page readonly
1F23E46A000
heap
page read and write
1F23E465000
heap
page read and write
1F23E2A0000
heap
page read and write
7FF6AADD1000
unkown
page readonly
7FF6A92E1000
unkown
page execute read
7FF6AA682000
unkown
page readonly
7FF6A60E0000
unkown
page readonly
1F23E319000
heap
page read and write
1F23E0B0000
heap
page read and write
1F23E31F000
heap
page read and write
7FF6AA2FB000
unkown
page write copy
7FF6AA693000
unkown
page readonly
7FF6AAE40000
unkown
page readonly
7FF6AAE98000
unkown
page readonly
1F23E2C0000
heap
page read and write
7FF6A60E0000
unkown
page readonly
7FF6AA9A5000
unkown
page readonly
7FF6AAD5E000
unkown
page readonly
1F23E311000
heap
page read and write
7FF6AA425000
unkown
page write copy
7FF6A74E1000
unkown
page execute read
7FF6AAE1F000
unkown
page readonly
1F23E31B000
heap
page read and write
7FF6A60E1000
unkown
page execute read
7FF6AA685000
unkown
page readonly
7FF6AA68C000
unkown
page readonly
1F23E33E000
heap
page read and write
7FF6A88E1000
unkown
page execute read
7FF6AAE1A000
unkown
page readonly
1F23E46E000
heap
page read and write
1F23E319000
heap
page read and write
7FF6AAE47000
unkown
page readonly
1F23E33E000
heap
page read and write
1F23E0B6000
heap
page read and write
1F23E0BC000
heap
page read and write
1F23E33E000
heap
page read and write
7FF6AAE32000
unkown
page readonly
1F23E33E000
heap
page read and write
7FF6A7EE1000
unkown
page execute read
7FF6AA8CF000
unkown
page readonly
7FF6A88E1000
unkown
page execute read
7FF6AA688000
unkown
page readonly
86F85FD000
stack
page read and write
86F81FC000
stack
page read and write
1F23E317000
heap
page read and write
7FF6AA42D000
unkown
page readonly
7FF6AAE44000
unkown
page readonly
7FF6AA840000
unkown
page readonly
1F23E33E000
heap
page read and write
1F23E315000
heap
page read and write
7FF6AA691000
unkown
page readonly
7FF6AAE35000
unkown
page readonly
7FF6AA67D000
unkown
page readonly
7FF6A60E1000
unkown
page execute read
7FF6AAE27000
unkown
page readonly
7FF6A74E1000
unkown
page execute read
7FF6A6AE1000
unkown
page execute read
1F23E33E000
heap
page read and write
1F23E469000
heap
page read and write
7FF6AAE24000
unkown
page readonly
1F23E310000
heap
page read and write
86F83FE000
stack
page read and write
7FF6AA99A000
unkown
page readonly
7FF6AA9A9000
unkown
page readonly
7FF6AADD6000
unkown
page readonly
1F23E46E000
heap
page read and write
1F23E31E000
heap
page read and write
7FF6AA427000
unkown
page write copy
1F23E33E000
heap
page read and write
1F23E460000
heap
page read and write
7FF6A6AE1000
unkown
page execute read
7FF6ACA01000
unkown
page readonly
7FF6AAB90000
unkown
page readonly
1F23FE00000
heap
page read and write
7FF6AAE3D000
unkown
page readonly
7FF6ACA0C000
unkown
page readonly
7FF6A9CE1000
unkown
page execute read
There are 73 hidden memdumps, click here to show them.