IOC Report
SecuriteInfo.com.Trojan.GenericKD.71965879.10556.925.exe

loading gif

Files

File Path
Type
Category
Malicious
SecuriteInfo.com.Trojan.GenericKD.71965879.10556.925.exe
PE32+ executable (console) x86-64, for MS Windows
initial sample
malicious
\Device\ConDrv
ASCII text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.71965879.10556.925.exe
"C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.71965879.10556.925.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
https://www.sysinternals.com0
unknown
http://www.microsoft.co
unknown

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Sysinternals\????????.
EulaAccepted

Memdumps

Base Address
Regiontype
Protect
Malicious
288AAC45000
heap
page read and write
288AAA84000
heap
page read and write
9595CFE000
stack
page read and write
288AAB60000
heap
page read and write
288AAA69000
heap
page read and write
7FF7D95A6000
unkown
page readonly
288AC820000
trusted library allocation
page read and write
288AE120000
trusted library allocation
page read and write
288AAA70000
heap
page read and write
7FF7D95A6000
unkown
page readonly
7FF7D958A000
unkown
page readonly
288AAA73000
heap
page read and write
7FF7D95A3000
unkown
page read and write
288AABB0000
heap
page read and write
288AAA6C000
heap
page read and write
288AAA4C000
heap
page read and write
288AABE0000
heap
page read and write
95959FE000
stack
page read and write
288AAC20000
heap
page read and write
288AAA8C000
heap
page read and write
288AAC40000
heap
page read and write
95958FA000
stack
page read and write
7FF7D95A9000
unkown
page readonly
7FF7D9560000
unkown
page readonly
288AAA87000
heap
page read and write
7FF7D958A000
unkown
page readonly
9595BFE000
stack
page read and write
7FF7D95A3000
unkown
page write copy
7FF7D9561000
unkown
page execute read
288AC820000
heap
page read and write
288AAAA4000
heap
page read and write
7FF7D9560000
unkown
page readonly
288AAA6C000
heap
page read and write
288AA960000
heap
page read and write
288AABB4000
heap
page read and write
288AAA8C000
heap
page read and write
288AAA9B000
heap
page read and write
288AAA82000
heap
page read and write
9595AFE000
stack
page read and write
288AAA68000
heap
page read and write
288AAA40000
heap
page read and write
288AAB40000
heap
page read and write
7FF7D95A9000
unkown
page readonly
288AAA95000
heap
page read and write
288AAA70000
heap
page read and write
7FF7D9561000
unkown
page execute read
288AAC4B000
heap
page read and write
288AAA74000
heap
page read and write
288AAA9B000
heap
page read and write
There are 39 hidden memdumps, click here to show them.