IOC Report
updater.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\updater.exe
"C:\Users\user\Desktop\updater.exe"
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
E80000
heap
page read and write
1280000
heap
page read and write
A80000
unkown
page readonly
780000
heap
page read and write
B1A000
unkown
page readonly
7D0000
heap
page read and write
107E000
stack
page read and write
B1A000
unkown
page readonly
D10000
heap
page read and write
E88000
heap
page read and write
CC0000
heap
page read and write
E92000
heap
page read and write
B44000
unkown
page write copy
A3E000
stack
page read and write
A80000
unkown
page readonly
A81000
unkown
page execute read
A81000
unkown
page execute read
B47000
unkown
page readonly
B47000
unkown
page readonly
B44000
unkown
page read and write
7CE000
stack
page read and write
117D000
stack
page read and write
71B000
stack
page read and write
C5D000
stack
page read and write
There are 14 hidden memdumps, click here to show them.