IOC Report
rsatcustominstaller.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\rsatcustominstaller.exe
"C:\Users\user\Desktop\rsatcustominstaller.exe"
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Start_AdminToolsRoot
malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
StartMenuAdminTools
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7FF60C034000
unkown
page readonly
1ED9C110000
heap
page read and write
7FF60C031000
unkown
page execute read
415367F000
stack
page read and write
7FF60C030000
unkown
page readonly
7FF60C038000
unkown
page readonly
1ED9C470000
heap
page read and write
7FF60C031000
unkown
page execute read
1ED9C1F0000
heap
page read and write
7FF60C037000
unkown
page write copy
7FF60C034000
unkown
page readonly
1ED9C2C0000
heap
page read and write
1ED9C2C7000
heap
page read and write
1ED9C210000
heap
page read and write
1ED9C475000
heap
page read and write
7FF60C037000
unkown
page read and write
7FF60C038000
unkown
page readonly
415332C000
stack
page read and write
41533AE000
stack
page read and write
7FF60C030000
unkown
page readonly
There are 10 hidden memdumps, click here to show them.