IOCReport

loading gif

Processes

Path
Cmdline
Malicious
C:\Windows\System32\wscript.exe
'C:\Windows\System32\WScript.exe' 'C:\Users\user\Desktop\#U5e94#U4ed8#U5e10#U5355.JS'
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
25B6565B000
unkown
page read and write
clean
7FF4FA93F000
unkown
page readonly
clean
CBB6FFE000
unkown
page read and write
clean
7FF4FA99D000
unkown
page readonly
clean
7FF4FA91A000
unkown
page readonly
clean
25B65642000
heap default
page read and write
clean
25B65658000
unkown
page read and write
clean
7FF4FA908000
unkown
page readonly
clean
25B66F90000
unkown
page readonly
clean
7FF4FA92E000
unkown
page readonly
clean
7FF4FA994000
unkown
page readonly
clean
7FF4FA985000
unkown
page readonly
clean
7FF4FA902000
unkown
page readonly
clean
7FF4FA181000
unkown
page readonly
clean
25B65663000
unkown
page read and write
clean
25B67070000
heap private
page read and write
clean
7FF4FA9F0000
unkown
page readonly
clean
7FF4FA8F0000
unkown
page readonly
clean
25B655D0000
unkown
page read and write
clean
25B6565B000
unkown
page read and write
clean
7FF4E7104000
unkown
page readonly
clean
25B65658000
unkown
page read and write
clean
25B65682000
unkown
page read and write
clean
7FF4FA997000
unkown
page readonly
clean
7FF4FA89A000
unkown
page readonly
clean
7FF4FA990000
unkown
page readonly
clean
7FF4FA961000
unkown
page readonly
clean
7FF4FA8F2000
unkown
page readonly
clean
25B654A0000
unkown
page readonly
clean
CBB6EFE000
unkown
page read and write
clean
7FF4FA9EE000
unkown
page readonly
clean
25B65500000
unkown
page readonly
clean
25B67080000
unkown
page readonly
clean
25B65682000
unkown
page read and write
clean
7FF4FA96C000
unkown
page readonly
clean
25B6566B000
unkown
page read and write
clean
25B657E5000
heap private
page read and write
clean
7FF4FA949000
unkown
page readonly
clean
25B65682000
unkown
page read and write
clean
7FF4FA935000
unkown
page readonly
clean
7FF4FA9F9000
unkown
page readonly
clean
CBB73FE000
unkown
page read and write
clean
7FF4FA906000
unkown
page readonly
clean
25B655F0000
unkown
page read and write
clean
25B6567D000
unkown
page read and write
clean
25B65662000
unkown
page read and write
clean
25B6565B000
unkown
page read and write
clean
25B65620000
unkown
page readonly
clean
7FF4FA9F9000
unkown
page readonly
clean
25B6565B000
unkown
page read and write
clean
7FF4FA8A4000
unkown
page readonly
clean
25B6564E000
unkown
page read and write
clean
25B6564E000
unkown
page read and write
clean
7FF4FA966000
unkown
page readonly
clean
25B657F0000
unkown
page readonly
clean
25B65682000
unkown
page read and write
clean
7FF4E7104000
unkown
page readonly
clean
CBB74FF000
unkown
page read and write
clean
25B65638000
heap default
page read and write
clean
CBB75FF000
unkown
page read and write
clean
7FF4FA19B000
unkown
page readonly
clean
7FF4FA976000
unkown
page readonly
clean
25B65610000
unkown
page readonly
clean
CBB71FF000
unkown
page read and write
clean
25B657E0000
heap private
page read and write
clean
25B65657000
unkown
page read and write
clean
CBB6BA9000
unkown
page read and write
clean
25B6566A000
unkown
page read and write
clean
7FF4FA97C000
unkown
page readonly
clean
25B673C0000
unkown
page read and write
clean
25B65630000
heap default
page read and write
clean
25B6565B000
unkown
page read and write
clean
25B65649000
unkown
page read and write
clean
25B65658000
unkown
page read and write
clean
7FF4FA95D000
unkown
page readonly
clean
CBB72FE000
unkown
page read and write
clean
7FF4FA9A2000
unkown
page readonly
clean
7FF4FA8FF000
unkown
page readonly
clean
25B6567C000
unkown
page read and write
clean
There are 69 hidden memdumps, click here to show them.