IOCReport

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\GqSL8M2a72.exe
'C:\Users\user\Desktop\GqSL8M2a72.exe'
malicious
C:\Users\user\Desktop\GqSL8M2a72.exe
'C:\Users\user\Desktop\GqSL8M2a72.exe'
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7FF536415000
unkown
page readonly
clean
480000
heap default
page read and write
clean
3B6000
unkown
page read and write
clean
5B5000
heap default
page read and write
clean
2220000
unkown
page readonly
clean
7FF53620F000
unkown
page readonly
clean
7FF53647E000
unkown
page readonly
clean
290659F0000
heap default
page read and write
clean
400000
unkown image
page execute and read and write
clean
427000
unkown image
page readonly
clean
7FF536489000
unkown
page readonly
clean
29065A29000
unkown
page read and write
clean
680000
heap default
page read and write
clean
A7E000
stack
page read and write
clean
46E000
unkown
page read and write
clean
7FF535F80000
unkown
page readonly
clean
7FF53624E000
unkown
page readonly
clean
7FF536382000
unkown
page readonly
clean
29065A13000
unkown
page read and write
clean
7FF5362FC000
unkown
page readonly
clean
7FF536398000
unkown
page readonly
clean
19C000
stack
page read and write
clean
94E18FF000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
5B0000
heap default
page read and write
clean
29065A46000
unkown
page read and write
clean
401000
unkown image
page execute read
clean
427000
unkown image
page readonly
clean
9B000
unkown
page read and write
clean
7FF53625A000
unkown
page readonly
clean
7FF5362C1000
unkown
page readonly
clean
A0F000
stack
page read and write
clean
7FF536424000
unkown
page readonly
clean
94E15FE000
unkown
page read and write
clean
7FF535F90000
unkown
page readonly
clean
29065A3C000
unkown
page read and write
clean
610000
unkown
page readonly
clean
2260000
heap private
page read and write
clean
29065A50000
unkown
page read and write
clean
29065A6E000
unkown
page read and write
clean
29066140000
unkown
page readonly
clean
427000
unkown image
page readonly
clean
2300000
heap private
page read and write
clean
7FF5363FC000
unkown
page readonly
clean
29065A8A000
unkown
page read and write
clean
94E12FD000
unkown
page read and write
clean
4AE000
unkown
page read and write
clean
23D0000
heap private
page read and write
clean
7FF536481000
unkown
page readonly
clean
29065A00000
unkown
page read and write
clean
5E0000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
4C0000
unkown
page readonly
clean
5C0000
unkown
page readonly
clean
5CE000
unkown
page read and write
clean
29066150000
unkown
page read and write
clean
29065B13000
unkown
page read and write
clean
7FF536392000
unkown
page readonly
clean
A80000
unkown
page readonly
clean
7FF536427000
unkown
page readonly
clean
425000
unkown
page readonly
clean
3B2000
unkown
page read and write
clean
8CF000
stack
page read and write
clean
428000
unkown image
page write copy
clean
94E16F7000
unkown
page read and write
clean
7FF5363BE000
unkown
page readonly
clean
78F000
stack
page read and write
clean
400000
unkown
page execute and read and write
clean
7FF536278000
unkown
page readonly
clean
A10000
unkown
page readonly
clean
29065990000
heap private
page read and write
clean
29065A4B000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
46E000
unkown
page read and write
clean
7FF536489000
unkown
page readonly
clean
97F000
stack
page read and write
clean
19C000
stack
page read and write
clean
5D0000
unkown
page readonly
clean
29065B08000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
470000
unkown
page readonly
clean
428000
unkown image
page read and write
clean
29065B00000
unkown
page read and write
clean
7FF5363AA000
unkown
page readonly
clean
7FF535F7A000
unkown
page readonly
clean
29065ED0000
unkown
page readonly
clean
24B000
unkown
page read and write
clean
94E137E000
unkown
page read and write
clean
1F0000
unkown
page read and write
clean
7FF536420000
unkown
page readonly
clean
68A000
heap default
page read and write
clean
422000
unkown
page read and write
clean
94E157B000
unkown
page read and write
clean
4B0000
heap default
page read and write
clean
428000
unkown image
page write copy
clean
2300000
heap private
page read and write
clean
265E000
heap private
page read and write
clean
90E000
unkown
page read and write
clean
29066202000
unkown
page read and write
clean
7FF53629D000
unkown
page readonly
clean
580000
unkown
page read and write
clean
401000
unkown image
page execute read
clean
7FF5363D9000
unkown
page readonly
clean
7FF5362C7000
unkown
page readonly
clean
7FF5363F6000
unkown
page readonly
clean
401000
unkown image
page execute read
clean
9D000
unkown
page read and write
clean
7FF536396000
unkown
page readonly
clean
7FF53640C000
unkown
page readonly
clean
7FF5363ED000
unkown
page readonly
clean
401000
unkown
page execute read
clean
29066740000
unkown
page readonly
clean
488000
heap default
page read and write
clean
29065A4D000
unkown
page read and write
clean
29065C00000
unkown
page readonly
clean
7FF5361AA000
unkown
page readonly
clean
29065A55000
unkown
page read and write
clean
29065CD0000
unkown
page readonly
clean
87F000
stack
page read and write
clean
7CE000
unkown
page read and write
clean
7FF536293000
unkown
page readonly
clean
24F000
unkown
page read and write
clean
7FF536406000
unkown
page readonly
clean
7FF536380000
unkown
page readonly
clean
400000
unkown image
page readonly
clean
29065B02000
unkown
page read and write
clean
4A2000
heap default
page read and write
clean
7FF5363CF000
unkown
page readonly
clean
2560000
heap private
page read and write
clean
94E127B000
unkown
page read and write
clean
29066400000
unkown
page readonly
clean
7FF5363C5000
unkown
page readonly
clean
94E17FF000
unkown
page read and write
clean
There are 123 hidden memdumps, click here to show them.