IOCReport

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\RICHIESTA DI OFFERTA.exe
'C:\Users\user\Desktop\RICHIESTA DI OFFERTA.exe'
malicious

URLs

Name
IP
Malicious
https://bamontarquitectura.com.mx/IRANSAT_kowbB4.bi}
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
1E47000
heap private
page read and write
clean
32B2000
unkown
page readonly
clean
4F0000
unkown
page readonly
clean
1E20000
heap private
page read and write
clean
435000
unkown image
page readonly
clean
1DCC000
unkown
page execute and read and write
clean
23B000
heap private
page read and write
clean
3182000
unkown
page readonly
clean
3E0000
unkown
page read and write
clean
31B2000
unkown
page readonly
clean
300000
unkown
page readonly
clean
31A6000
unkown
page readonly
clean
3236000
unkown
page readonly
clean
3239000
unkown
page readonly
clean
220000
unkown
page execute read
clean
89000
unkown
page read and write
clean
31E2000
unkown
page readonly
clean
400000
unkown image
page readonly
clean
3114000
unkown
page readonly
clean
18C000
unkown
page read and write
clean
32A5000
unkown
page readonly
clean
435000
unkown image
page readonly
clean
401000
unkown image
page execute read
clean
2792000
heap private
page read and write
clean
2770000
heap private
page read and write
clean
1F10000
unkown
page read and write
clean
20000
unkown
page read and write
clean
1D40000
unkown
page read and write
clean
34A0000
unkown
page readonly
clean
433000
unkown image
page read and write
clean
3132000
unkown
page readonly
clean
31D6000
unkown
page readonly
clean
34C0000
unkown
page readonly
clean
2F58000
unkown
page readonly
clean
610000
unkown
page readonly
clean
7A0000
heap private
page read and write
clean
3282000
unkown
page readonly
clean
510000
heap default
page read and write
clean
790000
unkown
page readonly
clean
3134000
unkown
page readonly
clean
2774000
heap private
page read and write
clean
32B9000
unkown
page readonly
clean
3195000
unkown
page readonly
clean
2310000
unkown
page readonly
clean
3225000
unkown
page readonly
clean
440000
unkown
page read and write
clean
3152000
unkown
page readonly
clean
3112000
unkown
page readonly
clean
517000
heap default
page read and write
clean
1F00000
heap private
page read and write
clean
3442000
unkown
page readonly
clean
401000
unkown image
page execute read
clean
31C5000
unkown
page readonly
clean
534000
heap default
page read and write
clean
3289000
unkown
page readonly
clean
3275000
unkown
page readonly
clean
1B0000
unkown
page readonly
clean
3206000
unkown
page readonly
clean
27B0000
unkown
page read and write
clean
32D5000
unkown
page readonly
clean
4C0000
unkown
page write copy
clean
3052000
unkown
page readonly
clean
230000
heap private
page read and write
clean
3480000
unkown
page readonly
clean
2F52000
unkown
page readonly
clean
2BD0000
unkown
page readonly
clean
400000
unkown image
page readonly
clean
4D0000
unkown
page readonly
clean
280000
heap default
page read and write
clean
3212000
unkown
page readonly
clean
31F5000
unkown
page readonly
clean
238000
heap private
page read and write
clean
234000
heap private
page read and write
clean
400000
unkown image
page readonly
clean
1E2A000
heap private
page read and write
clean
270000
unkown
page readonly
clean
3259000
unkown
page readonly
clean
3F0000
heap private
page read and write
clean
2BB0000
unkown
page readonly
clean
323D000
unkown
page readonly
clean
3252000
unkown
page readonly
clean
3154000
unkown
page readonly
clean
7EFDF000
unkown
page read and write
clean
There are 73 hidden memdumps, click here to show them.