IOCReport

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.Variant.Graftor.981190.24096.exe
'C:\Users\user\Desktop\SecuriteInfo.com.Variant.Graftor.981190.24096.exe'
malicious

URLs

Name
IP
Malicious
https://kinmirai.org/wp-content/bin_lOulvHP91.bip
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
401000
unkown image
page execute read
malicious
401000
unkown image
page execute read
malicious
2A90000
unkown
page execute and read and write
malicious
1A8F32A0000
unkown
page read and write
clean
16DF092F000
unkown
page read and write
clean
7FF5CC959000
unkown
page readonly
clean
16DF0282000
unkown
page read and write
clean
7FF55F950000
unkown
page readonly
clean
7FF5C0CBB000
unkown
page readonly
clean
16DF099F000
unkown
page read and write
clean
19249202000
unkown
page read and write
clean
1A8F2FD0000
heap private
page read and write
clean
7FF5DC07D000
unkown
page readonly
clean
59834CB000
unkown
page read and write
clean
7FF5C14F7000
unkown
page readonly
clean
3B0000
unkown
page read and write
clean
A97C0FE000
unkown
page read and write
clean
7FF5DC10A000
unkown
page readonly
clean
2251A4E0000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
7FF5DC0ED000
unkown
page readonly
clean
7FF5D23A7000
unkown
page readonly
clean
7FF5D23A7000
unkown
page readonly
clean
31E2B7F000
unkown
page read and write
clean
1A8F3110000
unkown
page readonly
clean
1A8F8590000
unkown
page read and write
clean
16DF024B000
unkown
page read and write
clean
7FF5DC0E1000
unkown
page readonly
clean
7FF5B67EF000
unkown
page readonly
clean
16DF0010000
heap default
page read and write
clean
2251B170000
unkown
page readonly
clean
20426613000
unkown
page read and write
clean
2A2667F0000
heap default
page read and write
clean
7FF55E15F000
unkown
page readonly
clean
7FF5DC126000
unkown
page readonly
clean
7FF55E23A000
unkown
page readonly
clean
19248990000
unkown
page readonly
clean
7FF55E217000
unkown
page readonly
clean
16DF02B1000
unkown
page read and write
clean
238F9829000
unkown
page read and write
clean
7FF5C1338000
unkown
page readonly
clean
16DF092F000
unkown
page read and write
clean
16DF09C8000
unkown
page read and write
clean
7FF5B64F7000
unkown
page readonly
clean
1A8F44C1000
unkown
page read and write
clean
7FF5CC91D000
unkown
page readonly
clean
7FF55FBF7000
unkown
page readonly
clean
2A266807000
heap default
page read and write
clean
7FF5C14B7000
unkown
page readonly
clean
7FF55FC36000
unkown
page readonly
clean
16DF0985000
unkown
page read and write
clean
16DF099D000
unkown
page read and write
clean
7FF55FA03000
unkown
page readonly
clean
7FF5D21B8000
unkown
page readonly
clean
1A8F3815000
unkown
page read and write
clean
2A266940000
unkown
page readonly
clean
1A8F8A40000
unkown
page readonly
clean
7FF55E0A8000
unkown
page readonly
clean
19248910000
heap private
page read and write
clean
19248A55000
unkown
page read and write
clean
7FF55DED1000
unkown
page readonly
clean
7FF55F7DC000
unkown
page readonly
clean
7FF5D22E6000
unkown
page readonly
clean
7FF5DC0F7000
unkown
page readonly
clean
16DF0954000
unkown
page read and write
clean
7FF55F91F000
unkown
page readonly
clean
16DF0E9B000
unkown
page read and write
clean
16DF099F000
unkown
page read and write
clean
400000
unkown image
page readonly
clean
D844879000
unkown
page read and write
clean
2251B160000
unkown
page read and write
clean
16DF099D000
unkown
page read and write
clean
718000
heap private
page read and write
clean
1A8F8A30000
unkown
page readonly
clean
16DF0288000
unkown
page read and write
clean
7FF5B66CB000
unkown
page readonly
clean
7FF5D202B000
unkown
page readonly