IOC Report

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\mU9H96igb3.exe
'C:\Users\user\Desktop\mU9H96igb3.exe'
malicious

URLs

Name
IP
Malicious
http://implantecapilarpereira.com/NetGen
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
4BF0000
unkown
page execute and read and write
malicious
7FFC2000
unkown image
page readonly
clean
400000
unkown image
page readonly
clean
2278000
heap private
page read and write
clean
401000
unkown image
page execute read
clean
30000
unkown image
page read and write
clean
C30000
unkown image
page readonly
clean
400000
unkown image
page readonly
clean
7FFC0000
unkown image
page readonly
clean
2200000
unkown image
page readonly
clean
486E000
stack
page read and write
clean
9A000
unkown
page read and write
clean
2CA0000
unkown
page read and write
clean
2400000
heap private
page read and write
clean
5E4000
heap private
page read and write
clean
2270000
heap private
page read and write
clean
5C0000
unkown
page execute read
clean
2230000
heap private
page read and write
clean
2220000
unkown
page read and write
clean
7FFB2000
unkown image
page readonly
clean
42F000
unkown image
page read and write
clean
2C1E000
unkown image
page read and write
clean
5E0000
heap private
page read and write
clean
5FA000
heap default
page read and write
clean
496F000
stack
page read and write
clean
431000
unkown image
page readonly
clean
DB0000
unkown image
page readonly
clean
530000
heap default
page read and write
clean
2380000
unkown
page read and write
clean
DC0000
unkown image
page readonly
clean
7FEB0000
unkown image
page readonly
clean
21F0000
unkown
page read and write
clean
7FFD0000
unkown image
page readonly
clean
2239000
heap private
page read and write
clean
7FFC0000
unkown image
page readonly
clean
A30000
unkown image
page readonly
clean
5D0000
heap private
page read and write
clean
7FFB0000
unkown image
page readonly
clean
2410000
unkown
page read and write
clean
7FFC2000
unkown image
page readonly
clean
1F0000
unkown
page read and write
clean
7FFB0000
unkown image
page readonly
clean
431000
unkown image
page readonly
clean
2B50000
unkown image
page readonly
clean
2280000
unkown
page read and write
clean
401000
unkown image
page execute read
clean
40000
unkown image
page readonly
clean
3EA000
unkown
page read and write
clean
3EE000
unkown
page read and write
clean
472E000
stack
page read and write
clean
482F000
stack
page read and write
clean
400000
unkown image
page readonly
clean
7FFB2000
unkown image
page readonly
clean
2275000
heap private
page read and write
clean
612000
heap default
page read and write
clean
40000
unkown image
page readonly
clean
510000
unkown image
page readonly
clean
2240000
unkown
page read and write
clean
5F0000
heap default
page read and write
clean
1A0000
unkown image
page readonly
clean
520000
unkown
page read and write
clean
19C000
unkown
page read and write
clean
7FFD0000
unkown image
page readonly
clean
There are 53 hidden memdumps, click here to show them.