IOC Report

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\dngqoAXyDd.exe
"C:\Users\user\Desktop\dngqoAXyDd.exe"
malicious
C:\Windows\System32\wermgr.exe
C:\Windows\system32\wermgr.exe
malicious
C:\Windows\System32\cmd.exe
C:\Windows\system32\cmd.exe
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
B31000
unkown
page execute and read and write
malicious
7FF582865000
unkown image
page readonly
clean
7FF58277A000
unkown image
page readonly
clean
511E000
unkown
page read and write
clean
399E000
unkown
page read and write
clean
7FF529BA2000
unkown image
page readonly
clean
29D2000
unkown
page read and write
clean
5400000
unkown
page read and write
clean
4408000
unkown
page read and write
clean
7FF5685D7000
unkown image
page readonly
clean
7DF589890000
unkown image
page readonly
clean
22833CA0000
unkown
page read and write
clean
7DF5D72A2000
unkown image
page readonly
clean
4A7A000
unkown
page read and write
clean
7FF52955A000
unkown image
page readonly
clean
239D40A3000
heap private
page read and write
clean
7FF57FAB7000
unkown image
page readonly
clean
6684000
unkown
page read and write
clean
7DF5D72A2000
unkown image
page readonly
clean
1AC71102000
unkown
page read and write
clean
7FF529829000
unkown image
page readonly
clean
3ADC000
unkown
page read and write
clean
7FF529AD2000
unkown image
page readonly
clean
17BD0383000
unkown
page read and write
clean
2CA6000
unkown
page read and write
clean
2282E5D0000
unkown image
page readonly
clean
1776F2F0000
unkown image
page readonly
clean
7324000
unkown
page read and write
clean
3440000
unkown
page read and write
clean
4A46000
unkown
page read and write
clean
1AC7104A000
unkown
page read and write
clean
A4E000
stack
page read and write
clean
7FF5686B7000
unkown image
page readonly
clean
5456000
unkown
page read and write
clean
61FC3F7000
stack
page read and write
clean
7AAC000
unkown
page read and write
clean
180000
unkown image
page readonly
clean
78F0000
unkown
page read and write
clean
4F66000
unkown
page read and write
clean
17BD0390000
unkown
page read and write
clean
2880000
heap private
page read and write
clean
7FF529A84000
unkown image
page readonly
clean
2000E340000
unkown
page read and write
clean
5C64000
unkown
page read and write
clean
98C7D7F000
stack
page read and write
clean
5DA4000
unkown
page read and write
clean
2CD8000
unkown
page read and write
clean
17BCFCD0000
unkown image
page readonly
clean
619E000
unkown
page read and write
clean
2928000
unkown
page read and write
clean
651E000
unkown
page read and write
clean
40AC000
unkown
page read and write
clean
2B84000
unkown
page read and write
clean
7DF5724C0000
unkown image
page readonly
clean
4E78000
unkown
page read and write
clean
397C000
unkown
page read and write
clean
6B62000
unkown
page read and write
clean
40F2000
unkown
page read and write
clean
7FF57F975000
unkown image
page readonly
clean
7FF56849A000
unkown image
page readonly
clean
29833288000
unkown
page read and write
clean
98C7E7D000
stack
page read and write
clean
76B0000
unkown
page read and write
clean
4104000
unkown
page read and write
clean
17BD0379000
unkown
page read and write
clean
7FF529A80000
unkown image
page readonly
clean
239D40A3000
heap private
page read and write
clean
7F022000
unkown image
page readonly
clean
239D42A1000
heap private
page read and write
clean
7FF5827D6000
unkown image
page readonly
clean
753A000
unkown
page read and write
clean
7FF52993A000
unkown image
page readonly
clean
DBF000
stack
page read and write
clean
17BCF990000
unkown image
page readonly
clean