IOC Report

loading gif

Files

File Path
Type
Category
Malicious
exe.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Temp\~DF56168A067CC46460.TMP
data
dropped
clean

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\exe.exe
"C:\Users\user\Desktop\exe.exe"
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
2C0000
unkown
page execute and read and write
malicious
7EFC0000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
520000
heap private
page read and write
clean
2470000
unkown
page read and write
clean
190000
unkown image
page readonly
clean
7F0000
unkown image
page readonly
clean
8B000
unkown
page read and write
clean
420000
unkown image
page readonly
clean
1DA0000
unkown
page read and write
clean
810000
unkown image
page readonly
clean
7EFD0000
unkown image
page readonly
clean
401000
unkown image
page execute read
clean
290000
unkown image
page readonly
clean
25B4000
heap private
page read and write
clean
7EFB2000
unkown image
page readonly
clean
2700000
heap private
page read and write
clean
577000
heap default
page read and write
clean
20000
unkown
page read and write
clean
41E000
unkown image
page read and write
clean
2740000
unkown image
page read and write
clean
9A0000
unkown image
page readonly
clean
400000
unkown image
page readonly
clean
2A0000
unkown image
page read and write
clean
7EFC2000
unkown image
page readonly
clean
2572000
heap private
page read and write
clean
10000
unkown image
page read and write
clean
18D000
unkown
page read and write
clean
25BB000
heap private
page read and write
clean
2554000
heap private
page read and write
clean
7EFC0000
unkown image
page readonly
clean
270A000
heap private
page read and write
clean
7EFB0000
unkown image
page readonly
clean
401000
unkown image
page execute read
clean
800000
heap private
page read and write
clean
7EFC2000
unkown image
page readonly
clean
25B8000
heap private
page read and write
clean
400000
unkown image
page readonly
clean
594000
heap default
page read and write
clean
400000
unkown image
page readonly
clean
7EFDF000
unkown
page read and write
clean
2E0000
heap private
page read and write
clean
570000
heap default
page read and write
clean
370000
unkown image
page read and write
clean
7EFE0000
unkown image
page readonly
clean
670000
unkown image
page readonly
clean
220000
unkown
page execute read
clean
7EFB0000
unkown image
page readonly
clean
25B0000
heap private
page read and write
clean
2550000
heap private
page read and write
clean
420000
unkown image
page readonly
clean
430000
unkown image
page readonly
clean
7EFB2000
unkown image
page readonly
clean
2F0000
heap default
page read and write
clean
2728000
heap private
page read and write
clean
There are 45 hidden memdumps, click here to show them.