IOC Report

loading gif

Processes

Path
Cmdline
Malicious
C:\Windows\System32\loaddll64.exe
loaddll64.exe "C:\Users\user\Desktop\1e60aca0000.dll"
malicious
C:\Windows\System32\rundll32.exe
rundll32.exe C:\Users\user\Desktop\1e60aca0000.dll,#1
malicious
C:\Windows\System32\rundll32.exe
rundll32.exe "C:\Users\user\Desktop\1e60aca0000.dll",#1
malicious
C:\Windows\System32\cmd.exe
cmd.exe /C rundll32.exe "C:\Users\user\Desktop\1e60aca0000.dll",#1
clean

Memdumps

Base Address
Regiontype
Protect
Malicious
202B5F08000
unkown
page read and write
clean
2B7C27CD000
unkown
page read and write
clean
294F2400000
unkown image
page readonly
clean
294F7574000
unkown
page read and write
clean
2AB7F902000
unkown
page read and write
clean
1E3B705F000
unkown
page read and write
clean
7DF427930000
unkown image
page readonly
clean
1E3B7580000
unkown image
page readonly
clean
1E3B7061000
unkown
page read and write
clean
294F78AC000
unkown
page read and write
clean
7DF5942C0000
unkown image
page readonly
clean
7DF58A8D2000
unkown image
page readonly
clean
7FF54D2F5000
unkown image
page readonly
clean
7FF574FCE000
unkown image
page readonly
clean
7FF517AA8000
unkown image
page readonly
clean
1F61D2B0000
unkown image
page readonly
clean
7FF54D3BF000
unkown image
page readonly
clean
7DF5487E2000
unkown image
page readonly
clean
7FF5B2EF0000
unkown image
page readonly
clean
7FF5B2F7A000
unkown image
page readonly
clean
7FF5183E3000
unkown image
page readonly
clean
7FF4C1D60000
unkown image
page readonly
clean
2B7C2777000
unkown
page read and write
clean
7FF51413B000
unkown image
page readonly
clean
9E6B32C000
unkown
page read and write
clean
7FF532EBD000
unkown image
page readonly
clean
7FF59C47E000
unkown image
page readonly
clean
1E3B706B000
unkown
page read and write
clean
7FF574F19000
unkown image
page readonly
clean
7FF51415E000
unkown image
page readonly
clean
21B854D0000
unkown image
page readonly
clean
7FF574FDD000
unkown image
page readonly
clean
294F78F0000
unkown
page read and write
clean
7FF517B4F000
unkown image
page readonly
clean
294F1EB0000
unkown image
page readonly
clean
2B7C1CA0000
unkown image
page readonly
clean
7DF5942C0000
unkown image
page readonly
clean
7FF5CF58F000
unkown image
page readonly
clean
21F90308000
unkown
page read and write
clean
2462BE80000
unkown image
page read and write
clean
7FF59013E000
unkown image
page readonly
clean
7DF562CB0000
unkown image
page readonly
clean
7FF5D9977000
unkown image
page readonly
clean
7FF532EC4000
unkown image
page readonly
clean
7FF54D3BF000
unkown image
page readonly
clean
66BF78B000
unkown
page read and write
clean
1D07E62A000
unkown
page read and write
clean
7FF529B7A000
unkown image
page readonly
clean
2AB7F823000
unkown
page read and write
clean
7FF5B2EA4000
unkown image
page readonly
clean
7FF57E935000
unkown image
page readonly
clean
14A42171000
unkown
page read and write
clean
294F7410000
unkown
page read and write
clean
2B7C1E56000
unkown
page read and write
clean
294F2107000
unkown
page read and write
clean
7FF54D2F9000
unkown image
page readonly
clean
7DF4887A0000
unkown image
page readonly
clean
7FF514128000
unkown image
page readonly
clean
1F61D542000
unkown
page read and write
clean
66BFC7E000
stack
page read and write
clean
7FF5D9A7B000
unkown image
page readonly
clean
202B5E3C000
unkown
page read and write
clean
294F2055000
unkown
page read and write
clean
7FF574A8F000
unkown image
page readonly
clean
7DF5EF382000
unkown image
page readonly
clean
7FF51414D000
unkown image
page readonly
clean
97D7DFE000
stack
page read and write
clean
218B9029000
unkown
page read and write
clean
7FF54D3AE000
unkown image
page readonly
clean
14E22523000
heap private
page read and write
clean
7DF5487F0000
unkown image
page readonly
clean
2B7C2C02000
unkown
page read and write
clean
7DF5487D2000
unkown image
page readonly
clean