IOC Report
null.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\null.exe
"C:\Users\user\Desktop\null.exe"
malicious
C:\Users\user\Desktop\null.exe
C:\Users\user\Desktop\null.exe
malicious
C:\Users\user\Desktop\null.exe
-a
malicious

Domains

Name
IP
Malicious
t1.hinitial.com
95.85.91.147

IPs

IP
Domain
Country
Malicious
95.85.91.147
t1.hinitial.com
Russian Federation

Memdumps

Base Address
Regiontype
Protect
Malicious
AE0000
heap
page read and write
D80000
heap
page read and write
1027000
heap
page read and write
7FF7A43BF000
unkown
page readonly
1300000
heap
page read and write
7FF7A43A0000
unkown
page readonly
14B5000
heap
page read and write
1013000
heap
page read and write
13F0000
heap
page read and write
7FF7A43BB000
unkown
page read and write
7FF7A43A0000
unkown
page readonly
940000
heap
page read and write
7FF7A43BB000
unkown
page write copy
1026000
heap
page read and write
1040000
heap
page read and write
F3F000
stack
page read and write
1014000
heap
page read and write
B70000
heap
page read and write
7FF7A43BF000
unkown
page readonly
1020000
heap
page read and write
7FF7A43BF000
unkown
page readonly
7FF7A43BB000
unkown
page write copy
7FF7A43A1000
unkown
page execute read
7FF7A43BF000
unkown
page readonly
7FF7A43BB000
unkown
page write copy
180C000
stack
page read and write
2E20000
heap
page read and write
EFC000
stack
page read and write
7FF7A43BB000
unkown
page read and write
7FF7A43B5000
unkown
page readonly
FF0000
heap
page read and write
101F000
heap
page read and write
B94000
heap
page read and write
D8C000
heap
page read and write
B40000
heap
page read and write
1026000
heap
page read and write
7FF7A43BB000
unkown
page read and write
7FF7A43B5000
unkown
page readonly
13EE000
stack
page read and write
1022000
heap
page read and write
7FF7A43BF000
unkown
page readonly
7FF7A43A0000
unkown
page readonly
BA1000
heap
page read and write
7FF7A43BF000
unkown
page readonly
7FF7A43B5000
unkown
page readonly
7FF7A43B5000
unkown
page readonly
10F0000
heap
page read and write
7FF7A43B5000
unkown
page readonly
7FF7A43A0000
unkown
page readonly
7FF7A43A1000
unkown
page execute read
1026000
heap
page read and write
7FF7A43A1000
unkown
page execute read
10D0000
heap
page read and write
190F000
stack
page read and write
11EF000
stack
page read and write
2C60000
heap
page read and write
D00000
heap
page read and write
1100000
heap
page read and write
B78000
heap
page read and write
10F5000
heap
page read and write
2CA0000
heap
page read and write
7FF7A43A0000
unkown
page readonly
114E000
stack
page read and write
7FF7A43A0000
unkown
page readonly
7FF7A43B5000
unkown
page readonly
124F000
stack
page read and write
FF9000
heap
page read and write
12EF000
stack
page read and write
B91000
heap
page read and write
CFC000
stack
page read and write
B3C000
stack
page read and write
8E0000
heap
page read and write
2E26000
heap
page read and write
7FF7A43A1000
unkown
page execute read
104F000
stack
page read and write
1020000
heap
page read and write
7FF7A43A1000
unkown
page execute read
A00000
heap
page read and write
14B0000
heap
page read and write
7FF7A43A1000
unkown
page execute read
There are 70 hidden memdumps, click here to show them.