IOC Report
6qr4g3TReL.bin

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\6qr4g3TReL.exe
"C:\Users\user\Desktop\6qr4g3TReL.exe"
malicious

URLs

Name
IP
Malicious
http://www.google.com/webhp
unknown
http://www.google.com/webhpbcSeTcbPrivilege.exeSOFTWARE
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
406000
unkown
page readonly
560000
heap
page read and write
41D000
unkown
page execute and write copy
67C23EE000
unkown
page read and write
174B2560000
unkown
page readonly
174B2629000
unkown
page read and write
174B2800000
unkown
page readonly
405000
unkown
page write copy
500000
trusted library allocation
page read and write
174B2653000
unkown
page read and write
5E0000
direct allocation
page execute and read and write
30000
heap
page read and write
174B2B80000
unkown
page readonly
5C0000
direct allocation
page execute and read and write
67C267F000
unkown
page read and write
2280000
heap
page read and write
5AE000
stack
page read and write
423000
direct allocation
page execute and read and write
174B3FA0000
unkown
page read and write
400000
unkown
page readonly
174B2B90000
unkown
page readonly
5D0000
heap
page read and write
174B2A00000
unkown
page readonly
400000
direct allocation
page execute and read and write
565000
heap
page read and write
41F000
unkown
page readonly
67C236D000
stack
page read and write
174B2500000
unkown
page write copy
174B264E000
unkown
page read and write
9C000
stack
page read and write
174B2609000
unkown
page read and write
174B2420000
heap
page read and write
174B23C0000
heap
page read and write
174B2600000
unkown
page read and write
174B23B0000
heap
page read and write
174B2550000
unkown
page readonly
21A0000
heap
page read and write
174B2613000
unkown
page read and write
84F000
stack
page read and write
67C26FE000
unkown
page read and write
174B261F000
unkown
page read and write
404000
unkown
page readonly
54E000
stack
page read and write
5C0000
direct allocation
page execute and read and write
65A000
heap
page read and write
650000
heap
page read and write
401000
unkown
page execute read
5B0000
heap
page read and write
174B2702000
unkown
page read and write
19C000
stack
page read and write
174B2632000
unkown
page read and write
174B2602000
unkown
page read and write
94F000
stack
page read and write
There are 43 hidden memdumps, click here to show them.