IOC Report
WinSockClientVault.dll

loading gif

Processes

Path
Cmdline
Malicious
C:\Windows\System32\loaddll32.exe
loaddll32.exe "C:\Users\user\Desktop\WinSockClientVault.dll"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd.exe /C rundll32.exe "C:\Users\user\Desktop\WinSockClientVault.dll",#1
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe "C:\Users\user\Desktop\WinSockClientVault.dll",#1

Memdumps

Base Address
Regiontype
Protect
Malicious
240000
heap
page read and write
6690000
trusted library allocation
page read and write
ED0000
heap
page read and write
75E000
stack
page read and write
35E0000
heap
page read and write
330A000
heap
page read and write
9AE000
stack
page read and write
35EA000
heap
page read and write
B8B000
stack
page read and write
EAE000
stack
page read and write
BCB000
stack
page read and write
3349000
heap
page read and write
332D000
heap
page read and write
3300000
heap
page read and write
BD0000
heap
page read and write
34BF000
stack
page read and write
3AD000
stack
page read and write
3570000
heap
page read and write
3335000
heap
page read and write
332E000
heap
page read and write
347E000
stack
page read and write
10E0000
heap
page read and write
3349000
heap
page read and write
3329000
heap
page read and write
332D000
heap
page read and write
343F000
stack
page read and write
700000
heap
page read and write
77B000
heap
page read and write
3335000
heap
page read and write
3335000
heap
page read and write
3336000
heap
page read and write
3325000
heap
page read and write
32FE000
stack
page read and write
3325000
heap
page read and write
10F0000
heap
page read and write
AAF000
stack
page read and write
96F000
stack
page read and write
770000
heap
page read and write
3F0000
heap
page read and write
332D000
heap
page read and write
FEF000
stack
page read and write
3331000
heap
page read and write
332D000
heap
page read and write
B20000
heap
page read and write
3337000
heap
page read and write
2AD000
stack
page read and write
3335000
heap
page read and write
332A000
heap
page read and write
E30000
heap
page read and write
3574000
heap
page read and write
35E7000
heap
page read and write
There are 41 hidden memdumps, click here to show them.