IOC Report
SecuriteInfo.com.Win64.TrojanX-gen.8144.20316.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.Win64.TrojanX-gen.8144.20316.exe
"C:\Users\user\Desktop\SecuriteInfo.com.Win64.TrojanX-gen.8144.20316.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
http://crl.thawte.com/ThawteTimestampingCA.crl0
unknown
http://ocsp.thawte.com0
unknown
https://curl.haxx.se/docs/http-cookies.html
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
7FF7B34AF000
unkown
page readonly
1E329A66000
heap
page read and write
7FF7B34F6000
unkown
page read and write
7FF7B34F6000
unkown
page write copy
7FF7B34F9000
unkown
page readonly
1E329A60000
heap
page read and write
7FF7B34AE000
unkown
page read and write
7FF7B33B0000
unkown
page readonly
7FF7B34F9000
unkown
page readonly
7FF7B34AE000
unkown
page readonly
1E329A10000
heap
page read and write
6EBA6FC000
stack
page read and write
1E329A6C000
heap
page read and write
7FF7B33B1000
unkown
page execute read
7FF7B33B0000
unkown
page readonly
1E329930000
heap
page read and write
7FF7B33B1000
unkown
page execute read
There are 7 hidden memdumps, click here to show them.