IOC Report
PI_230524.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\PI_230524.exe
"C:\Users\user\Desktop\PI_230524.exe"

URLs

Name
IP
Malicious
http://nsis.sf.net/NSIS_Errors
unknown
http://nsis.sf.net/NSIS_Error
unknown
http://nsis.sf.net/NSIS_ErrorError
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
7B3000
unkown
page readonly
A48000
heap
page read and write
7E0000
heap
page read and write
99000
stack
page read and write
401000
unkown
page execute read
7CC000
unkown
page readonly
4500000
trusted library allocation
page read and write
A52000
heap
page read and write
A4E000
heap
page read and write
A4C000
heap
page read and write
408000
unkown
page readonly
7C5000
unkown
page readonly
A2D000
heap
page read and write
2A6F000
stack
page read and write
A52000
heap
page read and write
A54000
heap
page read and write
7C3000
unkown
page readonly
7CC000
unkown
page readonly
4410000
heap
page read and write
A4E000
heap
page read and write
400000
unkown
page readonly
A10000
heap
page read and write
9A0000
heap
page read and write
401000
unkown
page execute read
25AF000
stack
page read and write
A4F000
heap
page read and write
A4C000
heap
page read and write
A0E000
stack
page read and write
A18000
heap
page read and write
8A5000
heap
page read and write
A4E000
heap
page read and write
870000
heap
page read and write
995000
heap
page read and write
2AA0000
heap
page read and write
990000
heap
page read and write
7B3000
unkown
page readonly
19A000
stack
page read and write
400000
unkown
page readonly
A4F000
heap
page read and write
999000
heap
page read and write
A3C000
heap
page read and write
7B6000
unkown
page readonly
A6A000
heap
page read and write
296E000
stack
page read and write
A3C000
heap
page read and write
7C5000
unkown
page readonly
A44000
heap
page read and write
7B6000
unkown
page readonly
82E000
stack
page read and write
86E000
stack
page read and write
40A000
unkown
page read and write
78A000
unkown
page read and write
C0F000
stack
page read and write
40A000
unkown
page write copy
8A0000
heap
page read and write
7C3000
unkown
page readonly
25E4000
heap
page read and write
7A1000
unkown
page read and write
9C0000
heap
page read and write
A48000
heap
page read and write
25E0000
heap
page read and write
D0F000
stack
page read and write
A4C000
heap
page read and write
408000
unkown
page readonly
A56000
heap
page read and write
4420000
heap
page read and write
7AA000
unkown
page read and write
There are 57 hidden memdumps, click here to show them.