IOC Report
NtpService.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\NtpService.exe
"C:\Users\user\Desktop\NtpService.exe"
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7FF639C38000
unkown
page write copy
7FF639C30000
unkown
page readonly
66B8DFE000
stack
page read and write
210D2FD6000
heap
page read and write
7FF639C34000
unkown
page readonly
66B89FB000
stack
page read and write
210D2F60000
heap
page read and write
7FF639C37000
unkown
page read and write
7FF639C31000
unkown
page execute read
7FF639C31000
unkown
page execute read
7FF639C37000
unkown
page write copy
210D2E80000
heap
page read and write
7FF639C30000
unkown
page readonly
210D2FD9000
heap
page read and write
210D2FB0000
heap
page read and write
7FF639C36000
unkown
page readonly
66B8BFF000
stack
page read and write
210D2FDC000
heap
page read and write
7FF639C34000
unkown
page readonly
210D2FD0000
heap
page read and write
7FF639C36000
unkown
page readonly
210D2F90000
heap
page read and write
There are 12 hidden memdumps, click here to show them.