IOC Report
pwdump.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\pwdump.exe
"C:\Users\user\Desktop\pwdump.exe"
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
431000
unkown
page readonly
1FB0000
heap
page read and write
431000
unkown
page readonly
42C000
unkown
page read and write
440000
heap
page read and write
42F000
unkown
page read and write
890000
heap
page read and write
42D000
unkown
page write copy
45D000
heap
page read and write
401000
unkown
page execute read
1FB5000
heap
page read and write
400000
unkown
page readonly
429000
unkown
page write copy
401000
unkown
page execute read
18D000
stack
page read and write
5A0000
heap
page read and write
42C000
unkown
page write copy
422000
unkown
page readonly
5A7000
heap
page read and write
8D000
stack
page read and write
10000
heap
page read and write
310000
heap
page read and write
5C4000
heap
page read and write
429000
unkown
page read and write
400000
unkown
page readonly
20000
heap
page read and write
422000
unkown
page readonly
There are 17 hidden memdumps, click here to show them.