IOC Report
NBhsazR1jn.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\NBhsazR1jn.exe
"C:\Users\user\Desktop\NBhsazR1jn.exe"
malicious

IPs

IP
Domain
Country
Malicious
77.91.77.81
unknown
Russian Federation
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
761000
unkown
page execute read
malicious
761000
unkown
page execute read
malicious
760000
unkown
page readonly
19E000
stack
page read and write
1E0000
heap
page read and write
AB2000
unkown
page execute and write copy
760000
unkown
page readonly
AB2000
unkown
page execute and write copy
560000
heap
page read and write
9D000
stack
page read and write