IOC Report
checksums.txt

loading gif

Processes

Path
Cmdline
Malicious
C:\Windows\System32\notepad.exe
"C:\Windows\system32\NOTEPAD.EXE" C:\Users\user\Desktop\checksums.txt

Domains

Name
IP
Malicious
18.31.95.13.in-addr.arpa
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
1CDD80C0000
heap
page read and write
1CDD99A0000
heap
page read and write
1CDD8100000
heap
page read and write
1CDD9A20000
heap
page read and write
1CDD813C000
heap
page read and write
1CDD99C5000
heap
page read and write
1CDD9EF0000
heap
page read and write
B5A1A78000
stack
page read and write
1CDDB790000
trusted library allocation
page read and write
1CDD9A23000
heap
page read and write
B5A1BFD000
stack
page read and write
1CDD99CC000
heap
page read and write
1CDD817D000
heap
page read and write
1CDD8108000
heap
page read and write
1CDDA1C0000
heap
page read and write
1CDD9DE0000
trusted library allocation
page read and write
1CDD99C0000
heap
page read and write
1CDD8132000
heap
page read and write
1CDD8110000
heap
page read and write
B5A1CFF000
stack
page read and write
1CDD7FE0000
heap
page read and write
There are 11 hidden memdumps, click here to show them.