IOC Report
SecuriteInfo.com.Trojan-Downloader.Win32.Banload.24378.5325.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Downloader.Win32.Banload.24378.5325.exe
"C:\Users\user\Desktop\SecuriteInfo.com.Trojan-Downloader.Win32.Banload.24378.5325.exe"
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
2240000
heap
page read and write
400000
unkown
page readonly
750000
heap
page read and write
1F0000
heap
page read and write
940000
heap
page read and write
560000
heap
page read and write
759000
heap
page read and write
790000
heap
page read and write
75B000
heap
page read and write
790000
heap
page read and write
75B000
heap
page read and write
975000
heap
page read and write
5AE000
stack
page read and write
792000
heap
page read and write
2124000
direct allocation
page read and write
920000
heap
page read and write
540000
heap
page read and write
400000
unkown
page readonly
29DE000
stack
page read and write
930000
direct allocation
page execute and read and write
756000
heap
page read and write
99000
stack
page read and write
19C000
stack
page read and write
401000
unkown
page execute and read and write
3EA0000
trusted library allocation
page read and write
747000
heap
page read and write
7A5000
heap
page read and write
2124000
direct allocation
page read and write
72E000
heap
page read and write
75B000
heap
page read and write
720000
heap
page read and write
445000
unkown
page execute and write copy
2250000
heap
page read and write
299F000
stack
page read and write
6AF000
stack
page read and write
979000
heap
page read and write
757000
heap
page read and write
2120000
direct allocation
page read and write
469000
unkown
page read and write
759000
heap
page read and write
72A000
heap
page read and write
45F000
unkown
page execute and read and write
970000
heap
page read and write
289E000
stack
page read and write
2ADF000
stack
page read and write
468000
unkown
page write copy
943000
heap
page read and write
There are 37 hidden memdumps, click here to show them.