IOC Report
LisectAVT_2403002B_445.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\LisectAVT_2403002B_445.exe
"C:\Users\user\Desktop\LisectAVT_2403002B_445.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
edurestunningcrackyow.fun
malicious
pooreveningfuseor.pw
malicious
associationokeo.shop
malicious
colorfulequalugliess.shop
malicious
turkeyunlikelyofw.shop
malicious
detectordiscusser.shop
malicious
wisemassiveharmonious.shop
malicious
sideindexfollowragelrew.pw
malicious
relevantvoicelesskw.shop
malicious
https://associationokeo.shop/api
unknown
https://turkeyunlikelyofw.shop/p
unknown
https://associationokeo.shop/_
unknown
https://turkeyunlikelyofw.shop/api
unknown
https://turkeyunlikelyofw.shop/
unknown
https://associationokeo.shop/apiM
unknown
https://edurestunningcrackyow.fun/
unknown
https://colorfulequalugliess.shop/K
unknown
https://pooreveningfuseor.pw/t
unknown
https://detectordiscusser.shop/apie
unknown
https://detectordiscusser.shop/
unknown
https://detectordiscusser.shop/api
unknown
https://associationokeo.shop//
unknown
https://relevantvoicelesskw.shop//
unknown
https://pooreveningfuseor.pw/
unknown
https://associationokeo.shop/i
unknown
There are 15 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
edurestunningcrackyow.fun
unknown
malicious
turkeyunlikelyofw.shop
unknown
malicious
sideindexfollowragelrew.pw
unknown
malicious
detectordiscusser.shop
unknown
malicious
relevantvoicelesskw.shop
unknown
malicious
pooreveningfuseor.pw
unknown
malicious
wisemassiveharmonious.shop
unknown
malicious
associationokeo.shop
unknown
malicious
colorfulequalugliess.shop
unknown
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
5A0000
unkown
page read and write
malicious
902000
heap
page read and write
92B000
heap
page read and write
90E000
heap
page read and write
27CF000
stack
page read and write
860000
remote allocation
page read and write
90C000
heap
page read and write
254D000
stack
page read and write
400000
unkown
page readonly
902000
heap
page read and write
8E7000
heap
page read and write
19A000
stack
page read and write
80D000
stack
page read and write
902000
heap
page read and write
8BE000
heap
page read and write
90E000
heap
page read and write
90E000
heap
page read and write
2D8E000
stack
page read and write
6D1000
direct allocation
page execute read
9C000
stack
page read and write
AAF000
stack
page read and write
923000
heap
page read and write
5E8000
unkown
page readonly
92B000
heap
page read and write
290F000
stack
page read and write
923000
heap
page read and write
268E000
stack
page read and write
6D0000
direct allocation
page read and write
70A000
direct allocation
page read and write
401000
unkown
page execute read
8DC000
heap
page read and write
8E7000
heap
page read and write
BAF000
stack
page read and write
92B000
heap
page read and write
5E8000
unkown
page readonly
8EC000
heap
page read and write
8E5000
heap
page read and write
870000
heap
page read and write
599000
unkown
page readonly
90E000
heap
page read and write
5A0000
unkown
page write copy
280E000
stack
page read and write
244D000
stack
page read and write
92B000
heap
page read and write
2C8E000
stack
page read and write
860000
remote allocation
page read and write
599000
unkown
page readonly
8B0000
heap
page read and write
714000
direct allocation
page readonly
2458000
trusted library allocation
page read and write
84E000
stack
page read and write
8E7000
heap
page read and write
8BA000
heap
page read and write
79E000
stack
page read and write
7C0000
heap
page read and write
1F0000
heap
page read and write
923000
heap
page read and write
923000
heap
page read and write
400000
unkown
page readonly
860000
remote allocation
page read and write
6C0000
heap
page read and write
8D6000
heap
page read and write
75E000
stack
page read and write
401000
unkown
page execute read
258E000
stack
page read and write
8EC000
heap
page read and write
8EC000
heap
page read and write
26CE000
stack
page read and write
90B000
heap
page read and write
707000
direct allocation
page readonly
There are 60 hidden memdumps, click here to show them.