IOC Report
LisectAVT_2403002A_464.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\LisectAVT_2403002A_464.exe
"C:\Users\user\Desktop\LisectAVT_2403002A_464.exe"
malicious

URLs

Name
IP
Malicious
https://ipinfo.io/https://www.maxmind.com/en/locate-my-ip-addressWs2_32.dll
unknown
http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
unknown
http://www.winimage.com/zLibDll
unknown
https://t.me/RiseProSUPPORT
unknown
https://sectigo.com/CPS0
unknown
http://ocsp.sectigo.com0
unknown
http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
unknown

IPs

IP
Domain
Country
Malicious
193.233.132.109
unknown
Russian Federation

Memdumps

Base Address
Regiontype
Protect
Malicious
806000
heap
page read and write
764000
heap
page read and write
2D50000
heap
page read and write
F03000
unkown
page execute read
AE0000
unkown
page readonly
7DA000
heap
page read and write
764000
heap
page read and write
780000
heap
page read and write
2D60000
trusted library allocation
page read and write
764000
heap
page read and write
764000
heap
page read and write
760000
heap
page read and write
764000
heap
page read and write
2E50000
heap
page read and write
770000
heap
page read and write
7D0000
heap
page read and write
1466000
unkown
page readonly
764000
heap
page read and write
764000
heap
page read and write
2F6B000
heap
page read and write
764000
heap
page read and write
2D60000
heap
page read and write
80E000
heap
page read and write
2E61000
heap
page read and write
C0E000
unkown
page read and write
325E000
stack
page read and write
C3B000
unkown
page read and write
80E000
heap
page read and write
3FC000
stack
page read and write
7DE000
heap
page read and write
2E60000
heap
page read and write
1466000
unkown
page readonly
AE1000
unkown
page execute read
C41000
unkown
page execute read
BED000
unkown
page readonly
F03000
unkown
page execute read
2D55000
heap
page read and write
AE0000
unkown
page readonly
802000
heap
page read and write
2E61000
heap
page read and write
6FD000
stack
page read and write
C13000
unkown
page execute read
2DEE000
stack
page read and write
F02000
unkown
page read and write
There are 34 hidden memdumps, click here to show them.