IOC Report
LisectAVT_2403002A_240.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\LisectAVT_2403002A_240.exe
"C:\Users\user\Desktop\LisectAVT_2403002A_240.exe"
malicious

URLs

Name
IP
Malicious
https://ipinfo.io/https://www.maxmind.com/en/locate-my-ip-addressWs2_32.dll
unknown
http://www.winimage.com/zLibDll
unknown
https://t.me/RiseProSUPPORT
unknown
http://www.altools.co.kr
unknown

IPs

IP
Domain
Country
Malicious
5.42.65.117
unknown
Russian Federation

Memdumps

Base Address
Regiontype
Protect
Malicious
148F000
heap
page read and write
13D4000
heap
page read and write
13D0000
heap
page read and write
13D4000
heap
page read and write
145A000
heap
page read and write
324D000
heap
page read and write
13D4000
heap
page read and write
1483000
heap
page read and write
13D4000
heap
page read and write
620000
unkown
page readonly
1450000
heap
page read and write
F2B000
unkown
page readonly
12FC000
stack
page read and write
13D4000
heap
page read and write
13F0000
trusted library allocation
page read and write
13D4000
heap
page read and write
148F000
heap
page read and write
3090000
heap
page read and write
145E000
heap
page read and write
13D4000
heap
page read and write
72D000
unkown
page readonly
13D4000
heap
page read and write
143D000
stack
page read and write
30A1000
heap
page read and write
77B000
unkown
page read and write
1340000
heap
page read and write
1330000
heap
page read and write
74E000
unkown
page read and write
1487000
heap
page read and write
620000
unkown
page readonly
30A0000
heap
page read and write
A08000
unkown
page execute read
A07000
unkown
page read and write
30A1000
heap
page read and write
FCC000
stack
page read and write
3230000
heap
page read and write
A08000
unkown
page execute read
147B000
heap
page read and write
621000
unkown
page execute read
F2B000
unkown
page readonly
353E000
stack
page read and write
781000
unkown
page execute read
753000
unkown
page execute read
There are 33 hidden memdumps, click here to show them.