IOC Report
cHZiG7fsJb.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\cHZiG7fsJb.exe
"C:\Users\user\Desktop\cHZiG7fsJb.exe"
malicious

URLs

Name
IP
Malicious
http://www.apache.org/licenses/LICENSE-2.0
unknown
http://www.apache.org/
unknown
http://www.zeustech.net/
unknown

IPs

IP
Domain
Country
Malicious
212.192.213.56
unknown
Russian Federation
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
401000
unkown
page execute read
malicious
590000
direct allocation
page execute and read and write
malicious
401000
unkown
page execute read
malicious
64A000
heap
page read and write
40D000
unkown
page write copy
1F0000
heap
page read and write
40D000
unkown
page write copy
40C000
unkown
page readonly
93F000
stack
page read and write
64E000
heap
page read and write
470000
heap
page read and write
58E000
stack
page read and write
400000
unkown
page readonly
46E000
stack
page read and write
415000
unkown
page readonly
475000
heap
page read and write
9D000
stack
page read and write
19D000
stack
page read and write
40C000
unkown
page readonly
5A0000
heap
page read and write
420000
heap
page read and write
400000
unkown
page readonly
640000
heap
page read and write
83F000
stack
page read and write
B10000
heap
page read and write
415000
unkown
page readonly
There are 16 hidden memdumps, click here to show them.