IOC Report
Aura.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Aura.exe
"C:\Users\user\Desktop\Aura.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

Memdumps

Base Address
Regiontype
Protect
Malicious
2C2C000
direct allocation
page read and write
2BC5000
heap
page read and write
841000
unkown
page write copy
30D0000
direct allocation
page execute read
D5C000
stack
page read and write
2BC0000
heap
page read and write
111F000
stack
page read and write
F4B000
heap
page read and write
F63000
heap
page read and write
F5F000
heap
page read and write
2C1D000
direct allocation
page readonly
F20000
heap
page read and write
F60000
heap
page read and write
85A000
unkown
page write copy
841000
unkown
page write copy
858000
unkown
page read and write
DC0000
heap
page read and write
51000
unkown
page execute read
F60000
heap
page read and write
84B000
unkown
page read and write
50000
unkown
page readonly
679000
unkown
page readonly
2C2E000
direct allocation
page readonly
2A20000
heap
page read and write
F5F000
heap
page read and write
84C000
unkown
page write copy
8AA000
unkown
page readonly
9D62000
direct allocation
page execute read
9EE0000
trusted library allocation
page read and write
2B90000
heap
page read and write
2BB4000
heap
page read and write
325B000
heap
page read and write
DD0000
heap
page read and write
F5C000
heap
page read and write
8AA000
unkown
page readonly
2BD0000
direct allocation
page readonly
51000
unkown
page execute read
4BDD000
direct allocation
page read and write
E1E000
stack
page read and write
51000
unkown
page execute read
2BD1000
direct allocation
page execute read
84A000
unkown
page write copy
8A7000
unkown
page read and write
2D7E000
stack
page read and write
2B80000
heap
page read and write
F2E000
heap
page read and write
FC3000
heap
page read and write
679000
unkown
page readonly
2C7B000
stack
page read and write
2BB0000
heap
page read and write
F2A000
heap
page read and write
849000
unkown
page read and write
2BC9000
heap
page read and write
E40000
heap
page read and write
50000
unkown
page readonly
C5C000
stack
page read and write
There are 46 hidden memdumps, click here to show them.