IOC Report
wsmprovhost.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\wsmprovhost.exe
"C:\Users\user\Desktop\wsmprovhost.exe"
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
26CDF5E0000
heap
page read and write
26CDF5B0000
heap
page read and write
7FF7ECB11000
unkown
page execute read
26CDF640000
heap
page read and write
7FF7ECB1B000
unkown
page readonly
7FF7ECB15000
unkown
page readonly
26CE1200000
heap
page read and write
F3A38FF000
stack
page read and write
26CDF8E5000
heap
page read and write
F3A387E000
stack
page read and write
7FF7ECB10000
unkown
page readonly
7FF7ECB15000
unkown
page readonly
7FF7ECB1C000
unkown
page write copy
26CDF670000
heap
page read and write
7FF7ECB11000
unkown
page execute read
7FF7ECB1A000
unkown
page read and write
26CDF5A0000
heap
page read and write
7FF7ECB10000
unkown
page readonly
F3A367C000
stack
page read and write
7FF7ECB1B000
unkown
page readonly
7FF7ECB1D000
unkown
page readonly
26CDF679000
heap
page read and write
26CDF8E0000
heap
page read and write
26CE1203000
heap
page read and write
There are 14 hidden memdumps, click here to show them.