IOC Report
demon.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\demon.exe
"C:\Users\user\Desktop\demon.exe"
malicious

URLs

Name
IP
Malicious
https://87.120.113.125/2
unknown
https://87.120.113.125/Q
unknown
https://87.120.113.125:443/X
unknown
https://87.120.113.125/Pw
unknown
https://87.120.113.125/
unknown
https://87.120.113.125/H
unknown
https://87.120.113.125/g
unknown
https://87.120.113.125/F
unknown
https://87.120.113.125/%
unknown
https://87.120.113.125:443/
unknown

IPs

IP
Domain
Country
Malicious
87.120.113.125
unknown
Bulgaria

Memdumps

Base Address
Regiontype
Protect
Malicious
7FF7C5E9A000
unkown
page readonly
19756FB5000
heap
page read and write
19756E40000
heap
page read and write
7FF7C5E80000
unkown
page readonly
19756FC0000
heap
page read and write
19756F30000
heap
page read and write
7FF7C5E80000
unkown
page readonly
3BE19FC000
stack
page read and write
19756F65000
heap
page read and write
19757090000
remote allocation
page read and write
3BE1DFE000
stack
page read and write
19756F8A000
heap
page read and write
19757050000
heap
page read and write
19757030000
heap
page read and write
3BE21FE000
stack
page read and write
19757090000
remote allocation
page read and write
19756F3B000
heap
page read and write
19756F63000
heap
page read and write
7FF7C5E81000
unkown
page execute read
19756FC7000
heap
page read and write
19756F36000
heap
page read and write
7FF7C5E81000
unkown
page execute read
19756F5D000
heap
page read and write
3BE13FC000
stack
page read and write
19756F9D000
heap
page read and write
19757090000
remote allocation
page read and write
19756FB7000
heap
page read and write
7FF7C5E99000
unkown
page write copy
7FF7C5E9A000
unkown
page readonly
19756F68000
heap
page read and write
19756F6C000
heap
page read and write
7FF7C5E9D000
unkown
page readonly
19756F8F000
heap
page read and write
19756FAD000
heap
page read and write
7FF7C5E99000
unkown
page read and write
197571D5000
heap
page read and write
7FF7C5E9D000
unkown
page readonly
3BE1BFD000
stack
page read and write
197571D0000
heap
page read and write
There are 29 hidden memdumps, click here to show them.