IOC Report
Setup.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Setup.exe
"C:\Users\user\Desktop\Setup.exe"
malicious

URLs

Name
IP
Malicious
servicedny.site
malicious
goalyfeastz.site
malicious
contemteny.site
malicious
faulteyotk.site
malicious
drinkyresule.cyou
malicious
opposezmny.site
malicious
seallysl.site
malicious
dilemmadu.site
malicious
authorisev.site
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
D80000
heap
page read and write
1250000
heap
page read and write
57F000
unkown
page read and write
147A000
heap
page read and write
531000
unkown
page execute read
D70000
heap
page read and write
144B000
heap
page read and write
145D000
heap
page read and write
579000
unkown
page write copy
1475000
heap
page read and write
D1C000
stack
page read and write
531000
unkown
page execute read
576000
unkown
page readonly
530000
unkown
page readonly
2D40000
heap
page read and write
576000
unkown
page readonly
589000
unkown
page readonly
579000
unkown
page write copy
DF0000
heap
page read and write
1440000
heap
page read and write
589000
unkown
page readonly
530000
unkown
page readonly
10FC000
stack
page read and write
There are 13 hidden memdumps, click here to show them.