IOC Report
WinZip Smart Monitor Service.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\WinZip Smart Monitor Service.exe
"C:\Users\user\Desktop\WinZip Smart Monitor Service.exe"

URLs

Name
IP
Malicious
http://crl3.di
unknown
https://updaterv.winzip.com/api/updateWZSNUpdates
unknown
http://cacerts.digicert
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
23388E31000
heap
page read and write
23388E23000
heap
page read and write
23388DE6000
heap
page read and write
91025FE000
stack
page read and write
2338A790000
heap
page read and write
23388DD5000
heap
page read and write
23388C00000
heap
page read and write
23388DE6000
heap
page read and write
7FF6BF430000
unkown
page readonly
23388E34000
heap
page read and write
7FF6BF431000
unkown
page execute read
910216B000
stack
page read and write
7FF6BF57D000
unkown
page write copy
91028FE000
stack
page read and write
7FF6BF522000
unkown
page readonly
23388DE9000
heap
page read and write
23388E3C000
heap
page read and write
2338AAE0000
heap
page read and write
7FF6BF522000
unkown
page readonly
23388DB8000
heap
page read and write
2338A6F0000
heap
page read and write
7FF6BF58F000
unkown
page readonly
7FF6BF58F000
unkown
page readonly
7FF6BF431000
unkown
page execute read
23388E39000
heap
page read and write
23388E23000
heap
page read and write
23388E23000
heap
page read and write
91027FF000
stack
page read and write
7FF6BF58B000
unkown
page read and write
23388CE0000
heap
page read and write
7FF6BF57C000
unkown
page write copy
91024FE000
stack
page read and write
23388E32000
heap
page read and write
23388E3D000
heap
page read and write
23388DE9000
heap
page read and write
23388E39000
heap
page read and write
2338AAE1000
heap
page read and write
23388DB0000
heap
page read and write
23388D10000
heap
page read and write
2338A795000
heap
page read and write
23388E3A000
heap
page read and write
7FF6BF57C000
unkown
page read and write
23388DE9000
heap
page read and write
23388E23000
heap
page read and write
7FF6BF430000
unkown
page readonly
23388E23000
heap
page read and write
23388DDA000
heap
page read and write
There are 37 hidden memdumps, click here to show them.