IOC Report
5ZjBJd69zi.exe

loading gif

Files

File Path
Type
Category
Malicious
5ZjBJd69zi.exe
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
initial sample
malicious
C:\Windows\microsofthelp.exe
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\5ZjBJd69zi.exe
"C:\Users\user\Desktop\5ZjBJd69zi.exe"
malicious
C:\Windows\microsofthelp.exe
"C:\Windows\microsofthelp.exe"
malicious

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
microsofthelp
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
401000
unkown
page execute and write copy
malicious
401000
unkown
page execute and write copy
malicious
406000
unkown
page execute and write copy
malicious
49E000
heap
page read and write
malicious
406000
unkown
page execute and write copy
malicious
49A000
heap
page read and write
40C000
unkown
page write copy
409000
unkown
page execute and write copy
89F000
stack
page read and write
400000
unkown
page readonly
405000
unkown
page execute and read and write
400000
unkown
page readonly
409000
unkown
page execute and write copy
68A000
heap
page read and write
408000
unkown
page execute and write copy
405000
unkown
page execute and read and write
698000
heap
page read and write
408000
unkown
page execute and write copy
400000
unkown
page readonly
79E000
stack
page read and write
1F0000
heap
page read and write
75F000
stack
page read and write
410000
heap
page read and write
400000
unkown
page readonly
408000
unkown
page execute and read and write
401000
unkown
page execute and write copy
40C000
unkown
page write copy
19D000
stack
page read and write
680000
heap
page read and write
40C000
unkown
page read and write
40C000
unkown
page read and write
480000
heap
page read and write
420000
heap
page read and write
490000
heap
page read and write
9C000
stack
page read and write
68E000
heap
page read and write
19D000
stack
page read and write
401000
unkown
page execute and write copy
1F0000
heap
page read and write
A40000
heap
page read and write
9C000
stack
page read and write
46E000
stack
page read and write
8F0000
heap
page read and write
408000
unkown
page execute and read and write
410000
heap
page read and write
4B5000
heap
page read and write
There are 36 hidden memdumps, click here to show them.