IOC Report
R2T8ccXCek.exe

loading gif

Files

File Path
Type
Category
Malicious
R2T8ccXCek.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
C:\Users\user\AppData\Roaming\ConsolHQ LTD\ConsoleHQ 1.12.3\install\decoder.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\R2T8ccXCek.exe
"C:\Users\user\Desktop\R2T8ccXCek.exe"

Memdumps

Base Address
Regiontype
Protect
Malicious
2D2E000
stack
page read and write
9F1000
unkown
page execute read
605000
heap
page read and write
26A0000
heap
page read and write
9C0000
heap
page read and write
271E000
stack
page read and write
CB6000
unkown
page readonly
727000
heap
page read and write
704000
heap
page read and write
281E000
stack
page read and write
DFE000
stack
page read and write
9F0000
unkown
page readonly
2FB0000
trusted library allocation
page read and write
C8E000
unkown
page read and write
439000
stack
page read and write
6A0000
heap
page read and write
70F000
heap
page read and write
6B4000
heap
page read and write
2840000
heap
page read and write
9F0000
unkown
page readonly
C08000
unkown
page readonly
6CC000
heap
page read and write
2CEF000
stack
page read and write
26D5000
heap
page read and write
70A000
heap
page read and write
2F20000
heap
page read and write
600000
heap
page read and write
580000
heap
page read and write
38FF000
stack
page read and write
704000
heap
page read and write
6EC000
heap
page read and write
26DB000
heap
page read and write
26D0000
heap
page read and write
6EC000
heap
page read and write
96F000
stack
page read and write
6AA000
heap
page read and write
5CE000
stack
page read and write
64E000
stack
page read and write
53B000
stack
page read and write
670000
heap
page read and write
C97000
unkown
page readonly
2844000
heap
page read and write
C97000
unkown
page readonly
727000
heap
page read and write
C93000
unkown
page write copy
C94000
unkown
page read and write
C92000
unkown
page write copy
C08000
unkown
page readonly
C8E000
unkown
page write copy
37FE000
stack
page read and write
570000
heap
page read and write
CB6000
unkown
page readonly
6B3000
heap
page read and write
9F1000
unkown
page execute read
2BEE000
stack
page read and write
6CF000
heap
page read and write
2E2F000
stack
page read and write
690000
heap
page read and write
There are 48 hidden memdumps, click here to show them.