IOC Report
Convert.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Convert.exe
"C:\Users\user\Desktop\Convert.exe"

URLs

Name
IP
Malicious
http://www.joshmadison.com/software
unknown

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Joshua F. Madison\Convert\Settings
LastTab
HKEY_CURRENT_USER\SOFTWARE\Joshua F. Madison\Convert\Acceleration
Value
HKEY_CURRENT_USER\SOFTWARE\Joshua F. Madison\Convert\Acceleration
InputUnit

Memdumps

Base Address
Regiontype
Protect
Malicious
680000
heap
page read and write
24B4000
heap
page read and write
1F0000
heap
page read and write
51E000
heap
page read and write
22F0000
heap
page read and write
21B0000
heap
page read and write
26B4000
heap
page read and write
508000
heap
page read and write
21E0000
direct allocation
page read and write
85F000
stack
page read and write
50D000
heap
page read and write
21D9000
heap
page read and write
19B000
stack
page read and write
4DE000
stack
page read and write
263E000
stack
page read and write
517000
heap
page read and write
21D0000
heap
page read and write
517000
heap
page read and write
401000
unkown
page execute read
490000
heap
page read and write
518000
heap
page read and write
24B0000
heap
page read and write
401000
unkown
page execute read
535000
heap
page read and write
4EE000
heap
page read and write
46C000
unkown
page write copy
400000
unkown
page readonly
511000
heap
page read and write
45F000
unkown
page readonly
481000
unkown
page read and write
488000
unkown
page readonly
511000
heap
page read and write
52D000
heap
page read and write
24FE000
stack
page read and write
488000
unkown
page readonly
660000
heap
page read and write
21D5000
heap
page read and write
4EA000
heap
page read and write
4160000
trusted library allocation
page read and write
46C000
unkown
page write copy
4E0000
heap
page read and write
685000
heap
page read and write
99000
stack
page read and write
400000
unkown
page readonly
27BF000
stack
page read and write
26B0000
heap
page read and write
45F000
unkown
page readonly
25FF000
stack
page read and write
2190000
heap
page read and write
There are 39 hidden memdumps, click here to show them.