IOC Report
QF8iBLjaKJ.vbs

loading gif

Processes

Path
Cmdline
Malicious
C:\Windows\System32\wscript.exe
C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\QF8iBLjaKJ.vbs"
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
23B3539C000
heap
page read and write
5C970FF000
stack
page read and write
5C96DFE000
stack
page read and write
23B35670000
heap
page read and write
23B35360000
heap
page read and write
23B35675000
heap
page read and write
23B35530000
heap
page read and write
23B36F10000
heap
page read and write
23B3539D000
heap
page read and write
23B353AD000
heap
page read and write
23B35550000
heap
page read and write
23B35350000
heap
page read and write
5C96FFF000
stack
page read and write
23B3538B000
heap
page read and write
23B35396000
heap
page read and write
23B3537C000
heap
page read and write
23B35381000
heap
page read and write
23B353B2000
heap
page read and write
23B35381000
heap
page read and write
5C96CFF000
stack
page read and write
23B353AF000
heap
page read and write
23B35396000
heap
page read and write
23B37010000
heap
page read and write
23B35396000
heap
page read and write
23B3538A000
heap
page read and write
5C9697A000
stack
page read and write
23B35370000
heap
page read and write
23B35367000
heap
page read and write
There are 18 hidden memdumps, click here to show them.