IOC Report
51FZ8pgLbe.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\51FZ8pgLbe.exe
"C:\Users\user\Desktop\51FZ8pgLbe.exe"
malicious

IPs

IP
Domain
Country
Malicious
116.198.232.205
unknown
China
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
32CF000
stack
page read and write
110A000
heap
page read and write
823000
unkown
page readonly
1100000
heap
page read and write
6A8000
unkown
page read and write
F05000
heap
page read and write
820000
unkown
page readonly
2BF0000
heap
page read and write
1140000
heap
page read and write
2B20000
heap
page read and write
104F000
stack
page read and write
530000
unkown
page readonly
2DF7000
heap
page read and write
531000
unkown
page execute read
C3B000
stack
page read and write
820000
unkown
page readonly
2AA0000
heap
page read and write
530000
unkown
page readonly
65A000
unkown
page readonly
33CF000
stack
page read and write
110E000
heap
page read and write
E80000
heap
page read and write
10F0000
heap
page read and write
2B0D000
stack
page read and write
2EC0000
heap
page read and write
2DED000
stack
page read and write
6A0000
unkown
page read and write
2FCF000
stack
page read and write
2E7E000
stack
page read and write
2DF4000
heap
page read and write
6A0000
unkown
page write copy
30CF000
stack
page read and write
F00000
heap
page read and write
2B23000
heap
page read and write
F4E000
unkown
page read and write
6B1000
unkown
page readonly
531000
unkown
page execute read
823000
unkown
page readonly
2AB0000
heap
page read and write
65A000
unkown
page readonly
D3C000
stack
page read and write
2B60000
heap
page read and write
2DF0000
heap
page read and write
123E000
stack
page read and write
2E3E000
stack
page read and write
6B1000
unkown
page readonly
127E000
stack
page read and write
DA0000
heap
page read and write
There are 38 hidden memdumps, click here to show them.