IOC Report
KPT_BMU_Bootload_V1.01.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\KPT_BMU_Bootload_V1.01.exe
"C:\Users\user\Desktop\KPT_BMU_Bootload_V1.01.exe"

Memdumps

Base Address
Regiontype
Protect
Malicious
401000
unkown
page execute read
405000
unkown
page readonly
401000
unkown
page execute read
408000
unkown
page readonly
406000
unkown
page readonly
19D000
stack
page read and write
400000
unkown
page readonly
41E000
heap
page read and write
408000
unkown
page readonly
41A000
heap
page read and write
510000
heap
page read and write
400000
unkown
page readonly
5C0000
heap
page read and write
1F0000
heap
page read and write
407000
unkown
page write copy
405000
unkown
page read and write
9D000
stack
page read and write
407000
unkown
page write copy
410000
heap
page read and write
There are 9 hidden memdumps, click here to show them.