IOC Report
Infor IDF Auxiliary Machine.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Infor IDF Auxiliary Machine.exe
"C:\Users\user\Desktop\Infor IDF Auxiliary Machine.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
http://java.sun.com
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
43C000
unkown
page execute and read and write
400000
unkown
page readonly
79F000
stack
page read and write
19D000
stack
page read and write
400000
unkown
page readonly
5C0000
heap
page read and write
7DE000
stack
page read and write
8DF000
stack
page read and write
430000
unkown
page execute and read and write
2190000
heap
page read and write
43C000
unkown
page execute and write copy
47A000
heap
page read and write
401000
unkown
page execute and write copy
2090000
direct allocation
page execute and read and write
9C000
stack
page read and write
401000
unkown
page execute and read and write
450000
heap
page read and write
5BE000
stack
page read and write
2170000
heap
page read and write
460000
heap
page read and write
47E000
heap
page read and write
570000
direct allocation
page execute and read and write
470000
heap
page read and write
There are 13 hidden memdumps, click here to show them.