IOC Report
SecuriteInfo.com.PUA.VMProtect.7160.22341.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.PUA.VMProtect.7160.22341.exe
"C:\Users\user\Desktop\SecuriteInfo.com.PUA.VMProtect.7160.22341.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

Memdumps

Base Address
Regiontype
Protect
Malicious
330EFFF000
stack
page read and write
7FF66A61D000
unkown
page execute read
16DB0700000
heap
page read and write
16DB0706000
heap
page read and write
16DB08D0000
heap
page read and write
16DB070D000
heap
page read and write
7FF66A798000
unkown
page readonly
7FF66A165000
unkown
page execute read
7FF66A61C000
unkown
page read and write
7FF669C00000
unkown
page readonly
330EBDC000
stack
page read and write
16DB06F0000
heap
page read and write
7FF66A798000
unkown
page readonly
7FF66A165000
unkown
page execute read
7FF669C00000
unkown
page readonly
There are 5 hidden memdumps, click here to show them.