IOC Report
SecuriteInfo.com.PUA.VMProtect.28434.4337.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.PUA.VMProtect.28434.4337.exe
"C:\Users\user\Desktop\SecuriteInfo.com.PUA.VMProtect.28434.4337.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

Memdumps

Base Address
Regiontype
Protect
Malicious
7FF6D95FA000
unkown
page readonly
7FF6D91A6000
unkown
page read and write
244BEBEC000
heap
page read and write
7FF6D91A7000
unkown
page execute read
7FF6D8FCE000
unkown
page execute read
7FF6D8A70000
unkown
page readonly
7FF6D8A70000
unkown
page readonly
244BEB00000
heap
page read and write
61B96FC000
stack
page read and write
244BECE0000
heap
page read and write
7FF6D95FA000
unkown
page readonly
244BEBE0000
heap
page read and write
244BEBE6000
heap
page read and write
7FF6D8FCE000
unkown
page execute read
There are 4 hidden memdumps, click here to show them.