IOC Report
SecuriteInfo.com.PUA.VMProtect.10672.3906.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.PUA.VMProtect.10672.3906.exe
"C:\Users\user\Desktop\SecuriteInfo.com.PUA.VMProtect.10672.3906.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

Memdumps

Base Address
Regiontype
Protect
Malicious
10AE8E10000
heap
page read and write
10AE8E1C000
heap
page read and write
7FF621E7B000
unkown
page execute read
10AE8BF0000
heap
page read and write
7FF621E7B000
unkown
page execute read
7FF6226AD000
unkown
page readonly
7FF621630000
unkown
page readonly
52EAFC000
stack
page read and write
7FF6226AD000
unkown
page readonly
10AE8E16000
heap
page read and write
7FF6221F8000
unkown
page execute read
7FF6221F7000
unkown
page read and write
7FF621630000
unkown
page readonly
10AE8D50000
heap
page read and write
There are 4 hidden memdumps, click here to show them.