IOC Report
BouncyCastle.Crypto.dll

loading gif

Processes

Path
Cmdline
Malicious
C:\Windows\System32\loaddll32.exe
loaddll32.exe "C:\Users\user\Desktop\BouncyCastle.Crypto.dll"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd.exe /C rundll32.exe "C:\Users\user\Desktop\BouncyCastle.Crypto.dll",#1
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe "C:\Users\user\Desktop\BouncyCastle.Crypto.dll",#1

Memdumps

Base Address
Regiontype
Protect
Malicious
FED000
stack
page read and write
1590000
heap
page read and write
759000
stack
page read and write
B41000
heap
page read and write
14BE000
stack
page read and write
AB0000
heap
page read and write
474F000
stack
page read and write
B33000
heap
page read and write
1430000
heap
page read and write
B2C000
heap
page read and write
B38000
heap
page read and write
B39000
heap
page read and write
A9A000
heap
page read and write
A90000
heap
page read and write
B1A000
heap
page read and write
B56000
heap
page read and write
159B000
heap
page read and write
188F000
stack
page read and write
A8E000
stack
page read and write
5EE4000
heap
page read and write
B38000
heap
page read and write
5FE0000
heap
page read and write
19D0000
heap
page read and write
12FD000
stack
page read and write
1470000
heap
page read and write
B56000
heap
page read and write
1350000
heap
page read and write
159F000
heap
page read and write
A00000
heap
page read and write
B41000
heap
page read and write
A96000
heap
page read and write
14FE000
stack
page read and write
5EE0000
heap
page read and write
6400000
trusted library allocation
page read and write
B10000
heap
page read and write
B38000
heap
page read and write
B35000
heap
page read and write
B42000
heap
page read and write
178F000
stack
page read and write
B56000
heap
page read and write
AFF000
stack
page read and write
A10000
heap
page read and write
B53000
heap
page read and write
470E000
stack
page read and write
5FF0000
heap
page read and write
B2F000
heap
page read and write
79C000
stack
page read and write
There are 37 hidden memdumps, click here to show them.