IOC Report
e90zPYFENm.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\e90zPYFENm.exe
"C:\Users\user\Desktop\e90zPYFENm.exe"
malicious

URLs

Name
IP
Malicious
http://119.45.147.28/cLzHwODM/SM8omDxZewgwWjFYVimA4g64y1JdIzY4ApXywlnL9_kGiyhwOZf2xLuhPjwY_i
malicious
https://119.45.147.28/cLzHwODM/SM8omDxZewgwWjFYVimA4g64y1JdIzY4ApXywlnL9_kGiyhwOZf2xLuhPjwY_i)
unknown
https://119.45.147.28/cLzHwODM/SM8omDxZewgwWjFYVimA4g64y1JdIzY4ApXywlnL9_kGiyhwOZf2xLuhPjwY_i
unknown
https://119.45.147.28/a81-46d0-b6b6-535557bcc5fa
unknown
https://119.45.147.28/LzHwODM/SM8omDxZewgwWjFYVimA4g64y1JdIzY4ApXywlnL9_kGiyhwOZf2xLuhPjwY_i
unknown
https://119.45.147.28/
unknown
https://119.45.147.28/u
unknown
https://119.45.147.28/cLzHwODM/SM8omDxZewgwWjFYVimA4g64y1JdIzY4ApXywlnL9_kGiyhwOZf2xLuhPjwY_iuq
unknown
https://119.45.147.28/mP%
unknown

IPs

IP
Domain
Country
Malicious
119.45.147.28
unknown
China
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
22BBCE50000
heap
page read and write
malicious
22BBCDE0000
heap
page execute and read and write
malicious
22BBCC43000
heap
page read and write
7FF71F480000
unkown
page readonly
22BBCC14000
heap
page read and write
36F27FA000
stack
page read and write
22BBCC24000
heap
page read and write
22BBCAC0000
heap
page read and write
7FF71F491000
unkown
page readonly
7FF71F491000
unkown
page readonly
7FF71F499000
unkown
page readonly
22BBCC3B000
heap
page read and write
36F2FFE000
stack
page read and write
22BBCD90000
remote allocation
page read and write
36F37FD000
stack
page read and write
22BBCCB0000
heap
page read and write
22BBCBB0000
heap
page read and write
36F31FE000
stack
page read and write
22BBCC43000
heap
page read and write
36F33FE000
stack
page read and write
22BBCE55000
heap
page read and write
22BBCD90000
remote allocation
page read and write
36F35FB000
stack
page read and write
22BBCBBC000
heap
page read and write
22BBCC0A000
heap
page read and write
7FF71F481000
unkown
page execute read
22BBCD90000
remote allocation
page read and write
22BBCC3B000
heap
page read and write
22BBCCD0000
heap
page read and write
22BBCBEC000
heap
page read and write
22BBCC0A000
heap
page read and write
7FF71F490000
unkown
page write copy
22BBCC3B000
heap
page read and write
36F39FD000
stack
page read and write
7FF71F490000
unkown
page write copy
7FF71F481000
unkown
page execute read
7FF71F496000
unkown
page write copy
22BBCC3B000
heap
page read and write
22BBCC14000
heap
page read and write
22BBCBB6000
heap
page read and write
7FF71F496000
unkown
page read and write
22BBCBEE000
heap
page read and write
22BBCBEE000
heap
page read and write
7FF71F499000
unkown
page readonly
7FF71F480000
unkown
page readonly
There are 35 hidden memdumps, click here to show them.