IOC Report
mTGDPqzxwu.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\mTGDPqzxwu.exe
"C:\Users\user\Desktop\mTGDPqzxwu.exe"
malicious

URLs

Name
IP
Malicious
https://curl.se/docs/hsts.html
unknown
https://curl.se/docs/alt-svc.html#
unknown
https://curl.se/docs/http-cookies.html#
unknown
http://27.25.156.102:9999/style.html
unknown
https://curl.se/docs/alt-svc.html
unknown
https://curl.se/docs/http-cookies.html
unknown
https://curl.se/docs/hsts.html#
unknown
http://27.25.156.102:9999/style.htmlSoftware
unknown

Domains

Name
IP
Malicious
206.23.85.13.in-addr.arpa
unknown
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
1490000
heap
page read and write
1310000
heap
page read and write
72D000
unkown
page readonly
6FC000
unkown
page readonly
1190000
heap
page read and write
149A000
heap
page read and write
72D000
unkown
page readonly
71A000
unkown
page readonly
149E000
heap
page read and write
680000
unkown
page readonly
681000
unkown
page execute read
6FB000
unkown
page readonly
1270000
heap
page read and write
6FB000
unkown
page read and write
714000
unkown
page write copy
681000
unkown
page execute read
103D000
stack
page read and write
714000
unkown
page read and write
168F000
stack
page read and write
12FE000
stack
page read and write
71A000
unkown
page readonly
113C000
stack
page read and write
680000
unkown
page readonly
There are 13 hidden memdumps, click here to show them.