IOC Report
9HwMaWcccx.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\9HwMaWcccx.exe
"C:\Users\user\Desktop\9HwMaWcccx.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
http://103.239.244.218:8898/1c5b7aafca5f2cef32b8aea1ded2a1e9ed7a8f4b6d7cc93d3f1b914b61ea0731a?datamo
unknown
http://www.eyuyan.com)DVarFileInfo$
unknown
http://top6666.top/top/version.txt
unknown
http://crl.thawte.com/ThawteTimestampingCA.crl0
unknown
http://103.239.244.218:8898/
unknown
http://ocsp.thawte.com0
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
7FF69C32F000
unkown
page readonly
malicious
7FF69C32E000
unkown
page readonly
malicious
7FF69C2D0000
unkown
page readonly
1A7E5DE0000
heap
page read and write
7FF69C2D1000
unkown
page execute read
7FF69C3DC000
unkown
page readonly
7FF69C556000
unkown
page readonly
1A7E5DA0000
heap
page read and write
1A7E5DEC000
heap
page read and write
7FF69C554000
unkown
page write copy
7FF69C2D1000
unkown
page execute read
72CAEFF000
stack
page read and write
7FF69C32E000
unkown
page read and write
1A7E5DE9000
heap
page read and write
7FF69C2D0000
unkown
page readonly
72CACFB000
stack
page read and write
1A7E5DB0000
heap
page read and write
7FF69C554000
unkown
page read and write
7FF69C3DC000
unkown
page readonly
7FF69C556000
unkown
page readonly
There are 10 hidden memdumps, click here to show them.