IOC Report
5390d36a371f0598b86301961d5fdb329e368e7a

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\5390d36a371f0598b86301961d5fdb329e368e7a.exe
"C:\Users\user\Desktop\5390d36a371f0598b86301961d5fdb329e368e7a.exe"
malicious

URLs

Name
IP
Malicious
http://www.winimage.com/zLibDll
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
140038000
unkown
page readonly
140026000
unkown
page readonly
140000000
unkown
page readonly
140001000
unkown
page execute read
140036000
unkown
page write copy
140036000
unkown
page write copy
140038000
unkown
page readonly
140026000
unkown
page readonly
140000000
unkown
page readonly
140001000
unkown
page execute read