IOC Report
SecuriteInfo.com.Win64.MalwareX-gen.32396.3970.exe

loading gif

Files

File Path
Type
Category
Malicious
SecuriteInfo.com.Win64.MalwareX-gen.32396.3970.exe
PE32+ executable (console) x86-64, for MS Windows
initial sample
malicious
\Device\ConDrv
ASCII text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.32396.3970.exe
"C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.32396.3970.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

Memdumps

Base Address
Regiontype
Protect
Malicious
15E87BC9000
heap
page read and write
7FF7DC6D4000
unkown
page readonly
7FF7DC6D7000
unkown
page readonly
15E87BD1000
heap
page read and write
15E87DB0000
heap
page read and write
1000FD000
stack
page read and write
7FF7DC6D1000
unkown
page execute read
7FF7DC6D0000
unkown
page readonly
7FF7DC6D1000
unkown
page execute read
7FF7DC6D0000
unkown
page readonly
7FF7DC6D4000
unkown
page readonly
15E87BCE000
heap
page read and write
1001FF000
stack
page read and write
15E87D90000
heap
page read and write
7FF7DC6D7000
unkown
page readonly
15E87BB0000
heap
page read and write
15E87EA0000
heap
page read and write
15E87BC0000
heap
page read and write
1004FF000
stack
page read and write
There are 9 hidden memdumps, click here to show them.