IOC Report
game.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\game.exe
"C:\Users\user\Desktop\game.exe"

URLs

Name
IP
Malicious
http://cert.ssl.com/SSL.com-timeStamping-I-RSA-R1.cer0Q
unknown
http://cert.ssl.com/SSLcom-SubCA-CodeSigning-RSA-4096-R1.cer0
unknown
http://ocsps.ssl.com0
unknown
http://crls.ssl.com/ssl.com-rsa-RootCA.crl0
unknown
http://crls.ssl.com/SSL.com-timeStamping-I-RSA-R1.crl0
unknown
http://crls.ssl.com/SSLcom-SubCA-CodeSigning-RSA-4096-R1.crl0
unknown
http://ocsps.ssl.com0Q
unknown
https://www.ssl.com/repository0
unknown
http://ocsps.ssl.com0?
unknown
http://www.ssl.com/repository/SSLcomRootCertificationAuthorityRSA.crt0
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
6C2000
heap
page read and write
A0E000
stack
page read and write
278B000
heap
page read and write
2CCF000
stack
page read and write
6F9000
heap
page read and write
970000
heap
page read and write
69E000
heap
page read and write
2684000
heap
page read and write
2780000
heap
page read and write
2DCF000
stack
page read and write
4E0000
heap
page read and write
6DE000
heap
page read and write
6BD000
heap
page read and write
2785000
heap
page read and write
5450000
heap
page read and write
261E000
stack
page read and write
19B000
stack
page read and write
6BA000
heap
page read and write
6C9000
heap
page read and write
6C5000
heap
page read and write
2DD0000
heap
page read and write
69C000
heap
page read and write
86F000
stack
page read and write
6F8000
heap
page read and write
A10000
heap
page read and write
D66000
unkown
page readonly
6F8000
heap
page read and write
52E000
stack
page read and write
A30000
unkown
page readonly
2620000
heap
page read and write
6E4000
heap
page read and write
D58000
unkown
page read and write
D58000
unkown
page write copy
2680000
heap
page read and write
5E0000
heap
page read and write
A31000
unkown
page execute read
A30000
unkown
page readonly
575000
heap
page read and write
50AF000
unkown
page read and write
CAB000
unkown
page readonly
D66000
unkown
page readonly
CAB000
unkown
page readonly
9A000
stack
page read and write
67A000
heap
page read and write
A31000
unkown
page execute read
670000
heap
page read and write
400000
heap
page read and write
694000
heap
page read and write
6BA000
heap
page read and write
96E000
stack
page read and write
D5A000
unkown
page write copy
266E000
stack
page read and write
9CD000
stack
page read and write
2FCF000
stack
page read and write
6C9000
heap
page read and write
6DE000
heap
page read and write
5D0000
heap
page read and write
6BD000
heap
page read and write
6E7000
heap
page read and write
56E000
stack
page read and write
D5B000
unkown
page read and write
3050000
trusted library allocation
page read and write
6E6000
heap
page read and write
6E7000
heap
page read and write
570000
heap
page read and write
6C5000
heap
page read and write
There are 56 hidden memdumps, click here to show them.