IOC Report
putty1.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\putty1.exe
"C:\Users\user\Desktop\putty1.exe"

URLs

Name
IP
Malicious
http://crt.sectigo.com/SectigoPublicCodeSigningCAR36.crt0#
unknown
http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
unknown
https://sectigo.com/CPS0
unknown
http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#
unknown
http://crl.sectigo.com/SectigoPublicCodeSigningCAR36.crl0y
unknown
http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0
unknown
http://ocsp.sectigo.com0
unknown
https://www.chiark.greenend.org.uk/~sgtatham/putty/
unknown
https://www.chiark.greenend.org.uk/~sgtatham/putty/0
unknown
http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
1645000
heap
page read and write
16E2000
heap
page read and write
16A2000
heap
page read and write
167E000
heap
page read and write
EEA000
unkown
page readonly
EE2000
unkown
page write copy
442F000
stack
page read and write
DE0000
unkown
page readonly
1640000
heap
page read and write
EA9000
unkown
page readonly
EE2000
unkown
page read and write
FD5000
stack
page read and write
40DF000
stack
page read and write
1620000
heap
page read and write
14E7000
heap
page read and write
36A0000
trusted library allocation
page read and write
45E1000
heap
page read and write
3FDE000
stack
page read and write
12FA000
stack
page read and write
3110000
unkown
page read and write
3120000
heap
page read and write
42EF000
stack
page read and write
45E0000
heap
page read and write
1650000
heap
page read and write
3254000
heap
page read and write
322E000
stack
page read and write
DE1000
unkown
page execute read
3F9F000
stack
page read and write
1420000
heap
page read and write
EE4000
unkown
page read and write
1340000
heap
page read and write
41EE000
stack
page read and write
169E000
heap
page read and write
16E5000
heap
page read and write
EA9000
unkown
page readonly
DE0000
unkown
page readonly
1649000
heap
page read and write
15F0000
heap
page read and write
DE1000
unkown
page execute read
EEA000
unkown
page readonly
14E5000
heap
page read and write
432E000
stack
page read and write
3250000
heap
page read and write
1670000
heap
page read and write
167A000
heap
page read and write
14E0000
heap
page read and write
There are 36 hidden memdumps, click here to show them.