IOC Report
Cleaning_Tool_for_Driver_Select1.17.exe

loading gif

Files

File Path
Type
Category
Malicious
Cleaning_Tool_for_Driver_Select1.17.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
C:\Users\user\Desktop\DriverSelect_CleaningTool.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\Desktop\DriverSelect_CleaningTool.pdf
PDF document, version 1.5 (zip deflate encoded)
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Cleaning_Tool_for_Driver_Select1.17.exe
"C:\Users\user\Desktop\Cleaning_Tool_for_Driver_Select1.17.exe"

Memdumps

Base Address
Regiontype
Protect
Malicious
8CF000
stack
page read and write
98000
stack
page read and write
2A23000
heap
page read and write
434000
unkown
page write copy
22DE000
stack
page read and write
4B70000
direct allocation
page read and write
2350000
heap
page read and write
2270000
heap
page read and write
460A000
heap
page read and write
28DE000
stack
page read and write
4E10000
direct allocation
page read and write
401000
unkown
page execute read
29DF000
stack
page read and write
3E00000
trusted library allocation
page read and write
6B7000
heap
page read and write
2A62000
heap
page read and write
4C90000
heap
page read and write
6BD000
heap
page read and write
2A22000
heap
page read and write
4C91000
heap
page read and write
1F0000
heap
page read and write
4CD0000
heap
page read and write
42D000
unkown
page readonly
401000
unkown
page execute read
4C11000
heap
page read and write
434000
unkown
page read and write
2180000
heap
page read and write
2353000
heap
page read and write
19C000
stack
page read and write
2B70000
heap
page read and write
57E000
stack
page read and write
4B6D000
direct allocation
page read and write
69E000
heap
page read and write
535000
heap
page read and write
6CE000
heap
page read and write
400000
unkown
page readonly
6E1000
heap
page read and write
6E1000
heap
page read and write
2AA2000
heap
page read and write
47E2000
direct allocation
page read and write
4C91000
heap
page read and write
29E1000
heap
page read and write
2A22000
heap
page read and write
6DE000
heap
page read and write
400000
unkown
page readonly
2A63000
heap
page read and write
6C5000
heap
page read and write
21B5000
heap
page read and write
7CE000
stack
page read and write
6E1000
heap
page read and write
43A000
unkown
page readonly
4D10000
heap
page read and write
6C1000
heap
page read and write
29E0000
heap
page read and write
510000
heap
page read and write
69A000
heap
page read and write
21B0000
heap
page read and write
6C6000
heap
page read and write
21BA000
heap
page read and write
47E0000
direct allocation
page read and write
47ED000
direct allocation
page read and write
530000
heap
page read and write
67F000
stack
page read and write
6C5000
heap
page read and write
6CB000
heap
page read and write
4C10000
heap
page read and write
29E3000
heap
page read and write
47F0000
direct allocation
page read and write
4860000
direct allocation
page read and write
4C50000
heap
page read and write
279F000
stack
page read and write
43A000
unkown
page readonly
6C1000
heap
page read and write
6C9000
heap
page read and write
690000
heap
page read and write
2A63000
heap
page read and write
4B62000
direct allocation
page read and write
6CE000
heap
page read and write
2170000
heap
page read and write
42D000
unkown
page readonly
4C11000
heap
page read and write
2180000
heap
page read and write
There are 72 hidden memdumps, click here to show them.