IOC Report
test.vbs.danger

loading gif

Processes

Path
Cmdline
Malicious
C:\Windows\System32\wscript.exe
C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\test.vbs.vbs"
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
1CA5000
heap
page read and write
3769000
heap
page read and write
37F000
heap
page read and write
3760000
heap
page read and write
330000
heap
page read and write
194000
heap
page read and write
10000
heap
page read and write
3516000
heap
page read and write
36E000
heap
page read and write
38C000
heap
page read and write
2B6000
stack
page read and write
1CDB000
heap
page read and write
20EF000
stack
page read and write
34E0000
heap
page read and write
389000
heap
page read and write
2BB000
stack
page read and write
389000
heap
page read and write
1CA0000
heap
page read and write
337000
heap
page read and write
3BA000
heap
page read and write
190000
heap
page read and write
37A000
heap
page read and write
150000
heap
page read and write
43DE000
stack
page read and write
38A000
heap
page read and write
466000
heap
page read and write
36EF000
stack
page read and write
3765000
heap
page read and write
1FAF000
stack
page read and write
430000
heap
page read and write
3C2000
heap
page read and write
154000
heap
page read and write
3C2000
heap
page read and write
There are 23 hidden memdumps, click here to show them.