IOC Report
5HnWIsZYYh.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\5HnWIsZYYh.exe
"C:\Users\user\Desktop\5HnWIsZYYh.exe"
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
482000
unkown
page readonly
2E30000
heap
page read and write
950000
heap
page read and write
2DD0000
heap
page read and write
400000
unkown
page readonly
2E50000
heap
page read and write
3C0E000
stack
page read and write
4AB000
unkown
page readonly
490000
unkown
page write copy
9A000
stack
page read and write
8B4000
stack
page read and write
401000
unkown
page execute read
491000
unkown
page write copy
492000
unkown
page read and write
482000
unkown
page readonly
2E94000
heap
page read and write
9E5000
heap
page read and write
A2E000
heap
page read and write
2E90000
heap
page read and write
110000
heap
page read and write
996000
heap
page read and write
39E0000
heap
page read and write
A32000
heap
page read and write
9FE000
heap
page read and write
39DF000
stack
page read and write
3C20000
heap
page read and write
415E000
stack
page read and write
2DCE000
stack
page read and write
9F0000
heap
page read and write
6CAF000
stack
page read and write
A43000
heap
page read and write
100000
heap
page read and write
35DE000
stack
page read and write
4AB000
unkown
page readonly
4A8000
unkown
page read and write
39F0000
heap
page read and write
9DE000
stack
page read and write
400000
unkown
page readonly
9FA000
heap
page read and write
490000
unkown
page read and write
120000
heap
page read and write
990000
heap
page read and write
411F000
stack
page read and write
8AF000
stack
page read and write
125000
heap
page read and write
9E0000
heap
page read and write
401000
unkown
page execute read
There are 37 hidden memdumps, click here to show them.