IOC Report
winmerge-master.zip

loading gif

Processes

Path
Cmdline
Malicious
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding

Memdumps

Base Address
Regiontype
Protect
Malicious
2BA6E0D0000
heap
page read and write
2BA6E0F0000
heap
page read and write
D0D57EE000
stack
page read and write
D0D5A7F000
stack
page read and write
2BA6E169000
heap
page read and write
2BA6E3C5000
heap
page read and write
D0D576F000
stack
page read and write
2BA6E160000
heap
page read and write
2BA6E0C0000
heap
page read and write
2BA6FD00000
heap
page read and write
2BA6E3C0000
heap
page read and write
D0D56EC000
stack
page read and write
There are 2 hidden memdumps, click here to show them.