IOC Report
winmerge-master.zip

loading gif

Processes

Path
Cmdline
Malicious
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding

Memdumps

Base Address
Regiontype
Protect
Malicious
2B4019B5000
heap
page read and write
2B401748000
heap
page read and write
2B403320000
heap
page read and write
E06A27E000
stack
page read and write
E069F5F000
stack
page read and write
2B4016B0000
heap
page read and write
E069FDF000
stack
page read and write
2B401690000
heap
page read and write
2B401740000
heap
page read and write
2B401680000
heap
page read and write
E069EDC000
stack
page read and write
2B4019B0000
heap
page read and write
There are 2 hidden memdumps, click here to show them.