IOC Report
cache.vbs

loading gif

Processes

Path
Cmdline
Malicious
C:\Windows\System32\wscript.exe
C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\cache.vbs"
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
17088842000
heap
page read and write
1708885B000
heap
page read and write
1708884E000
heap
page read and write
17088857000
heap
page read and write
170869D2000
heap
page read and write
17086A1A000
heap
page read and write
1708884E000
heap
page read and write
17086920000
heap
page read and write
17086A1F000
heap
page read and write
1708699B000
heap
page read and write
170869FF000
heap
page read and write
7FFB1E0E1000
unkown
page execute read
17088858000
heap
page read and write
17088857000
heap
page read and write
7FFB1E0E0000
unkown
page readonly
17086A1F000
heap
page read and write
17086A0B000
heap
page read and write
170869E8000
heap
page read and write
17086A03000
heap
page read and write
17088841000
heap
page read and write
1708699C000
heap
page read and write
17086998000
heap
page read and write
170869DB000
heap
page read and write
170869F0000
heap
page read and write
1708885B000
heap
page read and write
170869DA000
heap
page read and write
1708699E000
heap
page read and write
17088840000
heap
page read and write
31EAFEA000
stack
page read and write
7FFB1E100000
unkown
page read and write
170869ED000
heap
page read and write
17086A17000
heap
page read and write
170869F3000
heap
page read and write
170869CD000
heap
page read and write
31EB6FF000
stack
page read and write
17088857000
heap
page read and write
1708699B000
heap
page read and write
17086900000
heap
page read and write
170869B0000
heap
page read and write
1708884E000
heap
page read and write
1708699E000
heap
page read and write
1708884E000
heap
page read and write
170869EC000
heap
page read and write
17086A1E000
heap
page read and write
17086A1F000
heap
page read and write
17086A15000
heap
page read and write
7FFB1E102000
unkown
page readonly
1708699E000
heap
page read and write
1708884C000
heap
page read and write
17088846000
heap
page read and write
17086A1F000
heap
page read and write
17086A0B000
heap
page read and write
17086A0F000
heap
page read and write
17086999000
heap
page read and write
1708699A000
heap
page read and write
17088843000
heap
page read and write
1708884A000
heap
page read and write
170884F0000
heap
page read and write
31EB3FE000
stack
page read and write
1708884E000
heap
page read and write
31EB2FE000
stack
page read and write
170868F0000
heap
page read and write
170869E7000
heap
page read and write
17086998000
heap
page read and write
17086A0B000
heap
page read and write
7FFB1E0F6000
unkown
page readonly
31EB5FF000
stack
page read and write
17086A0B000
heap
page read and write
17086990000
heap
page read and write
17088857000
heap
page read and write
17088857000
heap
page read and write
7FFB1E105000
unkown
page readonly
17086995000
heap
page read and write
17088841000
heap
page read and write
170869D2000
heap
page read and write
There are 65 hidden memdumps, click here to show them.