IOC Report
setup.exe

loading gif

Files

File Path
Type
Category
Malicious
setup.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
C:\Windows\ST6UNST.000
ASCII text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\setup.exe
"C:\Users\user\Desktop\setup.exe"

Memdumps

Base Address
Regiontype
Protect
Malicious
401000
unkown
page execute read
41E000
unkown
page read and write
780000
heap
page read and write
7CE000
stack
page read and write
5D1000
heap
page read and write
59E000
heap
page read and write
21D0000
heap
page read and write
1D0000
heap
page read and write
98000
stack
page read and write
2130000
heap
page read and write
5F2000
heap
page read and write
5CC000
heap
page read and write
5CC000
heap
page read and write
19A000
stack
page read and write
41A000
unkown
page readonly
805000
heap
page read and write
80A000
heap
page read and write
601000
heap
page read and write
5C9000
heap
page read and write
5D7000
heap
page read and write
20AF000
stack
page read and write
41E000
unkown
page write copy
428000
unkown
page readonly
428000
unkown
page readonly
784000
heap
page read and write
5D9000
heap
page read and write
41A000
unkown
page readonly
5DA000
heap
page read and write
41C000
unkown
page write copy
2AF0000
trusted library allocation
page read and write
5DD000
heap
page read and write
5DC000
heap
page read and write
58B000
heap
page read and write
21E0000
direct allocation
page read and write
510000
heap
page read and write
77F000
stack
page read and write
401000
unkown
page execute read
5DD000
heap
page read and write
400000
unkown
page readonly
423000
unkown
page read and write
5D9000
heap
page read and write
7F0000
heap
page read and write
800000
heap
page read and write
5DC000
heap
page read and write
56E000
stack
page read and write
580000
heap
page read and write
5E0000
heap
page read and write
2170000
heap
page read and write
400000
unkown
page readonly
5DD000
heap
page read and write
2150000
heap
page read and write
5DC000
heap
page read and write
430000
heap
page read and write
41C000
unkown
page read and write
1D5000
heap
page read and write
5FA000
heap
page read and write
There are 46 hidden memdumps, click here to show them.