IOC Report
SecuriteInfo.com.W64.Rozena.EL.gen.Eldorado.9177.9340.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.W64.Rozena.EL.gen.Eldorado.9177.9340.exe
"C:\Users\user\Desktop\SecuriteInfo.com.W64.Rozena.EL.gen.Eldorado.9177.9340.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

Memdumps

Base Address
Regiontype
Protect
Malicious
17B2B5AF000
heap
page read and write
17B2B57B000
heap
page read and write
17B2B58A000
heap
page read and write
17B2B584000
heap
page read and write
17B2D310000
heap
page read and write
17B2B5A1000
heap
page read and write
7FF63AFE4000
unkown
page readonly
17B2B520000
heap
page read and write
7FF63AFE1000
unkown
page execute read
17B2B590000
heap
page read and write
7FF63AFE4000
unkown
page readonly
17B2B58A000
heap
page read and write
17B2B566000
heap
page read and write
17B2B58C000
heap
page read and write
7FF63AFE2000
unkown
page readonly
17B2E820000
heap
page read and write
17B2EB70000
trusted library allocation
page read and write
6C927FE000
stack
page read and write
17B2B57F000
heap
page read and write
7FF63AFE2000
unkown
page readonly
7FF63AFE1000
unkown
page execute read
17B2D455000
heap
page read and write
17B2B56C000
heap
page read and write
17B2D450000
heap
page read and write
17B2B596000
heap
page read and write
7FF63AFE0000
unkown
page readonly
6C926FB000
stack
page read and write
17B2CE00000
heap
page read and write
17B2B440000
heap
page read and write
6C928FE000
stack
page read and write
17B2B5A9000
heap
page read and write
17B2E823000
heap
page read and write
17B2E6C0000
heap
page read and write
7FF63AFE0000
unkown
page readonly
17B2B57B000
heap
page read and write
17B2B560000
heap
page read and write
17B2B584000
heap
page read and write
17B2B5A8000
heap
page read and write
17B2D45A000
heap
page read and write
There are 29 hidden memdumps, click here to show them.