IOC Report
SecuriteInfo.com.Win32.Trojan-gen.8494.11198.exe

loading gif

Files

File Path
Type
Category
Malicious
SecuriteInfo.com.Win32.Trojan-gen.8494.11198.exe
PE32 executable (console) Intel 80386, for MS Windows
initial sample
malicious
\Device\ConDrv
ASCII text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-gen.8494.11198.exe
"C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-gen.8494.11198.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\cmd.exe /c pause

Memdumps

Base Address
Regiontype
Protect
Malicious
D0D000
stack
page read and write
687000
unkown
page readonly
10FD000
stack
page read and write
139A000
heap
page read and write
D70000
heap
page read and write
687000
unkown
page readonly
674000
unkown
page readonly
674000
unkown
page readonly
650000
unkown
page readonly
1390000
heap
page read and write
1230000
heap
page read and write
D80000
heap
page read and write
685000
unkown
page readonly
651000
unkown
page execute read
683000
unkown
page write copy
651000
unkown
page execute read
139E000
heap
page read and write
683000
unkown
page read and write
650000
unkown
page readonly
685000
unkown
page readonly
There are 10 hidden memdumps, click here to show them.