IOC Report
awg.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\awg.exe
"C:\Users\user\Desktop\awg.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
http://crt.sectigo.com/SectigoPublicCodeSigningCAR36.crt0#
unknown
https://git.zx2c4.com/wireguard-tools/
unknown
http://crl.sectigo.com/SectigoPublicTimeStampingRootR46.crl0
unknown
https://sectigo.com/CPS0
unknown
http://crt.sectigo.com/SectigoPublicTimeStampingCAR36.crt0#
unknown
http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#
unknown
http://crl.sectigo.com/SectigoPublicCodeSigningCAR36.crl0y
unknown
http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0
unknown
http://ocsp.sectigo.com0
unknown
http://crl.sectigo.com/SectigoPublicTimeStampingCAR36.crl0z
unknown
https://www.wireguard.com/D
unknown
http://crt.sectigo.com/SectigoPublicTimeStampingRootR46.p7c0#
unknown
There are 2 hidden URLs, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
2B0ADB9D000
heap
page read and write
7FF73D41C000
unkown
page readonly
7FF73D419000
unkown
page readonly
E5174FF000
stack
page read and write
7FF73D3F1000
unkown
page execute read
7FF73D40D000
unkown
page readonly
2B0ADA90000
heap
page read and write
2B0ADE80000
heap
page read and write
7FF73D41C000
unkown
page readonly
7FF73D3F0000
unkown
page readonly
E51719C000
stack
page read and write
2B0AD9B0000
heap
page read and write
7FF73D411000
unkown
page read and write
2B0ADBA0000
heap
page read and write
2B0ADAB0000
heap
page read and write
7FF73D3F0000
unkown
page readonly
7FF73D40D000
unkown
page readonly
7FF73D3F1000
unkown
page execute read
E5175FF000
stack
page read and write
2B0ADB90000
heap
page read and write
7FF73D419000
unkown
page readonly
7FF73D411000
unkown
page write copy
2B0ADB9B000
heap
page read and write
There are 13 hidden memdumps, click here to show them.