IOC Report
SecuriteInfo.com.Trojan.GenericKD.73712167.7295.25660.exe

loading gif

Files

File Path
Type
Category
Malicious
SecuriteInfo.com.Trojan.GenericKD.73712167.7295.25660.exe
PE32+ executable (console) x86-64, for MS Windows
initial sample
malicious
\Device\ConDrv
ASCII text, with no line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.73712167.7295.25660.exe
"C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.73712167.7295.25660.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

Memdumps

Base Address
Regiontype
Protect
Malicious
7FF6CEBF8000
unkown
page readonly
25566670000
heap
page read and write
9C7AAFC000
stack
page read and write
7FF6CEBF8000
unkown
page readonly
7FF6CEBF0000
unkown
page readonly
7FF6CEBF7000
unkown
page write copy
7FF6CEBF4000
unkown
page readonly
7FF6CEBF7000
unkown
page read and write
7FF6CEBF0000
unkown
page readonly
7FF6CEBF1000
unkown
page execute read
25566750000
heap
page read and write
255667BC000
heap
page read and write
7FF6CEBF4000
unkown
page readonly
7FF6CEBF1000
unkown
page execute read
255667B0000
heap
page read and write
There are 5 hidden memdumps, click here to show them.