IOC Report
SecuriteInfo.com.HackTool.Win32.Crack.28815.11045.exe

loading gif

Files

File Path
Type
Category
Malicious
SecuriteInfo.com.HackTool.Win32.Crack.28815.11045.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
\Device\ConDrv
ASCII text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\SecuriteInfo.com.HackTool.Win32.Crack.28815.11045.exe
"C:\Users\user\Desktop\SecuriteInfo.com.HackTool.Win32.Crack.28815.11045.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
https://www.newtonsoft.com/json
unknown
https://www.nuget.org/packages/Newtonsoft.Json.Bson
unknown
http://james.newtonking.com/projects/json
unknown
https://www.newtonsoft.com/jsonschema
unknown
https://github.com/JamesNK/Newtonsoft.Json
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
2611000
trusted library allocation
page read and write
malicious
92000
unkown
page readonly
malicious
800000
trusted library allocation
page read and write
E6000
unkown
page readonly
8D1000
heap
page read and write
25B7000
trusted library allocation
page read and write
A80000
heap
page read and write
860000
trusted library allocation
page execute and read and write
510000
heap
page read and write
A70000
trusted library allocation
page read and write
870000
trusted library allocation
page read and write
827000
trusted library allocation
page execute and read and write
49FE000
stack
page read and write
1AC000
stack
page read and write
81A000
trusted library allocation
page execute and read and write
690000
heap
page read and write
89A000
heap
page read and write
8E3000
heap
page read and write
7F0000
trusted library allocation
page read and write
6E6000
heap
page read and write
25C0000
trusted library allocation
page read and write
259E000
stack
page read and write
2430000
trusted library section
page read and write
4A3E000
stack
page read and write
249E000
stack
page read and write
363D000
trusted library allocation
page read and write
25B5000
trusted library allocation
page read and write
2600000
heap
page execute and read and write
890000
heap
page read and write
7FD000
trusted library allocation
page execute and read and write
242E000
stack
page read and write
850000
heap
page read and write
25BA000
trusted library allocation
page read and write
4DEF000
stack
page read and write
25C7000
trusted library allocation
page read and write
7F3000
trusted library allocation
page execute and read and write
4F5000
stack
page read and write
7F4000
trusted library allocation
page read and write
6E0000
heap
page read and write
8C4000
heap
page read and write
4A40000
heap
page execute and read and write
8BB000
heap
page read and write
4B3E000
stack
page read and write
9CE000
stack
page read and write
90000
unkown
page readonly
FC000
unkown
page readonly
2450000
heap
page read and write
6D0000
trusted library allocation
page read and write
38AB000
trusted library allocation
page read and write
82B000
trusted library allocation
page execute and read and write
89E000
heap
page read and write
25B3000
trusted library allocation
page read and write
25B0000
trusted library allocation
page read and write
816000
trusted library allocation
page execute and read and write
A79000
trusted library allocation
page read and write
4EEE000
stack
page read and write
3611000
trusted library allocation
page read and write
5F0000
heap
page read and write
4C4E000
stack
page read and write
25D0000
trusted library allocation
page read and write
4A50000
trusted library section
page read and write
There are 51 hidden memdumps, click here to show them.