IOC Report
ZKNiiqoHKV.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\ZKNiiqoHKV.exe
"C:\Users\user\Desktop\ZKNiiqoHKV.exe"
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
141DC3000
unkown
page readonly
141D96000
unkown
page readonly
140001000
unkown
page execute read
1A0000
heap
page read and write
141DC3000
unkown
page readonly
141DB0000
unkown
page readonly
140000000
unkown
page readonly
140539000
unkown
page write copy
420000
heap
page read and write
141DB0000
unkown
page readonly
141DAB000
unkown
page readonly
14231B000
unkown
page execute read
141DD4000
unkown
page readonly
141E04000
unkown
page readonly
141DA9000
unkown
page read and write
14C000
stack
page read and write
141D0B000
unkown
page readonly
140000000
unkown
page readonly
141DAB000
unkown
page readonly
14043C000
unkown
page readonly
141DD4000
unkown
page readonly
7EE000
stack
page read and write
141D96000
unkown
page readonly
141E04000
unkown
page readonly
141DB7000
unkown
page readonly
141DA9000
unkown
page write copy
140539000
unkown
page write copy
140001000
unkown
page execute read
14231B000
unkown
page execute read
141D0B000
unkown
page readonly
14043C000
unkown
page readonly
141D39000
unkown
page readonly
429000
heap
page read and write
141DB7000
unkown
page readonly
141D39000
unkown
page readonly
190000
heap
page read and write
42C000
heap
page read and write
There are 27 hidden memdumps, click here to show them.