IOC Report
msimg32.dll

loading gif

Processes

Path
Cmdline
Malicious
C:\Windows\System32\loaddll32.exe
loaddll32.exe "C:\Users\user\Desktop\msimg32.dll"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\SysWOW64\cmd.exe
cmd.exe /C rundll32.exe "C:\Users\user\Desktop\msimg32.dll",#1
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe C:\Users\user\Desktop\msimg32.dll,AlphaBlend
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe "C:\Users\user\Desktop\msimg32.dll",#1
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe C:\Users\user\Desktop\msimg32.dll,AppendCaptureDeviceList
C:\Windows\SysWOW64\rundll32.exe
rundll32.exe C:\Users\user\Desktop\msimg32.dll,AppendDeviceList

URLs

Name
IP
Malicious
http://www.3dmm2.com/doom/
unknown
http://icculus.org/physfs/
unknown
http://icculus.org/physfs/4
unknown
http://icculus.org/physfs/T
unknown
http://icculus.org/physfs/t
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
6487A000
unkown
page readonly
4D40000
heap
page read and write
64979000
unkown
page readonly
648A1000
unkown
page write copy
64979000
unkown
page readonly
647E4000
unkown
page readonly
3150000
heap
page read and write
64877000
unkown
page read and write
70C000
stack
page read and write
648A1000
unkown
page write copy
860000
heap
page read and write
64878000
unkown
page write copy
647E4000
unkown
page readonly
648B7000
unkown
page readonly
64979000
unkown
page readonly
6493E000
unkown
page readonly
64877000
unkown
page read and write
6487A000
unkown
page readonly
2D3A000
heap
page read and write
647DA000
unkown
page write copy
648A0000
unkown
page read and write
8BF000
heap
page read and write
64878000
unkown
page write copy
AD0000
heap
page read and write
64871000
unkown
page write copy
64979000
unkown
page readonly
64878000
unkown
page write copy
64877000
unkown
page read and write
6493E000
unkown
page readonly
648B7000
unkown
page readonly
647E4000
unkown
page readonly
648A1000
unkown
page write copy
99E000
stack
page read and write
7D3000
heap
page read and write
7BA000
heap
page read and write
49F0000
heap
page read and write
647E4000
unkown
page readonly
648A0000
unkown
page read and write
4D0000
heap
page read and write
710000
heap
page read and write
645C1000
unkown
page execute read
9CB000
stack
page read and write
47A0000
heap
page read and write
BE3000
heap
page read and write
8A5000
heap
page read and write
64877000
unkown
page read and write
86B000
heap
page read and write
8EE000
stack
page read and write
64871000
unkown
page write copy
6493E000
unkown
page readonly
2DFC000
stack
page read and write
64871000
unkown
page write copy
303B000
stack
page read and write
6493E000
unkown
page readonly
760000
heap
page read and write
645C0000
unkown
page readonly
647E4000
unkown
page readonly
645C1000
unkown
page execute read
C40000
heap
page read and write
648B7000
unkown
page readonly
3AC000
stack
page read and write
A20000
heap
page read and write
648A0000
unkown
page read and write
BC0000
heap
page read and write
8E0000
heap
page read and write
33FF000
stack
page read and write
648A0000
unkown
page read and write
648A0000
unkown
page read and write
9B0000
heap
page read and write
647DA000
unkown
page write copy
645C0000
unkown
page readonly
3EB000
stack
page read and write
BCA000
heap
page read and write
96E000
stack
page read and write
A9F000
stack
page read and write
31D3000
heap
page read and write
33BE000
stack
page read and write
2D53000
heap
page read and write
C00000
heap
page read and write
645C1000
unkown
page execute read
2D30000
heap
page read and write
31BA000
heap
page read and write
3080000
heap
page read and write
648B7000
unkown
page readonly
7B0000
heap
page read and write
6487A000
unkown
page readonly
4E0000
heap
page read and write
730000
heap
page read and write
C30000
heap
page read and write
64871000
unkown
page write copy
64877000
unkown
page read and write
64979000
unkown
page readonly
30B0000
heap
page read and write
645C0000
unkown
page readonly
650000
heap
page read and write
6493E000
unkown
page readonly
2E20000
heap
page read and write
31B0000
heap
page read and write
98C000
stack
page read and write
648A1000
unkown
page write copy
647DA000
unkown
page write copy
7D0000
heap
page read and write
312E000
stack
page read and write
645C1000
unkown
page execute read
7C0000
heap
page read and write
85F000
stack
page read and write
64878000
unkown
page write copy
30A0000
heap
page read and write
62B000
stack
page read and write
75E000
stack
page read and write
648A1000
unkown
page write copy
64871000
unkown
page write copy
645C0000
unkown
page readonly
7B0000
heap
page read and write
92F000
stack
page read and write
2EA0000
heap
page read and write
3470000
heap
page read and write
9AF000
stack
page read and write
645C0000
unkown
page readonly
74B000
stack
page read and write
647DA000
unkown
page write copy
319F000
stack
page read and write
6487A000
unkown
page readonly
647DA000
unkown
page write copy
648B7000
unkown
page readonly
645C1000
unkown
page execute read
64878000
unkown
page write copy
46C000
stack
page read and write
6487A000
unkown
page readonly
86F000
heap
page read and write
There are 120 hidden memdumps, click here to show them.